<ipsrules>
  <group>
    <attacks>
    </attacks>
    <groupid>100</groupid>
    <groupname>OS</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>22092</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;19B7F2D6-1610-11D3-BF30-1AF820524153&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*19B7F2D6-1610-11D3-BF30-1AF820524153\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10013</id>
        <msg>WEB-ACTIVEX CCRP FolderTreeView ActiveX clsid access</msg>
        <url>ccrp.mvps.org/index.html?controls/ccrpftv6.htm</url>
      </rule>
      <rule>
        <bugtraq>22092</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|9|00|B|00|7|00|F|00|2|00|D|00|6|00|-|00|1|00|6|00|1|00|0|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|F|00|3|00|0|00|-|00|1|00|A|00|F|00|8|00|2|00|0|00|5|00|2|00|4|00|1|00|5|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x009\x00B\x007\x00F\x002\x00D\x006\x00-\x001\x006\x001\x000\x00-\x001\x001\x00D\x003\x00-\x00B\x00F\x003\x000\x00-\x001\x00A\x00F\x008\x002\x000\x005\x002\x004\x001\x005\x003\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10014</id>
        <msg>WEB-ACTIVEX CCRP FolderTreeView ActiveX clsid unicode access</msg>
        <url>ccrp.mvps.org/index.html?controls/ccrpftv6.htm</url>
      </rule>
      <rule>
        <bugtraq>22026</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EC4CF635-D196-11CE-9027-02608C4BF3B5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*EC4CF635-D196-11CE-9027-02608C4BF3B5\s*}?\4.*\3\.(UpdateRecord)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EC4CF635-D196-11CE-9027-02608C4BF3B5\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(UpdateRecord)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10015</id>
        <msg>WEB-ACTIVEX Oracle ORADC ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22026</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|C|00|4|00|C|00|F|00|6|00|3|00|5|00|-|00|D|00|1|00|9|00|6|00|-|00|1|00|1|00|C|00|E|00|-|00|9|00|0|00|2|00|7|00|-|00|0|00|2|00|6|00|0|00|8|00|C|00|4|00|B|00|F|00|3|00|B|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x00C\x004\x00C\x00F\x006\x003\x005\x00-\x00D\x001\x009\x006\x00-\x001\x001\x00C\x00E\x00-\x009\x000\x002\x007\x00-\x000\x002\x006\x000\x008\x00C\x004\x00B\x00F\x003\x00B\x005\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10016</id>
        <msg>WEB-ACTIVEX Oracle ORADC ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>22026</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ORADC.ORADCCtrl&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22ORADC.ORADCCtrl\x22|\x27ORADC.ORADCCtrl\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(UpdateRecord)\s*\(|.*\3\s*\.\s*(UpdateRecord)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ORADC.ORADCCtrl\x22|\x27ORADC.ORADCCtrl\x27)\s*\)(\s*\.\s*(UpdateRecord)\s*\(|.*\7\s*\.\s*(UpdateRecord)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10017</id>
        <msg>WEB-ACTIVEX Oracle ORADC ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-6917</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62B93DF0-8B02-11CE-876C-00805F842837; dce_opnum:38; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>10018</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ReserveGroup attempt</msg>
        <url>www.lssec.com/advisories/LS-20061001.pdf</url>
      </rule>
      <rule>
        <bugtraq>22005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [6503,6504]</filter1>
        <filter2>flow:established,to_server; dce_iface:506B1890-14C8-11D1-BBC3-00805FA6962E; dce_opnum:117; dce_stub_data; byte_test:4,&gt;,119,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>10050</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 ASDBLoginToComputer overflow attempt</msg>
        <url>www.kb.cert.org/vuls/id/180336</url>
      </rule>
      <rule>
        <bugtraq>33469</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;77829F14-D911-40FF-A2F0-D11DB8D6D0BC&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*77829F14-D911-40FF-A2F0-D11DB8D6D0BC\s*}?\s*(?P=q27)(\s|&gt;).*(?P=id1)\s*\.\s*(SetFormatLikeSample|CreateFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q28&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*77829F14-D911-40FF-A2F0-D11DB8D6D0BC\s*}?\s*(?P=q28)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\.(SetFormatLikeSample|CreateFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10084</id>
        <msg>WEB-ACTIVEX NCTAudioFile2 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/292713</url>
      </rule>
      <rule>
        <bugtraq>33469</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|7|00|8|00|2|00|9|00|F|00|1|00|4|00|-|00|D|00|9|00|1|00|1|00|-|00|4|00|0|00|F|00|F|00|-|00|A|00|2|00|F|00|0|00|-|00|D|00|1|00|1|00|D|00|B|00|8|00|D|00|6|00|D|00|0|00|B|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q29&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x007\x008\x002\x009\x00F\x001\x004\x00-\x00D\x009\x001\x001\x00-\x004\x000\x00F\x00F\x00-\x00A\x002\x00F\x000\x00-\x00D\x001\x001\x00D\x00B\x008\x00D\x006\x00D\x000\x00B\x00C\x00(}\x00)?(?P=q29)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10085</id>
        <msg>WEB-ACTIVEX NCTAudioFile2 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/292713</url>
      </rule>
      <rule>
        <bugtraq>33469</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCTAudioFile2.AudioFile&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCTAudioFile2\.AudioFile(\.\d)?\x22|\x27NCTAudioFile2\.AudioFile(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SetFormatLikeSample|CreateFile)\s*|.*(?P=v)\s*\.\s*(SetFormatLikeSample|CreateFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCTAudioFile2\.AudioFile(\.\d)?\x22|\x27NCTAudioFile2\.AudioFile(\.\d)?\x27)\s*\)(\s*\.\s*(SetFormatLikeSample|CreateFile)\s*|.*(?P=n)\s*\.\s*(SetFormatLikeSample|CreateFile)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10086</id>
        <msg>WEB-ACTIVEX NCTAudioFile2 ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/292713</url>
      </rule>
      <rule>
        <bugtraq>21992</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2006-4071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,wmf.download; content:&quot;|FC 02|&quot;; pcre:&quot;/\xFC\x02[\x08\x06]\x00.{4}(?!\x00\x00)/s&quot;; metadata:policy security-ips drop; classtype:web-application-attack;</filter2>
        <id>10115</id>
        <msg>WEB-CLIENT Microsoft WMF denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>22446</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;66F50F46-70A0-4A05-BD5E-FBCC0F9641EC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*66F50F46-70A0-4A05-BD5E-FBCC0F9641EC\s*}?\4.*\3\.(remove)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*66F50F46-70A0-4A05-BD5E-FBCC0F9641EC\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(remove)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10128</id>
        <msg>WEB-ACTIVEX Aliplay ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22446</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|6|00|F|00|5|00|0|00|F|00|4|00|6|00|-|00|7|00|0|00|A|00|0|00|-|00|4|00|A|00|0|00|5|00|-|00|B|00|D|00|5|00|E|00|-|00|F|00|B|00|C|00|C|00|0|00|F|00|9|00|6|00|4|00|1|00|E|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x006\x00F\x005\x000\x00F\x004\x006\x00-\x007\x000\x00A\x000\x00-\x004\x00A\x000\x005\x00-\x00B\x00D\x005\x00E\x00-\x00F\x00B\x00C\x00C\x000\x00F\x009\x006\x004\x001\x00E\x00C\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10129</id>
        <msg>WEB-ACTIVEX Aliplay ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4697</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6E3197A3-BBC3-11D4-84C0-00C04F7A06E5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E3197A3-BBC3-11D4-84C0-00C04F7A06E5\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10137</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4697</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|3|00|1|00|9|00|7|00|A|00|3|00|-|00|B|00|B|00|C|00|3|00|-|00|1|00|1|00|D|00|4|00|-|00|8|00|4|00|C|00|0|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|A|00|0|00|6|00|E|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00E\x003\x001\x009\x007\x00A\x003\x00-\x00B\x00B\x00C\x003\x00-\x001\x001\x00D\x004\x00-\x008\x004\x00C\x000\x00-\x000\x000\x00C\x000\x004\x00F\x007\x00A\x000\x006\x00E\x005\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10138</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4697</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IMESingleKanjiDict.8.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22IMESingleKanjiDict.8.1\x22|\x27IMESingleKanjiDict.8.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IMESingleKanjiDict.8.1\x22|\x27IMESingleKanjiDict.8.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10139</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4697</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DA56F851-D3C5-11D3-844C-00C04F7A06E5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DA56F851-D3C5-11D3-844C-00C04F7A06E5\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10140</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4697</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|A|00|5|00|6|00|F|00|8|00|5|00|1|00|-|00|D|00|3|00|C|00|5|00|-|00|1|00|1|00|D|00|3|00|-|00|8|00|4|00|4|00|C|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|A|00|0|00|6|00|E|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00A\x005\x006\x00F\x008\x005\x001\x00-\x00D\x003\x00C\x005\x00-\x001\x001\x00D\x003\x00-\x008\x004\x004\x00C\x00-\x000\x000\x00C\x000\x004\x00F\x007\x00A\x000\x006\x00E\x005\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10141</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;75C11604-5C51-48B2-B786-DF5E51D10EC9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*75C11604-5C51-48B2-B786-DF5E51D10EC9\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10142</id>
        <msg>WEB-ACTIVEX LexRefBilingualTextContext ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|5|00|C|00|1|00|1|00|6|00|0|00|4|00|-|00|5|00|C|00|5|00|1|00|-|00|4|00|8|00|B|00|2|00|-|00|B|00|7|00|8|00|6|00|-|00|D|00|F|00|5|00|E|00|5|00|1|00|D|00|1|00|0|00|E|00|C|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x005\x00C\x001\x001\x006\x000\x004\x00-\x005\x00C\x005\x001\x00-\x004\x008\x00B\x002\x00-\x00B\x007\x008\x006\x00-\x00D\x00F\x005\x00E\x005\x001\x00D\x001\x000\x00E\x00C\x009\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10143</id>
        <msg>WEB-ACTIVEX LexRefBilingualTextContext ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LR.LexRefBilingualTextContext.1.0.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22LR.LexRefBilingualTextContext.1.0.1\x22|\x27LR.LexRefBilingualTextContext.1.0.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LR.LexRefBilingualTextContext.1.0.1\x22|\x27LR.LexRefBilingualTextContext.1.0.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10144</id>
        <msg>WEB-ACTIVEX LexRefBilingualTextContext ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8422DAE3-9929-11CF-B8D3-004033373DA8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8422DAE3-9929-11CF-B8D3-004033373DA8\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10145</id>
        <msg>WEB-ACTIVEX HTML Inline Sound Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|4|00|2|00|2|00|D|00|A|00|E|00|3|00|-|00|9|00|9|00|2|00|9|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|8|00|D|00|3|00|-|00|0|00|0|00|4|00|0|00|3|00|3|00|3|00|7|00|3|00|D|00|A|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x004\x002\x002\x00D\x00A\x00E\x003\x00-\x009\x009\x002\x009\x00-\x001\x001\x00C\x00F\x00-\x00B\x008\x00D\x003\x00-\x000\x000\x004\x000\x003\x003\x003\x007\x003\x00D\x00A\x008\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10146</id>
        <msg>WEB-ACTIVEX HTML Inline Sound Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HTMLInlineSoundCtl.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22HTMLInlineSoundCtl.1\x22|\x27HTMLInlineSoundCtl.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HTMLInlineSoundCtl.1\x22|\x27HTMLInlineSoundCtl.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10147</id>
        <msg>WEB-ACTIVEX HTML Inline Sound Control ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8422DAE7-9929-11CF-B8D3-004033373DA8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8422DAE7-9929-11CF-B8D3-004033373DA8\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10148</id>
        <msg>WEB-ACTIVEX HTML Inline Movie Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|4|00|2|00|2|00|D|00|A|00|E|00|7|00|-|00|9|00|9|00|2|00|9|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|8|00|D|00|3|00|-|00|0|00|0|00|4|00|0|00|3|00|3|00|3|00|7|00|3|00|D|00|A|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x004\x002\x002\x00D\x00A\x00E\x007\x00-\x009\x009\x002\x009\x00-\x001\x001\x00C\x00F\x00-\x00B\x008\x00D\x003\x00-\x000\x000\x004\x000\x003\x003\x003\x007\x003\x00D\x00A\x008\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10149</id>
        <msg>WEB-ACTIVEX HTML Inline Movie Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HTMLInlineVideoCtl.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22HTMLInlineVideoCtl.1\x22|\x27HTMLInlineVideoCtl.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HTMLInlineVideoCtl.1\x22|\x27HTMLInlineVideoCtl.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10150</id>
        <msg>WEB-ACTIVEX HTML Inline Movie Control ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;261F6572-578B-40A7-B72E-61B7261D9F0C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*261F6572-578B-40A7-B72E-61B7261D9F0C\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10151</id>
        <msg>WEB-ACTIVEX BlnSetUser Proxy ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|6|00|1|00|F|00|6|00|5|00|7|00|2|00|-|00|5|00|7|00|8|00|B|00|-|00|4|00|0|00|A|00|7|00|-|00|B|00|7|00|2|00|E|00|-|00|6|00|1|00|B|00|7|00|2|00|6|00|1|00|D|00|9|00|F|00|0|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x006\x001\x00F\x006\x005\x007\x002\x00-\x005\x007\x008\x00B\x00-\x004\x000\x00A\x007\x00-\x00B\x007\x002\x00E\x00-\x006\x001\x00B\x007\x002\x006\x001\x00D\x009\x00F\x000\x00C\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10152</id>
        <msg>WEB-ACTIVEX BlnSetUser Proxy ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BlnMgrPs.BlnSetUserPs.11&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22BlnMgrPs.BlnSetUserPs.11\x22|\x27BlnMgrPs.BlnSetUserPs.11\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BlnMgrPs.BlnSetUserPs.11\x22|\x27BlnMgrPs.BlnSetUserPs.11\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10153</id>
        <msg>WEB-ACTIVEX BlnSetUser Proxy ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E56CCB42-598C-462D-9AD8-4FD5B4498C5D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E56CCB42-598C-462D-9AD8-4FD5B4498C5D\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10154</id>
        <msg>WEB-ACTIVEX BlnSetUser Proxy 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|5|00|6|00|C|00|C|00|B|00|4|00|2|00|-|00|5|00|9|00|8|00|C|00|-|00|4|00|6|00|2|00|D|00|-|00|9|00|A|00|D|00|8|00|-|00|4|00|F|00|D|00|5|00|B|00|4|00|4|00|9|00|8|00|C|00|5|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x005\x006\x00C\x00C\x00B\x004\x002\x00-\x005\x009\x008\x00C\x00-\x004\x006\x002\x00D\x00-\x009\x00A\x00D\x008\x00-\x004\x00F\x00D\x005\x00B\x004\x004\x009\x008\x00C\x005\x00D\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10155</id>
        <msg>WEB-ACTIVEX BlnSetUser Proxy 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-016.mspx</url>
      </rule>
      <rule>
        <bugtraq>22558</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;894A633E-F261-28BD-96F3-380EBEE1BADE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*894A633E-F261-28BD-96F3-380EBEE1BADE\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10156</id>
        <msg>WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-bonus-actsoft-dvd-tools.html</url>
      </rule>
      <rule>
        <bugtraq>22558</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|9|00|4|00|A|00|6|00|3|00|3|00|E|00|-|00|F|00|2|00|6|00|1|00|-|00|2|00|8|00|B|00|D|00|-|00|9|00|6|00|F|00|3|00|-|00|3|00|8|00|0|00|E|00|B|00|E|00|E|00|1|00|B|00|A|00|D|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10157</id>
        <msg>WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-bonus-actsoft-dvd-tools.html</url>
      </rule>
      <rule>
        <bugtraq>22110</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;19E6E148-BAEC-11D2-B03A-EAFC20524153&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*19E6E148-BAEC-11D2-B03A-EAFC20524153\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10162</id>
        <msg>WEB-ACTIVEX BrowseDialog ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22110</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|9|00|E|00|6|00|E|00|1|00|4|00|8|00|-|00|B|00|A|00|E|00|C|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|0|00|3|00|A|00|-|00|E|00|A|00|F|00|C|00|2|00|0|00|5|00|2|00|4|00|1|00|5|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x009\x00E\x006\x00E\x001\x004\x008\x00-\x00B\x00A\x00E\x00C\x00-\x001\x001\x00D\x002\x00-\x00B\x000\x003\x00A\x00-\x00E\x00A\x00F\x00C\x002\x000\x005\x002\x004\x001\x005\x003\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10163</id>
        <msg>WEB-ACTIVEX BrowseDialog ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>22676</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;08F04139-8DFC-11D2-80E9-006008B066EE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*08F04139-8DFC-11D2-80E9-006008B066EE\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10170</id>
        <msg>WEB-ACTIVEX Verisign ConfigCHK ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22676</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|8|00|F|00|0|00|4|00|1|00|3|00|9|00|-|00|8|00|D|00|F|00|C|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|0|00|E|00|9|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|B|00|0|00|6|00|6|00|E|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x008\x00F\x000\x004\x001\x003\x009\x00-\x008\x00D\x00F\x00C\x00-\x001\x001\x00D\x002\x00-\x008\x000\x00E\x009\x00-\x000\x000\x006\x000\x000\x008\x00B\x000\x006\x006\x00E\x00E\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10171</id>
        <msg>WEB-ACTIVEX Verisign ConfigCHK ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;60664CAF-AF0D-0004-A300-5C7D25FF22A0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*60664CAF-AF0D-0004-A300-5C7D25FF22A0\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10176</id>
        <msg>WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|0|00|6|00|6|00|4|00|C|00|A|00|F|00|-|00|A|00|F|00|0|00|D|00|-|00|0|00|0|00|0|00|4|00|-|00|A|00|3|00|0|00|0|00|-|00|5|00|C|00|7|00|D|00|2|00|5|00|F|00|F|00|2|00|2|00|A|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x000\x006\x006\x004\x00C\x00A\x00F\x00-\x00A\x00F\x000\x00D\x00-\x000\x000\x000\x004\x00-\x00A\x003\x000\x000\x00-\x005\x00C\x007\x00D\x002\x005\x00F\x00F\x002\x002\x00A\x000\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10177</id>
        <msg>WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Shell.Users.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22Shell\.Users\.1\x22|\x27Shell\.Users\.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Shell\.Users\.1\x22|\x27Shell\.Users\.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10178</id>
        <msg>WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;67DABFBF-D0AB-41fa-9C46-CC0F21721616&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*67DABFBF-D0AB-41fa-9C46-CC0F21721616\s*}?\4.*\3\.(Resize)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67DABFBF-D0AB-41fa-9C46-CC0F21721616\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(Resize)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10189</id>
        <msg>WEB-ACTIVEX DivXBrowserPlugin ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|D|00|A|00|B|00|F|00|B|00|F|00|-|00|D|00|0|00|A|00|B|00|-|00|4|00|1|00|f|00|a|00|-|00|9|00|C|00|4|00|6|00|-|00|C|00|C|00|0|00|F|00|2|00|1|00|7|00|2|00|1|00|6|00|1|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x007\x00D\x00A\x00B\x00F\x00B\x00F\x00-\x00D\x000\x00A\x00B\x00-\x004\x001\x00f\x00a\x00-\x009\x00C\x004\x006\x00-\x00C\x00C\x000\x00F\x002\x001\x007\x002\x001\x006\x001\x006\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10190</id>
        <msg>WEB-ACTIVEX DivXBrowserPlugin ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;npdivx.DivXBrowserPlugin&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22npdivx\.DivXBrowserPlugin\x22|\x27npdivx\.DivXBrowserPlugin\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(Resize)\s*\(|.*\3\s*\.\s*(Resize)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22npdivx\.DivXBrowserPlugin\x22|\x27npdivx\.DivXBrowserPlugin\x27)\s*\)(\s*\.\s*(Resize)\s*\(|.*\7\s*\.\s*(Resize)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10191</id>
        <msg>WEB-ACTIVEX DivXBrowserPlugin ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>22842</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6885</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;233C1507-6A77-46A4-9443-F871F945D258&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*233C1507-6A77-46A4-9443-F871F945D258\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*233C1507-6A77-46A4-9443-F871F945D258\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10214</id>
        <msg>WEB-ACTIVEX Shockwave ActiveX Control ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22842</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6885</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|3|00|3|00|C|00|1|00|5|00|0|00|7|00|-|00|6|00|A|00|7|00|7|00|-|00|4|00|6|00|A|00|4|00|-|00|9|00|4|00|4|00|3|00|-|00|F|00|8|00|7|00|1|00|F|00|9|00|4|00|5|00|D|00|2|00|5|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x003\x003\x00C\x001\x005\x000\x007\x00-\x006\x00A\x007\x007\x00-\x004\x006\x00A\x004\x00-\x009\x004\x004\x003\x00-\x00F\x008\x007\x001\x00F\x009\x004\x005\x00D\x002\x005\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10215</id>
        <msg>WEB-ACTIVEX Shockwave ActiveX Control ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>22842</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6885</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SWCtl.SWCtl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SWCtl\.SWCtl(\.\d)?\x22|\x27SWCtl\.SWCtl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress)\s*|.*(?P=v)\s*\.\s*(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SWCtl\.SWCtl(\.\d)?\x22|\x27SWCtl\.SWCtl(\.\d)?\x27)\s*\)(\s*\.\s*(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress)\s*|.*(?P=n)\s*\.\s*(BGCOLOR|SRC|AutoStart|Sound|DrawLogo|DrawPress)\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10216</id>
        <msg>WEB-ACTIVEX Shockwave ActiveX Control ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>22952</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4124FDF6-B540-44C5-96B4-A380CEE9826A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*4124FDF6-B540-44C5-96B4-A380CEE9826A\s*}?\4.*\3\.(ExportSiteList|VerifyPackageCatalog)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4124FDF6-B540-44C5-96B4-A380CEE9826A\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(ExportSiteList|VerifyPackageCatalog)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10387</id>
        <msg>WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX clsid access</msg>
        <url>knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&amp;docType=kc&amp;sliceId=SAL_Public&amp;externalId=612496</url>
      </rule>
      <rule>
        <bugtraq>22952</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|2|00|4|00|F|00|D|00|F|00|6|00|-|00|B|00|5|00|4|00|0|00|-|00|4|00|4|00|C|00|5|00|-|00|9|00|6|00|B|00|4|00|-|00|A|00|3|00|8|00|0|00|C|00|E|00|E|00|9|00|8|00|2|00|6|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x001\x002\x004\x00F\x00D\x00F\x006\x00-\x00B\x005\x004\x000\x00-\x004\x004\x00C\x005\x00-\x009\x006\x00B\x004\x00-\x00A\x003\x008\x000\x00C\x00E\x00E\x009\x008\x002\x006\x00A\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10388</id>
        <msg>WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX clsid unicode access</msg>
        <url>knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&amp;docType=kc&amp;sliceId=SAL_Public&amp;externalId=612496</url>
      </rule>
      <rule>
        <bugtraq>22952</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SiteManager.SiteMgr.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22SiteManager\.SiteMgr\.1\x22|\x27SiteManager\.SiteMgr\.1\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(ExportSiteList|VerifyPackageCatalog)\s*\(|.*\3\s*\.\s*(ExportSiteList|VerifyPackageCatalog)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SiteManager\.SiteMgr\.1\x22|\x27SiteManager\.SiteMgr\.1\x27)\s*\)(\s*\.\s*(ExportSiteList|VerifyPackageCatalog)\s*\(|.*\7\s*\.\s*(ExportSiteList|VerifyPackageCatalog)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10389</id>
        <msg>WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX function call access</msg>
        <url>knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&amp;docType=kc&amp;sliceId=SAL_Public&amp;externalId=612496</url>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;44990200-3c9d-426d-81df-aab636fa4345&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*44990200-3c9d-426d-81df-aab636fa4345\s*}?\4.*\3\.(EnableExtension)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*44990200-3c9d-426d-81df-aab636fa4345\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(EnableExtension)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10390</id>
        <msg>WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX clsid access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|9|00|9|00|0|00|2|00|0|00|0|00|-|00|3|00|c|00|9|00|d|00|-|00|4|00|2|00|6|00|d|00|-|00|8|00|1|00|d|00|f|00|-|00|a|00|a|00|b|00|6|00|3|00|6|00|f|00|a|00|4|00|3|00|4|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x009\x009\x000\x002\x000\x000\x00-\x003\x00c\x009\x00d\x00-\x004\x002\x006\x00d\x00-\x008\x001\x00d\x00f\x00-\x00a\x00a\x00b\x006\x003\x006\x00f\x00a\x004\x003\x004\x005\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10391</id>
        <msg>WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX clsid unicode access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SYMC.SmartIssue&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22SYMC\.SmartIssue\x22|\x27SYMC\.SmartIssue\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(EnableExtension)\s*\(|.*\3\s*\.\s*(EnableExtension)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SYMC\.SmartIssue\x22|\x27SYMC\.SmartIssue\x27)\s*\)(\s*\.\s*(EnableExtension)\s*\(|.*\7\s*\.\s*(EnableExtension)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10392</id>
        <msg>WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX function call access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EC5D5118-9FDE-4A3E-84F3-C2B711740E70&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*EC5D5118-9FDE-4A3E-84F3-C2B711740E70\s*}?\4.*\3\.(DownloadCertificateExt)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EC5D5118-9FDE-4A3E-84F3-C2B711740E70\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(DownloadCertificateExt)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10404</id>
        <msg>WEB-ACTIVEX SignKorea SKCommAX ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|C|00|5|00|D|00|5|00|1|00|1|00|8|00|-|00|9|00|F|00|D|00|E|00|-|00|4|00|A|00|3|00|E|00|-|00|8|00|4|00|F|00|3|00|-|00|C|00|2|00|B|00|7|00|1|00|1|00|7|00|4|00|0|00|E|00|7|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x00C\x005\x00D\x005\x001\x001\x008\x00-\x009\x00F\x00D\x00E\x00-\x004\x00A\x003\x00E\x00-\x008\x004\x00F\x003\x00-\x00C\x002\x00B\x007\x001\x001\x007\x004\x000\x00E\x007\x000\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10405</id>
        <msg>WEB-ACTIVEX SignKorea SKCommAX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SKCommAX&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22SKCommAX\x22|\x27SKCommAX\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(DownloadCertificateExt)\s*\(|.*\3\s*\.\s*(DownloadCertificateExt)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SKCommAX\x22|\x27SKCommAX\x27)\s*\)(\s*\.\s*(DownloadCertificateExt)\s*\(|.*\7\s*\.\s*(DownloadCertificateExt)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10406</id>
        <msg>WEB-ACTIVEX SignKorea SKCommAX ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1784</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0B9C9C7D-ED81-4594-AFCB-FC5588125382&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*0B9C9C7D-ED81-4594-AFCB-FC5588125382\s*}?\4.*\3\.(LoadLibrary)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0B9C9C7D-ED81-4594-AFCB-FC5588125382\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(LoadLibrary)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10412</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX clsid access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|B|00|9|00|C|00|9|00|C|00|7|00|D|00|-|00|E|00|D|00|8|00|1|00|-|00|4|00|5|00|9|00|4|00|-|00|A|00|F|00|C|00|B|00|-|00|F|00|C|00|5|00|5|00|8|00|8|00|1|00|2|00|5|00|3|00|8|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00B\x009\x00C\x009\x00C\x007\x00D\x00-\x00E\x00D\x008\x001\x00-\x004\x005\x009\x004\x00-\x00A\x00F\x00C\x00B\x00-\x00F\x00C\x005\x005\x008\x008\x001\x002\x005\x003\x008\x002\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10413</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX clsid unicode access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;JNILOADER.JNILoaderCtrl&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22JNILOADER\.JNILoaderCtrl\x22|\x27JNILOADER\.JNILoaderCtrl\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(LoadLibrary)\s*\(|.*\3\s*\.\s*(LoadLibrary)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22JNILOADER\.JNILoaderCtrl\x22|\x27JNILOADER\.JNILoaderCtrl\x27)\s*\)(\s*\.\s*(LoadLibrary)\s*\(|.*\7\s*\.\s*(LoadLibrary)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10414</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX function call access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7261EE42-318E-490A-AE8F-77649DBA1ECA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*7261EE42-318E-490A-AE8F-77649DBA1ECA\s*}?\4.*\3\.(LoadLibrary)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7261EE42-318E-490A-AE8F-77649DBA1ECA\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(LoadLibrary)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10415</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX clsid access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|2|00|6|00|1|00|E|00|E|00|4|00|2|00|-|00|3|00|1|00|8|00|E|00|-|00|4|00|9|00|0|00|A|00|-|00|A|00|E|00|8|00|F|00|-|00|7|00|7|00|6|00|4|00|9|00|D|00|B|00|A|00|1|00|E|00|C|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x002\x006\x001\x00E\x00E\x004\x002\x00-\x003\x001\x008\x00E\x00-\x004\x009\x000\x00A\x00-\x00A\x00E\x008\x00F\x00-\x007\x007\x006\x004\x009\x00D\x00B\x00A\x001\x00E\x00C\x00A\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10416</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX clsid unicode access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23201</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;JNILOADER.JNILoaderCtrl&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22JNILOADER\.JNILoaderCtrl\x22|\x27JNILOADER\.JNILoaderCtrl\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(LoadLibrary)\s*\(|.*\3\s*\.\s*(LoadLibrary)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22JNILOADER\.JNILoaderCtrl\x22|\x27JNILOADER\.JNILoaderCtrl\x27)\s*\)(\s*\.\s*(LoadLibrary)\s*\(|.*\7\s*\.\s*(LoadLibrary)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10417</id>
        <msg>WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX function call access</msg>
        <url>www.securityfocus.com/archive/1/464185</url>
      </rule>
      <rule>
        <bugtraq>23239</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1819</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;98C53984-8BF8-4D11-9B1C-C324FCA9CADE&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*98C53984-8BF8-4D11-9B1C-C324FCA9CADE\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ProgColor)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*98C53984-8BF8-4D11-9B1C-C324FCA9CADE\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(ProgColor))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10419</id>
        <msg>WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX clsid access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872</url>
      </rule>
      <rule>
        <bugtraq>23239</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1819</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|8|00|C|00|5|00|3|00|9|00|8|00|4|00|-|00|8|00|B|00|F|00|8|00|-|00|4|00|D|00|1|00|1|00|-|00|9|00|B|00|1|00|C|00|-|00|C|00|3|00|2|00|4|00|F|00|C|00|A|00|9|00|C|00|A|00|D|00|E|00|&quot;; nocase; content:&quot;P|00|r|00|o|00|g|00|C|00|o|00|l|00|o|00|r|00|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10420</id>
        <msg>WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX clsid unicode access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872</url>
      </rule>
      <rule>
        <bugtraq>23239</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1819</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SPIDERLib.Loader&quot;; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SPIDERLib\.Loader\x22|\x27SPIDERLib\.Loader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*ProgColor\s*|.*(?P=v)\s*\.\s*ProgColor\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SPIDERLib\.Loader\x22|\x27SPIDERLib\.Loader\x27)\s*\)(\s*\.\s*ProgColor\s*|.*(?P=n)\s*\.\s*ProgColor)\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10421</id>
        <msg>WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX function call access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872</url>
      </rule>
      <rule>
        <bugtraq>23239</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1819</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|P|00|I|00|D|00|E|00|R|00|L|00|i|00|b|00|.|00|L|00|o|00|a|00|d|00|e|00|r|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00P\x00I\x00D\x00E\x00R\x00L\x00i\x00b\x00.\x00L\x00o\x00a\x00d\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00P\x00I\x00D\x00E\x00R\x00L\x00i\x00b\x00.\x00L\x00o\x00a\x00d\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10422</id>
        <msg>WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX function call unicode access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872</url>
      </rule>
      <rule>
        <bugtraq>23291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1680</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2B323CD9-50E3-11D3-9466-00A0C9700498&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2B323CD9-50E3-11D3-9466-00A0C9700498\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(createAndJoinConference)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2B323CD9-50E3-11D3-9466-00A0C9700498\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(createAndJoinConference))\s*\(/Osi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10423</id>
        <msg>WEB-ACTIVEX Yahoo Audio Conferencing ActiveX clsid access</msg>
        <url>messenger.yahoo.com/security_update.php?id=031207</url>
      </rule>
      <rule>
        <bugtraq>23291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1680</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|B|00|3|00|2|00|3|00|C|00|D|00|9|00|-|00|5|00|0|00|E|00|3|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|4|00|6|00|6|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|7|00|0|00|0|00|4|00|9|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10424</id>
        <msg>WEB-ACTIVEX Yahoo Audio Conferencing ActiveX clsid unicode access</msg>
        <url>messenger.yahoo.com/security_update.php?id=031207</url>
      </rule>
      <rule>
        <bugtraq>23291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1680</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Yahoo.AudioConf&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Yahoo\.AudioConf\x22|\x27Yahoo\.AudioConf\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*createAndJoinConference\s*|.*(?P=v)\s*\.\s*createAndJoinConference\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Yahoo\.AudioConf\x22|\x27Yahoo\.AudioConf\x27)\s*\)(\s*\.\s*createAndJoinConference\s*|.*(?P=n)\s*\.\s*createAndJoinConference\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10425</id>
        <msg>WEB-ACTIVEX Yahoo Audio Conferencing ActiveX function call access</msg>
        <url>messenger.yahoo.com/security_update.php?id=031207</url>
      </rule>
      <rule>
        <bugtraq>23291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1680</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|a|00|h|00|o|00|o|00|.|00|A|00|u|00|d|00|i|00|o|00|C|00|o|00|n|00|f|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Y\x00a\x00h\x00o\x00o\x00.\x00A\x00u\x00d\x00i\x00o\x00C\x00o\x00n\x00f\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Y\x00a\x00h\x00o\x00o\x00.\x00A\x00u\x00d\x00i\x00o\x00C\x00o\x00n\x00f\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10426</id>
        <msg>WEB-ACTIVEX Yahoo Audio Conferencing ActiveX function call unicode access</msg>
        <url>messenger.yahoo.com/security_update.php?id=031207</url>
      </rule>
      <rule>
        <bugtraq>23325</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BA61606B-258C-4021-AD27-E07A3F3B91DB&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA61606B-258C-4021-AD27-E07A3F3B91DB\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA61606B-258C-4021-AD27-E07A3F3B91DB\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10427</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX clsid access</msg>
        <url>www.kaspersky.com/technews?id=203038694</url>
      </rule>
      <rule>
        <bugtraq>23325</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|6|00|1|00|6|00|0|00|6|00|B|00|-|00|2|00|5|00|8|00|C|00|-|00|4|00|0|00|2|00|1|00|-|00|A|00|D|00|2|00|7|00|-|00|E|00|0|00|7|00|A|00|3|00|F|00|3|00|B|00|9|00|1|00|D|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10428</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX clsid unicode access</msg>
        <url>www.kaspersky.com/technews?id=203038694</url>
      </rule>
      <rule>
        <bugtraq>23325</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;KL.SysInfo&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22KL\.SysInfo\x22|\x27KL\.SysInfo\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*|.*(?P=v)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22KL\.SysInfo\x22|\x27KL\.SysInfo\x27)\s*\)(\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*|.*(?P=n)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10429</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX function call access</msg>
        <url>www.kaspersky.com/technews?id=203038694</url>
      </rule>
      <rule>
        <bugtraq>23325</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;K|00|L|00|.|00|S|00|y|00|s|00|I|00|n|00|f|00|o|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)K\x00L\x00.\x00S\x00y\x00s\x00I\x00n\x00f\x00o\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)K\x00L\x00.\x00S\x00y\x00s\x00I\x00n\x00f\x00o\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10430</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX function call unicode access</msg>
        <url>www.kaspersky.com/technews?id=203038694</url>
      </rule>
      <rule>
        <bugtraq>23345</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D9EC22E7-1A86-4F7C-8940-0303AE5D6756&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D9EC22E7-1A86-4F7C-8940-0303AE5D6756\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D9EC22E7-1A86-4F7C-8940-0303AE5D6756\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10431</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX clsid access</msg>
        <url>www.kaspersky.com/technews?id=203038693</url>
      </rule>
      <rule>
        <bugtraq>23345</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|E|00|C|00|2|00|2|00|E|00|7|00|-|00|1|00|A|00|8|00|6|00|-|00|4|00|F|00|7|00|C|00|-|00|8|00|9|00|4|00|0|00|-|00|0|00|3|00|0|00|3|00|A|00|E|00|5|00|D|00|6|00|7|00|5|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10432</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX clsid unicode access</msg>
        <url>www.kaspersky.com/technews?id=203038693</url>
      </rule>
      <rule>
        <bugtraq>23345</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AxKLProd60.KAV60Info&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AxKLProd60\.KAV60Info\x22|\x27AxKLProd60\.KAV60Info\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*|.*(?P=v)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AxKLProd60\.KAV60Info\x22|\x27AxKLProd60\.KAV60Info\x27)\s*\)(\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*|.*(?P=n)\s*\.\s*(DeleteFile|StartBatchUploading|StartStrBatchUploading|StartUploading)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10433</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX function call access</msg>
        <url>www.kaspersky.com/technews?id=203038693</url>
      </rule>
      <rule>
        <bugtraq>23345</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|x|00|K|00|L|00|P|00|r|00|o|00|d|00|6|00|0|00|.|00|K|00|A|00|V|00|6|00|0|00|I|00|n|00|f|00|o|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00x\x00K\x00L\x00P\x00r\x00o\x00d\x006\x000\x00.\x00K\x00A\x00V\x006\x000\x00I\x00n\x00f\x00o\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00x\x00K\x00L\x00P\x00r\x00o\x00d\x006\x000\x00.\x00K\x00A\x00V\x006\x000\x00I\x00n\x00f\x00o\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10434</id>
        <msg>WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX function call unicode access</msg>
        <url>www.kaspersky.com/technews?id=203038693</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|g|00|e|00|n|00|t|00|.|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|.|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)A\x00g\x00e\x00n\x00t\x00.\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x001\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)A\x00g\x00e\x00n\x00t\x00.\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x001\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10465</id>
        <msg>WEB-ACTIVEX Microsoft Agent v1.5 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ef8d9f2a-f641-4ef0-b2ec-3ba2be7c2960&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*ef8d9f2a-f641-4ef0-b2ec-3ba2be7c2960\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10466</id>
        <msg>WEB-ACTIVEX iPIX Image Well ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|f|00|8|00|d|00|9|00|f|00|2|00|a|00|-|00|f|00|6|00|4|00|1|00|-|00|4|00|e|00|f|00|0|00|-|00|b|00|2|00|e|00|c|00|-|00|3|00|b|00|a|00|2|00|b|00|e|00|7|00|c|00|2|00|9|00|6|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10467</id>
        <msg>WEB-ACTIVEX iPIX Image Well ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iPIX.ImageWell&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iPIX\.ImageWell\x22|\x27iPIX\.ImageWell\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iPIX\.ImageWell\x22|\x27iPIX\.ImageWell\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10468</id>
        <msg>WEB-ACTIVEX iPIX Image Well ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iPIX.ImageWell&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iPIX\.ImageWell\x22|\x27iPIX\.ImageWell\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iPIX\.ImageWell\x22|\x27iPIX\.ImageWell\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10469</id>
        <msg>WEB-ACTIVEX iPIX Image Well ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d04a7099-0c25-4fc7-970f-6ec7d77886f3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*d04a7099-0c25-4fc7-970f-6ec7d77886f3\s*}?\s*(?P=q4)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10470</id>
        <msg>WEB-ACTIVEX iPIX Media Send Class ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|0|00|4|00|a|00|7|00|0|00|9|00|9|00|-|00|0|00|c|00|2|00|5|00|-|00|4|00|f|00|c|00|7|00|-|00|9|00|7|00|0|00|f|00|-|00|6|00|e|00|c|00|7|00|d|00|7|00|7|00|8|00|8|00|6|00|f|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q5&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10471</id>
        <msg>WEB-ACTIVEX iPIX Media Send Class ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iPIX.Rimfire4.1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iPIX\.Rimfire4\.1\x22|\x27iPIX\.Rimfire4\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iPIX\.Rimfire4\.1\x22|\x27iPIX\.Rimfire4\.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10472</id>
        <msg>WEB-ACTIVEX iPIX Media Send Class ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iPIX.Rimfire4.1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iPIX\.Rimfire4\.1\x22|\x27iPIX\.Rimfire4\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iPIX\.Rimfire4\.1\x22|\x27iPIX\.Rimfire4\.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10473</id>
        <msg>WEB-ACTIVEX iPIX Media Send Class ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1687</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;i|00|P|00|I|00|X|00|.|00|R|00|i|00|m|00|f|00|i|00|r|00|e|00|4|00|.|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)i\x00P\x00I\x00X\x00.\x00R\x00i\x00m\x00f\x00i\x00r\x00e\x004\x00.\x001\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)i\x00P\x00I\x00X\x00.\x00R\x00i\x00m\x00f\x00i\x00r\x00e\x004\x00.\x001\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10474</id>
        <msg>WEB-ACTIVEX iPIX Media Send Class ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/958609</url>
      </rule>
      <rule>
        <bugtraq>23420</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;798B9483-B7A6-46C1-9F17-C9B9F02EA811&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*798B9483-B7A6-46C1-9F17-C9B9F02EA811\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(MaDecodeData)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*798B9483-B7A6-46C1-9F17-C9B9F02EA811\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(MaDecodeData))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10476</id>
        <msg>WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>23420</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|8|00|B|00|9|00|4|00|8|00|3|00|-|00|B|00|7|00|A|00|6|00|-|00|4|00|6|00|C|00|1|00|-|00|9|00|F|00|1|00|7|00|-|00|C|00|9|00|B|00|9|00|F|00|0|00|2|00|E|00|A|00|8|00|1|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10477</id>
        <msg>WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23420</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MAPRINTMODULEWORK.MaPrintModuleWORKCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MAPRINTMODULEWORK\.MaPrintModuleWORKCtrl\x22|\x27MAPRINTMODULEWORK\.MaPrintModuleWORKCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*MaDecodeData\s*|.*(?P=v)\s*\.\s*MaDecodeData\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MAPRINTMODULEWORK\.MaPrintModuleWORKCtrl\x22|\x27MAPRINTMODULEWORK\.MaPrintModuleWORKCtrl\x27)\s*\)(\s*\.\s*MaDecodeData\s*|.*(?P=n)\s*\.\s*MaDecodeData\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10478</id>
        <msg>WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>23420</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|A|00|P|00|R|00|I|00|N|00|T|00|M|00|O|00|D|00|U|00|L|00|E|00|W|00|O|00|R|00|K|00|.|00|M|00|a|00|P|00|r|00|i|00|n|00|t|00|M|00|o|00|d|00|u|00|l|00|e|00|W|00|O|00|R|00|K|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)M\x00A\x00P\x00R\x00I\x00N\x00T\x00M\x00O\x00D\x00U\x00L\x00E\x00W\x00O\x00R\x00K\x00.\x00M\x00a\x00P\x00r\x00i\x00n\x00t\x00M\x00o\x00d\x00u\x00l\x00e\x00W\x00O\x00R\x00K\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)M\x00A\x00P\x00R\x00I\x00N\x00T\x00M\x00O\x00D\x00U\x00L\x00E\x00W\x00O\x00R\x00K\x00.\x00M\x00a\x00P\x00r\x00i\x00n\x00t\x00M\x00o\x00d\x00u\x00l\x00e\x00W\x00O\x00R\x00K\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10479</id>
        <msg>WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1690</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;052DF14F-6F28-44A0-9130-294FDA6176EB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*052DF14F-6F28-44A0-9130-294FDA6176EB\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10978</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveGS ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/118737</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1690</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|5|00|2|00|D|00|F|00|1|00|4|00|F|00|-|00|6|00|F|00|2|00|8|00|-|00|4|00|4|00|A|00|0|00|-|00|9|00|1|00|3|00|0|00|-|00|2|00|9|00|4|00|F|00|D|00|A|00|6|00|1|00|7|00|6|00|E|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10979</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveGS ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/118737</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1690</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ACTIVEGS.ActiveGSCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ACTIVEGS\.ActiveGSCtrl\x22|\x27ACTIVEGS\.ActiveGSCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ACTIVEGS\.ActiveGSCtrl\x22|\x27ACTIVEGS\.ActiveGSCtrl\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10980</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveGS ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/118737</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1690</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|C|00|T|00|I|00|V|00|E|00|G|00|S|00|.|00|A|00|c|00|t|00|i|00|v|00|e|00|G|00|S|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)A\x00C\x00T\x00I\x00V\x00E\x00G\x00S\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00G\x00S\x00C\x00t\x00r\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00C\x00T\x00I\x00V\x00E\x00G\x00S\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00G\x00S\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10981</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveGS ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/118737</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2078D6EC-693C-4FB2-AE7B-A6B8D2BC4DC8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2078D6EC-693C-4FB2-AE7B-A6B8D2BC4DC8\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10982</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveMod ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/962305</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|0|00|7|00|8|00|D|00|6|00|E|00|C|00|-|00|6|00|9|00|3|00|C|00|-|00|4|00|F|00|B|00|2|00|-|00|A|00|E|00|7|00|B|00|-|00|A|00|6|00|B|00|8|00|D|00|2|00|B|00|C|00|4|00|D|00|C|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10983</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveMod ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/962305</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ACTIVEMOD.ActiveModCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ACTIVEMOD\.ActiveModCtrl\x22|\x27ACTIVEMOD\.ActiveModCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ACTIVEMOD\.ActiveModCtrl\x22|\x27ACTIVEMOD\.ActiveModCtrl\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10984</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveMod ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/962305</url>
      </rule>
      <rule>
        <bugtraq>23554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|C|00|T|00|I|00|V|00|E|00|M|00|O|00|D|00|.|00|A|00|c|00|t|00|i|00|v|00|e|00|M|00|o|00|d|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)A\x00C\x00T\x00I\x00V\x00E\x00M\x00O\x00D\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00M\x00o\x00d\x00C\x00t\x00r\x00l\x00(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)A\x00C\x00T\x00I\x00V\x00E\x00M\x00O\x00D\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00M\x00o\x00d\x00C\x00t\x00r\x00l\x00(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10985</id>
        <msg>WEB-ACTIVEX Second Sight Software ActiveMod ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/962305</url>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0443</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F\s*}?\s*(?P=q11)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10986</id>
        <msg>WEB-ACTIVEX GraceNote CDDB ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0443</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|4|00|B|00|A|00|F|00|F|00|0|00|2|00|-|00|F|00|9|00|0|00|7|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|F|00|8|00|F|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|4|00|C|00|3|00|B|00|9|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q12&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10987</id>
        <msg>WEB-ACTIVEX GraceNote CDDB ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0443</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ClassCDDBControl.CddbSegments&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ClassCDDBControl\.CddbSegments\x22|\x27ClassCDDBControl\.CddbSegments\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ClassCDDBControl\.CddbSegments\x22|\x27ClassCDDBControl\.CddbSegments\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10988</id>
        <msg>WEB-ACTIVEX GraceNote CDDB ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0443</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|l|00|a|00|s|00|s|00|C|00|D|00|D|00|B|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|.|00|C|00|d|00|d|00|b|00|S|00|e|00|g|00|m|00|e|00|n|00|t|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)C\x00l\x00a\x00s\x00s\x00C\x00D\x00D\x00B\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00C\x00d\x00d\x00b\x00S\x00e\x00g\x00m\x00e\x00n\x00t\x00s\x00(?P=q13)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)C\x00l\x00a\x00s\x00s\x00C\x00D\x00D\x00B\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00C\x00d\x00d\x00b\x00S\x00e\x00g\x00m\x00e\x00n\x00t\x00s\x00(?P=q14)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10989</id>
        <msg>WEB-ACTIVEX GraceNote CDDB ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <bugtraq>23595</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AED98630-0251-4E83-917D-43A23D66D507&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AED98630-0251-4E83-917D-43A23D66D507\s*}?\s*(?P=q15)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10991</id>
        <msg>WEB-ACTIVEX Microgaming Download Helper ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/184473</url>
      </rule>
      <rule>
        <bugtraq>23595</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|E|00|D|00|9|00|8|00|6|00|3|00|0|00|-|00|0|00|2|00|5|00|1|00|-|00|4|00|E|00|8|00|3|00|-|00|9|00|1|00|7|00|D|00|-|00|4|00|3|00|A|00|2|00|3|00|D|00|6|00|6|00|D|00|5|00|0|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q16&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10992</id>
        <msg>WEB-ACTIVEX Microgaming Download Helper ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/184473</url>
      </rule>
      <rule>
        <bugtraq>23595</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DLHelper.WebHandler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DLHelper\.WebHandler\x22|\x27DLHelper\.WebHandler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DLHelper\.WebHandler\x22|\x27DLHelper\.WebHandler\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10993</id>
        <msg>WEB-ACTIVEX Microgaming Download Helper ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/184473</url>
      </rule>
      <rule>
        <bugtraq>23595</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|L|00|H|00|e|00|l|00|p|00|e|00|r|00|.|00|W|00|e|00|b|00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)D\x00L\x00H\x00e\x00l\x00p\x00e\x00r\x00.\x00W\x00e\x00b\x00H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q17)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q18&gt;\x22|\x27|)D\x00L\x00H\x00e\x00l\x00p\x00e\x00r\x00.\x00W\x00e\x00b\x00H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q18)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10994</id>
        <msg>WEB-ACTIVEX Microgaming Download Helper ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/184473</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;97AF4A45-49BE-4485-9F55-91AB40F22B92&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F22B92\s*}?\s*(?P=q19)(\s|&gt;).*(?P=id1)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q20&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F22B92\s*}?\s*(?P=q20)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\.(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile))\s*\(/siO&quot;; metadata:policy balanced-ips drop, policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11176</id>
        <msg>WEB-ACTIVEX PowerPoint Viewer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|7|00|A|00|F|00|4|00|A|00|4|00|5|00|-|00|4|00|9|00|B|00|E|00|-|00|4|00|4|00|8|00|5|00|-|00|9|00|F|00|5|00|5|00|-|00|9|00|1|00|A|00|B|00|4|00|0|00|F|00|2|00|2|00|B|00|9|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q21&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x007\x00A\x00F\x004\x00A\x004\x005\x00-\x004\x009\x00B\x00E\x00-\x004\x004\x008\x005\x00-\x009\x00F\x005\x005\x00-\x009\x001\x00A\x00B\x004\x000\x00F\x002\x002\x00B\x009\x002\x00(}\x00)?(?P=q21)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11177</id>
        <msg>WEB-ACTIVEX PowerPoint Viewer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OA.OACtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OA\.OACtrl(\.\d)?\x22|\x27OA\.OACtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=v)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OA\.OACtrl(\.\d)?\x22|\x27OA\.OACtrl(\.\d)?\x27)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=n)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11178</id>
        <msg>WEB-ACTIVEX PowerPoint Viewer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|A|00|.|00|O|00|A|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q22&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q22)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q23&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q23)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11179</id>
        <msg>WEB-ACTIVEX PowerPoint Viewer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html</url>
      </rule>
      <rule>
        <bugtraq>22558</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DVD_TOOLS.DVD_TOOLSCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DVD_TOOLS\.DVD_TOOLSCtrl\x22|\x27DVD_TOOLS\.DVD_TOOLSCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DVD_TOOLS\.DVD_TOOLSCtrl\x22|\x27DVD_TOOLS\.DVD_TOOLSCtrl\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11197</id>
        <msg>WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-bonus-actsoft-dvd-tools.html</url>
      </rule>
      <rule>
        <bugtraq>22558</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|V|00|D|00|_|00|T|00|O|00|O|00|L|00|S|00|.|00|D|00|V|00|D|00|_|00|T|00|O|00|O|00|L|00|S|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)D\x00V\x00D\x00_\x00T\x00O\x00O\x00L\x00S\x00.\x00D\x00V\x00D\x00_\x00T\x00O\x00O\x00L\x00S\x00C\x00t\x00r\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00V\x00D\x00_\x00T\x00O\x00O\x00L\x00S\x00.\x00D\x00V\x00D\x00_\x00T\x00O\x00O\x00L\x00S\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11198</id>
        <msg>WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-bonus-actsoft-dvd-tools.html</url>
      </rule>
      <rule>
        <bugtraq>23833</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;995A778F-E846-48DD-94F2-280FDED1AADF&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*995A778F-E846-48DD-94F2-280FDED1AADF\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(OpenDVD)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*995A778F-E846-48DD-94F2-280FDED1AADF\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(OpenDVD))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11206</id>
        <msg>WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html</url>
      </rule>
      <rule>
        <bugtraq>23833</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|9|00|5|00|A|00|7|00|7|00|8|00|F|00|-|00|E|00|8|00|4|00|6|00|-|00|4|00|8|00|D|00|D|00|-|00|9|00|4|00|F|00|2|00|-|00|2|00|8|00|0|00|F|00|D|00|E|00|D|00|1|00|A|00|A|00|D|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11207</id>
        <msg>WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html</url>
      </rule>
      <rule>
        <bugtraq>23833</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ADVDAUDIO.ADVDAUDIOCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ADVDAUDIO\.ADVDAUDIOCtrl\x22|\x27ADVDAUDIO\.ADVDAUDIOCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*OpenDVD\s*|.*(?P=v)\s*\.\s*OpenDVD\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ADVDAUDIO\.ADVDAUDIOCtrl\x22|\x27ADVDAUDIO\.ADVDAUDIOCtrl\x27)\s*\)(\s*\.\s*OpenDVD\s*|.*(?P=n)\s*\.\s*OpenDVD\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11208</id>
        <msg>WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html</url>
      </rule>
      <rule>
        <bugtraq>23833</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|D|00|V|00|D|00|A|00|U|00|D|00|I|00|O|00|.|00|A|00|D|00|V|00|D|00|A|00|U|00|D|00|I|00|O|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00D\x00V\x00D\x00A\x00U\x00D\x00I\x00O\x00.\x00A\x00D\x00V\x00D\x00A\x00U\x00D\x00I\x00O\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00D\x00V\x00D\x00A\x00U\x00D\x00I\x00O\x00.\x00A\x00D\x00V\x00D\x00A\x00U\x00D\x00I\x00O\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11209</id>
        <msg>WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html</url>
      </rule>
      <rule>
        <bugtraq>23838</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E2B7DDA9-38C5-11D5-91F6-00104BDB8FF9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E2B7DDA9-38C5-11D5-91F6-00104BDB8FF9\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(LockModules|UnlockModule)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E2B7DDA9-38C5-11D5-91F6-00104BDB8FF9\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(LockModules|UnlockModule))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11210</id>
        <msg>WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-06-sienzo-digital-music-mentor.html</url>
      </rule>
      <rule>
        <bugtraq>23838</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|2|00|B|00|7|00|D|00|D|00|A|00|9|00|-|00|3|00|8|00|C|00|5|00|-|00|1|00|1|00|D|00|5|00|-|00|9|00|1|00|F|00|6|00|-|00|0|00|0|00|1|00|0|00|4|00|B|00|D|00|B|00|8|00|F|00|F|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11211</id>
        <msg>WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-06-sienzo-digital-music-mentor.html</url>
      </rule>
      <rule>
        <bugtraq>23838</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DSKernel.LMDSKernel&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DSKernel\.LMDSKernel\x22|\x27DSKernel\.LMDSKernel\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(LockModules|UnlockModule)\s*|.*(?P=v)\s*\.\s*(LockModules|UnlockModule)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DSKernel\.LMDSKernel\x22|\x27DSKernel\.LMDSKernel\x27)\s*\)(\s*\.\s*(LockModules|UnlockModule)\s*|.*(?P=n)\s*\.\s*(LockModules|UnlockModule)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11212</id>
        <msg>WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-06-sienzo-digital-music-mentor.html</url>
      </rule>
      <rule>
        <bugtraq>23838</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|S|00|K|00|e|00|r|00|n|00|e|00|l|00|.|00|L|00|M|00|D|00|S|00|K|00|e|00|r|00|n|00|e|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)D\x00S\x00K\x00e\x00r\x00n\x00e\x00l\x00.\x00L\x00M\x00D\x00S\x00K\x00e\x00r\x00n\x00e\x00l\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)D\x00S\x00K\x00e\x00r\x00n\x00e\x00l\x00.\x00L\x00M\x00D\x00S\x00K\x00e\x00r\x00n\x00e\x00l\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11213</id>
        <msg>WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-06-sienzo-digital-music-mentor.html</url>
      </rule>
      <rule>
        <bugtraq>23853</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;28776DAD-5914-42A7-9139-8FD7C756BBDD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*28776DAD-5914-42A7-9139-8FD7C756BBDD\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(AddFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*28776DAD-5914-42A7-9139-8FD7C756BBDD\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(AddFile))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11214</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-07-versalsoft-http-file-uploader.html</url>
      </rule>
      <rule>
        <bugtraq>23853</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|8|00|7|00|7|00|6|00|D|00|A|00|D|00|-|00|5|00|9|00|1|00|4|00|-|00|4|00|2|00|A|00|7|00|-|00|9|00|1|00|3|00|9|00|-|00|8|00|F|00|D|00|7|00|C|00|7|00|5|00|6|00|B|00|B|00|D|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q13&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11215</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-07-versalsoft-http-file-uploader.html</url>
      </rule>
      <rule>
        <bugtraq>23853</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;UFileUploaderD.FileUploaderD&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22UFileUploaderD\.FileUploaderD\x22|\x27UFileUploaderD\.FileUploaderD\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddFile\s*|.*(?P=v)\s*\.\s*AddFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22UFileUploaderD\.FileUploaderD\x22|\x27UFileUploaderD\.FileUploaderD\x27)\s*\)(\s*\.\s*AddFile\s*|.*(?P=n)\s*\.\s*AddFile\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11216</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-07-versalsoft-http-file-uploader.html</url>
      </rule>
      <rule>
        <bugtraq>23853</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;U|00|F|00|i|00|l|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|D|00|.|00|F|00|i|00|l|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)U\x00F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00D\x00.\x00F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00D\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)U\x00F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00D\x00.\x00F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00D\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11217</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-07-versalsoft-http-file-uploader.html</url>
      </rule>
      <rule>
        <bugtraq>23869</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;62FA83F7-20EC-4D62-AC86-BAB705EE1CCD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*62FA83F7-20EC-4D62-AC86-BAB705EE1CCD\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(ConnectAsyncEx)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*62FA83F7-20EC-4D62-AC86-BAB705EE1CCD\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(ConnectAsyncEx))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11218</id>
        <msg>WEB-ACTIVEX SmartCode VNC Manager ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-08-smartcode-vnc-manager-36.html</url>
      </rule>
      <rule>
        <bugtraq>23869</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|2|00|F|00|A|00|8|00|3|00|F|00|7|00|-|00|2|00|0|00|E|00|C|00|-|00|4|00|D|00|6|00|2|00|-|00|A|00|C|00|8|00|6|00|-|00|B|00|A|00|B|00|7|00|0|00|5|00|E|00|E|00|1|00|C|00|C|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q18&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11219</id>
        <msg>WEB-ACTIVEX SmartCode VNC Manager ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-08-smartcode-vnc-manager-36.html</url>
      </rule>
      <rule>
        <bugtraq>23869</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SmartCode.ViewerX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SmartCode\.ViewerX\x22|\x27SmartCode\.ViewerX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*ConnectAsyncEx\s*|.*(?P=v)\s*\.\s*ConnectAsyncEx\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SmartCode\.ViewerX\x22|\x27SmartCode\.ViewerX\x27)\s*\)(\s*\.\s*ConnectAsyncEx\s*|.*(?P=n)\s*\.\s*ConnectAsyncEx\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11220</id>
        <msg>WEB-ACTIVEX SmartCode VNC Manager ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-08-smartcode-vnc-manager-36.html</url>
      </rule>
      <rule>
        <bugtraq>23869</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|m|00|a|00|r|00|t|00|C|00|o|00|d|00|e|00|.|00|V|00|i|00|e|00|w|00|e|00|r|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q19&gt;\x22|\x27|)S\x00m\x00a\x00r\x00t\x00C\x00o\x00d\x00e\x00.\x00V\x00i\x00e\x00w\x00e\x00r\x00X\x00(?P=q19)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)S\x00m\x00a\x00r\x00t\x00C\x00o\x00d\x00e\x00.\x00V\x00i\x00e\x00w\x00e\x00r\x00X\x00(?P=q20)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11221</id>
        <msg>WEB-ACTIVEX SmartCode VNC Manager ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-08-smartcode-vnc-manager-36.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2221</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D4FE6227-1288-11D0-9097-00AA004254A0&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D4FE6227-1288-11D0-9097-00AA004254A0\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAs)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D4FE6227-1288-11D0-9097-00AA004254A0\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveAs))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11224</id>
        <msg>WEB-ACTIVEX MSAuth ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2221</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|F|00|E|00|6|00|2|00|2|00|7|00|-|00|1|00|2|00|8|00|8|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|0|00|9|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|2|00|5|00|4|00|A|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11225</id>
        <msg>WEB-ACTIVEX MSAuth ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2221</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NMSA.SessionDescription&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NMSA\.SessionDescription\x22|\x27NMSA\.SessionDescription\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveAs\s*|.*(?P=v)\s*\.\s*SaveAs\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NMSA\.SessionDescription\x22|\x27NMSA\.SessionDescription\x27)\s*\)(\s*\.\s*SaveAs\s*|.*(?P=n)\s*\.\s*SaveAs\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11226</id>
        <msg>WEB-ACTIVEX MSAuth ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2221</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|M|00|S|00|A|00|.|00|S|00|e|00|s|00|s|00|i|00|o|00|n|00|D|00|e|00|s|00|c|00|r|00|i|00|p|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00M\x00S\x00A\x00.\x00S\x00e\x00s\x00s\x00i\x00o\x00n\x00D\x00e\x00s\x00c\x00r\x00i\x00p\x00t\x00i\x00o\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00M\x00S\x00A\x00.\x00S\x00e\x00s\x00s\x00i\x00o\x00n\x00D\x00e\x00s\x00c\x00r\x00i\x00p\x00t\x00i\x00o\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11227</id>
        <msg>WEB-ACTIVEX MSAuth ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0942</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BE4191FB-59EF-4825-AEFC-109727951E42&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BE4191FB-59EF-4825-AEFC-109727951E42\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11228</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=releases&amp;act=view&amp;type=1&amp;id=9</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0942</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|E|00|4|00|1|00|9|00|1|00|F|00|B|00|-|00|5|00|9|00|E|00|F|00|-|00|4|00|8|00|2|00|5|00|-|00|A|00|E|00|F|00|C|00|-|00|1|00|0|00|9|00|7|00|2|00|7|00|9|00|5|00|1|00|E|00|4|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11229</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX clsid unicode access</msg>
        <url>www.xsec.org/index.php?module=releases&amp;act=view&amp;type=1&amp;id=9</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;17E3A1C3-EA8A-4970-AF29-7F54610B1D4C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*17E3A1C3-EA8A-4970-AF29-7F54610B1D4C\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11230</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|7|00|E|00|3|00|A|00|1|00|C|00|3|00|-|00|E|00|A|00|8|00|A|00|-|00|4|00|9|00|7|00|0|00|-|00|A|00|F|00|2|00|9|00|-|00|7|00|F|00|5|00|4|00|6|00|1|00|0|00|B|00|1|00|D|00|4|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11231</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CAPICOM.Certificates&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CAPICOM\.Certificates\x22|\x27CAPICOM\.Certificates\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CAPICOM\.Certificates\x22|\x27CAPICOM\.Certificates\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11232</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|A|00|P|00|I|00|C|00|O|00|M|00|.|00|C|00|e|00|r|00|t|00|i|00|f|00|i|00|c|00|a|00|t|00|e|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)C\x00A\x00P\x00I\x00C\x00O\x00M\x00.\x00C\x00e\x00r\x00t\x00i\x00f\x00i\x00c\x00a\x00t\x00e\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00A\x00P\x00I\x00C\x00O\x00M\x00.\x00C\x00e\x00r\x00t\x00i\x00f\x00i\x00c\x00a\x00t\x00e\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11233</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FBAB033B-CDD0-4C5E-81AB-AEA575CD1338&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FBAB033B-CDD0-4C5E-81AB-AEA575CD1338\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11234</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0940</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|B|00|A|00|B|00|0|00|3|00|3|00|B|00|-|00|C|00|D|00|D|00|0|00|-|00|4|00|C|00|5|00|E|00|-|00|8|00|1|00|A|00|B|00|-|00|A|00|E|00|A|00|5|00|7|00|5|00|C|00|D|00|1|00|3|00|3|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11235</id>
        <msg>WEB-ACTIVEX Microsoft Cryptographic API COM 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;42B07B28-2280-4937-B035-0293FB812781&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42B07B28-2280-4937-B035-0293FB812781\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11239</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|B|00|0|00|7|00|B|00|2|00|8|00|-|00|2|00|2|00|8|00|0|00|-|00|4|00|9|00|3|00|7|00|-|00|B|00|0|00|3|00|5|00|-|00|0|00|2|00|9|00|3|00|F|00|B|00|8|00|1|00|2|00|7|00|8|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11240</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.Redirect&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DXImageTransform\.Microsoft\.Redirect\x22|\x27DXImageTransform\.Microsoft\.Redirect\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DXImageTransform\.Microsoft\.Redirect\x22|\x27DXImageTransform\.Microsoft\.Redirect\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11241</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|X|00|I|00|m|00|a|00|g|00|e|00|T|00|r|00|a|00|n|00|s|00|f|00|o|00|r|00|m|00|.|00|M|00|i|00|c|00|r|00|o|00|s|00|o|00|f|00|t|00|.|00|R|00|e|00|d|00|i|00|r|00|e|00|c|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)D\x00X\x00I\x00m\x00a\x00g\x00e\x00T\x00r\x00a\x00n\x00s\x00f\x00o\x00r\x00m\x00.\x00M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00R\x00e\x00d\x00i\x00r\x00e\x00c\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00X\x00I\x00m\x00a\x00g\x00e\x00T\x00r\x00a\x00n\x00s\x00f\x00o\x00r\x00m\x00.\x00M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00R\x00e\x00d\x00i\x00r\x00e\x00c\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11242</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;542FB453-5003-11CF-92A2-00AA00B8A733&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*542FB453-5003-11CF-92A2-00AA00B8A733\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11243</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAstatics ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|4|00|2|00|F|00|B|00|4|00|5|00|3|00|-|00|5|00|0|00|0|00|3|00|-|00|1|00|1|00|C|00|F|00|-|00|9|00|2|00|A|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|8|00|A|00|7|00|3|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11244</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAstatics ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAstatics&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DirectAnimation\.DAstatics\x22|\x27DirectAnimation\.DAstatics\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DirectAnimation\.DAstatics\x22|\x27DirectAnimation\.DAstatics\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11245</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAstatics ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|i|00|r|00|e|00|c|00|t|00|A|00|n|00|i|00|m|00|a|00|t|00|i|00|o|00|n|00|.|00|D|00|A|00|s|00|t|00|a|00|t|00|i|00|c|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00A\x00n\x00i\x00m\x00a\x00t\x00i\x00o\x00n\x00.\x00D\x00A\x00s\x00t\x00a\x00t\x00i\x00c\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00A\x00n\x00i\x00m\x00a\x00t\x00i\x00o\x00n\x00.\x00D\x00A\x00s\x00t\x00a\x00t\x00i\x00c\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11246</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAstatics ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-013.mspx</url>
      </rule>
      <rule>
        <bugtraq>23331</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1D95A7C7-3282-4DB7-9A48-7C39CE152A19&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1D95A7C7-3282-4DB7-9A48-7C39CE152A19\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11247</id>
        <msg>WEB-ACTIVEX Research In Motion TeamOn Import ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>23331</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|D|00|9|00|5|00|A|00|7|00|C|00|7|00|-|00|3|00|2|00|8|00|2|00|-|00|4|00|D|00|B|00|7|00|-|00|9|00|A|00|4|00|8|00|-|00|7|00|C|00|3|00|9|00|C|00|E|00|1|00|5|00|2|00|A|00|1|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11248</id>
        <msg>WEB-ACTIVEX Research In Motion TeamOn Import ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|e|00|0|00|1|00|1|00|5|00|9|00|0|00|-|00|0|00|5|00|3|00|1|00|-|00|4|00|8|00|0|00|4|00|-|00|9|00|c|00|9|00|c|00|-|00|3|00|f|00|e|00|d|00|c|00|7|00|e|00|6|00|e|00|5|00|c|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11249</id>
        <msg>WEB-ACTIVEX IE Address ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4EA7C4C5-C5C0-4F5C-A008-8293505F71CC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4EA7C4C5-C5C0-4F5C-A008-8293505F71CC\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11250</id>
        <msg>WEB-ACTIVEX Sony Rootkit Uninstaller ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|E|00|A|00|7|00|C|00|4|00|C|00|5|00|-|00|C|00|5|00|C|00|0|00|-|00|4|00|F|00|5|00|C|00|-|00|A|00|0|00|0|00|8|00|-|00|8|00|2|00|9|00|3|00|5|00|0|00|5|00|F|00|7|00|1|00|C|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11251</id>
        <msg>WEB-ACTIVEX Sony Rootkit Uninstaller ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;de011590-0531-4804-9c9c-3fedc7e6e5c8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*de011590-0531-4804-9c9c-3fedc7e6e5c8\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11252</id>
        <msg>WEB-ACTIVEX IE Address ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;288F1523-FAC4-11CE-B16F-00AA0060D93D&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*288F1523-FAC4-11CE-B16F-00AA0060D93D\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Filename)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*288F1523-FAC4-11CE-B16F-00AA0060D93D\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Filename))\s*=/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11253</id>
        <msg>WEB-ACTIVEX Microsoft MciWndx ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|8|00|8|00|F|00|1|00|5|00|2|00|3|00|-|00|F|00|A|00|C|00|4|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|1|00|6|00|F|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|0|00|D|00|9|00|3|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11254</id>
        <msg>WEB-ACTIVEX Microsoft MciWndx ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MCIWNDX.MCIWndXCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MCIWNDX\.MCIWndXCtrl\x22|\x27MCIWNDX\.MCIWndXCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Filename\s*|.*(?P=v)\s*\.\s*Filename\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MCIWNDX\.MCIWndXCtrl\x22|\x27MCIWNDX\.MCIWndXCtrl\x27)\s*\)(\s*\.\s*Filename\s*|.*(?P=n)\s*\.\s*Filename)\s*=/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11255</id>
        <msg>WEB-ACTIVEX Microsoft MciWndx ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|C|00|I|00|W|00|N|00|D|00|X|00|.|00|M|00|C|00|I|00|W|00|n|00|d|00|X|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)M\x00C\x00I\x00W\x00N\x00D\x00X\x00.\x00M\x00C\x00I\x00W\x00n\x00d\x00X\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)M\x00C\x00I\x00W\x00N\x00D\x00X\x00.\x00M\x00C\x00I\x00W\x00n\x00d\x00X\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11256</id>
        <msg>WEB-ACTIVEX Microsoft MciWndx ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CD3B09F1-26FB-41CD-B3F2-E178DFD3BCC6&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CD3B09F1-26FB-41CD-B3F2-E178DFD3BCC6\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Verify)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CD3B09F1-26FB-41CD-B3F2-E178DFD3BCC6\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Verify))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11259</id>
        <msg>WEB-ACTIVEX BarcodeWiz ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-09-barcodewiz-activex-control-20.html</url>
      </rule>
      <rule>
        <bugtraq>23891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|D|00|3|00|B|00|0|00|9|00|F|00|1|00|-|00|2|00|6|00|F|00|B|00|-|00|4|00|1|00|C|00|D|00|-|00|B|00|3|00|F|00|2|00|-|00|E|00|1|00|7|00|8|00|D|00|F|00|D|00|3|00|B|00|C|00|C|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11260</id>
        <msg>WEB-ACTIVEX BarcodeWiz ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-09-barcodewiz-activex-control-20.html</url>
      </rule>
      <rule>
        <bugtraq>23891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BarcodeWiz.BarcodeWiz&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22BarcodeWiz\.BarcodeWiz\x22|\x27BarcodeWiz\.BarcodeWiz\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Verify\s*|.*(?P=v)\s*\.\s*Verify\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BarcodeWiz\.BarcodeWiz\x22|\x27BarcodeWiz\.BarcodeWiz\x27)\s*\)(\s*\.\s*Verify\s*|.*(?P=n)\s*\.\s*Verify\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11261</id>
        <msg>WEB-ACTIVEX BarcodeWiz ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-09-barcodewiz-activex-control-20.html</url>
      </rule>
      <rule>
        <bugtraq>23891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|a|00|r|00|c|00|o|00|d|00|e|00|W|00|i|00|z|00|.|00|B|00|a|00|r|00|c|00|o|00|d|00|e|00|W|00|i|00|z|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)B\x00a\x00r\x00c\x00o\x00d\x00e\x00W\x00i\x00z\x00.\x00B\x00a\x00r\x00c\x00o\x00d\x00e\x00W\x00i\x00z\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)B\x00a\x00r\x00c\x00o\x00d\x00e\x00W\x00i\x00z\x00.\x00B\x00a\x00r\x00c\x00o\x00d\x00e\x00W\x00i\x00z\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11262</id>
        <msg>WEB-ACTIVEX BarcodeWiz ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-09-barcodewiz-activex-control-20.html</url>
      </rule>
      <rule>
        <bugtraq>23822</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3456</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;085ABFE2-D753-445C-8A2A-D4BD46CE0811&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*085ABFE2-D753-445C-8A2A-D4BD46CE0811\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11268</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus ActiveX clsid access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.05.09.html</url>
      </rule>
      <rule>
        <bugtraq>23822</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3456</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|8|00|5|00|A|00|B|00|F|00|E|00|2|00|-|00|D|00|7|00|5|00|3|00|-|00|4|00|4|00|5|00|C|00|-|00|8|00|A|00|2|00|A|00|-|00|D|00|4|00|B|00|D|00|4|00|6|00|C|00|E|00|0|00|8|00|1|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11269</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus ActiveX clsid unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.05.09.html</url>
      </rule>
      <rule>
        <bugtraq>23822</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3456</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Symantec.Norton.AntiVirus.NAVOptions&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Symantec\.Norton\.AntiVirus\.NAVOptions\x22|\x27Symantec\.Norton\.AntiVirus\.NAVOptions\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Symantec\.Norton\.AntiVirus\.NAVOptions\x22|\x27Symantec\.Norton\.AntiVirus\.NAVOptions\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11270</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus ActiveX function call access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.05.09.html</url>
      </rule>
      <rule>
        <bugtraq>23822</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3456</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|02|y|00|m|00|a|00|n|00|t|00|e|00|c|00|.|00|N|00|o|00|r|00|t|00|o|00|n|00|.|00|A|00|n|00|t|00|i|00|V|00|i|00|r|00|u|00|s|00|.|00|N|00|A|00|V|00|O|00|p|00|t|00|i|00|o|00|n|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)S\x00y\x00m\x00a\x00n\x00t\x00e\x00c\x00.\x00N\x00o\x00r\x00t\x00o\x00n\x00.\x00A\x00n\x00t\x00i\x00V\x00i\x00r\x00u\x00s\x00.\x00N\x00A\x00V\x00O\x00p\x00t\x00i\x00o\x00n\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00y\x00m\x00a\x00n\x00t\x00e\x00c\x00.\x00N\x00o\x00r\x00t\x00o\x00n\x00.\x00A\x00n\x00t\x00i\x00V\x00i\x00r\x00u\x00s\x00.\x00N\x00A\x00V\x00O\x00p\x00t\x00i\x00o\x00n\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11271</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus ActiveX function call unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.05.09.html</url>
      </rule>
      <rule>
        <bugtraq>23914</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2A515FCD-C0E9-4F38-9C77-2949514366F2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2A515FCD-C0E9-4F38-9C77-2949514366F2\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11274</id>
        <msg>WEB-ACTIVEX RControl ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-10-rcontroldll-v-1210-denial-of.html</url>
      </rule>
      <rule>
        <bugtraq>23914</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|A|00|5|00|1|00|5|00|F|00|C|00|D|00|-|00|C|00|0|00|E|00|9|00|-|00|4|00|F|00|3|00|8|00|-|00|9|00|C|00|7|00|7|00|-|00|2|00|9|00|4|00|9|00|5|00|1|00|4|00|3|00|6|00|6|00|F|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11275</id>
        <msg>WEB-ACTIVEX RControl ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-10-rcontroldll-v-1210-denial-of.html</url>
      </rule>
      <rule>
        <bugtraq>23907</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2225E9BC-AFB3-4ED4-B20E-4F6CF1C39F8B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2225E9BC-AFB3-4ED4-B20E-4F6CF1C39F8B\s*}?\s*(?P=q3)(\s|&gt;).*(?P=id1)\s*\.\s*(SetInputFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2225E9BC-AFB3-4ED4-B20E-4F6CF1C39F8B\s*}?\s*(?P=q4)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetInputFile))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11276</id>
        <msg>WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>23907</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|2|00|5|00|E|00|9|00|B|00|C|00|-|00|A|00|F|00|B|00|3|00|-|00|4|00|E|00|D|00|4|00|-|00|B|00|2|00|0|00|E|00|-|00|4|00|F|00|6|00|C|00|F|00|1|00|C|00|3|00|9|00|F|00|8|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q5&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11277</id>
        <msg>WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23907</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AviFix.AviFixer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AviFix\.AviFixer\x22|\x27AviFix\.AviFixer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetInputFile\s*|.*(?P=v)\s*\.\s*SetInputFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AviFix\.AviFixer\x22|\x27AviFix\.AviFixer\x27)\s*\)(\s*\.\s*SetInputFile\s*|.*(?P=n)\s*\.\s*SetInputFile\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11278</id>
        <msg>WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>23907</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|v|00|i|00|F|00|i|00|x|00|.|00|A|00|v|00|i|00|F|00|i|00|x|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q6&gt;\x22|\x27|)A\x00v\x00i\x00F\x00i\x00x\x00.\x00A\x00v\x00i\x00F\x00i\x00x\x00e\x00r\x00(?P=q6)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)A\x00v\x00i\x00F\x00i\x00x\x00.\x00A\x00v\x00i\x00F\x00i\x00x\x00e\x00r\x00(?P=q7)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11279</id>
        <msg>WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;584B432E-E0BD-4A78-BD77-665591DA84BB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*584B432E-E0BD-4A78-BD77-665591DA84BB\s*}?\s*(?P=q8)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11280</id>
        <msg>WEB-ACTIVEX FlexLabel ActiveX clsid access</msg>
        <url>www.securityfocus.com/archive/1/468070</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|8|00|4|00|B|00|4|00|3|00|2|00|E|00|-|00|E|00|0|00|B|00|D|00|-|00|4|00|A|00|7|00|8|00|-|00|B|00|D|00|7|00|7|00|-|00|6|00|6|00|5|00|5|00|9|00|1|00|D|00|A|00|8|00|4|00|B|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q9&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q9)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11281</id>
        <msg>WEB-ACTIVEX FlexLabel ActiveX clsid unicode access</msg>
        <url>www.securityfocus.com/archive/1/468070</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FlexLabelControl.FlexLabel&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22FlexLabelControl\.FlexLabel\x22|\x27FlexLabelControl\.FlexLabel\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22FlexLabelControl\.FlexLabel\x22|\x27FlexLabelControl\.FlexLabel\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11282</id>
        <msg>WEB-ACTIVEX FlexLabel ActiveX function call access</msg>
        <url>www.securityfocus.com/archive/1/468070</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|l|00|e|00|x|00|L|00|a|00|b|00|e|00|l|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|.|00|F|00|l|00|e|00|x|00|L|00|a|00|b|00|e|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)F\x00l\x00e\x00x\x00L\x00a\x00b\x00e\x00l\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00F\x00l\x00e\x00x\x00L\x00a\x00b\x00e\x00l\x00(?P=q10)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q11&gt;\x22|\x27|)F\x00l\x00e\x00x\x00L\x00a\x00b\x00e\x00l\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00F\x00l\x00e\x00x\x00L\x00a\x00b\x00e\x00l\x00(?P=q11)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11283</id>
        <msg>WEB-ACTIVEX FlexLabel ActiveX function call unicode access</msg>
        <url>www.securityfocus.com/archive/1/468070</url>
      </rule>
      <rule>
        <bugtraq>23900</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BE604333-B029-44E6-8367-1566B0AD7084&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BE604333-B029-44E6-8367-1566B0AD7084\s*}?\s*(?P=q12)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11284</id>
        <msg>WEB-ACTIVEX AudioCDRipper ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>23900</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|E|00|6|00|0|00|4|00|3|00|3|00|3|00|-|00|B|00|0|00|2|00|9|00|-|00|4|00|4|00|E|00|6|00|-|00|8|00|3|00|6|00|7|00|-|00|1|00|5|00|6|00|6|00|B|00|0|00|A|00|D|00|7|00|0|00|8|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q13&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11285</id>
        <msg>WEB-ACTIVEX AudioCDRipper ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23900</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Audio_CD_Ripper_OCX.cAudioCDRipper&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Audio_CD_Ripper_OCX\.cAudioCDRipper\x22|\x27Audio_CD_Ripper_OCX\.cAudioCDRipper\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Audio_CD_Ripper_OCX\.cAudioCDRipper\x22|\x27Audio_CD_Ripper_OCX\.cAudioCDRipper\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11286</id>
        <msg>WEB-ACTIVEX AudioCDRipper ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>23900</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|u|00|d|00|i|00|o|00|_|00|C|00|D|00|_|00|R|00|i|00|p|00|p|00|e|00|r|00|_|00|O|00|C|00|X|00|.|00|c|00|A|00|u|00|d|00|i|00|o|00|C|00|D|00|R|00|i|00|p|00|p|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)A\x00u\x00d\x00i\x00o\x00_\x00C\x00D\x00_\x00R\x00i\x00p\x00p\x00e\x00r\x00_\x00O\x00C\x00X\x00.\x00c\x00A\x00u\x00d\x00i\x00o\x00C\x00D\x00R\x00i\x00p\x00p\x00e\x00r\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)A\x00u\x00d\x00i\x00o\x00_\x00C\x00D\x00_\x00R\x00i\x00p\x00p\x00e\x00r\x00_\x00O\x00C\x00X\x00.\x00c\x00A\x00u\x00d\x00i\x00o\x00C\x00D\x00R\x00i\x00p\x00p\x00e\x00r\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11287</id>
        <msg>WEB-ACTIVEX AudioCDRipper ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24793</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BA726BF9-ED2F-461B-9447-CD5C7D66CE8D&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA726BF9-ED2F-461B-9447-CD5C7D66CE8D\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteProfile|SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA726BF9-ED2F-461B-9447-CD5C7D66CE8D\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteProfile|SaveToFile))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11291</id>
        <msg>WEB-ACTIVEX Hewlett Packard HPQVWOCX.DL ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24793</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|7|00|2|00|6|00|B|00|F|00|9|00|-|00|E|00|D|00|2|00|F|00|-|00|4|00|6|00|1|00|B|00|-|00|9|00|4|00|4|00|7|00|-|00|C|00|D|00|5|00|C|00|7|00|D|00|6|00|6|00|C|00|E|00|8|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11292</id>
        <msg>WEB-ACTIVEX Hewlett Packard HPQVWOCX.DL ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23954</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0C3874AA-AB39-4B5E-A768-45F3CE6C6819&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0C3874AA-AB39-4B5E-A768-45F3CE6C6819\s*}?\s*(?P=q3)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveEnhWMF)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0C3874AA-AB39-4B5E-A768-45F3CE6C6819\s*}?\s*(?P=q4)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveEnhWMF))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11293</id>
        <msg>WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-13-id-automation-linear-barcode.html</url>
      </rule>
      <rule>
        <bugtraq>23954</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|C|00|3|00|8|00|7|00|4|00|A|00|A|00|-|00|A|00|B|00|3|00|9|00|-|00|4|00|B|00|5|00|E|00|-|00|A|00|7|00|6|00|8|00|-|00|4|00|5|00|F|00|3|00|C|00|E|00|6|00|C|00|6|00|8|00|1|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q5&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11294</id>
        <msg>WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-13-id-automation-linear-barcode.html</url>
      </rule>
      <rule>
        <bugtraq>23954</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IDAuto.BarCode&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22IDAuto\.BarCode\x22|\x27IDAuto\.BarCode\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveEnhWMF\s*|.*(?P=v)\s*\.\s*SaveEnhWMF\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IDAuto\.BarCode\x22|\x27IDAuto\.BarCode\x27)\s*\)(\s*\.\s*SaveEnhWMF\s*|.*(?P=n)\s*\.\s*SaveEnhWMF\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11295</id>
        <msg>WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-13-id-automation-linear-barcode.html</url>
      </rule>
      <rule>
        <bugtraq>23954</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|D|00|A|00|u|00|t|00|o|00|.|00|B|00|a|00|r|00|C|00|o|00|d|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q6&gt;\x22|\x27|)I\x00D\x00A\x00u\x00t\x00o\x00.\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x00(?P=q6)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)I\x00D\x00A\x00u\x00t\x00o\x00.\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x00(?P=q7)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11296</id>
        <msg>WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-13-id-automation-linear-barcode.html</url>
      </rule>
      <rule>
        <bugtraq>23969</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;24E0CD64-A8DE-4BE4-9706-4CFC89D212C9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24E0CD64-A8DE-4BE4-9706-4CFC89D212C9\s*}?\s*(?P=q8)(\s|&gt;).*(?P=id1)\s*\.\s*(ConnectToDatabase)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24E0CD64-A8DE-4BE4-9706-4CFC89D212C9\s*}?\s*(?P=q9)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(ConnectToDatabase))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11297</id>
        <msg>WEB-ACTIVEX Clever Database Comparer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-14-clever-database-comparer.html</url>
      </rule>
      <rule>
        <bugtraq>23969</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|4|00|E|00|0|00|C|00|D|00|6|00|4|00|-|00|A|00|8|00|D|00|E|00|-|00|4|00|B|00|E|00|4|00|-|00|9|00|7|00|0|00|6|00|-|00|4|00|C|00|F|00|C|00|8|00|9|00|D|00|2|00|1|00|2|00|C|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q10&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11298</id>
        <msg>WEB-ACTIVEX Clever Database Comparer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-14-clever-database-comparer.html</url>
      </rule>
      <rule>
        <bugtraq>23969</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;comparerax.IBDBExtract&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22comparerax\.IBDBExtract\x22|\x27comparerax\.IBDBExtract\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*ConnectToDatabase\s*|.*(?P=v)\s*\.\s*ConnectToDatabase\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22comparerax\.IBDBExtract\x22|\x27comparerax\.IBDBExtract\x27)\s*\)(\s*\.\s*ConnectToDatabase\s*|.*(?P=n)\s*\.\s*ConnectToDatabase\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11299</id>
        <msg>WEB-ACTIVEX Clever Database Comparer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-14-clever-database-comparer.html</url>
      </rule>
      <rule>
        <bugtraq>23969</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c|00|o|00|m|00|p|00|a|00|r|00|e|00|r|00|a|00|x|00|.|00|I|00|B|00|D|00|B|00|E|00|x|00|t|00|r|00|a|00|c|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q11&gt;\x22|\x27|)c\x00o\x00m\x00p\x00a\x00r\x00e\x00r\x00a\x00x\x00.\x00I\x00B\x00D\x00B\x00E\x00x\x00t\x00r\x00a\x00c\x00t\x00(?P=q11)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)c\x00o\x00m\x00p\x00a\x00r\x00e\x00r\x00a\x00x\x00.\x00I\x00B\x00D\x00B\x00E\x00x\x00t\x00r\x00a\x00c\x00t\x00(?P=q12)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11300</id>
        <msg>WEB-ACTIVEX Clever Database Comparer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-14-clever-database-comparer.html</url>
      </rule>
      <rule>
        <bugtraq>23986</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;90403303-EF21-4771-A41A-651089892EDD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*90403303-EF21-4771-A41A-651089892EDD\s*}?\s*(?P=q13)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*90403303-EF21-4771-A41A-651089892EDD\s*}?\s*(?P=q14)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11301</id>
        <msg>WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>23986</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|0|00|4|00|0|00|3|00|3|00|0|00|3|00|-|00|E|00|F|00|2|00|1|00|-|00|4|00|7|00|7|00|1|00|-|00|A|00|4|00|1|00|A|00|-|00|6|00|5|00|1|00|0|00|8|00|9|00|8|00|9|00|2|00|E|00|D|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q15&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q15)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11302</id>
        <msg>WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>23986</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DEWizardAX.DEWizardX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DEWizardAX\.DEWizardX\x22|\x27DEWizardAX\.DEWizardX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=v)\s*\.\s*SaveToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DEWizardAX\.DEWizardX\x22|\x27DEWizardAX\.DEWizardX\x27)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=n)\s*\.\s*SaveToFile\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11303</id>
        <msg>WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>23986</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|E|00|W|00|i|00|z|00|a|00|r|00|d|00|A|00|X|00|.|00|D|00|E|00|W|00|i|00|z|00|a|00|r|00|d|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)D\x00E\x00W\x00i\x00z\x00a\x00r\x00d\x00A\x00X\x00.\x00D\x00E\x00W\x00i\x00z\x00a\x00r\x00d\x00X\x00(?P=q16)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)D\x00E\x00W\x00i\x00z\x00a\x00r\x00d\x00A\x00X\x00.\x00D\x00E\x00W\x00i\x00z\x00a\x00r\x00d\x00X\x00(?P=q17)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11304</id>
        <msg>WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0942</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ID2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ID2\x22|\x27ID2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ID2\x22|\x27ID2\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11324</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX function call access</msg>
        <url>www.xsec.org/index.php?module=releases&amp;act=view&amp;type=1&amp;id=9</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0942</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|D|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)I\x00D\x002\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00D\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11325</id>
        <msg>WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX function call unicode access</msg>
        <url>www.xsec.org/index.php?module=releases&amp;act=view&amp;type=1&amp;id=9</url>
      </rule>
      <rule>
        <bugtraq>23866</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2508</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3628</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; content:&quot;|00 00 14 00 1F 00|&quot;; within:6; distance:20; isdataat:100,relative; content:!&quot;|00 00|&quot;; within:96; distance:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>11618</id>
        <msg>EXPLOIT Trend Micro ServerProtect EarthAgent DCE-RPC Stack overflow</msg>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3147</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DCE2F8B1-A520-11D4-8FD0-00D0B7730277&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DCE2F8B1-A520-11D4-8FD0-00D0B7730277\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(server)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DCE2F8B1-A520-11D4-8FD0-00D0B7730277\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(server))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11822</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Upload ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3147</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|C|00|E|00|2|00|F|00|8|00|B|00|1|00|-|00|A|00|5|00|2|00|0|00|-|00|1|00|1|00|D|00|4|00|-|00|8|00|F|00|D|00|0|00|-|00|0|00|0|00|D|00|0|00|B|00|7|00|7|00|3|00|0|00|2|00|7|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11823</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Upload ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3147</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YWcUpl.WcUpload&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YWcUpl\.WcUpload\x22|\x27YWcUpl\.WcUpload\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*server\s*|.*(?P=v)\s*\.\s*server\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YWcUpl\.WcUpload\x22|\x27YWcUpl\.WcUpload\x27)\s*\)(\s*\.\s*server\s*|.*(?P=n)\s*\.\s*server)\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11824</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Upload ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3147</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|W|00|c|00|U|00|p|00|l|00|.|00|W|00|c|00|U|00|p|00|l|00|o|00|a|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)Y\x00W\x00c\x00U\x00p\x00l\x00.\x00W\x00c\x00U\x00p\x00l\x00o\x00a\x00d\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)Y\x00W\x00c\x00U\x00p\x00l\x00.\x00W\x00c\x00U\x00p\x00l\x00o\x00a\x00d\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11825</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Upload ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C26D9CA8-6747-11D5-AD4B-C01857C10000&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C26D9CA8-6747-11D5-AD4B-C01857C10000\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BeginPrint)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C26D9CA8-6747-11D5-AD4B-C01857C10000\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BeginPrint))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12010</id>
        <msg>WEB-ACTIVEX RKD Software BarCode ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|2|00|6|00|D|00|9|00|C|00|A|00|8|00|-|00|6|00|7|00|4|00|7|00|-|00|1|00|1|00|D|00|5|00|-|00|A|00|D|00|4|00|B|00|-|00|C|00|0|00|1|00|8|00|5|00|7|00|C|00|1|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12011</id>
        <msg>WEB-ACTIVEX RKD Software BarCode ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ABarCode.ActiveBC&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ABarCode\.ActiveBC\x22|\x27ABarCode\.ActiveBC\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*BeginPrint\s*|.*(?P=v)\s*\.\s*BeginPrint\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ABarCode\.ActiveBC\x22|\x27ABarCode\.ActiveBC\x27)\s*\)(\s*\.\s*BeginPrint\s*|.*(?P=n)\s*\.\s*BeginPrint\s*)\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12012</id>
        <msg>WEB-ACTIVEX RKD Software BarCode ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|B|00|a|00|r|00|C|00|o|00|d|00|e|00|.|00|A|00|c|00|t|00|i|00|v|00|e|00|B|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00B\x00C\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00B\x00C\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12013</id>
        <msg>WEB-ACTIVEX RKD Software BarCode ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-0040</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [389,3268]</filter1>
        <filter2>flow:to_server,established; content:&quot;0&quot;; depth:1; content:&quot;|66 84|&quot;; within:12; byte_test:4,&gt;,0x0F0000,0,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12069</id>
        <msg>EXPLOIT Microsoft Windows Active Directory Crafted LDAP ModifyRequest</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-039.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 443</filter1>
        <filter2>flow:to_server,established; content:&quot;|99 F3 00 00 00 00 00 00 FF FF FF FF|&quot;; depth:12; flowbits:set,AccessRemotePC_RPCdetection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12144</id>
        <msg>BACKDOOR access remote pc runtime detection - rpc setup</msg>
      </rule>
      <rule>
        <bugtraq>24653</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-2798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [749,1024:]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 08|@&quot;; depth:4; offset:16; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,8192,4,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12187</id>
        <msg>RPC portmap 2112 tcp rename_principal attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-005.txt</url>
      </rule>
      <rule>
        <bugtraq>24653</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-2798</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [749,1024:]</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 08|@&quot;; depth:4; offset:12; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,8192,4,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12188</id>
        <msg>RPC portmap 2112 udp rename_principal attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-005.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1442</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;substringData&quot;; nocase; pcre:&quot;/\w+\.substringData\([^\),]+,\s*(\d{4,}|25[7-9]|2[6-9][0-9]|[3-9][0-9]{2}|0x0*([1-9a-f][1-9a-f]{3,}|[2-9a-f][0-9a-f]{2}|1([0-9a-f][0-9a-f]|0[1-9a-f])))/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12279</id>
        <msg>WEB-CLIENT Microsoft XML substringData integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-031.mspx</url>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|08 05 03 00|&quot;; within:4; byte_test:4,&gt;,528,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12307</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetPagerNotifyConfig attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|00 1F 00|&quot;; within:3; distance:1; byte_test:4,&gt;,512,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12317</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect-earthagent RPCFN_CopyAUSrc attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|0C 01 03 00|&quot;; within:4; byte_test:4,&gt;,512,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12326</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _AddTaskExportLogItem attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;D|00 03 00|&quot;; within:4; byte_test:4,&gt;,520,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12332</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _TakeActionOnAFile attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; pcre:&quot;/^(\x10|\x0d)/Rs&quot;; content:&quot;|00 03 00|&quot;; within:3; byte_test:4,&gt;,38,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>12335</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_30010 overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;0|00 0A 00|&quot;; within:4; byte_test:4,&gt;,260,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12341</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_a0030 attempt</msg>
      </rule>
      <rule>
        <bugtraq>25395</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-4218</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|10 00 0A 00|&quot;; within:4; byte_test:4,&gt;,520,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12347</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetSvcImpersonateUser attempt</msg>
      </rule>
      <rule>
        <bugtraq>1163</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0347</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;BEAVIS&quot;; content:&quot;yep yep&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-recon;</filter2>
        <id>1239</id>
        <msg>NETBIOS RFParalyze Attempt</msg>
        <nessus>10392</nessus>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CF9DEB90-8DE3-11D5-BAE4-00105AAAFF94&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CF9DEB90-8DE3-11D5-BAE4-00105AAAFF94\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CF9DEB90-8DE3-11D5-BAE4-00105AAAFF94\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12393</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|9|00|D|00|E|00|B|00|9|00|0|00|-|00|8|00|D|00|E|00|3|00|-|00|1|00|1|00|D|00|5|00|-|00|B|00|A|00|E|00|4|00|-|00|0|00|0|00|1|00|0|00|5|00|A|00|A|00|A|00|F|00|F|00|9|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12394</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4F720B9C-24B1-4948-A035-8853DC01F19E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4F720B9C-24B1-4948-A035-8853DC01F19E\s*}?\s*(?P=q7)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4F720B9C-24B1-4948-A035-8853DC01F19E\s*}?\s*(?P=q8)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12395</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|F|00|7|00|2|00|0|00|B|00|9|00|C|00|-|00|2|00|4|00|B|00|1|00|-|00|4|00|9|00|4|00|8|00|-|00|A|00|0|00|3|00|5|00|-|00|8|00|8|00|5|00|3|00|D|00|C|00|0|00|1|00|F|00|1|00|9|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q9&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q9)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12396</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2EFF8C97-F2A8-4395-9F47-9A06F998BF88&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2EFF8C97-F2A8-4395-9F47-9A06F998BF88\s*}?\s*(?P=q10)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2EFF8C97-F2A8-4395-9F47-9A06F998BF88\s*}?\s*(?P=q11)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12397</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|E|00|F|00|F|00|8|00|C|00|9|00|7|00|-|00|F|00|2|00|A|00|8|00|-|00|4|00|3|00|9|00|5|00|-|00|9|00|F|00|4|00|7|00|-|00|9|00|A|00|0|00|6|00|F|00|9|00|9|00|8|00|B|00|F|00|8|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q12&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12398</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2CC3D8DE-18BF-43ff-8CB8-21B442300FD5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2CC3D8DE-18BF-43ff-8CB8-21B442300FD5\s*}?\s*(?P=q13)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2CC3D8DE-18BF-43ff-8CB8-21B442300FD5\s*}?\s*(?P=q14)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12399</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|C|00|C|00|3|00|D|00|8|00|D|00|E|00|-|00|1|00|8|00|B|00|F|00|-|00|4|00|3|00|f|00|f|00|-|00|8|00|C|00|B|00|8|00|-|00|2|00|1|00|B|00|4|00|4|00|2|00|3|00|0|00|0|00|F|00|D|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q15&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q15)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12400</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DBB177CC-6908-4b53-9BEE-F1C697818D65&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DBB177CC-6908-4b53-9BEE-F1C697818D65\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DBB177CC-6908-4b53-9BEE-F1C697818D65\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12401</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|B|00|B|00|1|00|7|00|7|00|C|00|C|00|-|00|6|00|9|00|0|00|8|00|-|00|4|00|b|00|5|00|3|00|-|00|9|00|B|00|E|00|E|00|-|00|F|00|1|00|C|00|6|00|9|00|7|00|8|00|1|00|8|00|D|00|6|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q18&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12402</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A80D199B-CFDD-4da4-8C47-2310D5B8DD97&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A80D199B-CFDD-4da4-8C47-2310D5B8DD97\s*}?\s*(?P=q19)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q20&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A80D199B-CFDD-4da4-8C47-2310D5B8DD97\s*}?\s*(?P=q20)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12403</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 6 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|8|00|0|00|D|00|1|00|9|00|9|00|B|00|-|00|C|00|F|00|D|00|D|00|-|00|4|00|d|00|a|00|4|00|-|00|8|00|C|00|4|00|7|00|-|00|2|00|3|00|1|00|0|00|D|00|5|00|B|00|8|00|D|00|D|00|9|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q21&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q21)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12404</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 6 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0D3983A9-4E29-4f33-8313-DA22B29D3F87&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m15&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m15)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0D3983A9-4E29-4f33-8313-DA22B29D3F87\s*}?\s*(?P=q22)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q23&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0D3983A9-4E29-4f33-8313-DA22B29D3F87\s*}?\s*(?P=q23)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m16&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m16)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12405</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 7 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|D|00|3|00|9|00|8|00|3|00|A|00|9|00|-|00|4|00|E|00|2|00|9|00|-|00|4|00|f|00|3|00|3|00|-|00|8|00|3|00|1|00|3|00|-|00|D|00|A|00|2|00|2|00|B|00|2|00|9|00|D|00|3|00|F|00|8|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q24&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q24)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12406</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 7 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D92D7607-05D9-4dd8-B68B-D458948FB883&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m17&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m17)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D92D7607-05D9-4dd8-B68B-D458948FB883\s*}?\s*(?P=q25)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q26&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D92D7607-05D9-4dd8-B68B-D458948FB883\s*}?\s*(?P=q26)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m18&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m18)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12407</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 8 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|2|00|D|00|7|00|6|00|0|00|7|00|-|00|0|00|5|00|D|00|9|00|-|00|4|00|d|00|d|00|8|00|-|00|B|00|6|00|8|00|B|00|-|00|D|00|4|00|5|00|8|00|9|00|4|00|8|00|F|00|B|00|8|00|8|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q27&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q27)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12408</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 8 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8CE3BAE6-AB66-40b6-9019-41E5282FF1E2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m19&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m19)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q28&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8CE3BAE6-AB66-40b6-9019-41E5282FF1E2\s*}?\s*(?P=q28)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q29&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8CE3BAE6-AB66-40b6-9019-41E5282FF1E2\s*}?\s*(?P=q29)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m20&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m20)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12409</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 9 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|C|00|E|00|3|00|B|00|A|00|E|00|6|00|-|00|A|00|B|00|6|00|6|00|-|00|4|00|0|00|b|00|6|00|-|00|9|00|0|00|1|00|9|00|-|00|4|00|1|00|E|00|5|00|2|00|8|00|2|00|F|00|F|00|1|00|E|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q30&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q30)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12410</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 9 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;40F8967E-34A6-474a-837A-CEC1E7DAC54C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*40F8967E-34A6-474a-837A-CEC1E7DAC54C\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(httpGETToFile|httpPOSTFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*40F8967E-34A6-474a-837A-CEC1E7DAC54C\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(httpGETToFile|httpPOSTFromFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12411</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 10 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|0|00|F|00|8|00|9|00|6|00|7|00|E|00|-|00|3|00|4|00|A|00|6|00|-|00|4|00|7|00|4|00|a|00|-|00|8|00|3|00|7|00|A|00|-|00|C|00|E|00|C|00|1|00|E|00|7|00|D|00|A|00|C|00|5|00|4|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12412</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Edition 10 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EF28418F-FFB2-11D0-861A-00A0C903A97F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EF28418F-FFB2-11D0-861A-00A0C903A97F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(FoxDoCmd)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EF28418F-FFB2-11D0-861A-00A0C903A97F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(FoxDoCmd))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12417</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|F|00|2|00|8|00|4|00|1|00|8|00|F|00|-|00|F|00|F|00|B|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|6|00|1|00|A|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|3|00|A|00|9|00|7|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12418</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;fpolectl.fpolectl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22fpolectl\.fpolectl\x22|\x27fpolectl\.fpolectl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*FoxDoCmd\s*|.*(?P=v)\s*\.\s*FoxDoCmd\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22fpolectl\.fpolectl\x22|\x27fpolectl\.fpolectl\x27)\s*\)(\s*\.\s*FoxDoCmd\s*|.*(?P=n)\s*\.\s*FoxDoCmd\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12419</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|p|00|o|00|l|00|e|00|c|00|t|00|l|00|.|00|f|00|p|00|o|00|l|00|e|00|c|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)f\x00p\x00o\x00l\x00e\x00c\x00t\x00l\x00.\x00f\x00p\x00o\x00l\x00e\x00c\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)f\x00p\x00o\x00l\x00e\x00c\x00t\x00l\x00.\x00f\x00p\x00o\x00l\x00e\x00c\x00t\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12420</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25702</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4982</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3BB56637-651D-4D1D-AFA4-C0506F57EAF8&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3BB56637-651D-4D1D-AFA4-C0506F57EAF8\s*}?\s*(?P=q21)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAsBMP|SaveAsWMF)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3BB56637-651D-4D1D-AFA4-C0506F57EAF8\s*}?\s*(?P=q22)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\.(SaveAsBMP|SaveAsWMF))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12466</id>
        <msg>WEB-ACTIVEX MW6 Technologies QRCode ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25702</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4982</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|B|00|B|00|5|00|6|00|6|00|3|00|7|00|-|00|6|00|5|00|1|00|D|00|-|00|4|00|D|00|1|00|D|00|-|00|A|00|F|00|A|00|4|00|-|00|C|00|0|00|5|00|0|00|6|00|F|00|5|00|7|00|E|00|A|00|F|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q23&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00B\x00B\x005\x006\x006\x003\x007\x00-\x006\x005\x001\x00D\x00-\x004\x00D\x001\x00D\x00-\x00A\x00F\x00A\x004\x00-\x00C\x000\x005\x000\x006\x00F\x005\x007\x00E\x00A\x00F\x008\x00(}\x00)?(?P=q23)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12467</id>
        <msg>WEB-ACTIVEX MW6 Technologies QRCode ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-6723</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:6bffd098-a112-3610-9833-46c3f87e345a; dce_opnum:2; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; content:&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_test:4,&gt;,52428800,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>12489</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrWkstaGetInfo attempt</msg>
      </rule>
      <rule>
        <bugtraq>25697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4916</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F3F381A3-4795-41FF-8190-7AA2A8102F85&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F3F381A3-4795-41FF-8190-7AA2A8102F85\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(FindFile|ListFiles)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F3F381A3-4795-41FF-8190-7AA2A8102F85\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(FindFile|ListFiles))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12612</id>
        <msg>WEB-ACTIVEX Microsoft Windows MFC Library ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4916</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|3|00|F|00|3|00|8|00|1|00|A|00|3|00|-|00|4|00|7|00|9|00|5|00|-|00|4|00|1|00|F|00|F|00|-|00|8|00|1|00|9|00|0|00|-|00|7|00|A|00|A|00|2|00|A|00|8|00|1|00|0|00|2|00|F|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x003\x00F\x003\x008\x001\x00A\x003\x00-\x004\x007\x009\x005\x00-\x004\x001\x00F\x00F\x00-\x008\x001\x009\x000\x00-\x007\x00A\x00A\x002\x00A\x008\x001\x000\x002\x00F\x008\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12613</id>
        <msg>WEB-ACTIVEX Microsoft Windows MFC Library ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4916</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HpqUtil.System&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22HpqUtil\.System(\.\d)?\x22|\x27HpqUtil\.System(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(FindFile|ListFiles)\s*|.*(?P=v)\s*\.\s*(FindFile|ListFiles)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HpqUtil\.System(\.\d)?\x22|\x27HpqUtil\.System(\.\d)?\x27)\s*\)(\s*\.\s*(FindFile|ListFiles)\s*|.*(?P=n)\s*\.\s*(FindFile|ListFiles)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12614</id>
        <msg>WEB-ACTIVEX Microsoft Windows MFC Library ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4916</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;H|00|p|00|q|00|U|00|t|00|i|00|l|00|.|00|S|00|y|00|s|00|t|00|e|00|m|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)H\x00p\x00q\x00U\x00t\x00i\x00l\x00.\x00S\x00y\x00s\x00t\x00e\x00m\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)H\x00p\x00q\x00U\x00t\x00i\x00l\x00.\x00S\x00y\x00s\x00t\x00e\x00m\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12615</id>
        <msg>WEB-ACTIVEX Microsoft Windows MFC Library ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;BEGIN|3A|VCARD&quot;; fast_pattern:only; pcre:&quot;/^URL\x3b\w+\x3amailto\x3a[^\n]*%[^\n]*\.(cmd|bat)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12664</id>
        <msg>MISC Microsoft Windows ShellExecute and IE7 url handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|22|.bat&quot;; nocase; pcre:&quot;/(mailto|telnet|news|nntp|snews)\x3A[^\n]*\x25[^\n]*\x22\x2Ebat/i&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12687</id>
        <msg>WEB-CLIENT Microsoft Windows ShellExecute and IE7 url handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-061.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|22|.cmd&quot;; nocase; pcre:&quot;/(mailto|telnet|news|nntp|snews)\x3A[^\n]*\x25[^\n]*\x22\x2Ecmd/i&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12688</id>
        <msg>WEB-CLIENT Microsoft Windows ShellExecute and IE7 url handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-061.mspx</url>
      </rule>
      <rule>
        <bugtraq>26573</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;47F59200-8783-11D2-8343-00A0C945A819&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*47F59200-8783-11D2-8343-00A0C945A819\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DoInstall|QueryComponents)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*47F59200-8783-11D2-8343-00A0C945A819\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DoInstall|QueryComponents))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12751</id>
        <msg>WEB-ACTIVEX RichFX Basic Player ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26573</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|F|00|5|00|9|00|2|00|0|00|0|00|-|00|8|00|7|00|8|00|3|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|3|00|4|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|4|00|5|00|A|00|8|00|1|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12752</id>
        <msg>WEB-ACTIVEX RichFX Basic Player ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26573</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RFXInstMgr.RFXInstMgr&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22RFXInstMgr\.RFXInstMgr\x22|\x27RFXInstMgr\.RFXInstMgr\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoInstall|QueryComponents)\s*|.*(?P=v)\s*\.\s*(DoInstall|QueryComponents)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RFXInstMgr\.RFXInstMgr\x22|\x27RFXInstMgr\.RFXInstMgr\x27)\s*\)(\s*\.\s*(DoInstall|QueryComponents)\s*|.*(?P=n)\s*\.\s*(DoInstall|QueryComponents)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12753</id>
        <msg>WEB-ACTIVEX RichFX Basic Player ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26573</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;R|00|F|00|X|00|I|00|n|00|s|00|t|00|M|00|g|00|r|00|.|00|R|00|F|00|X|00|I|00|n|00|s|00|t|00|M|00|g|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)R\x00F\x00X\x00I\x00n\x00s\x00t\x00M\x00g\x00r\x00.\x00R\x00F\x00X\x00I\x00n\x00s\x00t\x00M\x00g\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)R\x00F\x00X\x00I\x00n\x00s\x00t\x00M\x00g\x00r\x00.\x00R\x00F\x00X\x00I\x00n\x00s\x00t\x00M\x00g\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12754</id>
        <msg>WEB-ACTIVEX RichFX Basic Player ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26580</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;20C2C286-BDE8-441B-B73D-AFA22D914DA5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*20C2C286-BDE8-441B-B73D-AFA22D914DA5\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SetBkImage)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*20C2C286-BDE8-441B-B73D-AFA22D914DA5\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SetBkImage))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12755</id>
        <msg>WEB-ACTIVEX PPStream PowerList ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26580</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|0|00|C|00|2|00|C|00|2|00|8|00|6|00|-|00|B|00|D|00|E|00|8|00|-|00|4|00|4|00|1|00|B|00|-|00|B|00|7|00|3|00|D|00|-|00|A|00|F|00|A|00|2|00|2|00|D|00|9|00|1|00|4|00|D|00|A|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12756</id>
        <msg>WEB-ACTIVEX PPStream PowerList ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26656</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;02478D38-C3F9-4EFB-9B51-7695ECA05670&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*02478D38-C3F9-4EFB-9B51-7695ECA05670\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(c)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*02478D38-C3F9-4EFB-9B51-7695ECA05670\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(c))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12762</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26656</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|2|00|4|00|7|00|8|00|D|00|3|00|8|00|-|00|C|00|3|00|F|00|9|00|-|00|4|00|E|00|F|00|B|00|-|00|9|00|B|00|5|00|1|00|-|00|7|00|6|00|9|00|5|00|E|00|C|00|A|00|0|00|5|00|6|00|7|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12763</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26656</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;yt.ythelper&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22yt\.ythelper\x22|\x27yt\.ythelper\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*c\s*|.*(?P=v)\s*\.\s*c\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22yt\.ythelper\x22|\x27yt\.ythelper\x27)\s*\)(\s*\.\s*c\s*|.*(?P=n)\s*\.\s*c\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12764</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26656</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;y|00|t|00|.|00|y|00|t|00|h|00|e|00|l|00|p|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)y\x00t\x00.\x00y\x00t\x00h\x00e\x00l\x00p\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)y\x00t\x00.\x00y\x00t\x00h\x00e\x00l\x00p\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12765</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>17462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0003</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00C04FC29E36|7C|983A|7C|11D0|7C|65A3|7C 7C|BD96C556|7C 7C|clsid&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12770</id>
        <msg>SPECIFIC-THREATS obfuscated RDS.Dataspace ActiveX exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>25601</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4816</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;storm.setAttribute|28 22|classid|22|,|22|clsid|3A|6BE52E1D-E586-474f-A6E2-1A85A9B4D9FB|22 29|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12771</id>
        <msg>SPECIFIC-THREATS obfuscated BaoFeng Storm MPS.dll ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>25502</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;pps.setAttribute|28 22|classid|22|,|22|clsid|3A|5EC7C511-CD0F-42E6-830C-1BD9882F3458|22 29|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12772</id>
        <msg>SPECIFIC-THREATS obfuscated PPStream PowerPlayer ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6144</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;object id=|22|gl|22| classid=|22|clsid|3A|F3E70CEA-956E-49CC-B444-73AFE593AD7F|22|&gt;&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12773</id>
        <msg>SPECIFIC-THREATS obfuscated Xunlei Thunder PPLAYER.DLL ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26244</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5722</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;object classid=|22|clsid|3A|AE93C5DF-A990-11D1-AEBD-5254ABDD2B69|22|&quot;; nocase; content:&quot;LoveVChenzi&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12774</id>
        <msg>SPECIFIC-THREATS obfuscated GlobalLink ConnectAndEnterRoom ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26675</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E23FE9C6-778E-49D4-B537-38FCDE4887D8&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E23FE9C6-778E-49D4-B537-38FCDE4887D8\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(addTarget|getVariable|setVariable)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E23FE9C6-778E-49D4-B537-38FCDE4887D8\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(addTarget|getVariable|setVariable))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12803</id>
        <msg>WEB-ACTIVEX VideoLAN VLC ActiveX clsid access</msg>
        <url>www.videolan.org/sa0703.html</url>
      </rule>
      <rule>
        <bugtraq>26675</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|2|00|3|00|F|00|E|00|9|00|C|00|6|00|-|00|7|00|7|00|8|00|E|00|-|00|4|00|9|00|D|00|4|00|-|00|B|00|5|00|3|00|7|00|-|00|3|00|8|00|F|00|C|00|D|00|E|00|4|00|8|00|8|00|7|00|D|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12804</id>
        <msg>WEB-ACTIVEX VideoLAN VLC ActiveX clsid unicode access</msg>
        <url>www.videolan.org/sa0703.html</url>
      </rule>
      <rule>
        <bugtraq>26675</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VideoLAN.VLCPlugin&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VideoLAN\.VLCPlugin\x22|\x27VideoLAN\.VLCPlugin\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(addTarget|getVariable|setVariable)\s*|.*(?P=v)\s*\.\s*(addTarget|getVariable|setVariable)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VideoLAN\.VLCPlugin\x22|\x27VideoLAN\.VLCPlugin\x27)\s*\)(\s*\.\s*(addTarget|getVariable|setVariable)\s*|.*(?P=n)\s*\.\s*(addTarget|getVariable|setVariable)\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12805</id>
        <msg>WEB-ACTIVEX VideoLAN VLC ActiveX function call access</msg>
        <url>www.videolan.org/sa0703.html</url>
      </rule>
      <rule>
        <bugtraq>26675</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|d|00|e|00|o|00|L|00|A|00|N|00|.|00|V|00|L|00|C|00|P|00|l|00|u|00|g|00|i|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00d\x00e\x00o\x00L\x00A\x00N\x00.\x00V\x00L\x00C\x00P\x00l\x00u\x00g\x00i\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00i\x00d\x00e\x00o\x00L\x00A\x00N\x00.\x00V\x00L\x00C\x00P\x00l\x00u\x00g\x00i\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12806</id>
        <msg>WEB-ACTIVEX VideoLAN VLC ActiveX function call unicode access</msg>
        <url>www.videolan.org/sa0703.html</url>
      </rule>
      <rule>
        <bugtraq>21220</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5854</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:1; dce_stub_data; byte_test:4,&gt;,458,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>12808</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss OpenPrinter overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-5329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:established,to_server; dce_iface:88435ee0-861a-11ce-b86b-00001b27f656; dce_opnum:4; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12910</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 4 attempt</msg>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-5329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:established,to_server; dce_iface:88435ee0-861a-11ce-b86b-00001b27f656; dce_opnum:12; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12916</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 12 attempt</msg>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-5329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:established,to_server; dce_iface:88435ee0-861a-11ce-b86b-00001b27f656; dce_opnum:16; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12922</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 16 attempt</msg>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-5329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:established,to_server; dce_iface:88435ee0-861a-11ce-b86b-00001b27f656; dce_opnum:18; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12928</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 18 attempt</msg>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-5329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:established,to_server; dce_iface:88435ee0-861a-11ce-b86b-00001b27f656; dce_opnum:19; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>12934</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 19 attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-5351</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; byte_test:1,&gt;,0xFD,4; content:&quot;SMBr&quot;; depth:4; offset:5; content:&quot;|02|SMB 2.001|00|&quot;; offset:36; metadata:policy security-ips alert, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>12946</id>
        <msg>NETBIOS SMB-DS SMBv2 protocol negotiation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-5351</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; byte_test:1,&gt;,0xFD,4; content:&quot;SMBr&quot;; depth:4; offset:5; content:&quot;|02|SMB 2.001|00|&quot;; offset:36; metadata:policy security-ips alert, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>12947</id>
        <msg>NETBIOS SMB SMBv2 protocol negotiation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c1908682-7b2c-4ab0-b98e-183649a0bf84&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*c1908682-7b2c-4ab0-b98e-183649a0bf84\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12948</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 1 ActiveX clsid access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c|00|1|00|9|00|0|00|8|00|6|00|8|00|2|00|-|00|7|00|b|00|2|00|c|00|-|00|4|00|a|00|b|00|0|00|-|00|b|00|9|00|8|00|e|00|-|00|1|00|8|00|3|00|6|00|4|00|9|00|a|00|0|00|b|00|f|00|8|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12949</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 1 ActiveX clsid unicode access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0f6a72b9-d3c5-4fce-89a3-4e3d19c3580a&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0f6a72b9-d3c5-4fce-89a3-4e3d19c3580a\s*}?\s*(?P=q3)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12950</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 2 ActiveX clsid access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|f|00|6|00|a|00|7|00|2|00|b|00|9|00|-|00|d|00|3|00|c|00|5|00|-|00|4|00|f|00|c|00|e|00|-|00|8|00|9|00|a|00|3|00|-|00|4|00|e|00|3|00|d|00|1|00|9|00|c|00|3|00|5|00|8|00|0|00|a|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q4&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12951</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 2 ActiveX clsid unicode access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;66b4546f-c263-11d1-b1c9-444553540000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*66b4546f-c263-11d1-b1c9-444553540000\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12952</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 3 ActiveX clsid access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|6|00|b|00|4|00|5|00|4|00|6|00|f|00|-|00|c|00|2|00|6|00|3|00|-|00|1|00|1|00|d|00|1|00|-|00|b|00|1|00|c|00|9|00|-|00|4|00|4|00|4|00|5|00|5|00|3|00|5|00|4|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12953</id>
        <msg>WEB-ACTIVEX Vantage Linguistics 3 ActiveX clsid unicode access</msg>
        <url>www.vantagelinguistics.com/answerworks/release/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;201ea564-a6f6-11d1-811d-00c04fb6db36&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*201ea564-a6f6-11d1-811d-00c04fb6db36\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12954</id>
        <msg>WEB-ACTIVEX DXLTPI.DLL ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|0|00|1|00|e|00|a|00|5|00|6|00|4|00|-|00|a|00|6|00|f|00|6|00|-|00|1|00|1|00|d|00|1|00|-|00|8|00|1|00|1|00|d|00|-|00|0|00|0|00|c|00|0|00|4|00|f|00|b|00|6|00|d|00|b|00|3|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12955</id>
        <msg>WEB-ACTIVEX DXLTPI.DLL ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>11367</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|5|00|D|00|4|00|1|00|9|00|D|00|6|00|-|00|A|00|8|00|4|00|6|00|-|00|4|00|5|00|1|00|4|00|-|00|9|00|F|00|A|00|D|00|-|00|9|00|7|00|E|00|8|00|2|00|6|00|C|00|8|00|4|00|8|00|2|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12956</id>
        <msg>WEB-ACTIVEX MSN Heartbeat ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8c63daba-cba8-4b5d-a0f7-ae00f2920929&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8c63daba-cba8-4b5d-a0f7-ae00f2920929\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12957</id>
        <msg>WEB-ACTIVEX MSN Heartbeat 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|c|00|6|00|3|00|d|00|a|00|b|00|a|00|-|00|c|00|b|00|a|00|8|00|-|00|4|00|b|00|5|00|d|00|-|00|a|00|0|00|f|00|7|00|-|00|a|00|e|00|0|00|0|00|f|00|2|00|9|00|2|00|0|00|9|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12958</id>
        <msg>WEB-ACTIVEX MSN Heartbeat 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ae1c01e3-0283-11d3-9b3f-00c04f8ef466&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*ae1c01e3-0283-11d3-9b3f-00c04f8ef466\s*}?\s*(?P=q3)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12959</id>
        <msg>WEB-ACTIVEX MSN Heartbeat 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;a|00|e|00|1|00|c|00|0|00|1|00|e|00|3|00|-|00|0|00|2|00|8|00|3|00|-|00|1|00|1|00|d|00|3|00|-|00|9|00|b|00|3|00|f|00|-|00|0|00|0|00|c|00|0|00|4|00|f|00|8|00|e|00|f|00|4|00|6|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q4&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12960</id>
        <msg>WEB-ACTIVEX MSN Heartbeat 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AD5FBDB8-C518-47F7-B4F1-F1F58D21A716&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AD5FBDB8-C518-47F7-B4F1-F1F58D21A716\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12961</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|D|00|5|00|F|00|B|00|D|00|B|00|8|00|-|00|C|00|5|00|1|00|8|00|-|00|4|00|7|00|F|00|7|00|-|00|B|00|4|00|F|00|1|00|-|00|F|00|1|00|F|00|5|00|8|00|D|00|2|00|1|00|A|00|7|00|1|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12962</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;121E91E7-E915-4aa6-89F3-BA62D10A4C49&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*121E91E7-E915-4aa6-89F3-BA62D10A4C49\s*}?\s*(?P=q3)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12963</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|2|00|1|00|E|00|9|00|1|00|E|00|7|00|-|00|E|00|9|00|1|00|5|00|-|00|4|00|a|00|a|00|6|00|-|00|8|00|9|00|F|00|3|00|-|00|B|00|A|00|6|00|2|00|D|00|1|00|0|00|A|00|4|00|C|00|4|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q4&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12964</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C3C9CB67-F453-479a-9AB0-94AE65F2EB2F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C3C9CB67-F453-479a-9AB0-94AE65F2EB2F\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12965</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|3|00|C|00|9|00|C|00|B|00|6|00|7|00|-|00|F|00|4|00|5|00|3|00|-|00|4|00|7|00|9|00|a|00|-|00|9|00|A|00|B|00|0|00|-|00|9|00|4|00|A|00|E|00|6|00|5|00|F|00|2|00|E|00|B|00|2|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12966</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF54BFA2-474E-4b82-A5F3-B79E6F7A80B1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AF54BFA2-474E-4b82-A5F3-B79E6F7A80B1\s*}?\s*(?P=q7)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12967</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|5|00|4|00|B|00|F|00|A|00|2|00|-|00|4|00|7|00|4|00|E|00|-|00|4|00|b|00|8|00|2|00|-|00|A|00|5|00|F|00|3|00|-|00|B|00|7|00|9|00|E|00|6|00|F|00|7|00|A|00|8|00|0|00|B|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12968</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;823AA622-D72B-42d4-905D-FDD9FC9600FC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*823AA622-D72B-42d4-905D-FDD9FC9600FC\s*}?\s*(?P=q9)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12969</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|2|00|3|00|A|00|A|00|6|00|2|00|2|00|-|00|D|00|7|00|2|00|B|00|-|00|4|00|2|00|d|00|4|00|-|00|9|00|0|00|5|00|D|00|-|00|F|00|D|00|D|00|9|00|F|00|C|00|9|00|6|00|0|00|0|00|F|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q10&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12970</id>
        <msg>WEB-ACTIVEX Intuit QuickBooks Online Import 5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3895</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RIFF&quot;; pcre:&quot;/(idx1|movi|str[ndfhl]|avih|hdr1|LIST|JUNK)/&quot;; byte_test:4,&gt;,4294967286,0,little,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12971</id>
        <msg>EXPLOIT microsoft directshow wav file overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-064.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|01 CD 87 F4|Q|A9 CF 11 8E E6 00 C0 0C| Se&quot;; content:&quot; |DB FE|L|F6|u|CF 11 9C 0F 00 A0 C9 03|I|CB|&quot;; within:16; distance:8; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12972</id>
        <msg>WEB-CLIENT Microsoft Media Player .asf markers detected</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;35907DE0-E415-11CF-A917-00805F5C442B&quot;; byte_test:2, &gt;, 65476, 52, relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13158</id>
        <msg>WEB_CLIENT Microsoft Media Player asf streaming format interchange data integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;49F1A440-4ECE-11d0-A3AC-00A0C90348F6&quot;; byte_jump:4, 8, relative; byte_test:2, &gt;, 65527, 14, relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13159</id>
        <msg>WEB_CLIENT Microsoft Media Player asf streaming format audio error masking integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-068.mspx</url>
      </rule>
      <rule>
        <bugtraq>21220</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6114</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>13162</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26950</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6506</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7CB9D4F5-C492-42A4-93B1-3F7D6946470D&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7CB9D4F5-C492-42A4-93B1-3F7D6946470D\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile|LoadFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7CB9D4F5-C492-42A4-93B1-3F7D6946470D\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveToFile|LoadFromFile))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13219</id>
        <msg>WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26950</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6506</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|C|00|B|00|9|00|D|00|4|00|F|00|5|00|-|00|C|00|4|00|9|00|2|00|-|00|4|00|2|00|A|00|4|00|-|00|9|00|3|00|B|00|1|00|-|00|3|00|F|00|7|00|D|00|6|00|9|00|4|00|6|00|4|00|7|00|0|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00C\x00B\x009\x00D\x004\x00F\x005\x00-\x00C\x004\x009\x002\x00-\x004\x002\x00A\x004\x00-\x009\x003\x00B\x001\x00-\x003\x00F\x007\x00D\x006\x009\x004\x006\x004\x007\x000\x00D\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13220</id>
        <msg>WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26956</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6535</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;67CE97C5-ABE6-429A-B6BD-3BD1333A0825&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67CE97C5-ABE6-429A-B6BD-3BD1333A0825\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(IsTaggedBM)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67CE97C5-ABE6-429A-B6BD-3BD1333A0825\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(IsTaggedBM))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13224</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26956</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6535</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|C|00|E|00|9|00|7|00|C|00|5|00|-|00|A|00|B|00|E|00|6|00|-|00|4|00|2|00|9|00|A|00|-|00|B|00|6|00|B|00|D|00|-|00|3|00|B|00|D|00|1|00|3|00|3|00|3|00|A|00|0|00|8|00|2|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13225</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26956</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6535</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YShortcut_DLL.Shortcut&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YShortcut_DLL\.Shortcut\x22|\x27YShortcut_DLL\.Shortcut\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*IsTaggedBM\s*|.*(?P=v)\s*\.\s*IsTaggedBM\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YShortcut_DLL\.Shortcut\x22|\x27YShortcut_DLL\.Shortcut\x27)\s*\)(\s*\.\s*IsTaggedBM\s*|.*(?P=n)\s*\.\s*IsTaggedBM\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13226</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26956</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6535</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|S|00|h|00|o|00|r|00|t|00|c|00|u|00|t|00|_|00|D|00|L|00|L|00|.|00|S|00|h|00|o|00|r|00|t|00|c|00|u|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Y\x00S\x00h\x00o\x00r\x00t\x00c\x00u\x00t\x00_\x00D\x00L\x00L\x00.\x00S\x00h\x00o\x00r\x00t\x00c\x00u\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Y\x00S\x00h\x00o\x00r\x00t\x00c\x00u\x00t\x00_\x00D\x00L\x00L\x00.\x00S\x00h\x00o\x00r\x00t\x00c\x00u\x00t\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13227</id>
        <msg>WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F3 E1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13250</id>
        <msg>RPC portmap 390113 tcp request</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F3 E1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13251</id>
        <msg>RPC portmap 390113 udp request</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 05 F3 E1|&quot;; depth:4; offset:16; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;sn_sub_rqst&quot;; within:11; distance:12; byte_test:4,&gt;,234,5,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13252</id>
        <msg>RPC portmap 390113 tcp procedure 4 attempt</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 05 F3 E1|&quot;; depth:4; offset:12; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;sn_sub_rqst&quot;; within:11; distance:12; byte_test:4,&gt;,234,5,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13253</id>
        <msg>RPC portmap 390113 udp procedure 4 attempt</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F3 E1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13254</id>
        <msg>RPC portmap 390113 tcp request</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F3 E1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13255</id>
        <msg>RPC portmap 390113 udp request</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 05 F3 E1|&quot;; depth:4; offset:16; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;sn_sub_rqst&quot;; within:11; distance:12; byte_test:4,&gt;,234,5,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13256</id>
        <msg>RPC portmap 390113 tcp procedure 5 attempt</msg>
      </rule>
      <rule>
        <bugtraq>25375</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-3618</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 05 F3 E1|&quot;; depth:4; offset:12; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;sn_sub_rqst&quot;; within:11; distance:12; byte_test:4,&gt;,234,5,relative; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13257</id>
        <msg>RPC portmap 390113 udp procedure 5 attempt</msg>
      </rule>
      <rule>
        <bugtraq>27059</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F84E0B64-1E86-4640-8094-5B38CEB28C1E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F84E0B64-1E86-4640-8094-5B38CEB28C1E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F84E0B64-1E86-4640-8094-5B38CEB28C1E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(start))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13266</id>
        <msg>WEB-ACTIVEX SkyFex Client ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27059</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|8|00|4|00|E|00|0|00|B|00|6|00|4|00|-|00|1|00|E|00|8|00|6|00|-|00|4|00|6|00|4|00|0|00|-|00|8|00|0|00|9|00|4|00|-|00|5|00|B|00|3|00|8|00|C|00|E|00|B|00|2|00|8|00|C|00|1|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13267</id>
        <msg>WEB-ACTIVEX SkyFex Client ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27106</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D050D736-2D21-4723-AD58-5B541FFB6C11&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D050D736-2D21-4723-AD58-5B541FFB6C11\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetPassword)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D050D736-2D21-4723-AD58-5B541FFB6C11\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetPassword))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13273</id>
        <msg>WEB-ACTIVEX DivX Web Player ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27106</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|0|00|5|00|0|00|D|00|7|00|3|00|6|00|-|00|2|00|D|00|2|00|1|00|-|00|4|00|7|00|2|00|3|00|-|00|A|00|D|00|5|00|8|00|-|00|5|00|B|00|5|00|4|00|1|00|F|00|F|00|B|00|6|00|C|00|1|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13274</id>
        <msg>WEB-ACTIVEX DivX Web Player ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27106</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;npUpload.DivXContentUploadPlugin&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22npUpload\.DivXContentUploadPlugin\x22|\x27npUpload\.DivXContentUploadPlugin\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetPassword\s*|.*(?P=v)\s*\.\s*SetPassword\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22npUpload\.DivXContentUploadPlugin\x22|\x27npUpload\.DivXContentUploadPlugin\x27)\s*\)(\s*\.\s*SetPassword\s*|.*(?P=n)\s*\.\s*SetPassword\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13275</id>
        <msg>WEB-ACTIVEX DivX Web Player ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27106</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;n|00|p|00|U|00|p|00|l|00|o|00|a|00|d|00|.|00|D|00|i|00|v|00|X|00|C|00|o|00|n|00|t|00|e|00|n|00|t|00|U|00|p|00|l|00|o|00|a|00|d|00|P|00|l|00|u|00|g|00|i|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)n\x00p\x00U\x00p\x00l\x00o\x00a\x00d\x00.\x00D\x00i\x00v\x00X\x00C\x00o\x00n\x00t\x00e\x00n\x00t\x00U\x00p\x00l\x00o\x00a\x00d\x00P\x00l\x00u\x00g\x00i\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)n\x00p\x00U\x00p\x00l\x00o\x00a\x00d\x00.\x00D\x00i\x00v\x00X\x00C\x00o\x00n\x00t\x00e\x00n\x00t\x00U\x00p\x00l\x00o\x00a\x00d\x00P\x00l\x00u\x00g\x00i\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13276</id>
        <msg>WEB-ACTIVEX DivX Web Player ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27193</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0220</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;93CEA8A4-6059-4E0B-ADDD-73848153DD5E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*93CEA8A4-6059-4E0B-ADDD-73848153DD5E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DoWebLaunch)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*93CEA8A4-6059-4E0B-ADDD-73848153DD5E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DoWebLaunch))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13289</id>
        <msg>WEB-ACTIVEX Gatway CWebLaunchCtl ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/735441</url>
      </rule>
      <rule>
        <bugtraq>27193</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0220</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|3|00|C|00|E|00|A|00|8|00|A|00|4|00|-|00|6|00|0|00|5|00|9|00|-|00|4|00|E|00|0|00|B|00|-|00|A|00|D|00|D|00|D|00|-|00|7|00|3|00|8|00|4|00|8|00|1|00|5|00|3|00|D|00|D|00|5|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13290</id>
        <msg>WEB-ACTIVEX Gatway CWebLaunchCtl ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/735441</url>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B617B991-A767-4F05-99BA-AC6FCABB102E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B617B991-A767-4F05-99BA-AC6FCABB102E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B617B991-A767-4F05-99BA-AC6FCABB102E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveFile))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13294</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|6|00|1|00|7|00|B|00|9|00|9|00|1|00|-|00|A|00|7|00|6|00|7|00|-|00|4|00|F|00|0|00|5|00|-|00|9|00|9|00|B|00|A|00|-|00|A|00|C|00|6|00|F|00|C|00|A|00|B|00|B|00|1|00|0|00|2|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13295</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3B7C8860-D78F-101B-B9B5-04021C009402&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B7C8860-D78F-101B-B9B5-04021C009402\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B7C8860-D78F-101B-B9B5-04021C009402\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveFile))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13296</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|B|00|7|00|C|00|8|00|8|00|6|00|0|00|-|00|D|00|7|00|8|00|F|00|-|00|1|00|0|00|1|00|B|00|-|00|B|00|9|00|B|00|5|00|-|00|0|00|4|00|0|00|2|00|1|00|C|00|0|00|0|00|9|00|4|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13297</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RICHTEXT.RichTextCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22RICHTEXT\.RichTextCtrl\x22|\x27RICHTEXT\.RichTextCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveFile\s*|.*(?P=v)\s*\.\s*SaveFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RICHTEXT\.RichTextCtrl\x22|\x27RICHTEXT\.RichTextCtrl\x27)\s*\)(\s*\.\s*SaveFile\s*|.*(?P=n)\s*\.\s*SaveFile\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13298</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27201</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;R|00|I|00|C|00|H|00|T|00|E|00|X|00|T|00|.|00|R|00|i|00|c|00|h|00|T|00|e|00|x|00|t|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)R\x00I\x00C\x00H\x00T\x00E\x00X\x00T\x00.\x00R\x00i\x00c\x00h\x00T\x00e\x00x\x00t\x00C\x00t\x00r\x00l\x00(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)R\x00I\x00C\x00H\x00T\x00E\x00X\x00T\x00.\x00R\x00i\x00c\x00h\x00T\x00e\x00x\x00t\x00C\x00t\x00r\x00l\x00(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13299</id>
        <msg>WEB-ACTIVEX Microsoft Rich TextBox ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;008B6010-1F3D-11D1-B0C8-00A0C9055D74&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*008B6010-1F3D-11D1-B0C8-00A0C9055D74\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DoCmd)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*008B6010-1F3D-11D1-B0C8-00A0C9055D74\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DoCmd))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13303</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|8|00|B|00|6|00|0|00|1|00|0|00|-|00|1|00|F|00|3|00|D|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|0|00|C|00|8|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|5|00|5|00|D|00|7|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13304</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VisualFoxpro.Application&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VisualFoxpro\.Application\x22|\x27VisualFoxpro\.Application\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DoCmd\s*|.*(?P=v)\s*\.\s*DoCmd\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VisualFoxpro\.Application\x22|\x27VisualFoxpro\.Application\x27)\s*\)(\s*\.\s*DoCmd\s*|.*(?P=n)\s*\.\s*DoCmd\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13305</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|s|00|u|00|a|00|l|00|F|00|o|00|x|00|p|00|r|00|o|00|.|00|A|00|p|00|p|00|l|00|i|00|c|00|a|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00s\x00u\x00a\x00l\x00F\x00o\x00x\x00p\x00r\x00o\x00.\x00A\x00p\x00p\x00l\x00i\x00c\x00a\x00t\x00i\x00o\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00i\x00s\x00u\x00a\x00l\x00F\x00o\x00x\x00p\x00r\x00o\x00.\x00A\x00p\x00p\x00l\x00i\x00c\x00a\x00t\x00i\x00o\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13306</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2253F320-AB68-4A07-917D-4F12D8884A06&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2253F320-AB68-4A07-917D-4F12D8884A06\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(InternalTuneIn)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2253F320-AB68-4A07-917D-4F12D8884A06\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(InternalTuneIn))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13312</id>
        <msg>WEB-ACTIVEX StreamAudio ProxyManager ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|5|00|3|00|F|00|3|00|2|00|0|00|-|00|A|00|B|00|6|00|8|00|-|00|4|00|A|00|0|00|7|00|-|00|9|00|1|00|7|00|D|00|-|00|4|00|F|00|1|00|2|00|D|00|8|00|8|00|8|00|4|00|A|00|0|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13313</id>
        <msg>WEB-ACTIVEX StreamAudio ProxyManager ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Ccpm.ProxyManager&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Ccpm\.ProxyManager\x22|\x27Ccpm\.ProxyManager\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*InternalTuneIn\s*|.*(?P=v)\s*\.\s*InternalTuneIn\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Ccpm\.ProxyManager\x22|\x27Ccpm\.ProxyManager\x27)\s*\)(\s*\.\s*InternalTuneIn\s*|.*(?P=n)\s*\.\s*InternalTuneIn\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13314</id>
        <msg>WEB-ACTIVEX StreamAudio ProxyManager ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|c|00|p|00|m|00|.|00|P|00|r|00|o|00|x|00|y|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00c\x00p\x00m\x00.\x00P\x00r\x00o\x00x\x00y\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00c\x00p\x00m\x00.\x00P\x00r\x00o\x00x\x00y\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13315</id>
        <msg>WEB-ACTIVEX StreamAudio ProxyManager ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25295</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0DDF3BD2-E692-11D1-AB06-00AA00BDD685&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0DDF3BD2-E692-11D1-AB06-00AA00BDD685\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13321</id>
        <msg>WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>25295</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|D|00|D|00|F|00|3|00|B|00|D|00|2|00|-|00|E|00|6|00|9|00|2|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|B|00|0|00|6|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|D|00|D|00|6|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13322</id>
        <msg>WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>25295</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PDWizard.SetupPkgPanels&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PDWizard\.SetupPkgPanels\x22|\x27PDWizard\.SetupPkgPanels\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PDWizard\.SetupPkgPanels\x22|\x27PDWizard\.SetupPkgPanels\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13323</id>
        <msg>WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>25295</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|D|00|W|00|i|00|z|00|a|00|r|00|d|00|.|00|S|00|e|00|t|00|u|00|p|00|P|00|k|00|g|00|P|00|a|00|n|00|e|00|l|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00S\x00e\x00t\x00u\x00p\x00P\x00k\x00g\x00P\x00a\x00n\x00e\x00l\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00S\x00e\x00t\x00u\x00p\x00P\x00k\x00g\x00P\x00a\x00n\x00e\x00l\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13324</id>
        <msg>WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>27360</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AD315309-EA00-45AE-9E8E-B6A61CE6B974&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AD315309-EA00-45AE-9E8E-B6A61CE6B974\s*}?\s*(?P=q10)(\s|&gt;).*(?P=id1)\s*\.\s*(SetPort|SetIPAddress)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AD315309-EA00-45AE-9E8E-B6A61CE6B974\s*}?\s*(?P=q11)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SetPort|SetIPAddress))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13329</id>
        <msg>WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27360</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|D|00|3|00|1|00|5|00|3|00|0|00|9|00|-|00|E|00|A|00|0|00|0|00|-|00|4|00|5|00|A|00|E|00|-|00|9|00|E|00|8|00|E|00|-|00|B|00|6|00|A|00|6|00|1|00|C|00|E|00|6|00|B|00|9|00|7|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q12&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13330</id>
        <msg>WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27360</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RecordSend&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22RecordSend\x22|\x27RecordSend\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SetPort|SetIPAddress)\s*|.*(?P=v)\s*\.\s*(SetPort|SetIPAddress)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RecordSend\x22|\x27RecordSend\x27)\s*\)(\s*\.\s*(SetPort|SetIPAddress)\s*|.*(?P=n)\s*\.\s*(SetPort|SetIPAddress)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13331</id>
        <msg>WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27360</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;R|00|e|00|c|00|o|00|r|00|d|00|S|00|e|00|n|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)R\x00e\x00c\x00o\x00r\x00d\x00S\x00e\x00n\x00d\x00(?P=q13)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)R\x00e\x00c\x00o\x00r\x00d\x00S\x00e\x00n\x00d\x00(?P=q14)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13332</id>
        <msg>WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27384</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0437</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00000014-9593-4264-8B29-930B3E4EDCCD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00000014-9593-4264-8B29-930B3E4EDCCD\s*}?\s*(?P=q15)(\s|&gt;).*(?P=id1)\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00000014-9593-4264-8B29-930B3E4EDCCD\s*}?\s*(?P=q16)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13333</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27384</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0437</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|0|00|0|00|0|00|1|00|4|00|-|00|9|00|5|00|9|00|3|00|-|00|4|00|2|00|6|00|4|00|-|00|8|00|B|00|2|00|9|00|-|00|9|00|3|00|0|00|B|00|3|00|E|00|4|00|E|00|D|00|C|00|C|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q17&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q17)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13334</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27411</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C36112BF-2FA3-4694-8603-3B510EA3B465&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q18&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C36112BF-2FA3-4694-8603-3B510EA3B465\s*}?\s*(?P=q18)(\s|&gt;).*(?P=id1)\s*\.\s*(HandwriterFilename)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C36112BF-2FA3-4694-8603-3B510EA3B465\s*}?\s*(?P=q19)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\s*\.\s*(HandwriterFilename))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13335</id>
        <msg>WEB-ACTIVEX Lycos File Upload Component ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27411</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|3|00|6|00|1|00|1|00|2|00|B|00|F|00|-|00|2|00|F|00|A|00|3|00|-|00|4|00|6|00|9|00|4|00|-|00|8|00|6|00|0|00|3|00|-|00|3|00|B|00|5|00|1|00|0|00|E|00|A|00|3|00|B|00|4|00|6|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q20&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q20)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13336</id>
        <msg>WEB-ACTIVEX Lycos File Upload Component ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27424</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;309F674D-E4D3-46BD-B9E2-ED7DFD7FD176&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*309F674D-E4D3-46BD-B9E2-ED7DFD7FD176\s*}?\s*(?P=q21)(\s|&gt;).*(?P=id1)\s*\.\s*(ExecuteStr)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*309F674D-E4D3-46BD-B9E2-ED7DFD7FD176\s*}?\s*(?P=q22)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\.(ExecuteStr))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13337</id>
        <msg>WEB-ACTIVEX Comodo AntiVirus ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27424</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|0|00|9|00|F|00|6|00|7|00|4|00|D|00|-|00|E|00|4|00|D|00|3|00|-|00|4|00|6|00|B|00|D|00|-|00|B|00|9|00|E|00|2|00|-|00|E|00|D|00|7|00|D|00|F|00|D|00|7|00|F|00|D|00|1|00|7|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q23&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q23)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13338</id>
        <msg>WEB-ACTIVEX Comodo AntiVirus ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27438</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6054D082-355D-4B47-B77C-36A778899F48&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6054D082-355D-4B47-B77C-36A778899F48\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Upgrade)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6054D082-355D-4B47-B77C-36A778899F48\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Upgrade))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13348</id>
        <msg>WEB-ACTIVEX Move Networks Media Player ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27438</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|0|00|5|00|4|00|D|00|0|00|8|00|2|00|-|00|3|00|5|00|5|00|D|00|-|00|4|00|B|00|4|00|7|00|-|00|B|00|7|00|7|00|C|00|-|00|3|00|6|00|A|00|7|00|7|00|8|00|8|00|9|00|9|00|F|00|4|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13349</id>
        <msg>WEB-ACTIVEX Move Networks Media Player ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27438</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;QSP2IE.QSP2IE&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22QSP2IE\.QSP2IE\x22|\x27QSP2IE\.QSP2IE\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Upgrade\s*|.*(?P=v)\s*\.\s*Upgrade\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22QSP2IE\.QSP2IE\x22|\x27QSP2IE\.QSP2IE\x27)\s*\)(\s*\.\s*Upgrade\s*|.*(?P=n)\s*\.\s*Upgrade\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13350</id>
        <msg>WEB-ACTIVEX Move Networks Media Player ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27438</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Q|00|S|00|P|00|2|00|I|00|E|00|.|00|Q|00|S|00|P|00|2|00|I|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Q\x00S\x00P\x002\x00I\x00E\x00.\x00Q\x00S\x00P\x002\x00I\x00E\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Q\x00S\x00P\x002\x00I\x00E\x00.\x00Q\x00S\x00P\x002\x00I\x00E\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13351</id>
        <msg>WEB-ACTIVEX Move Networks Media Player ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27411</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FileUploader.FUploadCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22FileUploader\.FUploadCtl\x22|\x27FileUploader\.FUploadCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*HandwriterFilename\s*|.*(?P=v)\s*\.\s*HandwriterFilename\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22FileUploader\.FUploadCtl\x22|\x27FileUploader\.FUploadCtl\x27)\s*\)(\s*\.\s*HandwriterFilename\s*|.*(?P=n)\s*\.\s*HandwriterFilename)\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13352</id>
        <msg>WEB-ACTIVEX Lycos File Upload Component ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27411</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|i|00|l|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|.|00|F|00|U|00|p|00|l|00|o|00|a|00|d|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00.\x00F\x00U\x00p\x00l\x00o\x00a\x00d\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)F\x00i\x00l\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00.\x00F\x00U\x00p\x00l\x00o\x00a\x00d\x00C\x00t\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13353</id>
        <msg>WEB-ACTIVEX Lycos File Upload Component ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27384</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0437</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WebHPVCInstall.HPVirtualRooms14&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WebHPVCInstall\.HPVirtualRooms14\x22|\x27WebHPVCInstall\.HPVirtualRooms14\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot)\s*|.*(?P=v)\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WebHPVCInstall\.HPVirtualRooms14\x22|\x27WebHPVCInstall\.HPVirtualRooms14\x27)\s*\)(\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot)\s*|.*(?P=n)\s*\.\s*(AuthenticationURL|PortalAPIURL|cabroot))\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13354</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27384</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0437</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|e|00|b|00|H|00|P|00|V|00|C|00|I|00|n|00|s|00|t|00|a|00|l|00|l|00|.|00|H|00|P|00|V|00|i|00|r|00|t|00|u|00|a|00|l|00|R|00|o|00|o|00|m|00|s|00|1|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00e\x00b\x00H\x00P\x00V\x00C\x00I\x00n\x00s\x00t\x00a\x00l\x00l\x00.\x00H\x00P\x00V\x00i\x00r\x00t\x00u\x00a\x00l\x00R\x00o\x00o\x00m\x00s\x001\x004\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)W\x00e\x00b\x00H\x00P\x00V\x00C\x00I\x00n\x00s\x00t\x00a\x00l\x00l\x00.\x00H\x00P\x00V\x00i\x00r\x00t\x00u\x00a\x00l\x00R\x00o\x00o\x00m\x00s\x001\x004\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13355</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21401</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-6296</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:26; dce_stub_data; pcre:&quot;/^.{20}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,65536,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>13367</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss GetPrinterData attempt</msg>
      </rule>
      <rule>
        <bugtraq>27756</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5711</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5C6698D9-7BE4-4122-8EC5-291D84DBD4A0&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5C6698D9-7BE4-4122-8EC5-291D84DBD4A0\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5C6698D9-7BE4-4122-8EC5-291D84DBD4A0\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask))\s*=/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13419</id>
        <msg>WEB-ACTIVEX Facebook Photo Uploader ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27756</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5711</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|C|00|6|00|6|00|9|00|8|00|D|00|9|00|-|00|7|00|B|00|E|00|4|00|-|00|4|00|1|00|2|00|2|00|-|00|8|00|E|00|C|00|5|00|-|00|2|00|9|00|1|00|D|00|8|00|4|00|D|00|B|00|D|00|4|00|A|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x00C\x006\x006\x009\x008\x00D\x009\x00-\x007\x00B\x00E\x004\x00-\x004\x001\x002\x002\x00-\x008\x00E\x00C\x005\x00-\x002\x009\x001\x00D\x008\x004\x00D\x00B\x00D\x004\x00A\x000\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13420</id>
        <msg>WEB-ACTIVEX Facebook Photo Uploader ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27756</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5711</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TheFacebook.FacebookPhotoUploader4.4.1&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TheFacebook\.FacebookPhotoUploader4\.4\.1\x22|\x27TheFacebook\.FacebookPhotoUploader4\.4\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask)\s*|.*(?P=v)\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TheFacebook\.FacebookPhotoUploader4\.4\.1\x22|\x27TheFacebook\.FacebookPhotoUploader4\.4\.1\x27)\s*\)(\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask)\s*|.*(?P=n)\s*\.\s*(Action|ExtractExif|ExtractIptc|FileMask))\s*=/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13421</id>
        <msg>WEB-ACTIVEX Facebook Photo Uploader ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27756</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5711</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|h|00|e|00|F|00|a|00|c|00|e|00|b|00|o|00|o|00|k|00|.|00|F|00|a|00|c|00|e|00|b|00|o|00|o|00|k|00|P|00|h|00|o|00|t|00|o|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|4|00|.|00|4|00|.|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)T\x00h\x00e\x00F\x00a\x00c\x00e\x00b\x00o\x00o\x00k\x00.\x00F\x00a\x00c\x00e\x00b\x00o\x00o\x00k\x00P\x00h\x00o\x00t\x00o\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x004\x00.\x004\x00.\x001\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)T\x00h\x00e\x00F\x00a\x00c\x00e\x00b\x00o\x00o\x00k\x00.\x00F\x00a\x00c\x00e\x00b\x00o\x00o\x00k\x00P\x00h\x00o\x00t\x00o\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x004\x00.\x004\x00.\x001\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13422</id>
        <msg>WEB-ACTIVEX Facebook Photo Uploader ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27527</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7DD62E58-5FA8-11D2-AFB7-00104B64F126&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7DD62E58-5FA8-11D2-AFB7-00104B64F126\s*}?\s*(?P=q6)(\s|&gt;)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13423</id>
        <msg>WEB-ACTIVEX SwiftView ActiveX clsid access</msg>
        <url>www.swiftview.com/tech/security/bulletins/SBSV-07-10-02.htm</url>
      </rule>
      <rule>
        <bugtraq>27527</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|D|00|D|00|6|00|2|00|E|00|5|00|8|00|-|00|5|00|F|00|A|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|A|00|F|00|B|00|7|00|-|00|0|00|0|00|1|00|0|00|4|00|B|00|6|00|4|00|F|00|1|00|2|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q7&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13424</id>
        <msg>WEB-ACTIVEX SwiftView ActiveX clsid unicode access</msg>
        <url>www.swiftview.com/tech/security/bulletins/SBSV-07-10-02.htm</url>
      </rule>
      <rule>
        <bugtraq>27579</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5F810AFC-BB5F-4416-BE63-E01DD117BD6C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5F810AFC-BB5F-4416-BE63-E01DD117BD6C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddImage|AddButton)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5F810AFC-BB5F-4416-BE63-E01DD117BD6C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddImage|AddButton))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13426</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27579</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|F|00|8|00|1|00|0|00|A|00|F|00|C|00|-|00|B|00|B|00|5|00|F|00|-|00|4|00|4|00|1|00|6|00|-|00|B|00|E|00|6|00|3|00|-|00|E|00|0|00|1|00|D|00|D|00|1|00|1|00|7|00|B|00|D|00|6|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13427</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27579</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YMP.YMPDatagrid&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YMP\.YMPDatagrid\x22|\x27YMP\.YMPDatagrid\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(AddImage|AddButton)\s*|.*(?P=v)\s*\.\s*(AddImage|AddButton)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YMP\.YMPDatagrid\x22|\x27YMP\.YMPDatagrid\x27)\s*\)(\s*\.\s*(AddImage|AddButton)\s*|.*(?P=n)\s*\.\s*(AddImage|AddButton)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13428</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27579</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|M|00|P|00|.|00|Y|00|M|00|P|00|D|00|a|00|t|00|a|00|g|00|r|00|i|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Y\x00M\x00P\x00.\x00Y\x00M\x00P\x00D\x00a\x00t\x00a\x00g\x00r\x00i\x00d\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Y\x00M\x00P\x00.\x00Y\x00M\x00P\x00D\x00a\x00t\x00a\x00g\x00r\x00i\x00d\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13429</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27578</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;22FD7C0A-850C-4A53-9821-0B0915C96139&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*22FD7C0A-850C-4A53-9821-0B0915C96139\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(AddBitmap)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*22FD7C0A-850C-4A53-9821-0B0915C96139\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(AddBitmap))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13430</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27578</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|F|00|D|00|7|00|C|00|0|00|A|00|-|00|8|00|5|00|0|00|C|00|-|00|4|00|A|00|5|00|3|00|-|00|9|00|8|00|2|00|1|00|-|00|0|00|B|00|0|00|9|00|1|00|5|00|C|00|9|00|6|00|1|00|3|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13431</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27578</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YMG.YMGMediaGridAx&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YMG\.YMGMediaGridAx\x22|\x27YMG\.YMGMediaGridAx\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddBitmap\s*|.*(?P=v)\s*\.\s*AddBitmap\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YMG\.YMGMediaGridAx\x22|\x27YMG\.YMGMediaGridAx\x27)\s*\)(\s*\.\s*AddBitmap\s*|.*(?P=n)\s*\.\s*AddBitmap\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13432</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27578</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|M|00|G|00|.|00|Y|00|M|00|G|00|M|00|e|00|d|00|i|00|a|00|G|00|r|00|i|00|d|00|A|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)Y\x00M\x00G\x00.\x00Y\x00M\x00G\x00M\x00e\x00d\x00i\x00a\x00G\x00r\x00i\x00d\x00A\x00x\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)Y\x00M\x00G\x00.\x00Y\x00M\x00G\x00M\x00e\x00d\x00i\x00a\x00G\x00r\x00i\x00d\x00A\x00x\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13433</id>
        <msg>WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;61F5C358-60FB-4A23-A312-D2B556620F20&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*61F5C358-60FB-4A23-A312-D2B556620F20\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(hgs_startNotify)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*61F5C358-60FB-4A23-A312-D2B556620F20\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(hgs_startNotify))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13446</id>
        <msg>WEB-ACTIVEX GlobalLink HanGamePlugin ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|1|00|F|00|5|00|C|00|3|00|5|00|8|00|-|00|6|00|0|00|F|00|B|00|-|00|4|00|A|00|2|00|3|00|-|00|A|00|3|00|1|00|2|00|-|00|D|00|2|00|B|00|5|00|5|00|6|00|6|00|2|00|0|00|F|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13447</id>
        <msg>WEB-ACTIVEX GlobalLink HanGamePlugin ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0078</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13453, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13453</id>
        <msg>WEB-CLIENT Microsoft DXLUTBuilder ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0078</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13455, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13455</id>
        <msg>WEB-CLIENT Microsoft DXLUTBuilder ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0065</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13457, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13457</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0065</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13459, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13459</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-008.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.wps&quot;; nocase; http_uri; flowbits:set, works.download; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13465</id>
        <msg>WEB-CLIENT Microsoft Works file download request</msg>
      </rule>
      <rule>
        <bugtraq>27657</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,works.download; metadata: engine shared, soid 3|13466, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13466</id>
        <msg>WEB-CLIENT Microsoft Works file converter file section length headers memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-011.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0104</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|13471, service http, policy security-ips drop;</filter2>
        <id>13471</id>
        <msg>EXPLOIT Microsoft Publisher invalid pathname overwrite</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-012.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.pub&quot;; fast_pattern; nocase; http_uri; flowbits:set,http.pub; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>13473</id>
        <msg>WEB-MISC Microsoft Publisher file download</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0080</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13474, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13474</id>
        <msg>WEB-CLIENT Microsoft WebDAV MiniRedir remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>31370</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;36723f97-7aa0-11d4-8919-ff2d71d0d32c&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*36723f97-7aa0-11d4-8919-ff2d71d0d32c\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*36723f97-7aa0-11d4-8919-ff2d71d0d32c\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist))/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13523</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX clsid access</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html</url>
      </rule>
      <rule>
        <bugtraq>31370</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|6|00|7|00|2|00|3|00|f|00|9|00|7|00|-|00|7|00|a|00|a|00|0|00|-|00|1|00|1|00|d|00|4|00|-|00|8|00|9|00|1|00|9|00|-|00|f|00|f|00|2|00|d|00|7|00|1|00|d|00|0|00|d|00|3|00|2|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x006\x007\x002\x003\x00f\x009\x007\x00-\x007\x00a\x00a\x000\x00-\x001\x001\x00d\x004\x00-\x008\x009\x001\x009\x00-\x00f\x00f\x002\x00d\x007\x001\x00d\x000\x00d\x003\x002\x00c\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13524</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX clsid unicode access</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html</url>
      </rule>
      <rule>
        <bugtraq>31370</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ienipp.Novell iPrint Control&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ienipp\.Novell\s*iPrint\s*Control(\.\d)?\x22|\x27ienipp\.Novell\s*iPrint\s*Control(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist)\s*|.*(?P=v)\s*\.\s*(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ienipp\.Novell\s*iPrint\s*Control(\.\d)?\x22|\x27ienipp\.Novell\s*iPrint\s*Control(\.\d)?\x27)\s*\)(\s*\.\s*(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist)\s*|.*(?P=n)\s*\.\s*(ExecuteRequest|GetDriverFile|UploadPrinterDriver|UploadResource|GetPrinterURLlist)\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13525</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX function call access</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html</url>
      </rule>
      <rule>
        <bugtraq>31370</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;i|00|e|00|n|00|i|00|p|00|p|00|.|00|N|00|o|00|v|00|e|00|l|00|l|00| |00|i|00|P|00|r|00|i|00|n|00|t|00| |00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)i\x00e\x00n\x00i\x00p\x00p\x00.\x00N\x00o\x00v\x00e\x00l\x00l\x00(\s\x00)*i\x00P\x00r\x00i\x00n\x00t\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)i\x00e\x00n\x00i\x00p\x00p\x00.\x00N\x00o\x00v\x00e\x00l\x00l\x00(\s\x00)*i\x00P\x00r\x00i\x00n\x00t\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13526</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX function call unicode access</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html</url>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(url)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(url))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13527</id>
        <msg>WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|9|00|3|00|B|00|4|00|7|00|F|00|D|00|-|00|9|00|B|00|F|00|6|00|-|00|4|00|D|00|A|00|8|00|-|00|9|00|7|00|F|00|C|00|-|00|9|00|2|00|7|00|0|00|B|00|9|00|D|00|6|00|4|00|A|00|6|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13528</id>
        <msg>WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VAPgDecoder.VaPgCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VAPgDecoder\.VaPgCtrl\x22|\x27VAPgDecoder\.VaPgCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*url\s*|.*(?P=v)\s*\.\s*url\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VAPgDecoder\.VaPgCtrl\x22|\x27VAPgDecoder\.VaPgCtrl\x27)\s*\)(\s*\.\s*url\s*|.*(?P=n)\s*\.\s*url)\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13529</id>
        <msg>WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|A|00|P|00|g|00|D|00|e|00|c|00|o|00|d|00|e|00|r|00|.|00|V|00|a|00|P|00|g|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00A\x00P\x00g\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00V\x00a\x00P\x00g\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00A\x00P\x00g\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00V\x00a\x00P\x00g\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13530</id>
        <msg>WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;210D0CBC-8B17-48D1-B294-1A338DD2EB3A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*210D0CBC-8B17-48D1-B294-1A338DD2EB3A\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(url)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*210D0CBC-8B17-48D1-B294-1A338DD2EB3A\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(url))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13531</id>
        <msg>WEB-ACTIVEX 4xem VatCtrl ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|1|00|0|00|D|00|0|00|C|00|B|00|C|00|-|00|8|00|B|00|1|00|7|00|-|00|4|00|8|00|D|00|1|00|-|00|B|00|2|00|9|00|4|00|-|00|1|00|A|00|3|00|3|00|8|00|D|00|D|00|2|00|E|00|B|00|3|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13532</id>
        <msg>WEB-ACTIVEX 4xem VatCtrl ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VATDecoder.VatCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VATDecoder\.VatCtrl\x22|\x27VATDecoder\.VatCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*url\s*|.*(?P=v)\s*\.\s*url\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VATDecoder\.VatCtrl\x22|\x27VATDecoder\.VatCtrl\x27)\s*\)(\s*\.\s*url\s*|.*(?P=n)\s*\.\s*url)\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13533</id>
        <msg>WEB-ACTIVEX 4xem VatCtrl ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|A|00|T|00|D|00|e|00|c|00|o|00|d|00|e|00|r|00|.|00|V|00|a|00|t|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)V\x00A\x00T\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00V\x00a\x00t\x00C\x00t\x00r\x00l\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)V\x00A\x00T\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00V\x00a\x00t\x00C\x00t\x00r\x00l\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13534</id>
        <msg>WEB-ACTIVEX 4xem VatCtrl ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;45830FF9-D9E6-4F41-86ED-B266933D8E90&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*45830FF9-D9E6-4F41-86ED-B266933D8E90\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(url)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*45830FF9-D9E6-4F41-86ED-B266933D8E90\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\s*\.\s*(url))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13535</id>
        <msg>WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|5|00|8|00|3|00|0|00|F|00|F|00|9|00|-|00|D|00|9|00|E|00|6|00|-|00|4|00|F|00|4|00|1|00|-|00|8|00|6|00|E|00|D|00|-|00|B|00|2|00|6|00|6|00|9|00|3|00|3|00|D|00|8|00|E|00|9|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q13&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13536</id>
        <msg>WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RtspVaPgDecoder.RtspVaPgCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22RtspVaPgDecoder\.RtspVaPgCtrl\x22|\x27RtspVaPgDecoder\.RtspVaPgCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*url\s*|.*(?P=v)\s*\.\s*url\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RtspVaPgDecoder\.RtspVaPgCtrl\x22|\x27RtspVaPgDecoder\.RtspVaPgCtrl\x27)\s*\)(\s*\.\s*url\s*|.*(?P=n)\s*\.\s*url)\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13537</id>
        <msg>WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28010</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;R|00|t|00|s|00|p|00|V|00|a|00|P|00|g|00|D|00|e|00|c|00|o|00|d|00|e|00|r|00|.|00|R|00|t|00|s|00|p|00|V|00|a|00|P|00|g|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)R\x00t\x00s\x00p\x00V\x00a\x00P\x00g\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00R\x00t\x00s\x00p\x00V\x00a\x00P\x00g\x00C\x00t\x00r\x00l\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)R\x00t\x00s\x00p\x00V\x00a\x00P\x00g\x00D\x00e\x00c\x00o\x00d\x00e\x00r\x00.\x00R\x00t\x00s\x00p\x00V\x00a\x00P\x00g\x00C\x00t\x00r\x00l\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13538</id>
        <msg>WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;22acd16f-99eb-11d2-9bb3-00400561d975&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*22acd16f-99eb-11d2-9bb3-00400561d975\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(save)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*22acd16f-99eb-11d2-9bb3-00400561d975\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(save))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13539</id>
        <msg>WEB-ACTIVEX Symantec Backup Exec ActiveX clsid access</msg>
        <url>www.symantec.com/avcenter/security/Content/2008.02.28.html</url>
      </rule>
      <rule>
        <bugtraq>26904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|a|00|c|00|d|00|1|00|6|00|f|00|-|00|9|00|9|00|e|00|b|00|-|00|1|00|1|00|d|00|2|00|-|00|9|00|b|00|b|00|3|00|-|00|0|00|0|00|4|00|0|00|0|00|5|00|6|00|1|00|d|00|9|00|7|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13540</id>
        <msg>WEB-ACTIVEX Symantec Backup Exec ActiveX clsid unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2008.02.28.html</url>
      </rule>
      <rule>
        <bugtraq>26904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iPVATLCalendar.PVCalendar&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iPVATLCalendar\.PVCalendar\x22|\x27iPVATLCalendar\.PVCalendar\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*save\s*|.*(?P=v)\s*\.\s*save\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iPVATLCalendar\.PVCalendar\x22|\x27iPVATLCalendar\.PVCalendar\x27)\s*\)(\s*\.\s*save\s*|.*(?P=n)\s*\.\s*save\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13541</id>
        <msg>WEB-ACTIVEX Symantec Backup Exec ActiveX function call access</msg>
        <url>www.symantec.com/avcenter/security/Content/2008.02.28.html</url>
      </rule>
      <rule>
        <bugtraq>26904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;i|00|P|00|V|00|A|00|T|00|L|00|C|00|a|00|l|00|e|00|n|00|d|00|a|00|r|00|.|00|P|00|V|00|C|00|a|00|l|00|e|00|n|00|d|00|a|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)i\x00P\x00V\x00A\x00T\x00L\x00C\x00a\x00l\x00e\x00n\x00d\x00a\x00r\x00.\x00P\x00V\x00C\x00a\x00l\x00e\x00n\x00d\x00a\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)i\x00P\x00V\x00A\x00T\x00L\x00C\x00a\x00l\x00e\x00n\x00d\x00a\x00r\x00.\x00P\x00V\x00C\x00a\x00l\x00e\x00n\x00d\x00a\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13542</id>
        <msg>WEB-ACTIVEX Symantec Backup Exec ActiveX function call unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2008.02.28.html</url>
      </rule>
      <rule>
        <bugtraq>28058</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13543</id>
        <msg>WEB-ACTIVEX Learn2 STRunner ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28058</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|B|00|7|00|2|00|C|00|C|00|A|00|4|00|-|00|5|00|F|00|1|00|1|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|C|00|B|00|5|00|-|00|0|00|0|00|0|00|0|00|C|00|0|00|E|00|C|00|9|00|F|00|D|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13544</id>
        <msg>WEB-ACTIVEX Learn2 STRunner ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28058</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;STRunner.Popup1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22STRunner\.Popup1\x22|\x27STRunner\.Popup1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22STRunner\.Popup1\x22|\x27STRunner\.Popup1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13545</id>
        <msg>WEB-ACTIVEX Learn2 STRunner ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28058</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|T|00|R|00|u|00|n|00|n|00|e|00|r|00|.|00|P|00|o|00|p|00|u|00|p|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)S\x00T\x00R\x00u\x00n\x00n\x00e\x00r\x00.\x00P\x00o\x00p\x00u\x00p\x001\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00T\x00R\x00u\x00n\x00n\x00e\x00r\x00.\x00P\x00o\x00p\x00u\x00p\x001\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13546</id>
        <msg>WEB-ACTIVEX Learn2 STRunner ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27715</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E9A7F56F-C40F-4928-8C6F-7A72F2A25222&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E9A7F56F-C40F-4928-8C6F-7A72F2A25222\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetLogging)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E9A7F56F-C40F-4928-8C6F-7A72F2A25222\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetLogging))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13547</id>
        <msg>WEB-ACTIVEX Sony ImageStation ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27715</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|9|00|A|00|7|00|F|00|5|00|6|00|F|00|-|00|C|00|4|00|0|00|F|00|-|00|4|00|9|00|2|00|8|00|-|00|8|00|C|00|6|00|F|00|-|00|7|00|A|00|7|00|2|00|F|00|2|00|A|00|2|00|5|00|2|00|2|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13548</id>
        <msg>WEB-ACTIVEX Sony ImageStation ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27715</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AxRUploadServer.AxRUploadControl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AxRUploadServer\.AxRUploadControl\x22|\x27AxRUploadServer\.AxRUploadControl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetLogging\s*|.*(?P=v)\s*\.\s*SetLogging\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AxRUploadServer\.AxRUploadControl\x22|\x27AxRUploadServer\.AxRUploadControl\x27)\s*\)(\s*\.\s*SetLogging\s*|.*(?P=n)\s*\.\s*SetLogging\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13549</id>
        <msg>WEB-ACTIVEX Sony ImageStation ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27715</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|x|00|R|00|U|00|p|00|l|00|o|00|a|00|d|00|S|00|e|00|r|00|v|00|e|00|r|00|.|00|A|00|x|00|R|00|U|00|p|00|l|00|o|00|a|00|d|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00x\x00R\x00U\x00p\x00l\x00o\x00a\x00d\x00S\x00e\x00r\x00v\x00e\x00r\x00.\x00A\x00x\x00R\x00U\x00p\x00l\x00o\x00a\x00d\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00x\x00R\x00U\x00p\x00l\x00o\x00a\x00d\x00S\x00e\x00r\x00v\x00e\x00r\x00.\x00A\x00x\x00R\x00U\x00p\x00l\x00o\x00a\x00d\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13550</id>
        <msg>WEB-ACTIVEX Sony ImageStation ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0118</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|13572, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13572</id>
        <msg>WEB-CLIENT Microsoft Powerpoint malformed shapeid arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-016.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0112</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.slk&quot;; nocase; http_uri; pcre:&quot;/^[^\?]*\.slk([\?\x5c\x2f]|$)/Usi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13583</id>
        <msg>WEB-CLIENT Microsoft SYmbolic LinK file download request</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0112</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,csv.download; content:&quot;ID|3B|P&quot;; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13585</id>
        <msg>WEB-CLIENT Microsoft SYmbolic LinK file download</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>28118</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;855F3B16-6D32-4FE6-8A56-BBB695989046&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*855F3B16-6D32-4FE6-8A56-BBB695989046\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(IsChecked|GetPropertyById)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*855F3B16-6D32-4FE6-8A56-BBB695989046\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(IsChecked|GetPropertyById))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13595</id>
        <msg>WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28118</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|5|00|5|00|F|00|3|00|B|00|1|00|6|00|-|00|6|00|D|00|3|00|2|00|-|00|4|00|F|00|E|00|6|00|-|00|8|00|A|00|5|00|6|00|-|00|B|00|B|00|B|00|6|00|9|00|5|00|9|00|8|00|9|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13596</id>
        <msg>WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28118</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;XTTB00001.XTTB00001&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22XTTB00001\.XTTB00001\x22|\x27XTTB00001\.XTTB00001\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(IsChecked|GetPropertyById)\s*|.*(?P=v)\s*\.\s*(IsChecked|GetPropertyById)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22XTTB00001\.XTTB00001\x22|\x27XTTB00001\.XTTB00001\x27)\s*\)(\s*\.\s*(IsChecked|GetPropertyById)\s*|.*(?P=n)\s*\.\s*(IsChecked|GetPropertyById)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13597</id>
        <msg>WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28118</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;X|00|T|00|T|00|B|00|0|00|0|00|0|00|0|00|1|00|.|00|X|00|T|00|T|00|B|00|0|00|0|00|0|00|0|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)X\x00T\x00T\x00B\x000\x000\x000\x000\x001\x00.\x00X\x00T\x00T\x00B\x000\x000\x000\x000\x001\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)X\x00T\x00T\x00B\x000\x000\x000\x000\x001\x00.\x00X\x00T\x00T\x00B\x000\x000\x000\x000\x001\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13598</id>
        <msg>WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28172</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1307</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D82303B7-A754-4DCB-8AFC-8CF99435AACE&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D82303B7-A754-4DCB-8AFC-8CF99435AACE\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SetUninstallName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D82303B7-A754-4DCB-8AFC-8CF99435AACE\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SetUninstallName))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13599</id>
        <msg>WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28172</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1307</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|8|00|2|00|3|00|0|00|3|00|B|00|7|00|-|00|A|00|7|00|5|00|4|00|-|00|4|00|D|00|C|00|B|00|-|00|8|00|A|00|F|00|C|00|-|00|8|00|C|00|F|00|9|00|9|00|4|00|3|00|5|00|A|00|A|00|C|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13600</id>
        <msg>WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28172</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1307</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;UpdateOcx2.KUpdateObj2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22UpdateOcx2\.KUpdateObj2\x22|\x27UpdateOcx2\.KUpdateObj2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetUninstallName\s*|.*(?P=v)\s*\.\s*SetUninstallName\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22UpdateOcx2\.KUpdateObj2\x22|\x27UpdateOcx2\.KUpdateObj2\x27)\s*\)(\s*\.\s*SetUninstallName\s*|.*(?P=n)\s*\.\s*SetUninstallName\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13601</id>
        <msg>WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28172</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1307</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;U|00|p|00|d|00|a|00|t|00|e|00|O|00|c|00|x|00|2|00|.|00|K|00|U|00|p|00|d|00|a|00|t|00|e|00|O|00|b|00|j|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)U\x00p\x00d\x00a\x00t\x00e\x00O\x00c\x00x\x002\x00.\x00K\x00U\x00p\x00d\x00a\x00t\x00e\x00O\x00b\x00j\x002\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)U\x00p\x00d\x00a\x00t\x00e\x00O\x00c\x00x\x002\x00.\x00K\x00U\x00p\x00d\x00a\x00t\x00e\x00O\x00b\x00j\x002\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13602</id>
        <msg>WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-5583</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>content:&quot;0&quot;; depth:1; content:&quot;|02|&quot;; within:1; distance:1; content:!&quot;|00|&quot;; within:1; distance:1; content:&quot;|04|&quot;; distance:2; byte_jump:1, 0, relative; content:&quot;|A5|&quot;; content:&quot;|02 01 00 02 01 04 02 01 03|&quot;; content:&quot;|00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; metadata:policy security-ips drop, service snmp; classtype:attempted-admin;</filter2>
        <id>13619</id>
        <msg>SPECIFIC-THREATS Microsoft getBulkRequest memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-074.mspx</url>
      </rule>
      <rule>
        <bugtraq>28268</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddColumn)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddColumn))\s*\(/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13621</id>
        <msg>WEB-ACTIVEX CA BrightStor ListCtrl ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28268</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|F|00|6|00|E|00|F|00|F|00|F|00|3|00|-|00|4|00|5|00|5|00|8|00|-|00|4|00|C|00|4|00|C|00|-|00|A|00|D|00|A|00|F|00|-|00|A|00|8|00|7|00|8|00|9|00|1|00|C|00|5|00|F|00|3|00|A|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13622</id>
        <msg>WEB-ACTIVEX CA BrightStor ListCtrl ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28268</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LISTCTRL.ListCtrlCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LISTCTRL\.ListCtrlCtrl\x22|\x27LISTCTRL\.ListCtrlCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddColumn\s*|.*(?P=v)\s*\.\s*AddColumn\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LISTCTRL\.ListCtrlCtrl\x22|\x27LISTCTRL\.ListCtrlCtrl\x27)\s*\)(\s*\.\s*AddColumn\s*|.*(?P=n)\s*\.\s*AddColumn\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13623</id>
        <msg>WEB-ACTIVEX CA BrightStor ListCtrl ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28268</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|I|00|S|00|T|00|C|00|T|00|R|00|L|00|.|00|L|00|i|00|s|00|t|00|C|00|t|00|r|00|l|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)L\x00I\x00S\x00T\x00C\x00T\x00R\x00L\x00.\x00L\x00i\x00s\x00t\x00C\x00t\x00r\x00l\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)L\x00I\x00S\x00T\x00C\x00T\x00R\x00L\x00.\x00L\x00i\x00s\x00t\x00C\x00t\x00r\x00l\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13624</id>
        <msg>WEB-ACTIVEX CA BrightStor ListCtrl ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26468</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-1092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:suspicious-filename-detect; metadata: engine shared, soid 3|13626, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13626</id>
        <msg>WEB-CLIENT Microsoft Access download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>26468</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-1092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:suspicious-filename-detect; metadata: engine shared, soid 3|13629, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13629</id>
        <msg>WEB-CLIENT Microsoft Access JSDB download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>26468</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-1092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:suspicious-filename-detect; metadata: engine shared, soid 3|13630, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13630</id>
        <msg>WEB-CLIENT Microsoft Access TJDB download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>26468</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-1092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:suspicious-filename-detect; metadata: engine shared, soid 3|13633, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13633</id>
        <msg>WEB-CLIENT Microsoft Access MSISAM download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>28292</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B20D9D6A-0DEC-4d76-9BEF-175896006B4A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B20D9D6A-0DEC-4d76-9BEF-175896006B4A\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13657</id>
        <msg>WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28292</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|2|00|0|00|D|00|9|00|D|00|6|00|A|00|-|00|0|00|D|00|E|00|C|00|-|00|4|00|d|00|7|00|6|00|-|00|9|00|B|00|E|00|F|00|-|00|1|00|7|00|5|00|8|00|9|00|6|00|0|00|0|00|6|00|B|00|4|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13658</id>
        <msg>WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28292</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BusinessObjects.RptViewerAX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22BusinessObjects\.RptViewerAX\x22|\x27BusinessObjects\.RptViewerAX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BusinessObjects\.RptViewerAX\x22|\x27BusinessObjects\.RptViewerAX\x27)\s*\)/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13659</id>
        <msg>WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28292</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|u|00|s|00|i|00|n|00|e|00|s|00|s|00|O|00|b|00|j|00|e|00|c|00|t|00|s|00|.|00|R|00|p|00|t|00|V|00|i|00|e|00|w|00|e|00|r|00|A|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)B\x00u\x00s\x00i\x00n\x00e\x00s\x00s\x00O\x00b\x00j\x00e\x00c\x00t\x00s\x00.\x00R\x00p\x00t\x00V\x00i\x00e\x00w\x00e\x00r\x00A\x00X\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)B\x00u\x00s\x00i\x00n\x00e\x00s\x00s\x00O\x00b\x00j\x00e\x00c\x00t\x00s\x00.\x00R\x00p\x00t\x00V\x00i\x00e\x00w\x00e\x00r\x00A\x00X\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13660</id>
        <msg>WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28301</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;04FD48E6-0712-4937-B09E-F3D285B11D82&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*04FD48E6-0712-4937-B09E-F3D285B11D82\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*RemoveFileOrDir|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*04FD48E6-0712-4937-B09E-F3D285B11D82\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.RemoveFileOrDir)\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13661</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Upload ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28301</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|4|00|F|00|D|00|4|00|8|00|E|00|6|00|-|00|0|00|7|00|1|00|2|00|-|00|4|00|9|00|3|00|7|00|-|00|B|00|0|00|9|00|E|00|-|00|F|00|3|00|D|00|2|00|8|00|5|00|B|00|1|00|1|00|D|00|8|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13662</id>
        <msg>WEB-ACTIVEX VeralSoft HTTP File Upload ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1083</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,emf.request; metadata: engine shared, soid 3|13666, policy security-ips drop;</filter2>
        <id>13666</id>
        <msg>WEB-CLIENT Microsoft GDI integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13668, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13668</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13670, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13670</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13672, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13672</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13674, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13674</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1087</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.emf&quot;; fast_pattern; nocase; http_uri; flowbits:set,emf.request; flowbits:noalert; classtype:attempted-user;</filter2>
        <id>13678</id>
        <msg>MISC Microsoft EMF metafile access detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-021.mspx</url>
      </rule>
      <rule>
        <bugtraq>28700</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1725</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;24445430-F789-11CE-86F8-0020AFD8C6DB&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24445430-F789-11CE-86F8-0020AFD8C6DB\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*WriteOFXDataFile|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24445430-F789-11CE-86F8-0020AFD8C6DB\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.WriteOFXDataFile)\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13679</id>
        <msg>WEB-ACTIVEX IBiz EBanking Integrator ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28700</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1725</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|4|00|4|00|4|00|5|00|4|00|3|00|0|00|-|00|F|00|7|00|8|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|6|00|F|00|8|00|-|00|0|00|0|00|2|00|0|00|A|00|F|00|D|00|8|00|C|00|6|00|D|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13680</id>
        <msg>WEB-ACTIVEX IBiz EBanking Integrator ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28666</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AA07EBD2-EBDD-4BD6-9F8F-114BD513492C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA07EBD2-EBDD-4BD6-9F8F-114BD513492C\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(HttpSkin|SkinPath)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA07EBD2-EBDD-4BD6-9F8F-114BD513492C\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(HttpSkin|SkinPath))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13681</id>
        <msg>WEB-ACTIVEX CDNetworks Nefficient Download ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28666</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|A|00|0|00|7|00|E|00|B|00|D|00|2|00|-|00|E|00|B|00|D|00|D|00|-|00|4|00|B|00|D|00|6|00|-|00|9|00|F|00|8|00|F|00|-|00|1|00|1|00|4|00|B|00|D|00|5|00|1|00|3|00|4|00|9|00|2|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13682</id>
        <msg>WEB-ACTIVEX CDNetworks Nefficient Download ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28666</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NeffyLauncher.NeffyLauncherCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NeffyLauncher\.NeffyLauncherCtl\x22|\x27NeffyLauncher\.NeffyLauncherCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(HttpSkin|SkinPath)\s*|.*(?P=v)\s*\.\s*(HttpSkin|SkinPath)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NeffyLauncher\.NeffyLauncherCtl\x22|\x27NeffyLauncher\.NeffyLauncherCtl\x27)\s*\)(\s*\.\s*(HttpSkin|SkinPath)\s*|.*(?P=n)\s*\.\s*(HttpSkin|SkinPath))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13683</id>
        <msg>WEB-ACTIVEX CDNetworks Nefficient Download ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28666</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|e|00|f|00|f|00|y|00|L|00|a|00|u|00|n|00|c|00|h|00|e|00|r|00|.|00|N|00|e|00|f|00|f|00|y|00|L|00|a|00|u|00|n|00|c|00|h|00|e|00|r|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)N\x00e\x00f\x00f\x00y\x00L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00.\x00N\x00e\x00f\x00f\x00y\x00L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00C\x00t\x00l\x00(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)N\x00e\x00f\x00f\x00y\x00L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00.\x00N\x00e\x00f\x00f\x00y\x00L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00C\x00t\x00l\x00(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13684</id>
        <msg>WEB-ACTIVEX CDNetworks Nefficient Download ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;39E861BD-E606-4733-8C79-FADDFD61DC8A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*39E861BD-E606-4733-8C79-FADDFD61DC8A\s*}?\s*(?P=q9)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveLastError)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*39E861BD-E606-4733-8C79-FADDFD61DC8A\s*}?\s*(?P=q10)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SaveLastError))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13685</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|9|00|E|00|8|00|6|00|1|00|B|00|D|00|-|00|E|00|6|00|0|00|6|00|-|00|4|00|7|00|3|00|3|00|-|00|8|00|C|00|7|00|9|00|-|00|F|00|A|00|D|00|D|00|F|00|D|00|6|00|1|00|D|00|C|00|8|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q11&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13686</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CHILKATHTTPLib.ChilkatHttp&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CHILKATHTTPLib\.ChilkatHttp\x22|\x27CHILKATHTTPLib\.ChilkatHttp\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveLastError\s*|.*(?P=v)\s*\.\s*SaveLastError\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CHILKATHTTPLib\.ChilkatHttp\x22|\x27CHILKATHTTPLib\.ChilkatHttp\x27)\s*\)(\s*\.\s*SaveLastError\s*|.*(?P=n)\s*\.\s*SaveLastError\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13687</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 1 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|H|00|I|00|L|00|K|00|A|00|T|00|H|00|T|00|T|00|P|00|L|00|i|00|b|00|.|00|C|00|h|00|i|00|l|00|k|00|a|00|t|00|H|00|t|00|t|00|p|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)C\x00H\x00I\x00L\x00K\x00A\x00T\x00H\x00T\x00T\x00P\x00L\x00i\x00b\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00H\x00t\x00t\x00p\x00(?P=q12)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)C\x00H\x00I\x00L\x00K\x00A\x00T\x00H\x00T\x00T\x00P\x00L\x00i\x00b\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00H\x00t\x00t\x00p\x00(?P=q13)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13688</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 1 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B973393F-27C7-4781-877D-8626AAEDF119&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B973393F-27C7-4781-877D-8626AAEDF119\s*}?\s*(?P=q14)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveLastError)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B973393F-27C7-4781-877D-8626AAEDF119\s*}?\s*(?P=q15)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(SaveLastError))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13689</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|9|00|7|00|3|00|3|00|9|00|3|00|F|00|-|00|2|00|7|00|C|00|7|00|-|00|4|00|7|00|8|00|1|00|-|00|8|00|7|00|7|00|D|00|-|00|8|00|6|00|2|00|6|00|A|00|A|00|E|00|D|00|F|00|1|00|1|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q16&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13690</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CHILKATHTTPLib.ChilkatHttpRequest&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CHILKATHTTPLib\.ChilkatHttpRequest\x22|\x27CHILKATHTTPLib\.ChilkatHttpRequest\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveLastError\s*|.*(?P=v)\s*\.\s*SaveLastError\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CHILKATHTTPLib\.ChilkatHttpRequest\x22|\x27CHILKATHTTPLib\.ChilkatHttpRequest\x27)\s*\)(\s*\.\s*SaveLastError\s*|.*(?P=n)\s*\.\s*SaveLastError\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13691</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 2 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|H|00|I|00|L|00|K|00|A|00|T|00|H|00|T|00|T|00|P|00|L|00|i|00|b|00|.|00|C|00|h|00|i|00|l|00|k|00|a|00|t|00|H|00|t|00|t|00|p|00|R|00|e|00|q|00|u|00|e|00|s|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)C\x00H\x00I\x00L\x00K\x00A\x00T\x00H\x00T\x00T\x00P\x00L\x00i\x00b\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00H\x00t\x00t\x00p\x00R\x00e\x00q\x00u\x00e\x00s\x00t\x00(?P=q17)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q18&gt;\x22|\x27|)C\x00H\x00I\x00L\x00K\x00A\x00T\x00H\x00T\x00T\x00P\x00L\x00i\x00b\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00H\x00t\x00t\x00p\x00R\x00e\x00q\x00u\x00e\x00s\x00t\x00(?P=q18)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13692</id>
        <msg>WEB-ACTIVEX Chilkat HTTP 2 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28809</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E6239EB3-E0B0-46DA-A215-CFA9B3B740C5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetColumnColor|SetColumnLabel)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetColumnColor|SetColumnLabel))\s*\(/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13699</id>
        <msg>WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28809</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|2|00|3|00|9|00|E|00|B|00|3|00|-|00|E|00|0|00|B|00|0|00|-|00|4|00|6|00|D|00|A|00|-|00|A|00|2|00|1|00|5|00|-|00|C|00|F|00|A|00|9|00|B|00|3|00|B|00|7|00|4|00|0|00|C|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x006\x002\x003\x009\x00E\x00B\x003\x00-\x00E\x000\x00B\x000\x00-\x004\x006\x00D\x00A\x00-\x00A\x002\x001\x005\x00-\x00C\x00F\x00A\x009\x00B\x003\x00B\x007\x004\x000\x00C\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13700</id>
        <msg>WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;17E67D4A-23A1-40D8-A049-EE34C0AF756A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q31&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*17E67D4A-23A1-40D8-A049-EE34C0AF756A\s*}?\s*(?P=q31)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13720</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|7|00|E|00|6|00|7|00|D|00|4|00|A|00|-|00|2|00|3|00|A|00|1|00|-|00|4|00|0|00|D|00|8|00|-|00|A|00|0|00|4|00|9|00|-|00|E|00|E|00|3|00|4|00|C|00|0|00|A|00|F|00|7|00|5|00|6|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q32&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x007\x00E\x006\x007\x00D\x004\x00A\x00-\x002\x003\x00A\x001\x00-\x004\x000\x00D\x008\x00-\x00A\x000\x004\x009\x00-\x00E\x00E\x003\x004\x00C\x000\x00A\x00F\x007\x005\x006\x00A\x00(}\x00)?(?P=q32)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13721</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;42C68651-1700-4750-A81F-A1F5110E0F66&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q33&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42C68651-1700-4750-A81F-A1F5110E0F66\s*}?\s*(?P=q33)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13722</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|C|00|6|00|8|00|6|00|5|00|1|00|-|00|1|00|7|00|0|00|0|00|-|00|4|00|7|00|5|00|0|00|-|00|A|00|8|00|1|00|F|00|-|00|A|00|1|00|F|00|5|00|1|00|1|00|0|00|E|00|0|00|F|00|6|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q34&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x002\x00C\x006\x008\x006\x005\x001\x00-\x001\x007\x000\x000\x00-\x004\x007\x005\x000\x00-\x00A\x008\x001\x00F\x00-\x00A\x001\x00F\x005\x001\x001\x000\x00E\x000\x00F\x006\x006\x00(}\x00)?(?P=q34)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13723</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4774922A-8983-4ECC-94FD-7235F06F53A1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q35&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4774922A-8983-4ECC-94FD-7235F06F53A1\s*}?\s*(?P=q35)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13724</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|7|00|4|00|9|00|2|00|2|00|A|00|-|00|8|00|9|00|8|00|3|00|-|00|4|00|E|00|C|00|C|00|-|00|9|00|4|00|F|00|D|00|-|00|7|00|2|00|3|00|5|00|F|00|0|00|6|00|F|00|5|00|3|00|A|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q36&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x007\x007\x004\x009\x002\x002\x00A\x00-\x008\x009\x008\x003\x00-\x004\x00E\x00C\x00C\x00-\x009\x004\x00F\x00D\x00-\x007\x002\x003\x005\x00F\x000\x006\x00F\x005\x003\x00A\x001\x00(}\x00)?(?P=q36)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13725</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;60178279-6D62-43af-A336-77925651A4C6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q37&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*60178279-6D62-43af-A336-77925651A4C6\s*}?\s*(?P=q37)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13726</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 6 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|0|00|1|00|7|00|8|00|2|00|7|00|9|00|-|00|6|00|D|00|6|00|2|00|-|00|4|00|3|00|a|00|f|00|-|00|A|00|3|00|3|00|6|00|-|00|7|00|7|00|9|00|2|00|5|00|6|00|5|00|1|00|A|00|4|00|C|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q38&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x000\x001\x007\x008\x002\x007\x009\x00-\x006\x00D\x006\x002\x00-\x004\x003\x00a\x00f\x00-\x00A\x003\x003\x006\x00-\x007\x007\x009\x002\x005\x006\x005\x001\x00A\x004\x00C\x006\x00(}\x00)?(?P=q38)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13727</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 6 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6470DE80-1635-4B5D-93A3-3701CE148A79&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q39&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6470DE80-1635-4B5D-93A3-3701CE148A79\s*}?\s*(?P=q39)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13728</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 7 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|4|00|7|00|0|00|D|00|E|00|8|00|0|00|-|00|1|00|6|00|3|00|5|00|-|00|4|00|B|00|5|00|D|00|-|00|9|00|3|00|A|00|3|00|-|00|3|00|7|00|0|00|1|00|C|00|E|00|1|00|4|00|8|00|A|00|7|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q40&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x004\x007\x000\x00D\x00E\x008\x000\x00-\x001\x006\x003\x005\x00-\x004\x00B\x005\x00D\x00-\x009\x003\x00A\x003\x00-\x003\x007\x000\x001\x00C\x00E\x001\x004\x008\x00A\x007\x009\x00(}\x00)?(?P=q40)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13729</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 7 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;784F2933-6BDD-4E5F-B1BA-A8D99B603649&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q41&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*784F2933-6BDD-4E5F-B1BA-A8D99B603649\s*}?\s*(?P=q41)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13730</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 8 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|8|00|4|00|F|00|2|00|9|00|3|00|3|00|-|00|6|00|B|00|D|00|D|00|-|00|4|00|E|00|5|00|F|00|-|00|B|00|1|00|B|00|A|00|-|00|A|00|8|00|D|00|9|00|9|00|B|00|6|00|0|00|3|00|6|00|4|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q42&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x008\x004\x00F\x002\x009\x003\x003\x00-\x006\x00B\x00D\x00D\x00-\x004\x00E\x005\x00F\x00-\x00B\x001\x00B\x00A\x00-\x00A\x008\x00D\x009\x009\x00B\x006\x000\x003\x006\x004\x009\x00(}\x00)?(?P=q42)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13731</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 8 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;910E7ADE-7F75-402D-A4A6-BB1A82362FCA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q43&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*910E7ADE-7F75-402D-A4A6-BB1A82362FCA\s*}?\s*(?P=q43)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13732</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 9 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|1|00|0|00|E|00|7|00|A|00|D|00|E|00|-|00|7|00|F|00|7|00|5|00|-|00|4|00|0|00|2|00|D|00|-|00|A|00|4|00|A|00|6|00|-|00|B|00|B|00|1|00|A|00|8|00|2|00|3|00|6|00|2|00|F|00|C|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q44&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x001\x000\x00E\x007\x00A\x00D\x00E\x00-\x007\x00F\x007\x005\x00-\x004\x000\x002\x00D\x00-\x00A\x004\x00A\x006\x00-\x00B\x00B\x001\x00A\x008\x002\x003\x006\x002\x00F\x00C\x00A\x00(}\x00)?(?P=q44)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13733</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 9 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;93441C07-E57E-4086-B912-F323D741A9D8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*93441C07-E57E-4086-B912-F323D741A9D8\s*}?\s*(?P=q4)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13734</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 10 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|3|00|4|00|4|00|1|00|C|00|0|00|7|00|-|00|E|00|5|00|7|00|E|00|-|00|4|00|0|00|8|00|6|00|-|00|B|00|9|00|1|00|2|00|-|00|F|00|3|00|2|00|3|00|D|00|7|00|4|00|1|00|A|00|9|00|D|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q5&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x003\x004\x004\x001\x00C\x000\x007\x00-\x00E\x005\x007\x00E\x00-\x004\x000\x008\x006\x00-\x00B\x009\x001\x002\x00-\x00F\x003\x002\x003\x00D\x007\x004\x001\x00A\x009\x00D\x008\x00(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13735</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 10 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A95845D8-8463-4605-B5FB-4F8CFBAC5C47&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A95845D8-8463-4605-B5FB-4F8CFBAC5C47\s*}?\s*(?P=q6)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13736</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 11 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|9|00|5|00|8|00|4|00|5|00|D|00|8|00|-|00|8|00|4|00|6|00|3|00|-|00|4|00|6|00|0|00|5|00|-|00|B|00|5|00|F|00|B|00|-|00|4|00|F|00|8|00|C|00|F|00|B|00|A|00|C|00|5|00|C|00|4|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q7&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x009\x005\x008\x004\x005\x00D\x008\x00-\x008\x004\x006\x003\x00-\x004\x006\x000\x005\x00-\x00B\x005\x00F\x00B\x00-\x004\x00F\x008\x00C\x00F\x00B\x00A\x00C\x005\x00C\x004\x007\x00(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13737</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 11 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AB049B11-607B-46C8-BBF7-F4D6AF301046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AB049B11-607B-46C8-BBF7-F4D6AF301046\s*}?\s*(?P=q8)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13738</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 12 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|B|00|0|00|4|00|9|00|B|00|1|00|1|00|-|00|6|00|0|00|7|00|B|00|-|00|4|00|6|00|C|00|8|00|-|00|B|00|B|00|F|00|7|00|-|00|F|00|4|00|D|00|6|00|A|00|F|00|3|00|0|00|1|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q9&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00B\x000\x004\x009\x00B\x001\x001\x00-\x006\x000\x007\x00B\x00-\x004\x006\x00C\x008\x00-\x00B\x00B\x00F\x007\x00-\x00F\x004\x00D\x006\x00A\x00F\x003\x000\x001\x000\x004\x006\x00(}\x00)?(?P=q9)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13739</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 12 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AB237044-8A3B-42BB-9EE1-9BFA6721D9ED&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AB237044-8A3B-42BB-9EE1-9BFA6721D9ED\s*}?\s*(?P=q10)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13740</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 13 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|B|00|2|00|3|00|7|00|0|00|4|00|4|00|-|00|8|00|A|00|3|00|B|00|-|00|4|00|2|00|B|00|B|00|-|00|9|00|E|00|E|00|1|00|-|00|9|00|B|00|F|00|A|00|6|00|7|00|2|00|1|00|D|00|9|00|E|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q11&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00B\x002\x003\x007\x000\x004\x004\x00-\x008\x00A\x003\x00B\x00-\x004\x002\x00B\x00B\x00-\x009\x00E\x00E\x001\x00-\x009\x00B\x00F\x00A\x006\x007\x002\x001\x00D\x009\x00E\x00D\x00(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13741</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 13 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B9C13CD0-5A97-4C6B-8A50-7638020E2462&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B9C13CD0-5A97-4C6B-8A50-7638020E2462\s*}?\s*(?P=q12)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13742</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 14 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|9|00|C|00|1|00|3|00|C|00|D|00|0|00|-|00|5|00|A|00|9|00|7|00|-|00|4|00|C|00|6|00|B|00|-|00|8|00|A|00|5|00|0|00|-|00|7|00|6|00|3|00|8|00|0|00|2|00|0|00|E|00|2|00|4|00|6|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q13&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x009\x00C\x001\x003\x00C\x00D\x000\x00-\x005\x00A\x009\x007\x00-\x004\x00C\x006\x00B\x00-\x008\x00A\x005\x000\x00-\x007\x006\x003\x008\x000\x002\x000\x00E\x002\x004\x006\x002\x00(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13743</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 14 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BF931895-AF82-467A-8819-917C6EE2D1F3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BF931895-AF82-467A-8819-917C6EE2D1F3\s*}?\s*(?P=q14)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13744</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 15 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|F|00|9|00|3|00|1|00|8|00|9|00|5|00|-|00|A|00|F|00|8|00|2|00|-|00|4|00|6|00|7|00|A|00|-|00|8|00|8|00|1|00|9|00|-|00|9|00|1|00|7|00|C|00|6|00|E|00|E|00|2|00|D|00|1|00|F|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q15&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00F\x009\x003\x001\x008\x009\x005\x00-\x00A\x00F\x008\x002\x00-\x004\x006\x007\x00A\x00-\x008\x008\x001\x009\x00-\x009\x001\x007\x00C\x006\x00E\x00E\x002\x00D\x001\x00F\x003\x00(}\x00)?(?P=q15)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13745</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 15 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C70D0641-DDE1-4FD7-A4D4-DA187B80741D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C70D0641-DDE1-4FD7-A4D4-DA187B80741D\s*}?\s*(?P=q16)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13746</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 16 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|7|00|0|00|D|00|0|00|6|00|4|00|1|00|-|00|D|00|D|00|E|00|1|00|-|00|4|00|F|00|D|00|7|00|-|00|A|00|4|00|D|00|4|00|-|00|D|00|A|00|1|00|8|00|7|00|B|00|8|00|0|00|7|00|4|00|1|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q17&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x007\x000\x00D\x000\x006\x004\x001\x00-\x00D\x00D\x00E\x001\x00-\x004\x00F\x00D\x007\x00-\x00A\x004\x00D\x004\x00-\x00D\x00A\x001\x008\x007\x00B\x008\x000\x007\x004\x001\x00D\x00(}\x00)?(?P=q17)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13747</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 16 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C94188F6-0F9F-46B3-8B78-D71907BD8B77&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q18&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C94188F6-0F9F-46B3-8B78-D71907BD8B77\s*}?\s*(?P=q18)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13748</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 17 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|9|00|4|00|1|00|8|00|8|00|F|00|6|00|-|00|0|00|F|00|9|00|F|00|-|00|4|00|6|00|B|00|3|00|-|00|8|00|B|00|7|00|8|00|-|00|D|00|7|00|1|00|9|00|0|00|7|00|B|00|D|00|8|00|B|00|7|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q19&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x009\x004\x001\x008\x008\x00F\x006\x00-\x000\x00F\x009\x00F\x00-\x004\x006\x00B\x003\x00-\x008\x00B\x007\x008\x00-\x00D\x007\x001\x009\x000\x007\x00B\x00D\x008\x00B\x007\x007\x00(}\x00)?(?P=q19)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13749</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 17 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CF6866F9-B67C-4B24-9957-F91E91E788DC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q20&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CF6866F9-B67C-4B24-9957-F91E91E788DC\s*}?\s*(?P=q20)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13750</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 18 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|6|00|8|00|6|00|6|00|F|00|9|00|-|00|B|00|6|00|7|00|C|00|-|00|4|00|B|00|2|00|4|00|-|00|9|00|9|00|5|00|7|00|-|00|F|00|9|00|1|00|E|00|9|00|1|00|E|00|7|00|8|00|8|00|D|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q21&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00F\x006\x008\x006\x006\x00F\x009\x00-\x00B\x006\x007\x00C\x00-\x004\x00B\x002\x004\x00-\x009\x009\x005\x007\x00-\x00F\x009\x001\x00E\x009\x001\x00E\x007\x008\x008\x00D\x00C\x00(}\x00)?(?P=q21)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13751</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 18 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DC4F9DA0-DB05-4BB0-8FB2-03A80FE98772&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DC4F9DA0-DB05-4BB0-8FB2-03A80FE98772\s*}?\s*(?P=q22)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13752</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 19 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|C|00|4|00|F|00|9|00|D|00|A|00|0|00|-|00|D|00|B|00|0|00|5|00|-|00|4|00|B|00|B|00|0|00|-|00|8|00|F|00|B|00|2|00|-|00|0|00|3|00|A|00|8|00|0|00|F|00|E|00|9|00|8|00|7|00|7|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q23&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00C\x004\x00F\x009\x00D\x00A\x000\x00-\x00D\x00B\x000\x005\x00-\x004\x00B\x00B\x000\x00-\x008\x00F\x00B\x002\x00-\x000\x003\x00A\x008\x000\x00F\x00E\x009\x008\x007\x007\x002\x00(}\x00)?(?P=q23)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13753</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 19 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DE233AFF-8BD5-457E-B7F0-702DBEA5A828&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DE233AFF-8BD5-457E-B7F0-702DBEA5A828\s*}?\s*(?P=q27)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13754</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 20 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|E|00|2|00|3|00|3|00|A|00|F|00|F|00|-|00|8|00|B|00|D|00|5|00|-|00|4|00|5|00|7|00|E|00|-|00|B|00|7|00|F|00|0|00|-|00|7|00|0|00|2|00|D|00|B|00|E|00|A|00|5|00|A|00|8|00|2|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q28&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00E\x002\x003\x003\x00A\x00F\x00F\x00-\x008\x00B\x00D\x005\x00-\x004\x005\x007\x00E\x00-\x00B\x007\x00F\x000\x00-\x007\x000\x002\x00D\x00B\x00E\x00A\x005\x00A\x008\x002\x008\x00(}\x00)?(?P=q28)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13755</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 20 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E12DA4F2-BDFB-4EAD-B12F-2725251FA6B0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q29&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E12DA4F2-BDFB-4EAD-B12F-2725251FA6B0\s*}?\s*(?P=q29)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13756</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 21 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28929</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0712</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|1|00|2|00|D|00|A|00|4|00|F|00|2|00|-|00|B|00|D|00|F|00|B|00|-|00|4|00|E|00|A|00|D|00|-|00|B|00|1|00|2|00|F|00|-|00|2|00|7|00|2|00|5|00|2|00|5|00|1|00|F|00|A|00|6|00|B|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q30&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x001\x002\x00D\x00A\x004\x00F\x002\x00-\x00B\x00D\x00F\x00B\x00-\x004\x00E\x00A\x00D\x00-\x00B\x001\x002\x00F\x00-\x002\x007\x002\x005\x002\x005\x001\x00F\x00A\x006\x00B\x000\x00(}\x00)?(?P=q30)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13757</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 21 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>28882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E5D419D6-A846-4514-9FAD-97E826C84822&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E5D419D6-A846-4514-9FAD-97E826C84822\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13758</id>
        <msg>WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|5|00|D|00|4|00|1|00|9|00|D|00|6|00|-|00|A|00|8|00|4|00|6|00|-|00|4|00|5|00|1|00|4|00|-|00|9|00|F|00|A|00|D|00|-|00|9|00|7|00|E|00|8|00|2|00|6|00|C|00|8|00|4|00|8|00|2|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13759</id>
        <msg>WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HeartbeatCtl.HeartbeatCt&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22HeartbeatCtl\.HeartbeatCt\x22|\x27HeartbeatCtl\.HeartbeatCt\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HeartbeatCtl\.HeartbeatCt\x22|\x27HeartbeatCtl\.HeartbeatCt\x27)\s*\)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13760</id>
        <msg>WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;H|00|e|00|a|00|r|00|t|00|b|00|e|00|a|00|t|00|C|00|t|00|l|00|.|00|H|00|e|00|a|00|r|00|t|00|b|00|e|00|a|00|t|00|C|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)H\x00e\x00a\x00r\x00t\x00b\x00e\x00a\x00t\x00C\x00t\x00l\x00.\x00H\x00e\x00a\x00r\x00t\x00b\x00e\x00a\x00t\x00C\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)H\x00e\x00a\x00r\x00t\x00b\x00e\x00a\x00t\x00C\x00t\x00l\x00.\x00H\x00e\x00a\x00r\x00t\x00b\x00e\x00a\x00t\x00C\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13761</id>
        <msg>WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29065</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2283BB66-A15D-4AC8-BA72-9C8C9F5A1691&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2283BB66-A15D-4AC8-BA72-9C8C9F5A1691\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13783</id>
        <msg>WEB-ACTIVEX Yahoo Assistant ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>29065</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|8|00|3|00|B|00|B|00|6|00|6|00|-|00|A|00|1|00|5|00|D|00|-|00|4|00|A|00|C|00|8|00|-|00|B|00|A|00|7|00|2|00|-|00|9|00|C|00|8|00|C|00|9|00|F|00|5|00|A|00|1|00|6|00|9|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13784</id>
        <msg>WEB-ACTIVEX Yahoo Assistant ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;61F5C358-60FB-4A23-A312-D2B556620F20&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*61F5C358-60FB-4A23-A312-D2B556620F20\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(hgs_startGame|hgs_startNotify)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*61F5C358-60FB-4A23-A312-D2B556620F20\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(hgs_startGame|hgs_startNotify))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13785</id>
        <msg>WEB-ACTIVEX Ourgame GLWorld ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|1|00|F|00|5|00|C|00|3|00|5|00|8|00|-|00|6|00|0|00|F|00|B|00|-|00|4|00|A|00|2|00|3|00|-|00|A|00|3|00|1|00|2|00|-|00|D|00|2|00|B|00|5|00|5|00|6|00|6|00|2|00|0|00|F|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13786</id>
        <msg>WEB-ACTIVEX Ourgame GLWorld ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HanGamePluginCn18.HanGamePluginCn18&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22HanGamePluginCn18\.HanGamePluginCn18\x22|\x27HanGamePluginCn18\.HanGamePluginCn18\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(hgs_startGame|hgs_startNotify)\s*|.*(?P=v)\s*\.\s*(hgs_startGame|hgs_startNotify)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HanGamePluginCn18\.HanGamePluginCn18\x22|\x27HanGamePluginCn18\.HanGamePluginCn18\x27)\s*\)(\s*\.\s*(hgs_startGame|hgs_startNotify)\s*|.*(?P=n)\s*\.\s*(hgs_startGame|hgs_startNotify)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13787</id>
        <msg>WEB-ACTIVEX Ourgame GLWorld ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27626</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;H|00|a|00|n|00|G|00|a|00|m|00|e|00|P|00|l|00|u|00|g|00|i|00|n|00|C|00|n|00|1|00|8|00|.|00|H|00|a|00|n|00|G|00|a|00|m|00|e|00|P|00|l|00|u|00|g|00|i|00|n|00|C|00|n|00|1|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)H\x00a\x00n\x00G\x00a\x00m\x00e\x00P\x00l\x00u\x00g\x00i\x00n\x00C\x00n\x001\x008\x00.\x00H\x00a\x00n\x00G\x00a\x00m\x00e\x00P\x00l\x00u\x00g\x00i\x00n\x00C\x00n\x001\x008\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)H\x00a\x00n\x00G\x00a\x00m\x00e\x00P\x00l\x00u\x00g\x00i\x00n\x00C\x00n\x001\x008\x00.\x00H\x00a\x00n\x00G\x00a\x00m\x00e\x00P\x00l\x00u\x00g\x00i\x00n\x00C\x00n\x001\x008\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13788</id>
        <msg>WEB-ACTIVEX Ourgame GLWorld ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-1437</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; flowbits:isset,download.pecompact.binary; metadata: engine shared, soid 3|13798, service http, policy security-ips drop;</filter2>
        <id>13798</id>
        <msg>WEB-CLIENT Microsoft malware protection engine denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-029.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-1438</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13802, service http, policy security-ips drop;</filter2>
        <id>13802</id>
        <msg>WEB-CLIENT Microsoft malware protection engine denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-029.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-1441</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; 224.0.0.0/4 any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13825, policy security-ips drop;</filter2>
        <id>13825</id>
        <msg>DOS Microsoft PGM fragment denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-036.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-1440</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; 224.0.0.0/4 any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13827, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13827</id>
        <msg>DOS Microsoft PGM denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>29536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0953</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;14C1B87C-3342-445F-9B5E-365FF330A3AC&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*14C1B87C-3342-445F-9B5E-365FF330A3AC\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*14C1B87C-3342-445F-9B5E-365FF330A3AC\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13857</id>
        <msg>WEB-ACTIVEX HP Instant Support DataManager ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>29536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0953</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|4|00|C|00|1|00|B|00|8|00|7|00|C|00|-|00|3|00|3|00|4|00|2|00|-|00|4|00|4|00|5|00|F|00|-|00|9|00|B|00|5|00|E|00|-|00|3|00|6|00|5|00|F|00|F|00|3|00|3|00|0|00|A|00|3|00|A|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x004\x00C\x001\x00B\x008\x007\x00C\x00-\x003\x003\x004\x002\x00-\x004\x004\x005\x00F\x00-\x009\x00B\x005\x00E\x00-\x003\x006\x005\x00F\x00F\x003\x003\x000\x00A\x003\x00A\x00C\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13858</id>
        <msg>WEB-ACTIVEX HP Instant Support DataManager ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>29536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0953</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HPISDataManagerLib.Datamgr&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22HPISDataManagerLib\.Datamgr\x22|\x27HPISDataManagerLib\.Datamgr\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile)\s*|.*(?P=v)\s*\.\s*(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HPISDataManagerLib\.Datamgr\x22|\x27HPISDataManagerLib\.Datamgr\x27)\s*\)(\s*\.\s*(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile)\s*|.*(?P=n)\s*\.\s*(DownloadFile|GetFileTime|MoveFile|StartApp|RegistryString|AppendStringToFile|DeleteStringFile)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13859</id>
        <msg>WEB-ACTIVEX HP Instant Support DataManager ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>29536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0953</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;H|00|P|00|I|00|S|00|D|00|a|00|t|00|a|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|L|00|i|00|b|00|.|00|D|00|a|00|t|00|a|00|m|00|g|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)H\x00P\x00I\x00S\x00D\x00a\x00t\x00a\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00L\x00i\x00b\x00.\x00D\x00a\x00t\x00a\x00m\x00g\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)H\x00P\x00I\x00S\x00D\x00a\x00t\x00a\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00L\x00i\x00b\x00.\x00D\x00a\x00t\x00a\x00m\x00g\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13860</id>
        <msg>WEB-ACTIVEX HP Instant Support DataManager ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>29963</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2CACD7BB-1C59-4BBB-8E81-6E83F82C813B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2CACD7BB-1C59-4BBB-8E81-6E83F82C813B\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Update)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2CACD7BB-1C59-4BBB-8E81-6E83F82C813B\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Update))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13883</id>
        <msg>WEB-ACTIVEX UUSee UUUpgrade ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>29963</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|C|00|A|00|C|00|D|00|7|00|B|00|B|00|-|00|1|00|C|00|5|00|9|00|-|00|4|00|B|00|B|00|B|00|-|00|8|00|E|00|8|00|1|00|-|00|6|00|E|00|8|00|3|00|F|00|8|00|2|00|C|00|8|00|1|00|3|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13884</id>
        <msg>WEB-ACTIVEX UUSee UUUpgrade ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29963</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;UUUPGRADE.UUUpgradeCtrl.1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22UUUPGRADE\.UUUpgradeCtrl\.1\x22|\x27UUUPGRADE\.UUUpgradeCtrl\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Update\s*|.*(?P=v)\s*\.\s*Update\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22UUUPGRADE\.UUUpgradeCtrl\.1\x22|\x27UUUPGRADE\.UUUpgradeCtrl\.1\x27)\s*\)(\s*\.\s*Update\s*|.*(?P=n)\s*\.\s*Update\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13885</id>
        <msg>WEB-ACTIVEX UUSee UUUpgrade ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>29963</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;U|00|U|00|U|00|P|00|G|00|R|00|A|00|D|00|E|00|.|00|U|00|U|00|U|00|p|00|g|00|r|00|a|00|d|00|e|00|C|00|t|00|r|00|l|00|.|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)U\x00U\x00U\x00P\x00G\x00R\x00A\x00D\x00E\x00.\x00U\x00U\x00U\x00p\x00g\x00r\x00a\x00d\x00e\x00C\x00t\x00r\x00l\x00.\x001\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)U\x00U\x00U\x00P\x00G\x00R\x00A\x00D\x00E\x00.\x00U\x00U\x00U\x00p\x00g\x00r\x00a\x00d\x00e\x00C\x00t\x00r\x00l\x00.\x001\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13886</id>
        <msg>WEB-ACTIVEX UUSee UUUpgrade ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-1435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.search-ms; metadata: engine shared, soid 3|13893, policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop;</filter2>
        <id>13893</id>
        <msg>WEB-CLIENT Microsoft malformed saved search heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F0E42D50-368C-11D0-AD81-00A0C90DC8D9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F0E42D50-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapshotPath|CompressedPath)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F0E42D50-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(SnapshotPath|CompressedPath))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13903</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|0|00|E|00|4|00|2|00|D|00|5|00|0|00|-|00|3|00|6|00|8|00|C|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|D|00|8|00|1|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|D|00|C|00|8|00|D|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13904</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;snpvw.Snapshot Viewer Control&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22snpvw\.Snapshot\s*Viewer\s*Control(\.\d)?\x22|\x27snpvw\.Snapshot\s*Viewer\s*Control(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SnapshotPath|CompressedPath)\s*|.*(?P=v)\s*\.\s*(SnapshotPath|CompressedPath)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22snpvw\.Snapshot\s*Viewer\s*Control(\.\d)?\x22|\x27snpvw\.Snapshot\s*Viewer\s*Control(\.\d)?\x27)\s*\)(\s*\.\s*(SnapshotPath|CompressedPath)\s*|.*(?P=n)\s*\.\s*(SnapshotPath|CompressedPath))\s*=/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13905</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;s|00|n|00|p|00|v|00|w|00|.|00|S|00|n|00|a|00|p|00|s|00|h|00|o|00|t|00| |00|V|00|i|00|e|00|w|00|e|00|r|00| |00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)s\x00n\x00p\x00v\x00w\x00.\x00S\x00n\x00a\x00p\x00s\x00h\x00o\x00t\x00(\s\x00)*V\x00i\x00e\x00w\x00e\x00r\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)s\x00n\x00p\x00v\x00w\x00.\x00S\x00n\x00a\x00p\x00s\x00h\x00o\x00t\x00(\s\x00)*V\x00i\x00e\x00w\x00e\x00r\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13906</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F0E42D60-368C-11D0-AD81-00A0C90DC8D9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F0E42D60-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapshotPath|CompressedPath)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F0E42D60-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(SnapshotPath|CompressedPath))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13907</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|0|00|E|00|4|00|2|00|D|00|6|00|0|00|-|00|3|00|6|00|8|00|C|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|D|00|8|00|1|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|D|00|C|00|8|00|D|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13908</id>
        <msg>WEB-ACTIVEX Microsoft Access Snapshot Viewer 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.search-ms&quot;; nocase; http_uri; flowbits:set,http.search-ms; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>13911</id>
        <msg>WEB-CLIENT Microsoft search file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>21155</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AcroPDF.PDF&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AcroPDF\.PDF(\.\d)?\x22|\x27AcroPDF\.PDF(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode)\s*|.*(?P=v)\s*\.\s*(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AcroPDF\.PDF(\.\d)?\x22|\x27AcroPDF\.PDF(\.\d)?\x27)\s*\)(\s*\.\s*(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode)\s*|.*(?P=n)\s*\.\s*(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode)\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13913</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX function call access</msg>
        <url>www.adobe.com/support/security/advisories/apsa06-02.html</url>
      </rule>
      <rule>
        <bugtraq>21155</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|c|00|r|00|o|00|P|00|D|00|F|00|.|00|P|00|D|00|F|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00c\x00r\x00o\x00P\x00D\x00F\x00.\x00P\x00D\x00F\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00c\x00r\x00o\x00P\x00D\x00F\x00.\x00P\x00D\x00F\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13914</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX function call unicode access</msg>
        <url>www.adobe.com/support/security/advisories/apsa06-02.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0082</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13965, service http, policy security-ips alert;</filter2>
        <id>13965</id>
        <msg>WEB-ACTIVEX Microsoft Message System ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0082</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13967, service http, policy security-ips alert;</filter2>
        <id>13967</id>
        <msg>WEB-ACTIVEX Microsoft Message System ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1455</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|13971, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13971</id>
        <msg>WEB-CLIENT Microsoft Powerpoint TxMasterStyle10Atom atom numLevels buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-051.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1457</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13975, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>13975</id>
        <msg>WEB-CLIENT Microsoft Windows Event System ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-049.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1457</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13977, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>13977</id>
        <msg>WEB-CLIENT Microsoft Windows Event System ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-049.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1457</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13979, service http, policy security-ips alert;</filter2>
        <id>13979</id>
        <msg>WEB-CLIENT Microsoft Windows Event System Subscription VBScript access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-049.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.ppt&quot;; nocase; http_uri; flowbits:set,ppt.download; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>13982</id>
        <msg>WEB-CLIENT Microsoft Powerpoint file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>30578</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;32E26FD9-F435-4A20-A561-35D4B987CFDC&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*32E26FD9-F435-4A20-A561-35D4B987CFDC\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(NewObject)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*32E26FD9-F435-4A20-A561-35D4B987CFDC\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(NewObject))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14013</id>
        <msg>WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX clsid access</msg>
        <url>www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml</url>
      </rule>
      <rule>
        <bugtraq>30578</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|2|00|E|00|2|00|6|00|F|00|D|00|9|00|-|00|F|00|4|00|3|00|5|00|-|00|4|00|A|00|2|00|0|00|-|00|A|00|5|00|6|00|1|00|-|00|3|00|5|00|D|00|4|00|B|00|9|00|8|00|7|00|C|00|F|00|D|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x002\x00E\x002\x006\x00F\x00D\x009\x00-\x00F\x004\x003\x005\x00-\x004\x00A\x002\x000\x00-\x00A\x005\x006\x001\x00-\x003\x005\x00D\x004\x00B\x009\x008\x007\x00C\x00F\x00D\x00C\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14014</id>
        <msg>WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX clsid unicode access</msg>
        <url>www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml</url>
      </rule>
      <rule>
        <bugtraq>30578</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WebexUCFObject.WebexUCFObject&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WebexUCFObject\.WebexUCFObject\x22|\x27WebexUCFObject\.WebexUCFObject\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*NewObject\s*|.*(?P=v)\s*\.\s*NewObject\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WebexUCFObject\.WebexUCFObject\x22|\x27WebexUCFObject\.WebexUCFObject\x27)\s*\)(\s*\.\s*NewObject\s*|.*(?P=n)\s*\.\s*NewObject\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14015</id>
        <msg>WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX function call access</msg>
        <url>www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml</url>
      </rule>
      <rule>
        <bugtraq>30578</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|e|00|b|00|e|00|x|00|U|00|C|00|F|00|O|00|b|00|j|00|e|00|c|00|t|00|.|00|W|00|e|00|b|00|e|00|x|00|U|00|C|00|F|00|O|00|b|00|j|00|e|00|c|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00e\x00b\x00e\x00x\x00U\x00C\x00F\x00O\x00b\x00j\x00e\x00c\x00t\x00.\x00W\x00e\x00b\x00e\x00x\x00U\x00C\x00F\x00O\x00b\x00j\x00e\x00c\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)W\x00e\x00b\x00e\x00x\x00U\x00C\x00F\x00O\x00b\x00j\x00e\x00c\x00t\x00.\x00W\x00e\x00b\x00e\x00x\x00U\x00C\x00F\x00O\x00b\x00j\x00e\x00c\x00t\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14016</id>
        <msg>WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX function call unicode access</msg>
        <url>www.cisco.com/warp/public/707/cisco-sa-20080814-webex.shtml</url>
      </rule>
      <rule>
        <bugtraq>30674</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C932BA85-4374-101B-A56C-00AA003668DC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C932BA85-4374-101B-A56C-00AA003668DC\s*}?\s*(?P=q13)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14021</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <bugtraq>30674</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|9|00|3|00|2|00|B|00|A|00|8|00|5|00|-|00|4|00|3|00|7|00|4|00|-|00|1|00|0|00|1|00|B|00|-|00|A|00|5|00|6|00|C|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|3|00|6|00|6|00|8|00|D|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q14&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x009\x003\x002\x00B\x00A\x008\x005\x00-\x004\x003\x007\x004\x00-\x001\x000\x001\x00B\x00-\x00A\x005\x006\x00C\x00-\x000\x000\x00A\x00A\x000\x000\x003\x006\x006\x008\x00D\x00C\x00(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14022</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <bugtraq>30674</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MSMask.MaskEdBox&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MSMask\.MaskEdBox(\.\d)?\x22|\x27MSMask\.MaskEdBox(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MSMask\.MaskEdBox(\.\d)?\x22|\x27MSMask\.MaskEdBox(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14023</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <bugtraq>30674</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|S|00|M|00|a|00|s|00|k|00|.|00|M|00|a|00|s|00|k|00|E|00|d|00|B|00|o|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)M\x00S\x00M\x00a\x00s\x00k\x00.\x00M\x00a\x00s\x00k\x00E\x00d\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q15)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)M\x00S\x00M\x00a\x00s\x00k\x00.\x00M\x00a\x00s\x00k\x00E\x00d\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q16)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14024</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E6239EB3-E0B0-46DA-A215-CFA9B3B740C5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetColumnLabel)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetColumnLabel))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14025</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|2|00|3|00|9|00|E|00|B|00|3|00|-|00|E|00|0|00|B|00|0|00|-|00|4|00|6|00|D|00|A|00|-|00|A|00|2|00|1|00|5|00|-|00|C|00|F|00|A|00|9|00|B|00|3|00|B|00|7|00|4|00|0|00|C|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x006\x002\x003\x009\x00E\x00B\x003\x00-\x00E\x000\x00B\x000\x00-\x004\x006\x00D\x00A\x00-\x00A\x002\x001\x005\x00-\x00C\x00F\x00A\x009\x00B\x003\x00B\x007\x004\x000\x00C\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14026</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28809</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CommonActiveX.ITRMLegendsCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CommonActiveX\.ITRMLegendsCtrl\x22|\x27CommonActiveX\.ITRMLegendsCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SetColumnColor|SetColumnLabel)\s*|.*(?P=v)\s*\.\s*(SetColumnColor|SetColumnLabel)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CommonActiveX\.ITRMLegendsCtrl\x22|\x27CommonActiveX\.ITRMLegendsCtrl\x27)\s*\)(\s*\.\s*(SetColumnColor|SetColumnLabel)\s*|.*(?P=n)\s*\.\s*(SetColumnColor|SetColumnLabel)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14027</id>
        <msg>WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28809</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|o|00|m|00|m|00|o|00|n|00|A|00|c|00|t|00|i|00|v|00|e|00|X|00|.|00|I|00|T|00|R|00|M|00|L|00|e|00|g|00|e|00|n|00|d|00|s|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00o\x00m\x00m\x00o\x00n\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00.\x00I\x00T\x00R\x00M\x00L\x00e\x00g\x00e\x00n\x00d\x00s\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00o\x00m\x00m\x00o\x00n\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00.\x00I\x00T\x00R\x00M\x00L\x00e\x00g\x00e\x00n\x00d\x00s\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14028</id>
        <msg>WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E6239EB3-E0B0-46DA-A215-CFA9B3B740C5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetColumnColor)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6239EB3-E0B0-46DA-A215-CFA9B3B740C5\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetColumnColor))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14029</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|2|00|3|00|9|00|E|00|B|00|3|00|-|00|E|00|0|00|B|00|0|00|-|00|4|00|6|00|D|00|A|00|-|00|A|00|2|00|1|00|5|00|-|00|C|00|F|00|A|00|9|00|B|00|3|00|B|00|7|00|4|00|0|00|C|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x006\x002\x003\x009\x00E\x00B\x003\x00-\x00E\x000\x00B\x000\x00-\x004\x006\x00D\x00A\x00-\x00A\x002\x001\x005\x00-\x00C\x00F\x00A\x009\x00B\x003\x00B\x007\x004\x000\x00C\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14030</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CommonActiveX.ITRMLegendsCtrl.1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CommonActiveX\.ITRMLegendsCtrl\.1\x22|\x27CommonActiveX\.ITRMLegendsCtrl\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetColumnColor\s*|.*(?P=v)\s*\.\s*SetColumnColor\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CommonActiveX\.ITRMLegendsCtrl\.1\x22|\x27CommonActiveX\.ITRMLegendsCtrl\.1\x27)\s*\)(\s*\.\s*SetColumnColor\s*|.*(?P=n)\s*\.\s*SetColumnColor\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14031</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1786</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|o|00|m|00|m|00|o|00|n|00|A|00|c|00|t|00|i|00|v|00|e|00|X|00|.|00|I|00|T|00|R|00|M|00|L|00|e|00|g|00|e|00|n|00|d|00|s|00|C|00|t|00|r|00|l|00|.|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00o\x00m\x00m\x00o\x00n\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00.\x00I\x00T\x00R\x00M\x00L\x00e\x00g\x00e\x00n\x00d\x00s\x00C\x00t\x00r\x00l\x00.\x001\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00o\x00m\x00m\x00o\x00n\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00.\x00I\x00T\x00R\x00M\x00L\x00e\x00g\x00e\x00n\x00d\x00s\x00C\x00t\x00r\x00l\x00.\x001\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14032</id>
        <msg>WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B60770C2-0390-41A8-A8DE-61889888D840&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B60770C2-0390-41A8-A8DE-61889888D840\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14088</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|6|00|0|00|7|00|7|00|0|00|C|00|2|00|-|00|0|00|3|00|9|00|0|00|-|00|4|00|1|00|A|00|8|00|-|00|A|00|8|00|D|00|E|00|-|00|6|00|1|00|8|00|8|00|9|00|8|00|8|00|8|00|D|00|8|00|4|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x006\x000\x007\x007\x000\x00C\x002\x00-\x000\x003\x009\x000\x00-\x004\x001\x00A\x008\x00-\x00A\x008\x00D\x00E\x00-\x006\x001\x008\x008\x009\x008\x008\x008\x00D\x008\x004\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14089</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;44A6A9CA-AC5B-4C39-8FE6-17E7D06903A9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q23&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*44A6A9CA-AC5B-4C39-8FE6-17E7D06903A9\s*}?\s*(?P=q23)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14090</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|A|00|6|00|A|00|9|00|C|00|A|00|-|00|A|00|C|00|5|00|B|00|-|00|4|00|C|00|3|00|9|00|-|00|8|00|F|00|E|00|6|00|-|00|1|00|7|00|E|00|7|00|D|00|0|00|6|00|9|00|0|00|3|00|A|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q24&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x00A\x006\x00A\x009\x00C\x00A\x00-\x00A\x00C\x005\x00B\x00-\x004\x00C\x003\x009\x00-\x008\x00F\x00E\x006\x00-\x001\x007\x00E\x007\x00D\x000\x006\x009\x000\x003\x00A\x009\x00(}\x00)?(?P=q24)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14091</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;76EE578D-314B-4755-8365-6E1722C001A2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q45&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*76EE578D-314B-4755-8365-6E1722C001A2\s*}?\s*(?P=q45)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14092</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|6|00|E|00|E|00|5|00|7|00|8|00|D|00|-|00|3|00|1|00|4|00|B|00|-|00|4|00|7|00|5|00|5|00|-|00|8|00|3|00|6|00|5|00|-|00|6|00|E|00|1|00|7|00|2|00|2|00|C|00|0|00|0|00|1|00|A|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q46&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x006\x00E\x00E\x005\x007\x008\x00D\x00-\x003\x001\x004\x00B\x00-\x004\x007\x005\x005\x00-\x008\x003\x006\x005\x00-\x006\x00E\x001\x007\x002\x002\x00C\x000\x000\x001\x00A\x002\x00(}\x00)?(?P=q46)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14093</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F89EF74A-956B-4BD3-A066-4F23DF891982&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q67&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F89EF74A-956B-4BD3-A066-4F23DF891982\s*}?\s*(?P=q67)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14094</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|8|00|9|00|E|00|F|00|7|00|4|00|A|00|-|00|9|00|5|00|6|00|B|00|-|00|4|00|B|00|D|00|3|00|-|00|A|00|0|00|6|00|6|00|-|00|4|00|F|00|2|00|3|00|D|00|F|00|8|00|9|00|1|00|9|00|8|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q68&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x008\x009\x00E\x00F\x007\x004\x00A\x00-\x009\x005\x006\x00B\x00-\x004\x00B\x00D\x003\x00-\x00A\x000\x006\x006\x00-\x004\x00F\x002\x003\x00D\x00F\x008\x009\x001\x009\x008\x002\x00(}\x00)?(?P=q68)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14095</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;101D2283-EED9-4BA2-8F3F-23DB860946EB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q89&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*101D2283-EED9-4BA2-8F3F-23DB860946EB\s*}?\s*(?P=q89)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14096</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|0|00|1|00|D|00|2|00|2|00|8|00|3|00|-|00|E|00|E|00|D|00|9|00|-|00|4|00|B|00|A|00|2|00|-|00|8|00|F|00|3|00|F|00|-|00|2|00|3|00|D|00|B|00|8|00|6|00|0|00|9|00|4|00|6|00|E|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q90&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x000\x001\x00D\x002\x002\x008\x003\x00-\x00E\x00E\x00D\x009\x00-\x004\x00B\x00A\x002\x00-\x008\x00F\x003\x00F\x00-\x002\x003\x00D\x00B\x008\x006\x000\x009\x004\x006\x00E\x00B\x00(}\x00)?(?P=q90)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14097</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;69C462E1-CD41-49E3-9EC2-D305155718C1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q111&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*69C462E1-CD41-49E3-9EC2-D305155718C1\s*}?\s*(?P=q111)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14098</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 6 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|9|00|C|00|4|00|6|00|2|00|E|00|1|00|-|00|C|00|D|00|4|00|1|00|-|00|4|00|9|00|E|00|3|00|-|00|9|00|E|00|C|00|2|00|-|00|D|00|3|00|0|00|5|00|1|00|5|00|5|00|7|00|1|00|8|00|C|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q112&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x009\x00C\x004\x006\x002\x00E\x001\x00-\x00C\x00D\x004\x001\x00-\x004\x009\x00E\x003\x00-\x009\x00E\x00C\x002\x00-\x00D\x003\x000\x005\x001\x005\x005\x007\x001\x008\x00C\x001\x00(}\x00)?(?P=q112)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14099</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 6 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;41473CFB-66B6-45B8-8FB3-2BC9C1FD87BA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q133&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*41473CFB-66B6-45B8-8FB3-2BC9C1FD87BA\s*}?\s*(?P=q133)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14100</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 7 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|4|00|7|00|3|00|C|00|F|00|B|00|-|00|6|00|6|00|B|00|6|00|-|00|4|00|5|00|B|00|8|00|-|00|8|00|F|00|B|00|3|00|-|00|2|00|B|00|C|00|9|00|C|00|1|00|F|00|D|00|8|00|7|00|B|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q134&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x001\x004\x007\x003\x00C\x00F\x00B\x00-\x006\x006\x00B\x006\x00-\x004\x005\x00B\x008\x00-\x008\x00F\x00B\x003\x00-\x002\x00B\x00C\x009\x00C\x001\x00F\x00D\x008\x007\x00B\x00A\x00(}\x00)?(?P=q134)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14101</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 7 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;108092BF-B7DB-40D1-B7FB-F55922FCC9BE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q139&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*108092BF-B7DB-40D1-B7FB-F55922FCC9BE\s*}?\s*(?P=q139)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14102</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 8 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|0|00|8|00|0|00|9|00|2|00|B|00|F|00|-|00|B|00|7|00|D|00|B|00|-|00|4|00|0|00|D|00|1|00|-|00|B|00|7|00|F|00|B|00|-|00|F|00|5|00|5|00|9|00|2|00|2|00|F|00|C|00|C|00|9|00|B|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q140&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x000\x008\x000\x009\x002\x00B\x00F\x00-\x00B\x007\x00D\x00B\x00-\x004\x000\x00D\x001\x00-\x00B\x007\x00F\x00B\x00-\x00F\x005\x005\x009\x002\x002\x00F\x00C\x00C\x009\x00B\x00E\x00(}\x00)?(?P=q140)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14103</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 8 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CF08D263-B832-42DB-8950-F40C9E672E27&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q141&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CF08D263-B832-42DB-8950-F40C9E672E27\s*}?\s*(?P=q141)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14104</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 9 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|0|00|8|00|D|00|2|00|6|00|3|00|-|00|B|00|8|00|3|00|2|00|-|00|4|00|2|00|D|00|B|00|-|00|8|00|9|00|5|00|0|00|-|00|F|00|4|00|0|00|C|00|9|00|E|00|6|00|7|00|2|00|E|00|2|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q142&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00F\x000\x008\x00D\x002\x006\x003\x00-\x00B\x008\x003\x002\x00-\x004\x002\x00D\x00B\x00-\x008\x009\x005\x000\x00-\x00F\x004\x000\x00C\x009\x00E\x006\x007\x002\x00E\x002\x007\x00(}\x00)?(?P=q142)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14105</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 9 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F1F51698-7B63-4394-8743-1F4CF1853DE1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F1F51698-7B63-4394-8743-1F4CF1853DE1\s*}?\s*(?P=q3)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14106</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 10 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|1|00|F|00|5|00|1|00|6|00|9|00|8|00|-|00|7|00|B|00|6|00|3|00|-|00|4|00|3|00|9|00|4|00|-|00|8|00|7|00|4|00|3|00|-|00|1|00|F|00|4|00|C|00|F|00|1|00|8|00|5|00|3|00|D|00|E|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q4&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x001\x00F\x005\x001\x006\x009\x008\x00-\x007\x00B\x006\x003\x00-\x004\x003\x009\x004\x00-\x008\x007\x004\x003\x00-\x001\x00F\x004\x00C\x00F\x001\x008\x005\x003\x00D\x00E\x001\x00(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14107</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 10 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;905BF7D7-6BC1-445A-BE53-9478AC096BEB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*905BF7D7-6BC1-445A-BE53-9478AC096BEB\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14108</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 11 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|0|00|5|00|B|00|F|00|7|00|D|00|7|00|-|00|6|00|B|00|C|00|1|00|-|00|4|00|4|00|5|00|A|00|-|00|B|00|E|00|5|00|3|00|-|00|9|00|4|00|7|00|8|00|A|00|C|00|0|00|9|00|6|00|B|00|E|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x000\x005\x00B\x00F\x007\x00D\x007\x00-\x006\x00B\x00C\x001\x00-\x004\x004\x005\x00A\x00-\x00B\x00E\x005\x003\x00-\x009\x004\x007\x008\x00A\x00C\x000\x009\x006\x00B\x00E\x00B\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14109</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 11 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;916063A5-0098-4FB7-8717-1B2C62DD4E45&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*916063A5-0098-4FB7-8717-1B2C62DD4E45\s*}?\s*(?P=q7)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14110</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 12 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|1|00|6|00|0|00|6|00|3|00|A|00|5|00|-|00|0|00|0|00|9|00|8|00|-|00|4|00|F|00|B|00|7|00|-|00|8|00|7|00|1|00|7|00|-|00|1|00|B|00|2|00|C|00|6|00|2|00|D|00|D|00|4|00|E|00|4|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x001\x006\x000\x006\x003\x00A\x005\x00-\x000\x000\x009\x008\x00-\x004\x00F\x00B\x007\x00-\x008\x007\x001\x007\x00-\x001\x00B\x002\x00C\x006\x002\x00D\x00D\x004\x00E\x004\x005\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14111</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 12 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4\s*}?\s*(?P=q9)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14112</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 13 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|E|00|2|00|B|00|9|00|3|00|7|00|E|00|-|00|E|00|A|00|7|00|D|00|-|00|4|00|A|00|8|00|D|00|-|00|8|00|8|00|8|00|C|00|-|00|B|00|6|00|8|00|D|00|7|00|F|00|7|00|2|00|A|00|3|00|C|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00E\x002\x00B\x009\x003\x007\x00E\x00-\x00E\x00A\x007\x00D\x00-\x004\x00A\x008\x00D\x00-\x008\x008\x008\x00C\x00-\x00B\x006\x008\x00D\x007\x00F\x007\x002\x00A\x003\x00C\x004\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14113</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 13 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AE6C4705-0F11-4ACB-BDD4-37F138BEF289&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AE6C4705-0F11-4ACB-BDD4-37F138BEF289\s*}?\s*(?P=q11)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14114</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 14 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|E|00|6|00|C|00|4|00|7|00|0|00|5|00|-|00|0|00|F|00|1|00|1|00|-|00|4|00|A|00|C|00|B|00|-|00|B|00|D|00|D|00|4|00|-|00|3|00|7|00|F|00|1|00|3|00|8|00|B|00|E|00|F|00|2|00|8|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q12&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00E\x006\x00C\x004\x007\x000\x005\x00-\x000\x00F\x001\x001\x00-\x004\x00A\x00C\x00B\x00-\x00B\x00D\x00D\x004\x00-\x003\x007\x00F\x001\x003\x008\x00B\x00E\x00F\x002\x008\x009\x00(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14115</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 14 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FA8932FF-E064-4378-901C-69CB94E3A20A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FA8932FF-E064-4378-901C-69CB94E3A20A\s*}?\s*(?P=q13)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14116</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 15 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|A|00|8|00|9|00|3|00|2|00|F|00|F|00|-|00|E|00|0|00|6|00|4|00|-|00|4|00|3|00|7|00|8|00|-|00|9|00|0|00|1|00|C|00|-|00|6|00|9|00|C|00|B|00|9|00|4|00|E|00|3|00|A|00|2|00|0|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q14&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00A\x008\x009\x003\x002\x00F\x00F\x00-\x00E\x000\x006\x004\x00-\x004\x003\x007\x008\x00-\x009\x000\x001\x00C\x00-\x006\x009\x00C\x00B\x009\x004\x00E\x003\x00A\x002\x000\x00A\x00(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14117</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 15 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3604EC19-E009-4DCB-ABC5-BB95BF92FD8B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3604EC19-E009-4DCB-ABC5-BB95BF92FD8B\s*}?\s*(?P=q15)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14118</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 16 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|6|00|0|00|4|00|E|00|C|00|1|00|9|00|-|00|E|00|0|00|0|00|9|00|-|00|4|00|D|00|C|00|B|00|-|00|A|00|B|00|C|00|5|00|-|00|B|00|B|00|9|00|5|00|B|00|F|00|9|00|2|00|F|00|D|00|8|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q16&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x006\x000\x004\x00E\x00C\x001\x009\x00-\x00E\x000\x000\x009\x00-\x004\x00D\x00C\x00B\x00-\x00A\x00B\x00C\x005\x00-\x00B\x00B\x009\x005\x00B\x00F\x009\x002\x00F\x00D\x008\x00B\x00(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14119</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 16 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;65FB3073-CA8E-42A1-9A9A-2F826D05A843&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*65FB3073-CA8E-42A1-9A9A-2F826D05A843\s*}?\s*(?P=q17)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14120</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 17 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|5|00|F|00|B|00|3|00|0|00|7|00|3|00|-|00|C|00|A|00|8|00|E|00|-|00|4|00|2|00|A|00|1|00|-|00|9|00|A|00|9|00|A|00|-|00|2|00|F|00|8|00|2|00|6|00|D|00|0|00|5|00|A|00|8|00|4|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q18&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x005\x00F\x00B\x003\x000\x007\x003\x00-\x00C\x00A\x008\x00E\x00-\x004\x002\x00A\x001\x00-\x009\x00A\x009\x00A\x00-\x002\x00F\x008\x002\x006\x00D\x000\x005\x00A\x008\x004\x003\x00(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14121</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 17 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7EB2A2EC-1C3A-4946-9614-86D3A10EDBF3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7EB2A2EC-1C3A-4946-9614-86D3A10EDBF3\s*}?\s*(?P=q19)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14122</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 18 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|E|00|B|00|2|00|A|00|2|00|E|00|C|00|-|00|1|00|C|00|3|00|A|00|-|00|4|00|9|00|4|00|6|00|-|00|9|00|6|00|1|00|4|00|-|00|8|00|6|00|D|00|3|00|A|00|1|00|0|00|E|00|D|00|B|00|F|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q20&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00E\x00B\x002\x00A\x002\x00E\x00C\x00-\x001\x00C\x003\x00A\x00-\x004\x009\x004\x006\x00-\x009\x006\x001\x004\x00-\x008\x006\x00D\x003\x00A\x001\x000\x00E\x00D\x00B\x00F\x003\x00(}\x00)?(?P=q20)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14123</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 18 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9BAFC7B3-F318-4BD4-BABB-6E403272615A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9BAFC7B3-F318-4BD4-BABB-6E403272615A\s*}?\s*(?P=q21)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14124</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 19 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|B|00|A|00|F|00|C|00|7|00|B|00|3|00|-|00|F|00|3|00|1|00|8|00|-|00|4|00|B|00|D|00|4|00|-|00|B|00|A|00|B|00|B|00|-|00|6|00|E|00|4|00|0|00|3|00|2|00|7|00|2|00|6|00|1|00|5|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q22&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00B\x00A\x00F\x00C\x007\x00B\x003\x00-\x00F\x003\x001\x008\x00-\x004\x00B\x00D\x004\x00-\x00B\x00A\x00B\x00B\x00-\x006\x00E\x004\x000\x003\x002\x007\x002\x006\x001\x005\x00A\x00(}\x00)?(?P=q22)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14125</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 19 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;05CDEE1D-D109-4992-B72B-6D4F5E2AB731&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*05CDEE1D-D109-4992-B72B-6D4F5E2AB731\s*}?\s*(?P=q25)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14126</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 20 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|5|00|C|00|D|00|E|00|E|00|1|00|D|00|-|00|D|00|1|00|0|00|9|00|-|00|4|00|9|00|9|00|2|00|-|00|B|00|7|00|2|00|B|00|-|00|6|00|D|00|4|00|F|00|5|00|E|00|2|00|A|00|B|00|7|00|3|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q26&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x005\x00C\x00D\x00E\x00E\x001\x00D\x00-\x00D\x001\x000\x009\x00-\x004\x009\x009\x002\x00-\x00B\x007\x002\x00B\x00-\x006\x00D\x004\x00F\x005\x00E\x002\x00A\x00B\x007\x003\x001\x00(}\x00)?(?P=q26)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14127</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 20 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;977315A5-C0DB-4EFD-89C2-10AA86CA39A5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*977315A5-C0DB-4EFD-89C2-10AA86CA39A5\s*}?\s*(?P=q27)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14128</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 21 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|7|00|7|00|3|00|1|00|5|00|A|00|5|00|-|00|C|00|0|00|D|00|B|00|-|00|4|00|E|00|F|00|D|00|-|00|8|00|9|00|C|00|2|00|-|00|1|00|0|00|A|00|A|00|8|00|6|00|C|00|A|00|3|00|9|00|A|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q28&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x007\x007\x003\x001\x005\x00A\x005\x00-\x00C\x000\x00D\x00B\x00-\x004\x00E\x00F\x00D\x00-\x008\x009\x00C\x002\x00-\x001\x000\x00A\x00A\x008\x006\x00C\x00A\x003\x009\x00A\x005\x00(}\x00)?(?P=q28)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14129</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 21 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1E0D3332-7441-44FF-A225-AF48E977D8B6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q29&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1E0D3332-7441-44FF-A225-AF48E977D8B6\s*}?\s*(?P=q29)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14130</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 22 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|E|00|0|00|D|00|3|00|3|00|3|00|2|00|-|00|7|00|4|00|4|00|1|00|-|00|4|00|4|00|F|00|F|00|-|00|A|00|2|00|2|00|5|00|-|00|A|00|F|00|4|00|8|00|E|00|9|00|7|00|7|00|D|00|8|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q30&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00E\x000\x00D\x003\x003\x003\x002\x00-\x007\x004\x004\x001\x00-\x004\x004\x00F\x00F\x00-\x00A\x002\x002\x005\x00-\x00A\x00F\x004\x008\x00E\x009\x007\x007\x00D\x008\x00B\x006\x00(}\x00)?(?P=q30)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14131</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 22 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B85537E9-2D9C-400A-BC92-B04F4D9FF17D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q31&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B85537E9-2D9C-400A-BC92-B04F4D9FF17D\s*}?\s*(?P=q31)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14132</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 23 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|8|00|5|00|5|00|3|00|7|00|E|00|9|00|-|00|2|00|D|00|9|00|C|00|-|00|4|00|0|00|0|00|A|00|-|00|B|00|C|00|9|00|2|00|-|00|B|00|0|00|4|00|F|00|4|00|D|00|9|00|F|00|F|00|1|00|7|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q32&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x008\x005\x005\x003\x007\x00E\x009\x00-\x002\x00D\x009\x00C\x00-\x004\x000\x000\x00A\x00-\x00B\x00C\x009\x002\x00-\x00B\x000\x004\x00F\x004\x00D\x009\x00F\x00F\x001\x007\x00D\x00(}\x00)?(?P=q32)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14133</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 23 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2C2DE2E6-2AD1-4301-A6A7-DF364858EF01&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q33&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2C2DE2E6-2AD1-4301-A6A7-DF364858EF01\s*}?\s*(?P=q33)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14134</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 24 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|C|00|2|00|D|00|E|00|2|00|E|00|6|00|-|00|2|00|A|00|D|00|1|00|-|00|4|00|3|00|0|00|1|00|-|00|A|00|6|00|A|00|7|00|-|00|D|00|F|00|3|00|6|00|4|00|8|00|5|00|8|00|E|00|F|00|0|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q34&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00C\x002\x00D\x00E\x002\x00E\x006\x00-\x002\x00A\x00D\x001\x00-\x004\x003\x000\x001\x00-\x00A\x006\x00A\x007\x00-\x00D\x00F\x003\x006\x004\x008\x005\x008\x00E\x00F\x000\x001\x00(}\x00)?(?P=q34)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14135</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 24 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0270E604-387F-48ED-BB6D-AA51F51D6FC3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q35&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0270E604-387F-48ED-BB6D-AA51F51D6FC3\s*}?\s*(?P=q35)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14136</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 25 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|2|00|7|00|0|00|E|00|6|00|0|00|4|00|-|00|3|00|8|00|7|00|F|00|-|00|4|00|8|00|E|00|D|00|-|00|B|00|B|00|6|00|D|00|-|00|A|00|A|00|5|00|1|00|F|00|5|00|1|00|D|00|6|00|F|00|C|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q36&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x002\x007\x000\x00E\x006\x000\x004\x00-\x003\x008\x007\x00F\x00-\x004\x008\x00E\x00D\x00-\x00B\x00B\x006\x00D\x00-\x00A\x00A\x005\x001\x00F\x005\x001\x00D\x006\x00F\x00C\x003\x00(}\x00)?(?P=q36)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14137</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 25 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FC28B75F-F9F6-4C92-AF91-14A3A51C49FB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q37&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FC28B75F-F9F6-4C92-AF91-14A3A51C49FB\s*}?\s*(?P=q37)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14138</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 26 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|C|00|2|00|8|00|B|00|7|00|5|00|F|00|-|00|F|00|9|00|F|00|6|00|-|00|4|00|C|00|9|00|2|00|-|00|A|00|F|00|9|00|1|00|-|00|1|00|4|00|A|00|3|00|A|00|5|00|1|00|C|00|4|00|9|00|F|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q38&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00C\x002\x008\x00B\x007\x005\x00F\x00-\x00F\x009\x00F\x006\x00-\x004\x00C\x009\x002\x00-\x00A\x00F\x009\x001\x00-\x001\x004\x00A\x003\x00A\x005\x001\x00C\x004\x009\x00F\x00B\x00(}\x00)?(?P=q38)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14139</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 26 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;86C2B477-5382-4A09-8CA3-E63B1158A377&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q39&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*86C2B477-5382-4A09-8CA3-E63B1158A377\s*}?\s*(?P=q39)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14140</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 27 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|6|00|C|00|2|00|B|00|4|00|7|00|7|00|-|00|5|00|3|00|8|00|2|00|-|00|4|00|A|00|0|00|9|00|-|00|8|00|C|00|A|00|3|00|-|00|E|00|6|00|3|00|B|00|1|00|1|00|5|00|8|00|A|00|3|00|7|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q40&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x006\x00C\x002\x00B\x004\x007\x007\x00-\x005\x003\x008\x002\x00-\x004\x00A\x000\x009\x00-\x008\x00C\x00A\x003\x00-\x00E\x006\x003\x00B\x001\x001\x005\x008\x00A\x003\x007\x007\x00(}\x00)?(?P=q40)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14141</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 27 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8CC18E3F-4E2B-4D27-840E-CB2F99A3A003&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q41&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8CC18E3F-4E2B-4D27-840E-CB2F99A3A003\s*}?\s*(?P=q41)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14142</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 28 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|C|00|C|00|1|00|8|00|E|00|3|00|F|00|-|00|4|00|E|00|2|00|B|00|-|00|4|00|D|00|2|00|7|00|-|00|8|00|4|00|0|00|E|00|-|00|C|00|B|00|2|00|F|00|9|00|9|00|A|00|3|00|A|00|0|00|0|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q42&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00C\x00C\x001\x008\x00E\x003\x00F\x00-\x004\x00E\x002\x00B\x00-\x004\x00D\x002\x007\x00-\x008\x004\x000\x00E\x00-\x00C\x00B\x002\x00F\x009\x009\x00A\x003\x00A\x000\x000\x003\x00(}\x00)?(?P=q42)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14143</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 28 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;68BBCA71-E1F6-47B2-87D3-369E1349D990&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q43&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*68BBCA71-E1F6-47B2-87D3-369E1349D990\s*}?\s*(?P=q43)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14144</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 29 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|B|00|B|00|C|00|A|00|7|00|1|00|-|00|E|00|1|00|F|00|6|00|-|00|4|00|7|00|B|00|2|00|-|00|8|00|7|00|D|00|3|00|-|00|3|00|6|00|9|00|E|00|1|00|3|00|4|00|9|00|D|00|9|00|9|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q44&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x008\x00B\x00B\x00C\x00A\x007\x001\x00-\x00E\x001\x00F\x006\x00-\x004\x007\x00B\x002\x00-\x008\x007\x00D\x003\x00-\x003\x006\x009\x00E\x001\x003\x004\x009\x00D\x009\x009\x000\x00(}\x00)?(?P=q44)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14145</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 29 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8DBC7A04-B478-41D5-BE05-5545D565B59C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q47&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8DBC7A04-B478-41D5-BE05-5545D565B59C\s*}?\s*(?P=q47)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14146</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 30 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|D|00|B|00|C|00|7|00|A|00|0|00|4|00|-|00|B|00|4|00|7|00|8|00|-|00|4|00|1|00|D|00|5|00|-|00|B|00|E|00|0|00|5|00|-|00|5|00|5|00|4|00|5|00|D|00|5|00|6|00|5|00|B|00|5|00|9|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q48&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00D\x00B\x00C\x007\x00A\x000\x004\x00-\x00B\x004\x007\x008\x00-\x004\x001\x00D\x005\x00-\x00B\x00E\x000\x005\x00-\x005\x005\x004\x005\x00D\x005\x006\x005\x00B\x005\x009\x00C\x00(}\x00)?(?P=q48)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14147</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 30 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D986FE4B-AE67-43C8-9A89-EADDEA3EC6B6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q49&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D986FE4B-AE67-43C8-9A89-EADDEA3EC6B6\s*}?\s*(?P=q49)(\s|&gt;)/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14148</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 31 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|8|00|6|00|F|00|E|00|4|00|B|00|-|00|A|00|E|00|6|00|7|00|-|00|4|00|3|00|C|00|8|00|-|00|9|00|A|00|8|00|9|00|-|00|E|00|A|00|D|00|D|00|E|00|A|00|3|00|E|00|C|00|6|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q50&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x009\x008\x006\x00F\x00E\x004\x00B\x00-\x00A\x00E\x006\x007\x00-\x004\x003\x00C\x008\x00-\x009\x00A\x008\x009\x00-\x00E\x00A\x00D\x00D\x00E\x00A\x003\x00E\x00C\x006\x00B\x006\x00(}\x00)?(?P=q50)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14149</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 31 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6CA73E8B-B584-4533-A405-3D6F9C012B56&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q51&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6CA73E8B-B584-4533-A405-3D6F9C012B56\s*}?\s*(?P=q51)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14150</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 32 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|C|00|A|00|7|00|3|00|E|00|8|00|B|00|-|00|B|00|5|00|8|00|4|00|-|00|4|00|5|00|3|00|3|00|-|00|A|00|4|00|0|00|5|00|-|00|3|00|D|00|6|00|F|00|9|00|C|00|0|00|1|00|2|00|B|00|5|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q52&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00C\x00A\x007\x003\x00E\x008\x00B\x00-\x00B\x005\x008\x004\x00-\x004\x005\x003\x003\x00-\x00A\x004\x000\x005\x00-\x003\x00D\x006\x00F\x009\x00C\x000\x001\x002\x00B\x005\x006\x00(}\x00)?(?P=q52)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14151</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 32 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A7866636-ED52-4722-82A9-6BAABEFDBF96&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q53&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A7866636-ED52-4722-82A9-6BAABEFDBF96\s*}?\s*(?P=q53)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14152</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 33 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|7|00|8|00|6|00|6|00|6|00|3|00|6|00|-|00|E|00|D|00|5|00|2|00|-|00|4|00|7|00|2|00|2|00|-|00|8|00|2|00|A|00|9|00|-|00|6|00|B|00|A|00|A|00|B|00|E|00|F|00|D|00|B|00|F|00|9|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q54&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x007\x008\x006\x006\x006\x003\x006\x00-\x00E\x00D\x005\x002\x00-\x004\x007\x002\x002\x00-\x008\x002\x00A\x009\x00-\x006\x00B\x00A\x00A\x00B\x00E\x00F\x00D\x00B\x00F\x009\x006\x00(}\x00)?(?P=q54)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14153</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 33 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B0A08D67-9464-4E73-A549-2CC208AC60D3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q55&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B0A08D67-9464-4E73-A549-2CC208AC60D3\s*}?\s*(?P=q55)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14154</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 34 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|A|00|0|00|8|00|D|00|6|00|7|00|-|00|9|00|4|00|6|00|4|00|-|00|4|00|E|00|7|00|3|00|-|00|A|00|5|00|4|00|9|00|-|00|2|00|C|00|C|00|2|00|0|00|8|00|A|00|C|00|6|00|0|00|D|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q56&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x000\x00A\x000\x008\x00D\x006\x007\x00-\x009\x004\x006\x004\x00-\x004\x00E\x007\x003\x00-\x00A\x005\x004\x009\x00-\x002\x00C\x00C\x002\x000\x008\x00A\x00C\x006\x000\x00D\x003\x00(}\x00)?(?P=q56)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14155</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 34 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3D6A1A85-DE54-4768-9951-053B3B02B9B0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q57&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3D6A1A85-DE54-4768-9951-053B3B02B9B0\s*}?\s*(?P=q57)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14156</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 35 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|D|00|6|00|A|00|1|00|A|00|8|00|5|00|-|00|D|00|E|00|5|00|4|00|-|00|4|00|7|00|6|00|8|00|-|00|9|00|9|00|5|00|1|00|-|00|0|00|5|00|3|00|B|00|3|00|B|00|0|00|2|00|B|00|9|00|B|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q58&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00D\x006\x00A\x001\x00A\x008\x005\x00-\x00D\x00E\x005\x004\x00-\x004\x007\x006\x008\x00-\x009\x009\x005\x001\x00-\x000\x005\x003\x00B\x003\x00B\x000\x002\x00B\x009\x00B\x000\x00(}\x00)?(?P=q58)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14157</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 35 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;947F2947-2296-42FE-92E6-E2E03519B895&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q59&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*947F2947-2296-42FE-92E6-E2E03519B895\s*}?\s*(?P=q59)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14158</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 36 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|4|00|7|00|F|00|2|00|9|00|4|00|7|00|-|00|2|00|2|00|9|00|6|00|-|00|4|00|2|00|F|00|E|00|-|00|9|00|2|00|E|00|6|00|-|00|E|00|2|00|E|00|0|00|3|00|5|00|1|00|9|00|B|00|8|00|9|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q60&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x004\x007\x00F\x002\x009\x004\x007\x00-\x002\x002\x009\x006\x00-\x004\x002\x00F\x00E\x00-\x009\x002\x00E\x006\x00-\x00E\x002\x00E\x000\x003\x005\x001\x009\x00B\x008\x009\x005\x00(}\x00)?(?P=q60)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14159</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 36 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;47AF06DD-8E1B-4CA4-8F55-6B1E9FF36ACB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q61&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*47AF06DD-8E1B-4CA4-8F55-6B1E9FF36ACB\s*}?\s*(?P=q61)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14160</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 37 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|A|00|F|00|0|00|6|00|D|00|D|00|-|00|8|00|E|00|1|00|B|00|-|00|4|00|C|00|A|00|4|00|-|00|8|00|F|00|5|00|5|00|-|00|6|00|B|00|1|00|E|00|9|00|F|00|F|00|3|00|6|00|A|00|C|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q62&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x007\x00A\x00F\x000\x006\x00D\x00D\x00-\x008\x00E\x001\x00B\x00-\x004\x00C\x00A\x004\x00-\x008\x00F\x005\x005\x00-\x006\x00B\x001\x00E\x009\x00F\x00F\x003\x006\x00A\x00C\x00B\x00(}\x00)?(?P=q62)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14161</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 37 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B26E6120-DD35-4BEA-B1E3-E75F546EBF2A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q63&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B26E6120-DD35-4BEA-B1E3-E75F546EBF2A\s*}?\s*(?P=q63)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14162</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 38 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|2|00|6|00|E|00|6|00|1|00|2|00|0|00|-|00|D|00|D|00|3|00|5|00|-|00|4|00|B|00|E|00|A|00|-|00|B|00|1|00|E|00|3|00|-|00|E|00|7|00|5|00|F|00|5|00|4|00|6|00|E|00|B|00|F|00|2|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q64&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x002\x006\x00E\x006\x001\x002\x000\x00-\x00D\x00D\x003\x005\x00-\x004\x00B\x00E\x00A\x00-\x00B\x001\x00E\x003\x00-\x00E\x007\x005\x00F\x005\x004\x006\x00E\x00B\x00F\x002\x00A\x00(}\x00)?(?P=q64)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14163</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 38 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;926618A9-4035-4CD6-8240-64C58EB37B07&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q65&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*926618A9-4035-4CD6-8240-64C58EB37B07\s*}?\s*(?P=q65)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14164</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 39 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|2|00|6|00|6|00|1|00|8|00|A|00|9|00|-|00|4|00|0|00|3|00|5|00|-|00|4|00|C|00|D|00|6|00|-|00|8|00|2|00|4|00|0|00|-|00|6|00|4|00|C|00|5|00|8|00|E|00|B|00|3|00|7|00|B|00|0|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q66&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x002\x006\x006\x001\x008\x00A\x009\x00-\x004\x000\x003\x005\x00-\x004\x00C\x00D\x006\x00-\x008\x002\x004\x000\x00-\x006\x004\x00C\x005\x008\x00E\x00B\x003\x007\x00B\x000\x007\x00(}\x00)?(?P=q66)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14165</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 39 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B95B52E9-B839-4412-96EB-4DABAB2E4E24&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q69&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B95B52E9-B839-4412-96EB-4DABAB2E4E24\s*}?\s*(?P=q69)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14166</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 40 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|9|00|5|00|B|00|5|00|2|00|E|00|9|00|-|00|B|00|8|00|3|00|9|00|-|00|4|00|4|00|1|00|2|00|-|00|9|00|6|00|E|00|B|00|-|00|4|00|D|00|A|00|B|00|A|00|B|00|2|00|E|00|4|00|E|00|2|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q70&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x009\x005\x00B\x005\x002\x00E\x009\x00-\x00B\x008\x003\x009\x00-\x004\x004\x001\x002\x00-\x009\x006\x00E\x00B\x00-\x004\x00D\x00A\x00B\x00A\x00B\x002\x00E\x004\x00E\x002\x004\x00(}\x00)?(?P=q70)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14167</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 40 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CB05A177-1069-4A7A-AB0A-5E6E00DCDB76&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q71&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CB05A177-1069-4A7A-AB0A-5E6E00DCDB76\s*}?\s*(?P=q71)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14168</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 41 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|B|00|0|00|5|00|A|00|1|00|7|00|7|00|-|00|1|00|0|00|6|00|9|00|-|00|4|00|A|00|7|00|A|00|-|00|A|00|B|00|0|00|A|00|-|00|5|00|E|00|6|00|E|00|0|00|0|00|D|00|C|00|D|00|B|00|7|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q72&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00B\x000\x005\x00A\x001\x007\x007\x00-\x001\x000\x006\x009\x00-\x004\x00A\x007\x00A\x00-\x00A\x00B\x000\x00A\x00-\x005\x00E\x006\x00E\x000\x000\x00D\x00C\x00D\x00B\x007\x006\x00(}\x00)?(?P=q72)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14169</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 41 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A233E654-53FF-43AA-B1E2-60DA2E89A1EC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q73&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A233E654-53FF-43AA-B1E2-60DA2E89A1EC\s*}?\s*(?P=q73)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14170</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 42 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|2|00|3|00|3|00|E|00|6|00|5|00|4|00|-|00|5|00|3|00|F|00|F|00|-|00|4|00|3|00|A|00|A|00|-|00|B|00|1|00|E|00|2|00|-|00|6|00|0|00|D|00|A|00|2|00|E|00|8|00|9|00|A|00|1|00|E|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q74&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x002\x003\x003\x00E\x006\x005\x004\x00-\x005\x003\x00F\x00F\x00-\x004\x003\x00A\x00A\x00-\x00B\x001\x00E\x002\x00-\x006\x000\x00D\x00A\x002\x00E\x008\x009\x00A\x001\x00E\x00C\x00(}\x00)?(?P=q74)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14171</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 42 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6981B978-70D9-40B9-B00E-903B6FC8CA8A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q75&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6981B978-70D9-40B9-B00E-903B6FC8CA8A\s*}?\s*(?P=q75)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14172</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 43 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|9|00|8|00|1|00|B|00|9|00|7|00|8|00|-|00|7|00|0|00|D|00|9|00|-|00|4|00|0|00|B|00|9|00|-|00|B|00|0|00|0|00|E|00|-|00|9|00|0|00|3|00|B|00|6|00|F|00|C|00|8|00|C|00|A|00|8|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q76&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x009\x008\x001\x00B\x009\x007\x008\x00-\x007\x000\x00D\x009\x00-\x004\x000\x00B\x009\x00-\x00B\x000\x000\x00E\x00-\x009\x000\x003\x00B\x006\x00F\x00C\x008\x00C\x00A\x008\x00A\x00(}\x00)?(?P=q76)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14173</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 43 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C86EE68A-9C77-4441-BD35-14CC6CC4A189&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q77&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C86EE68A-9C77-4441-BD35-14CC6CC4A189\s*}?\s*(?P=q77)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14174</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 44 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|8|00|6|00|E|00|E|00|6|00|8|00|A|00|-|00|9|00|C|00|7|00|7|00|-|00|4|00|4|00|4|00|1|00|-|00|B|00|D|00|3|00|5|00|-|00|1|00|4|00|C|00|C|00|6|00|C|00|C|00|4|00|A|00|1|00|8|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q78&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x008\x006\x00E\x00E\x006\x008\x00A\x00-\x009\x00C\x007\x007\x00-\x004\x004\x004\x001\x00-\x00B\x00D\x003\x005\x00-\x001\x004\x00C\x00C\x006\x00C\x00C\x004\x00A\x001\x008\x009\x00(}\x00)?(?P=q78)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14175</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 44 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2875E7A5-EE3C-4FE7-A23E-DE0529D12028&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q79&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2875E7A5-EE3C-4FE7-A23E-DE0529D12028\s*}?\s*(?P=q79)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14176</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 45 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|8|00|7|00|5|00|E|00|7|00|A|00|5|00|-|00|E|00|E|00|3|00|C|00|-|00|4|00|F|00|E|00|7|00|-|00|A|00|2|00|3|00|E|00|-|00|D|00|E|00|0|00|5|00|2|00|9|00|D|00|1|00|2|00|0|00|2|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q80&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x008\x007\x005\x00E\x007\x00A\x005\x00-\x00E\x00E\x003\x00C\x00-\x004\x00F\x00E\x007\x00-\x00A\x002\x003\x00E\x00-\x00D\x00E\x000\x005\x002\x009\x00D\x001\x002\x000\x002\x008\x00(}\x00)?(?P=q80)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14177</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 45 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;66E07EF9-4E89-4284-9632-6D6904B77732&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q81&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*66E07EF9-4E89-4284-9632-6D6904B77732\s*}?\s*(?P=q81)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14178</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 46 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|6|00|E|00|0|00|7|00|E|00|F|00|9|00|-|00|4|00|E|00|8|00|9|00|-|00|4|00|2|00|8|00|4|00|-|00|9|00|6|00|3|00|2|00|-|00|6|00|D|00|6|00|9|00|0|00|4|00|B|00|7|00|7|00|7|00|3|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q82&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x006\x00E\x000\x007\x00E\x00F\x009\x00-\x004\x00E\x008\x009\x00-\x004\x002\x008\x004\x00-\x009\x006\x003\x002\x00-\x006\x00D\x006\x009\x000\x004\x00B\x007\x007\x007\x003\x002\x00(}\x00)?(?P=q82)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14179</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 46 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00D46195-B634-4C41-B53B-5093527FB791&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q83&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00D46195-B634-4C41-B53B-5093527FB791\s*}?\s*(?P=q83)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14180</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 47 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|D|00|4|00|6|00|1|00|9|00|5|00|-|00|B|00|6|00|3|00|4|00|-|00|4|00|C|00|4|00|1|00|-|00|B|00|5|00|3|00|B|00|-|00|5|00|0|00|9|00|3|00|5|00|2|00|7|00|F|00|B|00|7|00|9|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q84&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x00D\x004\x006\x001\x009\x005\x00-\x00B\x006\x003\x004\x00-\x004\x00C\x004\x001\x00-\x00B\x005\x003\x00B\x00-\x005\x000\x009\x003\x005\x002\x007\x00F\x00B\x007\x009\x001\x00(}\x00)?(?P=q84)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14181</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 47 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;497EE41C-CE06-4DD4-8308-6C730713C646&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q85&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*497EE41C-CE06-4DD4-8308-6C730713C646\s*}?\s*(?P=q85)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14182</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 48 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|9|00|7|00|E|00|E|00|4|00|1|00|C|00|-|00|C|00|E|00|0|00|6|00|-|00|4|00|D|00|D|00|4|00|-|00|8|00|3|00|0|00|8|00|-|00|6|00|C|00|7|00|3|00|0|00|7|00|1|00|3|00|C|00|6|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q86&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x009\x007\x00E\x00E\x004\x001\x00C\x00-\x00C\x00E\x000\x006\x00-\x004\x00D\x00D\x004\x00-\x008\x003\x000\x008\x00-\x006\x00C\x007\x003\x000\x007\x001\x003\x00C\x006\x004\x006\x00(}\x00)?(?P=q86)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14183</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 48 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7A12547F-B772-4F2D-BE36-CE5D0FA886A1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q87&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7A12547F-B772-4F2D-BE36-CE5D0FA886A1\s*}?\s*(?P=q87)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14184</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 49 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|A|00|1|00|2|00|5|00|4|00|7|00|F|00|-|00|B|00|7|00|7|00|2|00|-|00|4|00|F|00|2|00|D|00|-|00|B|00|E|00|3|00|6|00|-|00|C|00|E|00|5|00|D|00|0|00|F|00|A|00|8|00|8|00|6|00|A|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q88&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00A\x001\x002\x005\x004\x007\x00F\x00-\x00B\x007\x007\x002\x00-\x004\x00F\x002\x00D\x00-\x00B\x00E\x003\x006\x00-\x00C\x00E\x005\x00D\x000\x00F\x00A\x008\x008\x006\x00A\x001\x00(}\x00)?(?P=q88)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14185</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 49 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0B9C0C26-728C-4FDA-B8DD-59806E20E4D9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q91&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0B9C0C26-728C-4FDA-B8DD-59806E20E4D9\s*}?\s*(?P=q91)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14186</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 50 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|B|00|9|00|C|00|0|00|C|00|2|00|6|00|-|00|7|00|2|00|8|00|C|00|-|00|4|00|F|00|D|00|A|00|-|00|B|00|8|00|D|00|D|00|-|00|5|00|9|00|8|00|0|00|6|00|E|00|2|00|0|00|E|00|4|00|D|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q92&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00B\x009\x00C\x000\x00C\x002\x006\x00-\x007\x002\x008\x00C\x00-\x004\x00F\x00D\x00A\x00-\x00B\x008\x00D\x00D\x00-\x005\x009\x008\x000\x006\x00E\x002\x000\x00E\x004\x00D\x009\x00(}\x00)?(?P=q92)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14187</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 50 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F399F5B6-3C63-4674-B0FF-E94328B1947D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q93&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F399F5B6-3C63-4674-B0FF-E94328B1947D\s*}?\s*(?P=q93)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14188</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 51 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|3|00|9|00|9|00|F|00|5|00|B|00|6|00|-|00|3|00|C|00|6|00|3|00|-|00|4|00|6|00|7|00|4|00|-|00|B|00|0|00|F|00|F|00|-|00|E|00|9|00|4|00|3|00|2|00|8|00|B|00|1|00|9|00|4|00|7|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q94&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x003\x009\x009\x00F\x005\x00B\x006\x00-\x003\x00C\x006\x003\x00-\x004\x006\x007\x004\x00-\x00B\x000\x00F\x00F\x00-\x00E\x009\x004\x003\x002\x008\x00B\x001\x009\x004\x007\x00D\x00(}\x00)?(?P=q94)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14189</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 51 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8C7A23D9-2A9B-4AEA-BA91-3003A316B44D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q95&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8C7A23D9-2A9B-4AEA-BA91-3003A316B44D\s*}?\s*(?P=q95)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14190</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 52 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|C|00|7|00|A|00|2|00|3|00|D|00|9|00|-|00|2|00|A|00|9|00|B|00|-|00|4|00|A|00|E|00|A|00|-|00|B|00|A|00|9|00|1|00|-|00|3|00|0|00|0|00|3|00|A|00|3|00|1|00|6|00|B|00|4|00|4|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q96&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00C\x007\x00A\x002\x003\x00D\x009\x00-\x002\x00A\x009\x00B\x00-\x004\x00A\x00E\x00A\x00-\x00B\x00A\x009\x001\x00-\x003\x000\x000\x003\x00A\x003\x001\x006\x00B\x004\x004\x00D\x00(}\x00)?(?P=q96)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14191</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 52 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E6127E3B-8D17-4BEA-A039-8BB9D0D105A2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q97&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E6127E3B-8D17-4BEA-A039-8BB9D0D105A2\s*}?\s*(?P=q97)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14192</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 53 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|1|00|2|00|7|00|E|00|3|00|B|00|-|00|8|00|D|00|1|00|7|00|-|00|4|00|B|00|E|00|A|00|-|00|A|00|0|00|3|00|9|00|-|00|8|00|B|00|B|00|9|00|D|00|0|00|D|00|1|00|0|00|5|00|A|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q98&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x006\x001\x002\x007\x00E\x003\x00B\x00-\x008\x00D\x001\x007\x00-\x004\x00B\x00E\x00A\x00-\x00A\x000\x003\x009\x00-\x008\x00B\x00B\x009\x00D\x000\x00D\x001\x000\x005\x00A\x002\x00(}\x00)?(?P=q98)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14193</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 53 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A3796166-A03C-418A-AF3A-060115D4E478&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q99&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A3796166-A03C-418A-AF3A-060115D4E478\s*}?\s*(?P=q99)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14194</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 54 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|3|00|7|00|9|00|6|00|1|00|6|00|6|00|-|00|A|00|0|00|3|00|C|00|-|00|4|00|1|00|8|00|A|00|-|00|A|00|F|00|3|00|A|00|-|00|0|00|6|00|0|00|1|00|1|00|5|00|D|00|4|00|E|00|4|00|7|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q100&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x003\x007\x009\x006\x001\x006\x006\x00-\x00A\x000\x003\x00C\x00-\x004\x001\x008\x00A\x00-\x00A\x00F\x003\x00A\x00-\x000\x006\x000\x001\x001\x005\x00D\x004\x00E\x004\x007\x008\x00(}\x00)?(?P=q100)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14195</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 54 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;73BCFD0F-0DAA-4B21-B709-2A8D9D9C692A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q101&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*73BCFD0F-0DAA-4B21-B709-2A8D9D9C692A\s*}?\s*(?P=q101)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14196</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 55 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|3|00|B|00|C|00|F|00|D|00|0|00|F|00|-|00|0|00|D|00|A|00|A|00|-|00|4|00|B|00|2|00|1|00|-|00|B|00|7|00|0|00|9|00|-|00|2|00|A|00|8|00|D|00|9|00|D|00|9|00|C|00|6|00|9|00|2|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q102&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x003\x00B\x00C\x00F\x00D\x000\x00F\x00-\x000\x00D\x00A\x00A\x00-\x004\x00B\x002\x001\x00-\x00B\x007\x000\x009\x00-\x002\x00A\x008\x00D\x009\x00D\x009\x00C\x006\x009\x002\x00A\x00(}\x00)?(?P=q102)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14197</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 55 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;93C5524B-97AE-491E-8EB7-2A3AD964F926&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q103&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*93C5524B-97AE-491E-8EB7-2A3AD964F926\s*}?\s*(?P=q103)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14198</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 56 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|3|00|C|00|5|00|5|00|2|00|4|00|B|00|-|00|9|00|7|00|A|00|E|00|-|00|4|00|9|00|1|00|E|00|-|00|8|00|E|00|B|00|7|00|-|00|2|00|A|00|3|00|A|00|D|00|9|00|6|00|4|00|F|00|9|00|2|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q104&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x003\x00C\x005\x005\x002\x004\x00B\x00-\x009\x007\x00A\x00E\x00-\x004\x009\x001\x00E\x00-\x008\x00E\x00B\x007\x00-\x002\x00A\x003\x00A\x00D\x009\x006\x004\x00F\x009\x002\x006\x00(}\x00)?(?P=q104)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14199</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 56 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;833E62AD-1655-499F-908E-62DCA1EB2EC6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q105&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*833E62AD-1655-499F-908E-62DCA1EB2EC6\s*}?\s*(?P=q105)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14200</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 57 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|3|00|3|00|E|00|6|00|2|00|A|00|D|00|-|00|1|00|6|00|5|00|5|00|-|00|4|00|9|00|9|00|F|00|-|00|9|00|0|00|8|00|E|00|-|00|6|00|2|00|D|00|C|00|A|00|1|00|E|00|B|00|2|00|E|00|C|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q106&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x003\x003\x00E\x006\x002\x00A\x00D\x00-\x001\x006\x005\x005\x00-\x004\x009\x009\x00F\x00-\x009\x000\x008\x00E\x00-\x006\x002\x00D\x00C\x00A\x001\x00E\x00B\x002\x00E\x00C\x006\x00(}\x00)?(?P=q106)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14201</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 57 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;285CAE3C-F16A-4A84-9A80-FF23D6E56D68&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q107&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*285CAE3C-F16A-4A84-9A80-FF23D6E56D68\s*}?\s*(?P=q107)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14202</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 58 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|8|00|5|00|C|00|A|00|E|00|3|00|C|00|-|00|F|00|1|00|6|00|A|00|-|00|4|00|A|00|8|00|4|00|-|00|9|00|A|00|8|00|0|00|-|00|F|00|F|00|2|00|3|00|D|00|6|00|E|00|5|00|6|00|D|00|6|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q108&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x008\x005\x00C\x00A\x00E\x003\x00C\x00-\x00F\x001\x006\x00A\x00-\x004\x00A\x008\x004\x00-\x009\x00A\x008\x000\x00-\x00F\x00F\x002\x003\x00D\x006\x00E\x005\x006\x00D\x006\x008\x00(}\x00)?(?P=q108)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14203</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 58 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AA13BD85-7EC0-4CC8-9958-1BB2AA32FD0B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q109&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA13BD85-7EC0-4CC8-9958-1BB2AA32FD0B\s*}?\s*(?P=q109)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14204</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 59 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|A|00|1|00|3|00|B|00|D|00|8|00|5|00|-|00|7|00|E|00|C|00|0|00|-|00|4|00|C|00|C|00|8|00|-|00|9|00|9|00|5|00|8|00|-|00|1|00|B|00|B|00|2|00|A|00|A|00|3|00|2|00|F|00|D|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q110&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00A\x001\x003\x00B\x00D\x008\x005\x00-\x007\x00E\x00C\x000\x00-\x004\x00C\x00C\x008\x00-\x009\x009\x005\x008\x00-\x001\x00B\x00B\x002\x00A\x00A\x003\x002\x00F\x00D\x000\x00B\x00(}\x00)?(?P=q110)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14205</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 59 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4614C49A-0B7D-4E0D-A877-38CCCFE7D589&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q113&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4614C49A-0B7D-4E0D-A877-38CCCFE7D589\s*}?\s*(?P=q113)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14206</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 60 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|6|00|1|00|4|00|C|00|4|00|9|00|A|00|-|00|0|00|B|00|7|00|D|00|-|00|4|00|E|00|0|00|D|00|-|00|A|00|8|00|7|00|7|00|-|00|3|00|8|00|C|00|C|00|C|00|F|00|E|00|7|00|D|00|5|00|8|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q114&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x006\x001\x004\x00C\x004\x009\x00A\x00-\x000\x00B\x007\x00D\x00-\x004\x00E\x000\x00D\x00-\x00A\x008\x007\x007\x00-\x003\x008\x00C\x00C\x00C\x00F\x00E\x007\x00D\x005\x008\x009\x00(}\x00)?(?P=q114)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14207</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 60 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;974E1D88-BADF-4C80-8594-A59039C992EA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q115&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*974E1D88-BADF-4C80-8594-A59039C992EA\s*}?\s*(?P=q115)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14208</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 61 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|7|00|4|00|E|00|1|00|D|00|8|00|8|00|-|00|B|00|A|00|D|00|F|00|-|00|4|00|C|00|8|00|0|00|-|00|8|00|5|00|9|00|4|00|-|00|A|00|5|00|9|00|0|00|3|00|9|00|C|00|9|00|9|00|2|00|E|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q116&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x007\x004\x00E\x001\x00D\x008\x008\x00-\x00B\x00A\x00D\x00F\x00-\x004\x00C\x008\x000\x00-\x008\x005\x009\x004\x00-\x00A\x005\x009\x000\x003\x009\x00C\x009\x009\x002\x00E\x00A\x00(}\x00)?(?P=q116)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14209</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 61 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;692898BE-C7CC-4CB3-A45C-66508B7E2C33&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q117&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*692898BE-C7CC-4CB3-A45C-66508B7E2C33\s*}?\s*(?P=q117)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14210</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 62 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|9|00|2|00|8|00|9|00|8|00|B|00|E|00|-|00|C|00|7|00|C|00|C|00|-|00|4|00|C|00|B|00|3|00|-|00|A|00|4|00|5|00|C|00|-|00|6|00|6|00|5|00|0|00|8|00|B|00|7|00|E|00|2|00|C|00|3|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q118&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x009\x002\x008\x009\x008\x00B\x00E\x00-\x00C\x007\x00C\x00C\x00-\x004\x00C\x00B\x003\x00-\x00A\x004\x005\x00C\x00-\x006\x006\x005\x000\x008\x00B\x007\x00E\x002\x00C\x003\x003\x00(}\x00)?(?P=q118)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14211</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 62 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F6A7FF1B-9951-4CBE-B197-EA554D6DF40D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q119&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F6A7FF1B-9951-4CBE-B197-EA554D6DF40D\s*}?\s*(?P=q119)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14212</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 63 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|6|00|A|00|7|00|F|00|F|00|1|00|B|00|-|00|9|00|9|00|5|00|1|00|-|00|4|00|C|00|B|00|E|00|-|00|B|00|1|00|9|00|7|00|-|00|E|00|A|00|5|00|5|00|4|00|D|00|6|00|D|00|F|00|4|00|0|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q120&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x006\x00A\x007\x00F\x00F\x001\x00B\x00-\x009\x009\x005\x001\x00-\x004\x00C\x00B\x00E\x00-\x00B\x001\x009\x007\x00-\x00E\x00A\x005\x005\x004\x00D\x006\x00D\x00F\x004\x000\x00D\x00(}\x00)?(?P=q120)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14213</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 63 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;038F6F55-C9F0-4601-8740-98EF1CA9DF9A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q121&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*038F6F55-C9F0-4601-8740-98EF1CA9DF9A\s*}?\s*(?P=q121)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14214</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 64 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|3|00|8|00|F|00|6|00|F|00|5|00|5|00|-|00|C|00|9|00|F|00|0|00|-|00|4|00|6|00|0|00|1|00|-|00|8|00|7|00|4|00|0|00|-|00|9|00|8|00|E|00|F|00|1|00|C|00|A|00|9|00|D|00|F|00|9|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q122&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x003\x008\x00F\x006\x00F\x005\x005\x00-\x00C\x009\x00F\x000\x00-\x004\x006\x000\x001\x00-\x008\x007\x004\x000\x00-\x009\x008\x00E\x00F\x001\x00C\x00A\x009\x00D\x00F\x009\x00A\x00(}\x00)?(?P=q122)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14215</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 64 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;652623DC-2BB4-4C1C-ADFB-57A218F1A5EE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q123&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*652623DC-2BB4-4C1C-ADFB-57A218F1A5EE\s*}?\s*(?P=q123)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14216</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 65 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|5|00|2|00|6|00|2|00|3|00|D|00|C|00|-|00|2|00|B|00|B|00|4|00|-|00|4|00|C|00|1|00|C|00|-|00|A|00|D|00|F|00|B|00|-|00|5|00|7|00|A|00|2|00|1|00|8|00|F|00|1|00|A|00|5|00|E|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q124&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x005\x002\x006\x002\x003\x00D\x00C\x00-\x002\x00B\x00B\x004\x00-\x004\x00C\x001\x00C\x00-\x00A\x00D\x00F\x00B\x00-\x005\x007\x00A\x002\x001\x008\x00F\x001\x00A\x005\x00E\x00E\x00(}\x00)?(?P=q124)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14217</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 65 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9275A865-754B-4EDF-B828-FED0F8D344FC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q125&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9275A865-754B-4EDF-B828-FED0F8D344FC\s*}?\s*(?P=q125)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14218</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 66 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|2|00|7|00|5|00|A|00|8|00|6|00|5|00|-|00|7|00|5|00|4|00|B|00|-|00|4|00|E|00|D|00|F|00|-|00|B|00|8|00|2|00|8|00|-|00|F|00|E|00|D|00|0|00|F|00|8|00|D|00|3|00|4|00|4|00|F|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q126&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x002\x007\x005\x00A\x008\x006\x005\x00-\x007\x005\x004\x00B\x00-\x004\x00E\x00D\x00F\x00-\x00B\x008\x002\x008\x00-\x00F\x00E\x00D\x000\x00F\x008\x00D\x003\x004\x004\x00F\x00C\x00(}\x00)?(?P=q126)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14219</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 66 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6C095616-6064-43ca-9180-CF1B6B6A0BE4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q127&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6C095616-6064-43ca-9180-CF1B6B6A0BE4\s*}?\s*(?P=q127)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14220</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 67 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|C|00|0|00|9|00|5|00|6|00|1|00|6|00|-|00|6|00|0|00|6|00|4|00|-|00|4|00|3|00|c|00|a|00|-|00|9|00|1|00|8|00|0|00|-|00|C|00|F|00|1|00|B|00|6|00|B|00|6|00|A|00|0|00|B|00|E|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q128&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00C\x000\x009\x005\x006\x001\x006\x00-\x006\x000\x006\x004\x00-\x004\x003\x00c\x00a\x00-\x009\x001\x008\x000\x00-\x00C\x00F\x001\x00B\x006\x00B\x006\x00A\x000\x00B\x00E\x004\x00(}\x00)?(?P=q128)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14221</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 67 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E1A26BBF-26C0-401d-B82B-5C4CC67457E0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q129&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E1A26BBF-26C0-401d-B82B-5C4CC67457E0\s*}?\s*(?P=q129)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14222</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 68 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|1|00|A|00|2|00|6|00|B|00|B|00|F|00|-|00|2|00|6|00|C|00|0|00|-|00|4|00|0|00|1|00|d|00|-|00|B|00|8|00|2|00|B|00|-|00|5|00|C|00|4|00|C|00|C|00|6|00|7|00|4|00|5|00|7|00|E|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q130&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x001\x00A\x002\x006\x00B\x00B\x00F\x00-\x002\x006\x00C\x000\x00-\x004\x000\x001\x00d\x00-\x00B\x008\x002\x00B\x00-\x005\x00C\x004\x00C\x00C\x006\x007\x004\x005\x007\x00E\x000\x00(}\x00)?(?P=q130)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14223</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 68 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q131&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98\s*}?\s*(?P=q131)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14224</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 69 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|7|00|3|00|B|00|A|00|E|00|F|00|A|00|-|00|E|00|E|00|6|00|5|00|-|00|4|00|9|00|4|00|D|00|-|00|B|00|E|00|D|00|B|00|-|00|D|00|D|00|3|00|E|00|5|00|A|00|3|00|4|00|F|00|A|00|9|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q132&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x007\x003\x00B\x00A\x00E\x00F\x00A\x00-\x00E\x00E\x006\x005\x00-\x004\x009\x004\x00D\x00-\x00B\x00E\x00D\x00B\x00-\x00D\x00D\x003\x00E\x005\x00A\x003\x004\x00F\x00A\x009\x008\x00(}\x00)?(?P=q132)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14225</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 69 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E4C97925-C194-4551-8831-EABBD0280885&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q135&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E4C97925-C194-4551-8831-EABBD0280885\s*}?\s*(?P=q135)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14226</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 70 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|4|00|C|00|9|00|7|00|9|00|2|00|5|00|-|00|C|00|1|00|9|00|4|00|-|00|4|00|5|00|5|00|1|00|-|00|8|00|8|00|3|00|1|00|-|00|E|00|A|00|B|00|B|00|D|00|0|00|2|00|8|00|0|00|8|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q136&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x004\x00C\x009\x007\x009\x002\x005\x00-\x00C\x001\x009\x004\x00-\x004\x005\x005\x001\x00-\x008\x008\x003\x001\x00-\x00E\x00A\x00B\x00B\x00D\x000\x002\x008\x000\x008\x008\x005\x00(}\x00)?(?P=q136)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14227</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 70 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CC7DA087-B7F4-4829-B038-DA01DFB5D879&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q137&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CC7DA087-B7F4-4829-B038-DA01DFB5D879\s*}?\s*(?P=q137)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14228</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 71 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|C|00|7|00|D|00|A|00|0|00|8|00|7|00|-|00|B|00|7|00|F|00|4|00|-|00|4|00|8|00|2|00|9|00|-|00|B|00|0|00|3|00|8|00|-|00|D|00|A|00|0|00|1|00|D|00|F|00|B|00|5|00|D|00|8|00|7|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q138&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00C\x007\x00D\x00A\x000\x008\x007\x00-\x00B\x007\x00F\x004\x00-\x004\x008\x002\x009\x00-\x00B\x000\x003\x008\x00-\x00D\x00A\x000\x001\x00D\x00F\x00B\x005\x00D\x008\x007\x009\x00(}\x00)?(?P=q138)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14229</id>
        <msg>WEB-ACTIVEX Aurigma unspecified 71 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>30826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1682</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E7B62F4E-82F4-11D2-BD41-00105A0A7E89&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E7B62F4E-82F4-11D2-BD41-00105A0A7E89\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BuildPath|GetDriveName|DriveExists|DeleteFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E7B62F4E-82F4-11D2-BD41-00105A0A7E89\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BuildPath|GetDriveName|DriveExists|DeleteFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14231</id>
        <msg>WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX clsid access</msg>
        <url>support.softartisans.com/Support-114.aspx</url>
      </rule>
      <rule>
        <bugtraq>30826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1682</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SoftArtisans.FileManager&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SoftArtisans\.FileManager\x22|\x27SoftArtisans\.FileManager\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(BuildPath|GetDriveName|DriveExists|DeleteFile)\s*|.*(?P=v)\s*\.\s*(BuildPath|GetDriveName|DriveExists|DeleteFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SoftArtisans\.FileManager\x22|\x27SoftArtisans\.FileManager\x27)\s*\)(\s*\.\s*(BuildPath|GetDriveName|DriveExists|DeleteFile)\s*|.*(?P=n)\s*\.\s*(BuildPath|GetDriveName|DriveExists|DeleteFile)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14233</id>
        <msg>WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX function call access</msg>
        <url>support.softartisans.com/Support-114.aspx</url>
      </rule>
      <rule>
        <bugtraq>30826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1682</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|o|00|f|00|t|00|A|00|r|00|t|00|i|00|s|00|a|00|n|00|s|00|.|00|F|00|i|00|l|00|e|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00o\x00f\x00t\x00A\x00r\x00t\x00i\x00s\x00a\x00n\x00s\x00.\x00F\x00i\x00l\x00e\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00o\x00f\x00t\x00A\x00r\x00t\x00i\x00s\x00a\x00n\x00s\x00.\x00F\x00i\x00l\x00e\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14234</id>
        <msg>WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX function call unicode access</msg>
        <url>support.softartisans.com/Support-114.aspx</url>
      </rule>
      <rule>
        <bugtraq>30891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F4A06697-C0E7-4BB6-8C3B-E01016A4408B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F4A06697-C0E7-4BB6-8C3B-E01016A4408B\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(RunApp|CreateURLShortcut)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F4A06697-C0E7-4BB6-8C3B-E01016A4408B\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(RunApp|CreateURLShortcut))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14239</id>
        <msg>WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>30891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|4|00|A|00|0|00|6|00|6|00|9|00|7|00|-|00|C|00|0|00|E|00|7|00|-|00|4|00|B|00|B|00|6|00|-|00|8|00|C|00|3|00|B|00|-|00|E|00|0|00|1|00|0|00|1|00|6|00|A|00|4|00|4|00|0|00|8|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x004\x00A\x000\x006\x006\x009\x007\x00-\x00C\x000\x00E\x007\x00-\x004\x00B\x00B\x006\x00-\x008\x00C\x003\x00B\x00-\x00E\x000\x001\x000\x001\x006\x00A\x004\x004\x000\x008\x00B\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14240</id>
        <msg>WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FwRemoteCfg.RemoteCfg&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22FwRemoteCfg\.RemoteCfg\x22|\x27FwRemoteCfg\.RemoteCfg\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(RunApp|CreateURLShortcut)\s*|.*(?P=v)\s*\.\s*(RunApp|CreateURLShortcut)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22FwRemoteCfg\.RemoteCfg\x22|\x27FwRemoteCfg\.RemoteCfg\x27)\s*\)(\s*\.\s*(RunApp|CreateURLShortcut)\s*|.*(?P=n)\s*\.\s*(RunApp|CreateURLShortcut)\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14241</id>
        <msg>WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>30891</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|w|00|R|00|e|00|m|00|o|00|t|00|e|00|C|00|f|00|g|00|.|00|R|00|e|00|m|00|o|00|t|00|e|00|C|00|f|00|g|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)F\x00w\x00R\x00e\x00m\x00o\x00t\x00e\x00C\x00f\x00g\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00C\x00f\x00g\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)F\x00w\x00R\x00e\x00m\x00o\x00t\x00e\x00C\x00f\x00g\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00C\x00f\x00g\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14242</id>
        <msg>WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30922</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;442599A9-EB41-4F1F-B999-737BC587F314&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*442599A9-EB41-4F1F-B999-737BC587F314\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Location)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*442599A9-EB41-4F1F-B999-737BC587F314\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Location))\s*=/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14243</id>
        <msg>WEB-ACTIVEX Najdi.si Toolbar ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>30922</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|2|00|5|00|9|00|9|00|A|00|9|00|-|00|E|00|B|00|4|00|1|00|-|00|4|00|F|00|1|00|F|00|-|00|B|00|9|00|9|00|9|00|-|00|7|00|3|00|7|00|B|00|C|00|5|00|8|00|7|00|F|00|3|00|1|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x002\x005\x009\x009\x00A\x009\x00-\x00E\x00B\x004\x001\x00-\x004\x00F\x001\x00F\x00-\x00B\x009\x009\x009\x00-\x007\x003\x007\x00B\x00C\x005\x008\x007\x00F\x003\x001\x004\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14244</id>
        <msg>WEB-ACTIVEX Najdi.si Toolbar ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30922</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Interseek.IEToolbar&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Interseek\.IEToolbar\x22|\x27Interseek\.IEToolbar\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Location\s*|.*(?P=v)\s*\.\s*Location\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Interseek\.IEToolbar\x22|\x27Interseek\.IEToolbar\x27)\s*\)(\s*\.\s*Location\s*|.*(?P=n)\s*\.\s*Location)\s*=/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14245</id>
        <msg>WEB-ACTIVEX Najdi.si Toolbar ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>30922</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|n|00|t|00|e|00|r|00|s|00|e|00|e|00|k|00|.|00|I|00|E|00|T|00|o|00|o|00|l|00|b|00|a|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00n\x00t\x00e\x00r\x00s\x00e\x00e\x00k\x00.\x00I\x00E\x00T\x00o\x00o\x00l\x00b\x00a\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)I\x00n\x00t\x00e\x00r\x00s\x00e\x00e\x00k\x00.\x00I\x00E\x00T\x00o\x00o\x00l\x00b\x00a\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14246</id>
        <msg>WEB-ACTIVEX Najdi.si Toolbar ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3430</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CA06EE71-7348-44C4-9540-AAF0E6BD1515&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CA06EE71-7348-44C4-9540-AAF0E6BD1515\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BgColor)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CA06EE71-7348-44C4-9540-AAF0E6BD1515\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BgColor))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14247</id>
        <msg>WEB-ACTIVEX Eyeball MessengerSDK ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>30424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3430</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|A|00|0|00|6|00|E|00|E|00|7|00|1|00|-|00|7|00|3|00|4|00|8|00|-|00|4|00|4|00|C|00|4|00|-|00|9|00|5|00|4|00|0|00|-|00|A|00|A|00|F|00|0|00|E|00|6|00|B|00|D|00|1|00|5|00|1|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00A\x000\x006\x00E\x00E\x007\x001\x00-\x007\x003\x004\x008\x00-\x004\x004\x00C\x004\x00-\x009\x005\x004\x000\x00-\x00A\x00A\x00F\x000\x00E\x006\x00B\x00D\x001\x005\x001\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14248</id>
        <msg>WEB-ACTIVEX Eyeball MessengerSDK ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3430</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EyeballSdk.VideoWindowCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EyeballSdk\.VideoWindowCtl\x22|\x27EyeballSdk\.VideoWindowCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*BgColor\s*|.*(?P=v)\s*\.\s*BgColor\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EyeballSdk\.VideoWindowCtl\x22|\x27EyeballSdk\.VideoWindowCtl\x27)\s*\)(\s*\.\s*BgColor\s*|.*(?P=n)\s*\.\s*BgColor\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14249</id>
        <msg>WEB-ACTIVEX Eyeball MessengerSDK ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>30424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3430</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|y|00|e|00|b|00|a|00|l|00|l|00|S|00|d|00|k|00|.|00|V|00|i|00|d|00|e|00|o|00|W|00|i|00|n|00|d|00|o|00|w|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00y\x00e\x00b\x00a\x00l\x00l\x00S\x00d\x00k\x00.\x00V\x00i\x00d\x00e\x00o\x00W\x00i\x00n\x00d\x00o\x00w\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00y\x00e\x00b\x00a\x00l\x00l\x00S\x00d\x00k\x00.\x00V\x00i\x00d\x00e\x00o\x00W\x00i\x00n\x00d\x00o\x00w\x00C\x00t\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14250</id>
        <msg>WEB-ACTIVEX Eyeball MessengerSDK ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3014</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14251, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14251</id>
        <msg>EXPLOIT Microsoft GDI malformed metarecord buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3012</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14259, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14259</id>
        <msg>WEB-CLIENT Microsoft GDI EMF malformed file buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>31069</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A1E75357-881A-419E-83E2-BB16DB197C68&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A1E75357-881A-419E-83E2-BB16DB197C68\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Save)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A1E75357-881A-419E-83E2-BB16DB197C68\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Save))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14266</id>
        <msg>WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31069</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|1|00|E|00|7|00|5|00|3|00|5|00|7|00|-|00|8|00|8|00|1|00|A|00|-|00|4|00|1|00|9|00|E|00|-|00|8|00|3|00|E|00|2|00|-|00|B|00|B|00|1|00|6|00|D|00|B|00|1|00|9|00|7|00|C|00|6|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x001\x00E\x007\x005\x003\x005\x007\x00-\x008\x008\x001\x00A\x00-\x004\x001\x009\x00E\x00-\x008\x003\x00E\x002\x00-\x00B\x00B\x001\x006\x00D\x00B\x001\x009\x007\x00C\x006\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14267</id>
        <msg>WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31069</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WiaLog&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WiaLog\x22|\x27WiaLog\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Save\s*|.*(?P=v)\s*\.\s*Save\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WiaLog\x22|\x27WiaLog\x27)\s*\)(\s*\.\s*Save\s*|.*(?P=n)\s*\.\s*Save\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14268</id>
        <msg>WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31069</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|i|00|a|00|L|00|o|00|g|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00i\x00a\x00L\x00o\x00g\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)W\x00i\x00a\x00L\x00o\x00g\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14269</id>
        <msg>WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0F748FDE-0597-443c-8596-71854C5EA20A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0F748FDE-0597-443c-8596-71854C5EA20A\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14270</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Locator ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|F|00|7|00|4|00|8|00|F|00|D|00|E|00|-|00|0|00|5|00|9|00|7|00|-|00|4|00|4|00|3|00|c|00|-|00|8|00|5|00|9|00|6|00|-|00|7|00|1|00|8|00|5|00|4|00|C|00|5|00|E|00|A|00|2|00|0|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00F\x007\x004\x008\x00F\x00D\x00E\x00-\x000\x005\x009\x007\x00-\x004\x004\x003\x00c\x00-\x008\x005\x009\x006\x00-\x007\x001\x008\x005\x004\x00C\x005\x00E\x00A\x002\x000\x00A\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14271</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Locator ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VieLib2.Vie2Locator&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VieLib2\.Vie2Locator\x22|\x27VieLib2\.Vie2Locator\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VieLib2\.Vie2Locator\x22|\x27VieLib2\.Vie2Locator\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14272</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Locator ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|L|00|i|00|b|00|2|00|.|00|V|00|i|00|e|00|2|00|L|00|o|00|c|00|a|00|t|00|o|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00L\x00o\x00c\x00a\x00t\x00o\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00L\x00o\x00c\x00a\x00t\x00o\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14273</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Locator ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1AF378DE-4574-4bb0-A5DF-F78FCAD28707&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1AF378DE-4574-4bb0-A5DF-F78FCAD28707\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14274</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|A|00|F|00|3|00|7|00|8|00|D|00|E|00|-|00|4|00|5|00|7|00|4|00|-|00|4|00|b|00|b|00|0|00|-|00|A|00|5|00|D|00|F|00|-|00|F|00|7|00|8|00|F|00|C|00|A|00|D|00|2|00|8|00|7|00|0|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00A\x00F\x003\x007\x008\x00D\x00E\x00-\x004\x005\x007\x004\x00-\x004\x00b\x00b\x000\x00-\x00A\x005\x00D\x00F\x00-\x00F\x007\x008\x00F\x00C\x00A\x00D\x002\x008\x007\x000\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14275</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vie2Lib.Vie2LinuxVolume&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vie2Lib\.Vie2LinuxVolume\x22|\x27Vie2Lib\.Vie2LinuxVolume\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vie2Lib\.Vie2LinuxVolume\x22|\x27Vie2Lib\.Vie2LinuxVolume\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14276</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|2|00|L|00|i|00|b|00|.|00|V|00|i|00|e|00|2|00|L|00|i|00|n|00|u|00|x|00|V|00|o|00|l|00|u|00|m|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00e\x002\x00L\x00i\x00b\x00.\x00V\x00i\x00e\x002\x00L\x00i\x00n\x00u\x00x\x00V\x00o\x00l\x00u\x00m\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x002\x00L\x00i\x00b\x00.\x00V\x00i\x00e\x002\x00L\x00i\x00n\x00u\x00x\x00V\x00o\x00l\x00u\x00m\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14277</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7B9C5422-39AA-4c21-BEEF-645E42EB4529&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7B9C5422-39AA-4c21-BEEF-645E42EB4529\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14278</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|B|00|9|00|C|00|5|00|4|00|2|00|2|00|-|00|3|00|9|00|A|00|A|00|-|00|4|00|c|00|2|00|1|00|-|00|B|00|E|00|E|00|F|00|-|00|6|00|4|00|5|00|E|00|4|00|2|00|E|00|B|00|4|00|5|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00B\x009\x00C\x005\x004\x002\x002\x00-\x003\x009\x00A\x00A\x00-\x004\x00c\x002\x001\x00-\x00B\x00E\x00E\x00F\x00-\x006\x004\x005\x00E\x004\x002\x00E\x00B\x004\x005\x002\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14279</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VieLib2.Vie2Process&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14280</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|L|00|i|00|b|00|2|00|.|00|V|00|i|00|e|00|2|00|P|00|r|00|o|00|c|00|e|00|s|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14281</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF13B07E-28A1-4CAC-9C9A-EC582E354A24&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AF13B07E-28A1-4CAC-9C9A-EC582E354A24\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14282</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|1|00|3|00|B|00|0|00|7|00|E|00|-|00|2|00|8|00|A|00|1|00|-|00|4|00|C|00|A|00|C|00|-|00|9|00|C|00|9|00|A|00|-|00|E|00|C|00|5|00|8|00|2|00|E|00|3|00|5|00|4|00|A|00|2|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00F\x001\x003\x00B\x000\x007\x00E\x00-\x002\x008\x00A\x001\x00-\x004\x00C\x00A\x00C\x00-\x009\x00C\x009\x00A\x00-\x00E\x00C\x005\x008\x002\x00E\x003\x005\x004\x00A\x002\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14283</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IntraProcessLogging.Logger&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22IntraProcessLogging\.Logger\x22|\x27IntraProcessLogging\.Logger\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IntraProcessLogging\.Logger\x22|\x27IntraProcessLogging\.Logger\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14284</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|n|00|t|00|r|00|a|00|P|00|r|00|o|00|c|00|e|00|s|00|s|00|L|00|o|00|g|00|g|00|i|00|n|00|g|00|.|00|L|00|o|00|g|00|g|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)I\x00n\x00t\x00r\x00a\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00L\x00o\x00g\x00g\x00i\x00n\x00g\x00.\x00L\x00o\x00g\x00g\x00e\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00n\x00t\x00r\x00a\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00L\x00o\x00g\x00g\x00i\x00n\x00g\x00.\x00L\x00o\x00g\x00g\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14285</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;07051fd9-3e4e-4f79-b1ac-0a2f9338f806&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*07051fd9-3e4e-4f79-b1ac-0a2f9338f806\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14286</id>
        <msg>WEB-ACTIVEX VMClientHosts Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|7|00|0|00|5|00|1|00|f|00|d|00|9|00|-|00|3|00|e|00|4|00|e|00|-|00|4|00|f|00|7|00|9|00|-|00|b|00|1|00|a|00|c|00|-|00|0|00|a|00|2|00|f|00|9|00|3|00|3|00|8|00|f|00|8|00|0|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x007\x000\x005\x001\x00f\x00d\x009\x00-\x003\x00e\x004\x00e\x00-\x004\x00f\x007\x009\x00-\x00b\x001\x00a\x00c\x00-\x000\x00a\x002\x00f\x009\x003\x003\x008\x00f\x008\x000\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14287</id>
        <msg>WEB-ACTIVEX VMClientHosts Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VMClientHosts&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VMClientHosts\x22|\x27vmdbCOM\.VMClientHosts\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VMClientHosts\x22|\x27vmdbCOM\.VMClientHosts\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14288</id>
        <msg>WEB-ACTIVEX VMClientHosts Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|C|00|l|00|i|00|e|00|n|00|t|00|H|00|o|00|s|00|t|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00H\x00o\x00s\x00t\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00H\x00o\x00s\x00t\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14289</id>
        <msg>WEB-ACTIVEX VMClientHosts Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;095DB814-94A0-4AD7-88C3-7DFBE688B12A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*095DB814-94A0-4AD7-88C3-7DFBE688B12A\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14290</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|9|00|5|00|D|00|B|00|8|00|1|00|4|00|-|00|9|00|4|00|A|00|0|00|-|00|4|00|A|00|D|00|7|00|-|00|8|00|8|00|C|00|3|00|-|00|7|00|D|00|F|00|B|00|E|00|6|00|8|00|8|00|B|00|1|00|2|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x009\x005\x00D\x00B\x008\x001\x004\x00-\x009\x004\x00A\x000\x00-\x004\x00A\x00D\x007\x00-\x008\x008\x00C\x003\x00-\x007\x00D\x00F\x00B\x00E\x006\x008\x008\x00B\x001\x002\x00A\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14291</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VhdCvtCom.DiskLibCreateParamObj&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VhdCvtCom\.DiskLibCreateParamObj\x22|\x27VhdCvtCom\.DiskLibCreateParamObj\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VhdCvtCom\.DiskLibCreateParamObj\x22|\x27VhdCvtCom\.DiskLibCreateParamObj\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14292</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|h|00|d|00|C|00|v|00|t|00|C|00|o|00|m|00|.|00|D|00|i|00|s|00|k|00|L|00|i|00|b|00|C|00|r|00|e|00|a|00|t|00|e|00|P|00|a|00|r|00|a|00|m|00|O|00|b|00|j|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00D\x00i\x00s\x00k\x00L\x00i\x00b\x00C\x00r\x00e\x00a\x00t\x00e\x00P\x00a\x00r\x00a\x00m\x00O\x00b\x00j\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00D\x00i\x00s\x00k\x00L\x00i\x00b\x00C\x00r\x00e\x00a\x00t\x00e\x00P\x00a\x00r\x00a\x00m\x00O\x00b\x00j\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14293</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0ce412d9-4520-4e5a-893d-88b3a8f29c97&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0ce412d9-4520-4e5a-893d-88b3a8f29c97\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14294</id>
        <msg>WEB-ACTIVEX RemoteDirDlg Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|c|00|e|00|4|00|1|00|2|00|d|00|9|00|-|00|4|00|5|00|2|00|0|00|-|00|4|00|e|00|5|00|a|00|-|00|8|00|9|00|3|00|d|00|-|00|8|00|8|00|b|00|3|00|a|00|8|00|f|00|2|00|9|00|c|00|9|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00c\x00e\x004\x001\x002\x00d\x009\x00-\x004\x005\x002\x000\x00-\x004\x00e\x005\x00a\x00-\x008\x009\x003\x00d\x00-\x008\x008\x00b\x003\x00a\x008\x00f\x002\x009\x00c\x009\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14295</id>
        <msg>WEB-ACTIVEX RemoteDirDlg Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.RemoteDirDlg&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.RemoteDirDlg\x22|\x27Vmappsdk\.RemoteDirDlg\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.RemoteDirDlg\x22|\x27Vmappsdk\.RemoteDirDlg\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14296</id>
        <msg>WEB-ACTIVEX RemoteDirDlg Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|R|00|e|00|m|00|o|00|t|00|e|00|D|00|i|00|r|00|D|00|l|00|g|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00D\x00i\x00r\x00D\x00l\x00g\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00D\x00i\x00r\x00D\x00l\x00g\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14297</id>
        <msg>WEB-ACTIVEX RemoteDirDlg Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;13E86A0C-FE7D-4573-A41D-6B5B00CCFE22&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*13E86A0C-FE7D-4573-A41D-6B5B00CCFE22\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14298</id>
        <msg>WEB-ACTIVEX TeamListViewWnd Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|3|00|E|00|8|00|6|00|A|00|0|00|C|00|-|00|F|00|E|00|7|00|D|00|-|00|4|00|5|00|7|00|3|00|-|00|A|00|4|00|1|00|D|00|-|00|6|00|B|00|5|00|B|00|0|00|0|00|C|00|C|00|F|00|E|00|2|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x003\x00E\x008\x006\x00A\x000\x00C\x00-\x00F\x00E\x007\x00D\x00-\x004\x005\x007\x003\x00-\x00A\x004\x001\x00D\x00-\x006\x00B\x005\x00B\x000\x000\x00C\x00C\x00F\x00E\x002\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14299</id>
        <msg>WEB-ACTIVEX TeamListViewWnd Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.TeamListViewWnd&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.TeamListViewWnd\x22|\x27Vmappsdk\.TeamListViewWnd\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.TeamListViewWnd\x22|\x27Vmappsdk\.TeamListViewWnd\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14300</id>
        <msg>WEB-ACTIVEX TeamListViewWnd Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|T|00|e|00|a|00|m|00|L|00|i|00|s|00|t|00|V|00|i|00|e|00|w|00|W|00|n|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00T\x00e\x00a\x00m\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x00W\x00n\x00d\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00T\x00e\x00a\x00m\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x00W\x00n\x00d\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14301</id>
        <msg>WEB-ACTIVEX TeamListViewWnd Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;164bdf7b-5c67-4daf-85a3-c6c927cb3d36&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*164bdf7b-5c67-4daf-85a3-c6c927cb3d36\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14302</id>
        <msg>WEB-ACTIVEX VMStatusbarCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|6|00|4|00|b|00|d|00|f|00|7|00|b|00|-|00|5|00|c|00|6|00|7|00|-|00|4|00|d|00|a|00|f|00|-|00|8|00|5|00|a|00|3|00|-|00|c|00|6|00|c|00|9|00|2|00|7|00|c|00|b|00|3|00|d|00|3|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x006\x004\x00b\x00d\x00f\x007\x00b\x00-\x005\x00c\x006\x007\x00-\x004\x00d\x00a\x00f\x00-\x008\x005\x00a\x003\x00-\x00c\x006\x00c\x009\x002\x007\x00c\x00b\x003\x00d\x003\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14303</id>
        <msg>WEB-ACTIVEX VMStatusbarCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VMStatusbarCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VMStatusbarCtl\x22|\x27Vmappsdk\.VMStatusbarCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VMStatusbarCtl\x22|\x27Vmappsdk\.VMStatusbarCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14304</id>
        <msg>WEB-ACTIVEX VMStatusbarCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|S|00|t|00|a|00|t|00|u|00|s|00|b|00|a|00|r|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00S\x00t\x00a\x00t\x00u\x00s\x00b\x00a\x00r\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00S\x00t\x00a\x00t\x00u\x00s\x00b\x00a\x00r\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14305</id>
        <msg>WEB-ACTIVEX VMStatusbarCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;17376C4D-A75F-4535-82EB-FF80EE02E405&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*17376C4D-A75F-4535-82EB-FF80EE02E405\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14306</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|7|00|3|00|7|00|6|00|C|00|4|00|D|00|-|00|A|00|7|00|5|00|F|00|-|00|4|00|5|00|3|00|5|00|-|00|8|00|2|00|E|00|B|00|-|00|F|00|F|00|8|00|0|00|E|00|E|00|0|00|2|00|E|00|4|00|0|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x007\x003\x007\x006\x00C\x004\x00D\x00-\x00A\x007\x005\x00F\x00-\x004\x005\x003\x005\x00-\x008\x002\x00E\x00B\x00-\x00F\x00F\x008\x000\x00E\x00E\x000\x002\x00E\x004\x000\x005\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14307</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmc2vmx.CoVPCConfiguration&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmc2vmx\.CoVPCConfiguration\x22|\x27Vmc2vmx\.CoVPCConfiguration\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmc2vmx\.CoVPCConfiguration\x22|\x27Vmc2vmx\.CoVPCConfiguration\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14308</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|c|00|2|00|v|00|m|00|x|00|.|00|C|00|o|00|V|00|P|00|C|00|C|00|o|00|n|00|f|00|i|00|g|00|u|00|r|00|a|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00C\x00o\x00n\x00f\x00i\x00g\x00u\x00r\x00a\x00t\x00i\x00o\x00n\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00C\x00o\x00n\x00f\x00i\x00g\x00u\x00r\x00a\x00t\x00i\x00o\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14309</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1c4387ae-2b23-4c45-8bc6-c1dfbddfb249&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1c4387ae-2b23-4c45-8bc6-c1dfbddfb249\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14310</id>
        <msg>WEB-ACTIVEX VmdbUpdate Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|c|00|4|00|3|00|8|00|7|00|a|00|e|00|-|00|2|00|b|00|2|00|3|00|-|00|4|00|c|00|4|00|5|00|-|00|8|00|b|00|c|00|6|00|-|00|c|00|1|00|d|00|f|00|b|00|d|00|d|00|f|00|b|00|2|00|4|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00c\x004\x003\x008\x007\x00a\x00e\x00-\x002\x00b\x002\x003\x00-\x004\x00c\x004\x005\x00-\x008\x00b\x00c\x006\x00-\x00c\x001\x00d\x00f\x00b\x00d\x00d\x00f\x00b\x002\x004\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14311</id>
        <msg>WEB-ACTIVEX VmdbUpdate Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbUpdate&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbUpdate\x22|\x27vmdbCOM\.VmdbUpdate\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbUpdate\x22|\x27vmdbCOM\.VmdbUpdate\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14312</id>
        <msg>WEB-ACTIVEX VmdbUpdate Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|U|00|p|00|d|00|a|00|t|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00p\x00d\x00a\x00t\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00p\x00d\x00a\x00t\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14313</id>
        <msg>WEB-ACTIVEX VmdbUpdate Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1dd25558-dda3-476a-a81c-a07b62f33725&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1dd25558-dda3-476a-a81c-a07b62f33725\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14314</id>
        <msg>WEB-ACTIVEX VMWare unspecified 1 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|d|00|d|00|2|00|5|00|5|00|5|00|8|00|-|00|d|00|d|00|a|00|3|00|-|00|4|00|7|00|6|00|a|00|-|00|a|00|8|00|1|00|c|00|-|00|a|00|0|00|7|00|b|00|6|00|2|00|f|00|3|00|3|00|7|00|2|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00d\x00d\x002\x005\x005\x005\x008\x00-\x00d\x00d\x00a\x003\x00-\x004\x007\x006\x00a\x00-\x00a\x008\x001\x00c\x00-\x00a\x000\x007\x00b\x006\x002\x00f\x003\x003\x007\x002\x005\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14315</id>
        <msg>WEB-ACTIVEX VMWare unspecified 1 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;22ff5311-53a4-4335-a2d9-b75e5731bbab&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*22ff5311-53a4-4335-a2d9-b75e5731bbab\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14316</id>
        <msg>WEB-ACTIVEX VmdbExecuteError Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|f|00|f|00|5|00|3|00|1|00|1|00|-|00|5|00|3|00|a|00|4|00|-|00|4|00|3|00|3|00|5|00|-|00|a|00|2|00|d|00|9|00|-|00|b|00|7|00|5|00|e|00|5|00|7|00|3|00|1|00|b|00|b|00|a|00|b|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x002\x00f\x00f\x005\x003\x001\x001\x00-\x005\x003\x00a\x004\x00-\x004\x003\x003\x005\x00-\x00a\x002\x00d\x009\x00-\x00b\x007\x005\x00e\x005\x007\x003\x001\x00b\x00b\x00a\x00b\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14317</id>
        <msg>WEB-ACTIVEX VmdbExecuteError Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VmdbCOM.VmdbExecuteError&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VmdbCOM\.VmdbExecuteError\x22|\x27VmdbCOM\.VmdbExecuteError\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VmdbCOM\.VmdbExecuteError\x22|\x27VmdbCOM\.VmdbExecuteError\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14318</id>
        <msg>WEB-ACTIVEX VmdbExecuteError Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|E|00|x|00|e|00|c|00|u|00|t|00|e|00|E|00|r|00|r|00|o|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00E\x00x\x00e\x00c\x00u\x00t\x00e\x00E\x00r\x00r\x00o\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00E\x00x\x00e\x00c\x00u\x00t\x00e\x00E\x00r\x00r\x00o\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14319</id>
        <msg>WEB-ACTIVEX VmdbExecuteError Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;271DC252-6FE1-4D59-9053-E4CF50AB99DE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*271DC252-6FE1-4D59-9053-E4CF50AB99DE\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14320</id>
        <msg>WEB-ACTIVEX VMWare unspecified 2 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|7|00|1|00|D|00|C|00|2|00|5|00|2|00|-|00|6|00|F|00|E|00|1|00|-|00|4|00|D|00|5|00|9|00|-|00|9|00|0|00|5|00|3|00|-|00|E|00|4|00|C|00|F|00|5|00|0|00|A|00|B|00|9|00|9|00|D|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x007\x001\x00D\x00C\x002\x005\x002\x00-\x006\x00F\x00E\x001\x00-\x004\x00D\x005\x009\x00-\x009\x000\x005\x003\x00-\x00E\x004\x00C\x00F\x005\x000\x00A\x00B\x009\x009\x00D\x00E\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14321</id>
        <msg>WEB-ACTIVEX VMWare unspecified 2 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;27602AF3-CEFF-4962-BE29-6FB66BCB9297&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*27602AF3-CEFF-4962-BE29-6FB66BCB9297\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14322</id>
        <msg>WEB-ACTIVEX reconfig.SysImageUti ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|7|00|6|00|0|00|2|00|A|00|F|00|3|00|-|00|C|00|E|00|F|00|F|00|-|00|4|00|9|00|6|00|2|00|-|00|B|00|E|00|2|00|9|00|-|00|6|00|F|00|B|00|6|00|6|00|B|00|C|00|B|00|9|00|2|00|9|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x007\x006\x000\x002\x00A\x00F\x003\x00-\x00C\x00E\x00F\x00F\x00-\x004\x009\x006\x002\x00-\x00B\x00E\x002\x009\x00-\x006\x00F\x00B\x006\x006\x00B\x00C\x00B\x009\x002\x009\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14323</id>
        <msg>WEB-ACTIVEX reconfig.SysImageUti ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;reconfig.SysImageUti&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22reconfig\.SysImageUti\x22|\x27reconfig\.SysImageUti\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22reconfig\.SysImageUti\x22|\x27reconfig\.SysImageUti\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14324</id>
        <msg>WEB-ACTIVEX reconfig.SysImageUti ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|e|00|c|00|o|00|n|00|f|00|i|00|g|00|.|00|S|00|y|00|s|00|I|00|m|00|a|00|g|00|e|00|U|00|t|00|i|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00S\x00y\x00s\x00I\x00m\x00a\x00g\x00e\x00U\x00t\x00i\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00S\x00y\x00s\x00I\x00m\x00a\x00g\x00e\x00U\x00t\x00i\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14325</id>
        <msg>WEB-ACTIVEX reconfig.SysImageUti ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2c10a98f-d64f-43b4-bed6-dd0e1bf2074c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2c10a98f-d64f-43b4-bed6-dd0e1bf2074c\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14326</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|c|00|1|00|0|00|a|00|9|00|8|00|f|00|-|00|d|00|6|00|4|00|f|00|-|00|4|00|3|00|b|00|4|00|-|00|b|00|e|00|d|00|6|00|-|00|d|00|d|00|0|00|e|00|1|00|b|00|f|00|2|00|0|00|7|00|4|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00c\x001\x000\x00a\x009\x008\x00f\x00-\x00d\x006\x004\x00f\x00-\x004\x003\x00b\x004\x00-\x00b\x00e\x00d\x006\x00-\x00d\x00d\x000\x00e\x001\x00b\x00f\x002\x000\x007\x004\x00c\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14327</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MSVDTQueryDesigne&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MSVDTQueryDesigne\x22|\x27MSVDTQueryDesigne\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MSVDTQueryDesigne\x22|\x27MSVDTQueryDesigne\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14328</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|S|00|V|00|D|00|T|00|Q|00|u|00|e|00|r|00|y|00|D|00|e|00|s|00|i|00|g|00|n|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)M\x00S\x00V\x00D\x00T\x00Q\x00u\x00e\x00r\x00y\x00D\x00e\x00s\x00i\x00g\x00n\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)M\x00S\x00V\x00D\x00T\x00Q\x00u\x00e\x00r\x00y\x00D\x00e\x00s\x00i\x00g\x00n\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14329</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2e1c00eb-6468-40ae-94b3-2c8d80080f21&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2e1c00eb-6468-40ae-94b3-2c8d80080f21\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14330</id>
        <msg>WEB-ACTIVEX VmdbContext Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|e|00|1|00|c|00|0|00|0|00|e|00|b|00|-|00|6|00|4|00|6|00|8|00|-|00|4|00|0|00|a|00|e|00|-|00|9|00|4|00|b|00|3|00|-|00|2|00|c|00|8|00|d|00|8|00|0|00|0|00|8|00|0|00|f|00|2|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00e\x001\x00c\x000\x000\x00e\x00b\x00-\x006\x004\x006\x008\x00-\x004\x000\x00a\x00e\x00-\x009\x004\x00b\x003\x00-\x002\x00c\x008\x00d\x008\x000\x000\x008\x000\x00f\x002\x001\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14331</id>
        <msg>WEB-ACTIVEX VmdbContext Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbContext&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbContext\x22|\x27vmdbCOM\.VmdbContext\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbContext\x22|\x27vmdbCOM\.VmdbContext\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14332</id>
        <msg>WEB-ACTIVEX VmdbContext Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|C|00|o|00|n|00|t|00|e|00|x|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00C\x00o\x00n\x00t\x00e\x00x\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00C\x00o\x00n\x00t\x00e\x00x\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14333</id>
        <msg>WEB-ACTIVEX VmdbContext Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;315cb05d-691f-4208-af14-0fa2fbb2cad6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*315cb05d-691f-4208-af14-0fa2fbb2cad6\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14334</id>
        <msg>WEB-ACTIVEX VMClientVMs Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|1|00|5|00|c|00|b|00|0|00|5|00|d|00|-|00|6|00|9|00|1|00|f|00|-|00|4|00|2|00|0|00|8|00|-|00|a|00|f|00|1|00|4|00|-|00|0|00|f|00|a|00|2|00|f|00|b|00|b|00|2|00|c|00|a|00|d|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x001\x005\x00c\x00b\x000\x005\x00d\x00-\x006\x009\x001\x00f\x00-\x004\x002\x000\x008\x00-\x00a\x00f\x001\x004\x00-\x000\x00f\x00a\x002\x00f\x00b\x00b\x002\x00c\x00a\x00d\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14335</id>
        <msg>WEB-ACTIVEX VMClientVMs Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VMClientVMs&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VMClientVMs\x22|\x27vmdbCOM\.VMClientVMs\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VMClientVMs\x22|\x27vmdbCOM\.VMClientVMs\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14336</id>
        <msg>WEB-ACTIVEX VMClientVMs Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|C|00|l|00|i|00|e|00|n|00|t|00|V|00|M|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00V\x00M\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00V\x00M\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14337</id>
        <msg>WEB-ACTIVEX VMClientVMs Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;37592010-a488-45dd-bf6d-00cc1b6fc0ce&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*37592010-a488-45dd-bf6d-00cc1b6fc0ce\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14338</id>
        <msg>WEB-ACTIVEX vmappPropObj Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|7|00|5|00|9|00|2|00|0|00|1|00|0|00|-|00|a|00|4|00|8|00|8|00|-|00|4|00|5|00|d|00|d|00|-|00|b|00|f|00|6|00|d|00|-|00|0|00|0|00|c|00|c|00|1|00|b|00|6|00|f|00|c|00|0|00|c|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x007\x005\x009\x002\x000\x001\x000\x00-\x00a\x004\x008\x008\x00-\x004\x005\x00d\x00d\x00-\x00b\x00f\x006\x00d\x00-\x000\x000\x00c\x00c\x001\x00b\x006\x00f\x00c\x000\x00c\x00e\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14339</id>
        <msg>WEB-ACTIVEX vmappPropObj Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.VmappPropObj&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.VmappPropObj\x22|\x27vmappsdk\.VmappPropObj\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.VmappPropObj\x22|\x27vmappsdk\.VmappPropObj\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14340</id>
        <msg>WEB-ACTIVEX vmappPropObj Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|m|00|a|00|p|00|p|00|P|00|r|00|o|00|p|00|O|00|b|00|j|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00O\x00b\x00j\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00O\x00b\x00j\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14341</id>
        <msg>WEB-ACTIVEX vmappPropObj Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3cdeda3a-114b-455e-8c8b-224db4bf29c2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3cdeda3a-114b-455e-8c8b-224db4bf29c2\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14342</id>
        <msg>WEB-ACTIVEX VMWare unspecified 3 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|c|00|d|00|e|00|d|00|a|00|3|00|a|00|-|00|1|00|1|00|4|00|b|00|-|00|4|00|5|00|5|00|e|00|-|00|8|00|c|00|8|00|b|00|-|00|2|00|2|00|4|00|d|00|b|00|4|00|b|00|f|00|2|00|9|00|c|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00c\x00d\x00e\x00d\x00a\x003\x00a\x00-\x001\x001\x004\x00b\x00-\x004\x005\x005\x00e\x00-\x008\x00c\x008\x00b\x00-\x002\x002\x004\x00d\x00b\x004\x00b\x00f\x002\x009\x00c\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14343</id>
        <msg>WEB-ACTIVEX VMWare unspecified 3 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3d41639a-88cc-43d2-b6cb-2ce98a24509d&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3d41639a-88cc-43d2-b6cb-2ce98a24509d\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14344</id>
        <msg>WEB-ACTIVEX VMMsg Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|d|00|4|00|1|00|6|00|3|00|9|00|a|00|-|00|8|00|8|00|c|00|c|00|-|00|4|00|3|00|d|00|2|00|-|00|b|00|6|00|c|00|b|00|-|00|2|00|c|00|e|00|9|00|8|00|a|00|2|00|4|00|5|00|0|00|9|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00d\x004\x001\x006\x003\x009\x00a\x00-\x008\x008\x00c\x00c\x00-\x004\x003\x00d\x002\x00-\x00b\x006\x00c\x00b\x00-\x002\x00c\x00e\x009\x008\x00a\x002\x004\x005\x000\x009\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14345</id>
        <msg>WEB-ACTIVEX VMMsg Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VMMsg&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VMMsg\x22|\x27Vmappsdk\.VMMsg\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VMMsg\x22|\x27Vmappsdk\.VMMsg\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14346</id>
        <msg>WEB-ACTIVEX VMMsg Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|M|00|s|00|g|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00M\x00s\x00g\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00M\x00s\x00g\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14347</id>
        <msg>WEB-ACTIVEX VMMsg Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3ddf644a-0e1a-4543-9595-4b917707a9a7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3ddf644a-0e1a-4543-9595-4b917707a9a7\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14348</id>
        <msg>WEB-ACTIVEX VMWare unspecified 4 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|d|00|d|00|f|00|6|00|4|00|4|00|a|00|-|00|0|00|e|00|1|00|a|00|-|00|4|00|5|00|4|00|3|00|-|00|9|00|5|00|9|00|5|00|-|00|4|00|b|00|9|00|1|00|7|00|7|00|0|00|7|00|a|00|9|00|a|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00d\x00d\x00f\x006\x004\x004\x00a\x00-\x000\x00e\x001\x00a\x00-\x004\x005\x004\x003\x00-\x009\x005\x009\x005\x00-\x004\x00b\x009\x001\x007\x007\x000\x007\x00a\x009\x00a\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14349</id>
        <msg>WEB-ACTIVEX VMWare unspecified 4 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;41DF0779-3632-4790-B40F-C44CFCF55CB6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*41DF0779-3632-4790-B40F-C44CFCF55CB6\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14350</id>
        <msg>WEB-ACTIVEX reconfig.PopulatedDi ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|D|00|F|00|0|00|7|00|7|00|9|00|-|00|3|00|6|00|3|00|2|00|-|00|4|00|7|00|9|00|0|00|-|00|B|00|4|00|0|00|F|00|-|00|C|00|4|00|4|00|C|00|F|00|C|00|F|00|5|00|5|00|C|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x001\x00D\x00F\x000\x007\x007\x009\x00-\x003\x006\x003\x002\x00-\x004\x007\x009\x000\x00-\x00B\x004\x000\x00F\x00-\x00C\x004\x004\x00C\x00F\x00C\x00F\x005\x005\x00C\x00B\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14351</id>
        <msg>WEB-ACTIVEX reconfig.PopulatedDi ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;reconfig.PopulatedDi&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22reconfig\.PopulatedDi\x22|\x27reconfig\.PopulatedDi\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22reconfig\.PopulatedDi\x22|\x27reconfig\.PopulatedDi\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14352</id>
        <msg>WEB-ACTIVEX reconfig.PopulatedDi ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|e|00|c|00|o|00|n|00|f|00|i|00|g|00|.|00|P|00|o|00|p|00|u|00|l|00|a|00|t|00|e|00|d|00|D|00|i|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00P\x00o\x00p\x00u\x00l\x00a\x00t\x00e\x00d\x00D\x00i\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00P\x00o\x00p\x00u\x00l\x00a\x00t\x00e\x00d\x00D\x00i\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14353</id>
        <msg>WEB-ACTIVEX reconfig.PopulatedDi ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;420F0000-71EB-4757-B979-418F039FC1F9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*420F0000-71EB-4757-B979-418F039FC1F9\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14354</id>
        <msg>WEB-ACTIVEX Elevated.ElevMgr ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|0|00|F|00|0|00|0|00|0|00|0|00|-|00|7|00|1|00|E|00|B|00|-|00|4|00|7|00|5|00|7|00|-|00|B|00|9|00|7|00|9|00|-|00|4|00|1|00|8|00|F|00|0|00|3|00|9|00|F|00|C|00|1|00|F|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x002\x000\x00F\x000\x000\x000\x000\x00-\x007\x001\x00E\x00B\x00-\x004\x007\x005\x007\x00-\x00B\x009\x007\x009\x00-\x004\x001\x008\x00F\x000\x003\x009\x00F\x00C\x001\x00F\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14355</id>
        <msg>WEB-ACTIVEX Elevated.ElevMgr ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Elevated.ElevMgr&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Elevated\.ElevMgr\x22|\x27Elevated\.ElevMgr\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Elevated\.ElevMgr\x22|\x27Elevated\.ElevMgr\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14356</id>
        <msg>WEB-ACTIVEX Elevated.ElevMgr ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|l|00|e|00|v|00|a|00|t|00|e|00|d|00|.|00|E|00|l|00|e|00|v|00|M|00|g|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00E\x00l\x00e\x00v\x00M\x00g\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00E\x00l\x00e\x00v\x00M\x00g\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14357</id>
        <msg>WEB-ACTIVEX Elevated.ElevMgr ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4249304b-198d-4b81-8250-29445ed99c2f&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4249304b-198d-4b81-8250-29445ed99c2f\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14358</id>
        <msg>WEB-ACTIVEX VMWare unspecified 5 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|4|00|9|00|3|00|0|00|4|00|b|00|-|00|1|00|9|00|8|00|d|00|-|00|4|00|b|00|8|00|1|00|-|00|8|00|2|00|5|00|0|00|-|00|2|00|9|00|4|00|4|00|5|00|e|00|d|00|9|00|9|00|c|00|2|00|f|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x002\x004\x009\x003\x000\x004\x00b\x00-\x001\x009\x008\x00d\x00-\x004\x00b\x008\x001\x00-\x008\x002\x005\x000\x00-\x002\x009\x004\x004\x005\x00e\x00d\x009\x009\x00c\x002\x00f\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14359</id>
        <msg>WEB-ACTIVEX VMWare unspecified 5 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;44d188a8-f3c4-49fe-96eb-a416259d7c4a&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*44d188a8-f3c4-49fe-96eb-a416259d7c4a\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14360</id>
        <msg>WEB-ACTIVEX HardwareCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|d|00|1|00|8|00|8|00|a|00|8|00|-|00|f|00|3|00|c|00|4|00|-|00|4|00|9|00|f|00|e|00|-|00|9|00|6|00|e|00|b|00|-|00|a|00|4|00|1|00|6|00|2|00|5|00|9|00|d|00|7|00|c|00|4|00|a|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x00d\x001\x008\x008\x00a\x008\x00-\x00f\x003\x00c\x004\x00-\x004\x009\x00f\x00e\x00-\x009\x006\x00e\x00b\x00-\x00a\x004\x001\x006\x002\x005\x009\x00d\x007\x00c\x004\x00a\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14361</id>
        <msg>WEB-ACTIVEX HardwareCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.HardwareCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.HardwareCtl\x22|\x27Vmappsdk\.HardwareCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.HardwareCtl\x22|\x27Vmappsdk\.HardwareCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14362</id>
        <msg>WEB-ACTIVEX HardwareCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|H|00|a|00|r|00|d|00|w|00|a|00|r|00|e|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00H\x00a\x00r\x00d\x00w\x00a\x00r\x00e\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00H\x00a\x00r\x00d\x00w\x00a\x00r\x00e\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14363</id>
        <msg>WEB-ACTIVEX HardwareCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;47266690-b412-4a6c-a072-2e97ce86a0b6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*47266690-b412-4a6c-a072-2e97ce86a0b6\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14364</id>
        <msg>WEB-ACTIVEX VMWare unspecified 6 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|2|00|6|00|6|00|6|00|9|00|0|00|-|00|b|00|4|00|1|00|2|00|-|00|4|00|a|00|6|00|c|00|-|00|a|00|0|00|7|00|2|00|-|00|2|00|e|00|9|00|7|00|c|00|e|00|8|00|6|00|a|00|0|00|b|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x007\x002\x006\x006\x006\x009\x000\x00-\x00b\x004\x001\x002\x00-\x004\x00a\x006\x00c\x00-\x00a\x000\x007\x002\x00-\x002\x00e\x009\x007\x00c\x00e\x008\x006\x00a\x000\x00b\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14365</id>
        <msg>WEB-ACTIVEX VMWare unspecified 6 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;477ca8b0-4c2a-40c9-a440-28acb95cfad8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*477ca8b0-4c2a-40c9-a440-28acb95cfad8\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14366</id>
        <msg>WEB-ACTIVEX VmdbQuery Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|7|00|c|00|a|00|8|00|b|00|0|00|-|00|4|00|c|00|2|00|a|00|-|00|4|00|0|00|c|00|9|00|-|00|a|00|4|00|4|00|0|00|-|00|2|00|8|00|a|00|c|00|b|00|9|00|5|00|c|00|f|00|a|00|d|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x007\x007\x00c\x00a\x008\x00b\x000\x00-\x004\x00c\x002\x00a\x00-\x004\x000\x00c\x009\x00-\x00a\x004\x004\x000\x00-\x002\x008\x00a\x00c\x00b\x009\x005\x00c\x00f\x00a\x00d\x008\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14367</id>
        <msg>WEB-ACTIVEX VmdbQuery Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VmdbCOM.VmdbQuery&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VmdbCOM\.VmdbQuery\x22|\x27VmdbCOM\.VmdbQuery\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VmdbCOM\.VmdbQuery\x22|\x27VmdbCOM\.VmdbQuery\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14368</id>
        <msg>WEB-ACTIVEX VmdbQuery Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|Q|00|u|00|e|00|r|00|y|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00Q\x00u\x00e\x00r\x00y\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00Q\x00u\x00e\x00r\x00y\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14369</id>
        <msg>WEB-ACTIVEX VmdbQuery Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;48a70f00-ae14-46ce-ac17-d2290d504b37&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*48a70f00-ae14-46ce-ac17-d2290d504b37\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14370</id>
        <msg>WEB-ACTIVEX vmappPropObj2 Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|8|00|a|00|7|00|0|00|f|00|0|00|0|00|-|00|a|00|e|00|1|00|4|00|-|00|4|00|6|00|c|00|e|00|-|00|a|00|c|00|1|00|7|00|-|00|d|00|2|00|2|00|9|00|0|00|d|00|5|00|0|00|4|00|b|00|3|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x008\x00a\x007\x000\x00f\x000\x000\x00-\x00a\x00e\x001\x004\x00-\x004\x006\x00c\x00e\x00-\x00a\x00c\x001\x007\x00-\x00d\x002\x002\x009\x000\x00d\x005\x000\x004\x00b\x003\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14371</id>
        <msg>WEB-ACTIVEX vmappPropObj2 Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.VmappPropObj2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.VmappPropObj2\x22|\x27vmappsdk\.VmappPropObj2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.VmappPropObj2\x22|\x27vmappsdk\.VmappPropObj2\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14372</id>
        <msg>WEB-ACTIVEX vmappPropObj2 Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|m|00|a|00|p|00|p|00|P|00|r|00|o|00|p|00|O|00|b|00|j|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00O\x00b\x00j\x002\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00O\x00b\x00j\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14373</id>
        <msg>WEB-ACTIVEX vmappPropObj2 Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;48e72e42-2d79-4d94-99f6-c859f3a46d42&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*48e72e42-2d79-4d94-99f6-c859f3a46d42\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14374</id>
        <msg>WEB-ACTIVEX VmappPoll Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|8|00|e|00|7|00|2|00|e|00|4|00|2|00|-|00|2|00|d|00|7|00|9|00|-|00|4|00|d|00|9|00|4|00|-|00|9|00|9|00|f|00|6|00|-|00|c|00|8|00|5|00|9|00|f|00|3|00|a|00|4|00|6|00|d|00|4|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x008\x00e\x007\x002\x00e\x004\x002\x00-\x002\x00d\x007\x009\x00-\x004\x00d\x009\x004\x00-\x009\x009\x00f\x006\x00-\x00c\x008\x005\x009\x00f\x003\x00a\x004\x006\x00d\x004\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14375</id>
        <msg>WEB-ACTIVEX VmappPoll Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.vmappPoll&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.vmappPoll\x22|\x27vmdbCOM\.vmappPoll\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.vmappPoll\x22|\x27vmdbCOM\.vmappPoll\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14376</id>
        <msg>WEB-ACTIVEX VmappPoll Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|v|00|m|00|a|00|p|00|p|00|P|00|o|00|l|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00v\x00m\x00a\x00p\x00p\x00P\x00o\x00l\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00v\x00m\x00a\x00p\x00p\x00P\x00o\x00l\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14377</id>
        <msg>WEB-ACTIVEX VmappPoll Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4cc34b9f-1536-4330-adfb-b0a68ce3d856&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4cc34b9f-1536-4330-adfb-b0a68ce3d856\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14378</id>
        <msg>WEB-ACTIVEX VMClient Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|c|00|c|00|3|00|4|00|b|00|9|00|f|00|-|00|1|00|5|00|3|00|6|00|-|00|4|00|3|00|3|00|0|00|-|00|a|00|d|00|f|00|b|00|-|00|b|00|0|00|a|00|6|00|8|00|c|00|e|00|3|00|d|00|8|00|5|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x00c\x00c\x003\x004\x00b\x009\x00f\x00-\x001\x005\x003\x006\x00-\x004\x003\x003\x000\x00-\x00a\x00d\x00f\x00b\x00-\x00b\x000\x00a\x006\x008\x00c\x00e\x003\x00d\x008\x005\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14379</id>
        <msg>WEB-ACTIVEX VMClient Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VMClient&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VMClient\x22|\x27vmdbCOM\.VMClient\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VMClient\x22|\x27vmdbCOM\.VMClient\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14380</id>
        <msg>WEB-ACTIVEX VMClient Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|C|00|l|00|i|00|e|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14381</id>
        <msg>WEB-ACTIVEX VMClient Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5647DAF6-85BE-4173-88E7-749322B243BE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5647DAF6-85BE-4173-88E7-749322B243BE\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14382</id>
        <msg>WEB-ACTIVEX Pq2vcom.Pq2v ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|6|00|4|00|7|00|D|00|A|00|F|00|6|00|-|00|8|00|5|00|B|00|E|00|-|00|4|00|1|00|7|00|3|00|-|00|8|00|8|00|E|00|7|00|-|00|7|00|4|00|9|00|3|00|2|00|2|00|B|00|2|00|4|00|3|00|B|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x006\x004\x007\x00D\x00A\x00F\x006\x00-\x008\x005\x00B\x00E\x00-\x004\x001\x007\x003\x00-\x008\x008\x00E\x007\x00-\x007\x004\x009\x003\x002\x002\x00B\x002\x004\x003\x00B\x00E\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14383</id>
        <msg>WEB-ACTIVEX Pq2vcom.Pq2v ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Pq2vcom.Pq2v&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Pq2vcom\.Pq2v\x22|\x27Pq2vcom\.Pq2v\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Pq2vcom\.Pq2v\x22|\x27Pq2vcom\.Pq2v\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14384</id>
        <msg>WEB-ACTIVEX Pq2vcom.Pq2v ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|q|00|2|00|v|00|c|00|o|00|m|00|.|00|P|00|q|00|2|00|v|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)P\x00q\x002\x00v\x00c\x00o\x00m\x00.\x00P\x00q\x002\x00v\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00q\x002\x00v\x00c\x00o\x00m\x00.\x00P\x00q\x002\x00v\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14385</id>
        <msg>WEB-ACTIVEX Pq2vcom.Pq2v ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5a8cce1b-1845-4a4b-9b89-c5a97d2acae2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5a8cce1b-1845-4a4b-9b89-c5a97d2acae2\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14386</id>
        <msg>WEB-ACTIVEX VmdbSchema Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|a|00|8|00|c|00|c|00|e|00|1|00|b|00|-|00|1|00|8|00|4|00|5|00|-|00|4|00|a|00|4|00|b|00|-|00|9|00|b|00|8|00|9|00|-|00|c|00|5|00|a|00|9|00|7|00|d|00|2|00|a|00|c|00|a|00|e|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x00a\x008\x00c\x00c\x00e\x001\x00b\x00-\x001\x008\x004\x005\x00-\x004\x00a\x004\x00b\x00-\x009\x00b\x008\x009\x00-\x00c\x005\x00a\x009\x007\x00d\x002\x00a\x00c\x00a\x00e\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14387</id>
        <msg>WEB-ACTIVEX VmdbSchema Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbSchema&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbSchema\x22|\x27vmdbCOM\.VmdbSchema\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbSchema\x22|\x27vmdbCOM\.VmdbSchema\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14388</id>
        <msg>WEB-ACTIVEX VmdbSchema Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|S|00|c|00|h|00|e|00|m|00|a|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00S\x00c\x00h\x00e\x00m\x00a\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00S\x00c\x00h\x00e\x00m\x00a\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14389</id>
        <msg>WEB-ACTIVEX VmdbSchema Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1AF378DE-4574-4bb0-A5DF-F78FCAD28707&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1AF378DE-4574-4bb0-A5DF-F78FCAD28707\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14390</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|A|00|F|00|3|00|7|00|8|00|D|00|E|00|-|00|4|00|5|00|7|00|4|00|-|00|4|00|b|00|b|00|0|00|-|00|A|00|5|00|D|00|F|00|-|00|F|00|7|00|8|00|F|00|C|00|A|00|D|00|2|00|8|00|7|00|0|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00A\x00F\x003\x007\x008\x00D\x00E\x00-\x004\x005\x007\x004\x00-\x004\x00b\x00b\x000\x00-\x00A\x005\x00D\x00F\x00-\x00F\x007\x008\x00F\x00C\x00A\x00D\x002\x008\x007\x000\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14391</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vie2Lib.Vie2LinuxVolume&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vie2Lib\.Vie2LinuxVolume\x22|\x27Vie2Lib\.Vie2LinuxVolume\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vie2Lib\.Vie2LinuxVolume\x22|\x27Vie2Lib\.Vie2LinuxVolume\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14392</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|2|00|L|00|i|00|b|00|.|00|V|00|i|00|e|00|2|00|L|00|i|00|n|00|u|00|x|00|V|00|o|00|l|00|u|00|m|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00e\x002\x00L\x00i\x00b\x00.\x00V\x00i\x00e\x002\x00L\x00i\x00n\x00u\x00x\x00V\x00o\x00l\x00u\x00m\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x002\x00L\x00i\x00b\x00.\x00V\x00i\x00e\x002\x00L\x00i\x00n\x00u\x00x\x00V\x00o\x00l\x00u\x00m\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14393</id>
        <msg>WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6874E949-7186-4308-A1B9-D55A91F60728&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6874E949-7186-4308-A1B9-D55A91F60728\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14394</id>
        <msg>WEB-ACTIVEX VixCOM.VixLib ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|7|00|4|00|E|00|9|00|4|00|9|00|-|00|7|00|1|00|8|00|6|00|-|00|4|00|3|00|0|00|8|00|-|00|A|00|1|00|B|00|9|00|-|00|D|00|5|00|5|00|A|00|9|00|1|00|F|00|6|00|0|00|7|00|2|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x008\x007\x004\x00E\x009\x004\x009\x00-\x007\x001\x008\x006\x00-\x004\x003\x000\x008\x00-\x00A\x001\x00B\x009\x00-\x00D\x005\x005\x00A\x009\x001\x00F\x006\x000\x007\x002\x008\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14395</id>
        <msg>WEB-ACTIVEX VixCOM.VixLib ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VixCOM.VixLib&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VixCOM\.VixLib\x22|\x27VixCOM\.VixLib\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VixCOM\.VixLib\x22|\x27VixCOM\.VixLib\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14396</id>
        <msg>WEB-ACTIVEX VixCOM.VixLib ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|x|00|C|00|O|00|M|00|.|00|V|00|i|00|x|00|L|00|i|00|b|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00x\x00C\x00O\x00M\x00.\x00V\x00i\x00x\x00L\x00i\x00b\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00x\x00C\x00O\x00M\x00.\x00V\x00i\x00x\x00L\x00i\x00b\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14397</id>
        <msg>WEB-ACTIVEX VixCOM.VixLib ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;68F1E07B-609F-4b87-9D57-A879023A75FC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*68F1E07B-609F-4b87-9D57-A879023A75FC\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14398</id>
        <msg>WEB-ACTIVEX vmappsdk.CuiObj ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|F|00|1|00|E|00|0|00|7|00|B|00|-|00|6|00|0|00|9|00|F|00|-|00|4|00|b|00|8|00|7|00|-|00|9|00|D|00|5|00|7|00|-|00|A|00|8|00|7|00|9|00|0|00|2|00|3|00|A|00|7|00|5|00|F|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x008\x00F\x001\x00E\x000\x007\x00B\x00-\x006\x000\x009\x00F\x00-\x004\x00b\x008\x007\x00-\x009\x00D\x005\x007\x00-\x00A\x008\x007\x009\x000\x002\x003\x00A\x007\x005\x00F\x00C\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14399</id>
        <msg>WEB-ACTIVEX vmappsdk.CuiObj ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.CuiObj&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.CuiObj\x22|\x27vmappsdk\.CuiObj\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.CuiObj\x22|\x27vmappsdk\.CuiObj\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14400</id>
        <msg>WEB-ACTIVEX vmappsdk.CuiObj ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|C|00|u|00|i|00|O|00|b|00|j|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00u\x00i\x00O\x00b\x00j\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00u\x00i\x00O\x00b\x00j\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14401</id>
        <msg>WEB-ACTIVEX vmappsdk.CuiObj ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6b681417-abe9-46ca-9615-8b96ec724d0c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6b681417-abe9-46ca-9615-8b96ec724d0c\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14402</id>
        <msg>WEB-ACTIVEX RemoteBrowseDlg Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|b|00|6|00|8|00|1|00|4|00|1|00|7|00|-|00|a|00|b|00|e|00|9|00|-|00|4|00|6|00|c|00|a|00|-|00|9|00|6|00|1|00|5|00|-|00|8|00|b|00|9|00|6|00|e|00|c|00|7|00|2|00|4|00|d|00|0|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00b\x006\x008\x001\x004\x001\x007\x00-\x00a\x00b\x00e\x009\x00-\x004\x006\x00c\x00a\x00-\x009\x006\x001\x005\x00-\x008\x00b\x009\x006\x00e\x00c\x007\x002\x004\x00d\x000\x00c\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14403</id>
        <msg>WEB-ACTIVEX RemoteBrowseDlg Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.RemoteBrowseDlg&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.RemoteBrowseDlg\x22|\x27Vmappsdk\.RemoteBrowseDlg\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.RemoteBrowseDlg\x22|\x27Vmappsdk\.RemoteBrowseDlg\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14404</id>
        <msg>WEB-ACTIVEX RemoteBrowseDlg Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|R|00|e|00|m|00|o|00|t|00|e|00|B|00|r|00|o|00|w|00|s|00|e|00|D|00|l|00|g|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00B\x00r\x00o\x00w\x00s\x00e\x00D\x00l\x00g\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00m\x00o\x00t\x00e\x00B\x00r\x00o\x00w\x00s\x00e\x00D\x00l\x00g\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14405</id>
        <msg>WEB-ACTIVEX RemoteBrowseDlg Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6bc34d15-ee92-46b3-8c6a-03de589ab727&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6bc34d15-ee92-46b3-8c6a-03de589ab727\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14406</id>
        <msg>WEB-ACTIVEX RegVmsCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|b|00|c|00|3|00|4|00|d|00|1|00|5|00|-|00|e|00|e|00|9|00|2|00|-|00|4|00|6|00|b|00|3|00|-|00|8|00|c|00|6|00|a|00|-|00|0|00|3|00|d|00|e|00|5|00|8|00|9|00|a|00|b|00|7|00|2|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00b\x00c\x003\x004\x00d\x001\x005\x00-\x00e\x00e\x009\x002\x00-\x004\x006\x00b\x003\x00-\x008\x00c\x006\x00a\x00-\x000\x003\x00d\x00e\x005\x008\x009\x00a\x00b\x007\x002\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14407</id>
        <msg>WEB-ACTIVEX RegVmsCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.RegVmsCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.RegVmsCtl\x22|\x27Vmappsdk\.RegVmsCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.RegVmsCtl\x22|\x27Vmappsdk\.RegVmsCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14408</id>
        <msg>WEB-ACTIVEX RegVmsCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|R|00|e|00|g|00|V|00|m|00|s|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00g\x00V\x00m\x00s\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00R\x00e\x00g\x00V\x00m\x00s\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14409</id>
        <msg>WEB-ACTIVEX RegVmsCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;733a5dfa-084e-4ecf-af13-95b852358dd3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*733a5dfa-084e-4ecf-af13-95b852358dd3\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14410</id>
        <msg>WEB-ACTIVEX VmdbEnumTags Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|3|00|3|00|a|00|5|00|d|00|f|00|a|00|-|00|0|00|8|00|4|00|e|00|-|00|4|00|e|00|c|00|f|00|-|00|a|00|f|00|1|00|3|00|-|00|9|00|5|00|b|00|8|00|5|00|2|00|3|00|5|00|8|00|d|00|d|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x003\x003\x00a\x005\x00d\x00f\x00a\x00-\x000\x008\x004\x00e\x00-\x004\x00e\x00c\x00f\x00-\x00a\x00f\x001\x003\x00-\x009\x005\x00b\x008\x005\x002\x003\x005\x008\x00d\x00d\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14411</id>
        <msg>WEB-ACTIVEX VmdbEnumTags Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbEnumTags&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbEnumTags\x22|\x27vmdbCOM\.VmdbEnumTags\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbEnumTags\x22|\x27vmdbCOM\.VmdbEnumTags\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14412</id>
        <msg>WEB-ACTIVEX VmdbEnumTags Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|E|00|n|00|u|00|m|00|T|00|a|00|g|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00E\x00n\x00u\x00m\x00T\x00a\x00g\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00E\x00n\x00u\x00m\x00T\x00a\x00g\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14413</id>
        <msg>WEB-ACTIVEX VmdbEnumTags Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;75869575-07ba-4c7e-8f8f-980dfbc12abd&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*75869575-07ba-4c7e-8f8f-980dfbc12abd\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14414</id>
        <msg>WEB-ACTIVEX VMWare unspecified 7 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|5|00|8|00|6|00|9|00|5|00|7|00|5|00|-|00|0|00|7|00|b|00|a|00|-|00|4|00|c|00|7|00|e|00|-|00|8|00|f|00|8|00|f|00|-|00|9|00|8|00|0|00|d|00|f|00|b|00|c|00|1|00|2|00|a|00|b|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x005\x008\x006\x009\x005\x007\x005\x00-\x000\x007\x00b\x00a\x00-\x004\x00c\x007\x00e\x00-\x008\x00f\x008\x00f\x00-\x009\x008\x000\x00d\x00f\x00b\x00c\x001\x002\x00a\x00b\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14415</id>
        <msg>WEB-ACTIVEX VMWare unspecified 7 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7B9C5422-39AA-4c21-BEEF-645E42EB4529&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7B9C5422-39AA-4c21-BEEF-645E42EB4529\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14416</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|B|00|9|00|C|00|5|00|4|00|2|00|2|00|-|00|3|00|9|00|A|00|A|00|-|00|4|00|c|00|2|00|1|00|-|00|B|00|E|00|E|00|F|00|-|00|6|00|4|00|5|00|E|00|4|00|2|00|E|00|B|00|4|00|5|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00B\x009\x00C\x005\x004\x002\x002\x00-\x003\x009\x00A\x00A\x00-\x004\x00c\x002\x001\x00-\x00B\x00E\x00E\x00F\x00-\x006\x004\x005\x00E\x004\x002\x00E\x00B\x004\x005\x002\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14417</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VieLib2.Vie2Process&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14418</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|L|00|i|00|b|00|2|00|.|00|V|00|i|00|e|00|2|00|P|00|r|00|o|00|c|00|e|00|s|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14419</id>
        <msg>WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7edd4fce-e178-47f2-ae05-c5936c843795&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7edd4fce-e178-47f2-ae05-c5936c843795\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14420</id>
        <msg>WEB-ACTIVEX VmdbDatabase Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|e|00|d|00|d|00|4|00|f|00|c|00|e|00|-|00|e|00|1|00|7|00|8|00|-|00|4|00|7|00|f|00|2|00|-|00|a|00|e|00|0|00|5|00|-|00|c|00|5|00|9|00|3|00|6|00|c|00|8|00|4|00|3|00|7|00|9|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00e\x00d\x00d\x004\x00f\x00c\x00e\x00-\x00e\x001\x007\x008\x00-\x004\x007\x00f\x002\x00-\x00a\x00e\x000\x005\x00-\x00c\x005\x009\x003\x006\x00c\x008\x004\x003\x007\x009\x005\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14421</id>
        <msg>WEB-ACTIVEX VmdbDatabase Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbDatabase&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbDatabase\x22|\x27vmdbCOM\.VmdbDatabase\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbDatabase\x22|\x27vmdbCOM\.VmdbDatabase\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14422</id>
        <msg>WEB-ACTIVEX VmdbDatabase Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|D|00|a|00|t|00|a|00|b|00|a|00|s|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00D\x00a\x00t\x00a\x00b\x00a\x00s\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00D\x00a\x00t\x00a\x00b\x00a\x00s\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14423</id>
        <msg>WEB-ACTIVEX VmdbDatabase Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;85691355-a4fa-4e2b-b461-8145f90aa8dc&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*85691355-a4fa-4e2b-b461-8145f90aa8dc\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14424</id>
        <msg>WEB-ACTIVEX VMAppSdkUtil Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|5|00|6|00|9|00|1|00|3|00|5|00|5|00|-|00|a|00|4|00|f|00|a|00|-|00|4|00|e|00|2|00|b|00|-|00|b|00|4|00|6|00|1|00|-|00|8|00|1|00|4|00|5|00|f|00|9|00|0|00|a|00|a|00|8|00|d|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x005\x006\x009\x001\x003\x005\x005\x00-\x00a\x004\x00f\x00a\x00-\x004\x00e\x002\x00b\x00-\x00b\x004\x006\x001\x00-\x008\x001\x004\x005\x00f\x009\x000\x00a\x00a\x008\x00d\x00c\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14425</id>
        <msg>WEB-ACTIVEX VMAppSdkUtil Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VMAppSdkUtil&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VMAppSdkUtil\x22|\x27Vmappsdk\.VMAppSdkUtil\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VMAppSdkUtil\x22|\x27Vmappsdk\.VMAppSdkUtil\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14426</id>
        <msg>WEB-ACTIVEX VMAppSdkUtil Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|A|00|p|00|p|00|S|00|d|00|k|00|U|00|t|00|i|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00A\x00p\x00p\x00S\x00d\x00k\x00U\x00t\x00i\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00A\x00p\x00p\x00S\x00d\x00k\x00U\x00t\x00i\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14427</id>
        <msg>WEB-ACTIVEX VMAppSdkUtil Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8f2f3b54-43cc-4912-9b48-bd500a023d40&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8f2f3b54-43cc-4912-9b48-bd500a023d40\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14428</id>
        <msg>WEB-ACTIVEX VMWare unspecified 8 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|f|00|2|00|f|00|3|00|b|00|5|00|4|00|-|00|4|00|3|00|c|00|c|00|-|00|4|00|9|00|1|00|2|00|-|00|9|00|b|00|4|00|8|00|-|00|b|00|d|00|5|00|0|00|0|00|a|00|0|00|2|00|3|00|d|00|4|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00f\x002\x00f\x003\x00b\x005\x004\x00-\x004\x003\x00c\x00c\x00-\x004\x009\x001\x002\x00-\x009\x00b\x004\x008\x00-\x00b\x00d\x005\x000\x000\x00a\x000\x002\x003\x00d\x004\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14429</id>
        <msg>WEB-ACTIVEX VMWare unspecified 8 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;92d37a66-dc23-4244-8add-2e8bdcafa9b2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*92d37a66-dc23-4244-8add-2e8bdcafa9b2\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14430</id>
        <msg>WEB-ACTIVEX VMEnumStrings Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|2|00|d|00|3|00|7|00|a|00|6|00|6|00|-|00|d|00|c|00|2|00|3|00|-|00|4|00|2|00|4|00|4|00|-|00|8|00|a|00|d|00|d|00|-|00|2|00|e|00|8|00|b|00|d|00|c|00|a|00|f|00|a|00|9|00|b|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x002\x00d\x003\x007\x00a\x006\x006\x00-\x00d\x00c\x002\x003\x00-\x004\x002\x004\x004\x00-\x008\x00a\x00d\x00d\x00-\x002\x00e\x008\x00b\x00d\x00c\x00a\x00f\x00a\x009\x00b\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14431</id>
        <msg>WEB-ACTIVEX VMEnumStrings Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.VMEnumStrings&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.VMEnumStrings\x22|\x27vmappsdk\.VMEnumStrings\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.VMEnumStrings\x22|\x27vmappsdk\.VMEnumStrings\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14432</id>
        <msg>WEB-ACTIVEX VMEnumStrings Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|E|00|n|00|u|00|m|00|S|00|t|00|r|00|i|00|n|00|g|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00E\x00n\x00u\x00m\x00S\x00t\x00r\x00i\x00n\x00g\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00E\x00n\x00u\x00m\x00S\x00t\x00r\x00i\x00n\x00g\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14433</id>
        <msg>WEB-ACTIVEX VMEnumStrings Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;93beec8b-783e-4f87-a1d7-61936f3805cf&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*93beec8b-783e-4f87-a1d7-61936f3805cf\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14434</id>
        <msg>WEB-ACTIVEX VMWare unspecified 9 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|3|00|b|00|e|00|e|00|c|00|8|00|b|00|-|00|7|00|8|00|3|00|e|00|-|00|4|00|f|00|8|00|7|00|-|00|a|00|1|00|d|00|7|00|-|00|6|00|1|00|9|00|3|00|6|00|f|00|3|00|8|00|0|00|5|00|c|00|f|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x003\x00b\x00e\x00e\x00c\x008\x00b\x00-\x007\x008\x003\x00e\x00-\x004\x00f\x008\x007\x00-\x00a\x001\x00d\x007\x00-\x006\x001\x009\x003\x006\x00f\x003\x008\x000\x005\x00c\x00f\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14435</id>
        <msg>WEB-ACTIVEX VMWare unspecified 9 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9663f7c7-44fb-4075-bc83-829b47db7936&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9663f7c7-44fb-4075-bc83-829b47db7936\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14436</id>
        <msg>WEB-ACTIVEX VMClientHost Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|6|00|6|00|3|00|f|00|7|00|c|00|7|00|-|00|4|00|4|00|f|00|b|00|-|00|4|00|0|00|7|00|5|00|-|00|b|00|c|00|8|00|3|00|-|00|8|00|2|00|9|00|b|00|4|00|7|00|d|00|b|00|7|00|9|00|3|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x006\x006\x003\x00f\x007\x00c\x007\x00-\x004\x004\x00f\x00b\x00-\x004\x000\x007\x005\x00-\x00b\x00c\x008\x003\x00-\x008\x002\x009\x00b\x004\x007\x00d\x00b\x007\x009\x003\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14437</id>
        <msg>WEB-ACTIVEX VMClientHost Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VMClientHost&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VMClientHost\x22|\x27vmdbCOM\.VMClientHost\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VMClientHost\x22|\x27vmdbCOM\.VMClientHost\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14438</id>
        <msg>WEB-ACTIVEX VMClientHost Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|C|00|l|00|i|00|e|00|n|00|t|00|H|00|o|00|s|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00H\x00o\x00s\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00H\x00o\x00s\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14439</id>
        <msg>WEB-ACTIVEX VMClientHost Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;96a05576-987f-4f6d-9102-8799e3ded07b&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*96a05576-987f-4f6d-9102-8799e3ded07b\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14440</id>
        <msg>WEB-ACTIVEX VMWare unspecified 10 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|6|00|a|00|0|00|5|00|5|00|7|00|6|00|-|00|9|00|8|00|7|00|f|00|-|00|4|00|f|00|6|00|d|00|-|00|9|00|1|00|0|00|2|00|-|00|8|00|7|00|9|00|9|00|e|00|3|00|d|00|e|00|d|00|0|00|7|00|b|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x006\x00a\x000\x005\x005\x007\x006\x00-\x009\x008\x007\x00f\x00-\x004\x00f\x006\x00d\x00-\x009\x001\x000\x002\x00-\x008\x007\x009\x009\x00e\x003\x00d\x00e\x00d\x000\x007\x00b\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14441</id>
        <msg>WEB-ACTIVEX VMWare unspecified 10 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;99a1b3a3-0c4c-4e08-a1b1-84a6e6ff414d&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*99a1b3a3-0c4c-4e08-a1b1-84a6e6ff414d\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14442</id>
        <msg>WEB-ACTIVEX VMWare unspecified 11 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|9|00|a|00|1|00|b|00|3|00|a|00|3|00|-|00|0|00|c|00|4|00|c|00|-|00|4|00|e|00|0|00|8|00|-|00|a|00|1|00|b|00|1|00|-|00|8|00|4|00|a|00|6|00|e|00|6|00|f|00|f|00|4|00|1|00|4|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x009\x00a\x001\x00b\x003\x00a\x003\x00-\x000\x00c\x004\x00c\x00-\x004\x00e\x000\x008\x00-\x00a\x001\x00b\x001\x00-\x008\x004\x00a\x006\x00e\x006\x00f\x00f\x004\x001\x004\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14443</id>
        <msg>WEB-ACTIVEX VMWare unspecified 11 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9d253f85-f9b1-446e-9122-7ef3e260c3e4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9d253f85-f9b1-446e-9122-7ef3e260c3e4\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14444</id>
        <msg>WEB-ACTIVEX VMWare unspecified 12 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|d|00|2|00|5|00|3|00|f|00|8|00|5|00|-|00|f|00|9|00|b|00|1|00|-|00|4|00|4|00|6|00|e|00|-|00|9|00|1|00|2|00|2|00|-|00|7|00|e|00|f|00|3|00|e|00|2|00|6|00|0|00|c|00|3|00|e|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00d\x002\x005\x003\x00f\x008\x005\x00-\x00f\x009\x00b\x001\x00-\x004\x004\x006\x00e\x00-\x009\x001\x002\x002\x00-\x007\x00e\x00f\x003\x00e\x002\x006\x000\x00c\x003\x00e\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14445</id>
        <msg>WEB-ACTIVEX VMWare unspecified 12 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9ea0c310-9140-4735-90db-5babc57583f0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9ea0c310-9140-4735-90db-5babc57583f0\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14446</id>
        <msg>WEB-ACTIVEX VMWare unspecified 13 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|e|00|a|00|0|00|c|00|3|00|1|00|0|00|-|00|9|00|1|00|4|00|0|00|-|00|4|00|7|00|3|00|5|00|-|00|9|00|0|00|d|00|b|00|-|00|5|00|b|00|a|00|b|00|c|00|5|00|7|00|5|00|8|00|3|00|f|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00e\x00a\x000\x00c\x003\x001\x000\x00-\x009\x001\x004\x000\x00-\x004\x007\x003\x005\x00-\x009\x000\x00d\x00b\x00-\x005\x00b\x00a\x00b\x00c\x005\x007\x005\x008\x003\x00f\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14447</id>
        <msg>WEB-ACTIVEX VMWare unspecified 13 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9ED5A5B3-C8D4-4597-B082-487008D75E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9ED5A5B3-C8D4-4597-B082-487008D75E3F\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14448</id>
        <msg>WEB-ACTIVEX reconfig.SystemReconfigur ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|E|00|D|00|5|00|A|00|5|00|B|00|3|00|-|00|C|00|8|00|D|00|4|00|-|00|4|00|5|00|9|00|7|00|-|00|B|00|0|00|8|00|2|00|-|00|4|00|8|00|7|00|0|00|0|00|8|00|D|00|7|00|5|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00E\x00D\x005\x00A\x005\x00B\x003\x00-\x00C\x008\x00D\x004\x00-\x004\x005\x009\x007\x00-\x00B\x000\x008\x002\x00-\x004\x008\x007\x000\x000\x008\x00D\x007\x005\x00E\x003\x00F\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14449</id>
        <msg>WEB-ACTIVEX reconfig.SystemReconfigur ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;reconfig.SystemReconfigur&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22reconfig\.SystemReconfigur\x22|\x27reconfig\.SystemReconfigur\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22reconfig\.SystemReconfigur\x22|\x27reconfig\.SystemReconfigur\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14450</id>
        <msg>WEB-ACTIVEX reconfig.SystemReconfigur ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|e|00|c|00|o|00|n|00|f|00|i|00|g|00|.|00|S|00|y|00|s|00|t|00|e|00|m|00|R|00|e|00|c|00|o|00|n|00|f|00|i|00|g|00|u|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00u\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00u\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14451</id>
        <msg>WEB-ACTIVEX reconfig.SystemReconfigur ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9F625D90-A74B-4dd8-9847-9CFD6F928FEF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9F625D90-A74B-4dd8-9847-9CFD6F928FEF\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14452</id>
        <msg>WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|F|00|6|00|2|00|5|00|D|00|9|00|0|00|-|00|A|00|7|00|4|00|B|00|-|00|4|00|d|00|d|00|8|00|-|00|9|00|8|00|4|00|7|00|-|00|9|00|C|00|F|00|D|00|6|00|F|00|9|00|2|00|8|00|F|00|E|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00F\x006\x002\x005\x00D\x009\x000\x00-\x00A\x007\x004\x00B\x00-\x004\x00d\x00d\x008\x00-\x009\x008\x004\x007\x00-\x009\x00C\x00F\x00D\x006\x00F\x009\x002\x008\x00F\x00E\x00F\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14453</id>
        <msg>WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmhwcfg.NwzCompleted&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmhwcfg\.NwzCompleted\x22|\x27vmhwcfg\.NwzCompleted\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmhwcfg\.NwzCompleted\x22|\x27vmhwcfg\.NwzCompleted\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14454</id>
        <msg>WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|h|00|w|00|c|00|f|00|g|00|.|00|N|00|w|00|z|00|C|00|o|00|m|00|p|00|l|00|e|00|t|00|e|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00h\x00w\x00c\x00f\x00g\x00.\x00N\x00w\x00z\x00C\x00o\x00m\x00p\x00l\x00e\x00t\x00e\x00d\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00h\x00w\x00c\x00f\x00g\x00.\x00N\x00w\x00z\x00C\x00o\x00m\x00p\x00l\x00e\x00t\x00e\x00d\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14455</id>
        <msg>WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;a170cd00-5ce4-46d0-b013-e804ffd1d929&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*a170cd00-5ce4-46d0-b013-e804ffd1d929\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14456</id>
        <msg>WEB-ACTIVEX MksCompatCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;a|00|1|00|7|00|0|00|c|00|d|00|0|00|0|00|-|00|5|00|c|00|e|00|4|00|-|00|4|00|6|00|d|00|0|00|-|00|b|00|0|00|1|00|3|00|-|00|e|00|8|00|0|00|4|00|f|00|f|00|d|00|1|00|d|00|9|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*a\x001\x007\x000\x00c\x00d\x000\x000\x00-\x005\x00c\x00e\x004\x00-\x004\x006\x00d\x000\x00-\x00b\x000\x001\x003\x00-\x00e\x008\x000\x004\x00f\x00f\x00d\x001\x00d\x009\x002\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14457</id>
        <msg>WEB-ACTIVEX MksCompatCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.MksCompatCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.MksCompatCtl\x22|\x27vmappsdk\.MksCompatCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.MksCompatCtl\x22|\x27vmappsdk\.MksCompatCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14458</id>
        <msg>WEB-ACTIVEX MksCompatCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|M|00|k|00|s|00|C|00|o|00|m|00|p|00|a|00|t|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00M\x00k\x00s\x00C\x00o\x00m\x00p\x00a\x00t\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00M\x00k\x00s\x00C\x00o\x00m\x00p\x00a\x00t\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14459</id>
        <msg>WEB-ACTIVEX MksCompatCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;aeab0a1a-4bcd-4fc2-9c70-0e0ae3b40350&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*aeab0a1a-4bcd-4fc2-9c70-0e0ae3b40350\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14460</id>
        <msg>WEB-ACTIVEX VMWare unspecified 14 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;a|00|e|00|a|00|b|00|0|00|a|00|1|00|a|00|-|00|4|00|b|00|c|00|d|00|-|00|4|00|f|00|c|00|2|00|-|00|9|00|c|00|7|00|0|00|-|00|0|00|e|00|0|00|a|00|e|00|3|00|b|00|4|00|0|00|3|00|5|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*a\x00e\x00a\x00b\x000\x00a\x001\x00a\x00-\x004\x00b\x00c\x00d\x00-\x004\x00f\x00c\x002\x00-\x009\x00c\x007\x000\x00-\x000\x00e\x000\x00a\x00e\x003\x00b\x004\x000\x003\x005\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14461</id>
        <msg>WEB-ACTIVEX VMWare unspecified 14 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF13B07E-28A1-4CAC-9C9A-EC582E354A24&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AF13B07E-28A1-4CAC-9C9A-EC582E354A24\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14462</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|1|00|3|00|B|00|0|00|7|00|E|00|-|00|2|00|8|00|A|00|1|00|-|00|4|00|C|00|A|00|C|00|-|00|9|00|C|00|9|00|A|00|-|00|E|00|C|00|5|00|8|00|2|00|E|00|3|00|5|00|4|00|A|00|2|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00F\x001\x003\x00B\x000\x007\x00E\x00-\x002\x008\x00A\x001\x00-\x004\x00C\x00A\x00C\x00-\x009\x00C\x009\x00A\x00-\x00E\x00C\x005\x008\x002\x00E\x003\x005\x004\x00A\x002\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14463</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IntraProcessLogging.Logger&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22IntraProcessLogging\.Logger\x22|\x27IntraProcessLogging\.Logger\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IntraProcessLogging\.Logger\x22|\x27IntraProcessLogging\.Logger\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14464</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|n|00|t|00|r|00|a|00|P|00|r|00|o|00|c|00|e|00|s|00|s|00|L|00|o|00|g|00|g|00|i|00|n|00|g|00|.|00|L|00|o|00|g|00|g|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)I\x00n\x00t\x00r\x00a\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00L\x00o\x00g\x00g\x00i\x00n\x00g\x00.\x00L\x00o\x00g\x00g\x00e\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00n\x00t\x00r\x00a\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00L\x00o\x00g\x00g\x00i\x00n\x00g\x00.\x00L\x00o\x00g\x00g\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14465</id>
        <msg>WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b39924ac-b164-4f0a-b2d8-f07295df710d&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*b39924ac-b164-4f0a-b2d8-f07295df710d\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14466</id>
        <msg>WEB-ACTIVEX VMWare unspecified 15 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b|00|3|00|9|00|9|00|2|00|4|00|a|00|c|00|-|00|b|00|1|00|6|00|4|00|-|00|4|00|f|00|0|00|a|00|-|00|b|00|2|00|d|00|8|00|-|00|f|00|0|00|7|00|2|00|9|00|5|00|d|00|f|00|7|00|1|00|0|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*b\x003\x009\x009\x002\x004\x00a\x00c\x00-\x00b\x001\x006\x004\x00-\x004\x00f\x000\x00a\x00-\x00b\x002\x00d\x008\x00-\x00f\x000\x007\x002\x009\x005\x00d\x00f\x007\x001\x000\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14467</id>
        <msg>WEB-ACTIVEX VMWare unspecified 15 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BC1F4B6F-13AB-4239-8C79-D6DCADC52BAA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BC1F4B6F-13AB-4239-8C79-D6DCADC52BAA\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14468</id>
        <msg>WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|C|00|1|00|F|00|4|00|B|00|6|00|F|00|-|00|1|00|3|00|A|00|B|00|-|00|4|00|2|00|3|00|9|00|-|00|8|00|C|00|7|00|9|00|-|00|D|00|6|00|D|00|C|00|A|00|D|00|C|00|5|00|2|00|B|00|A|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00C\x001\x00F\x004\x00B\x006\x00F\x00-\x001\x003\x00A\x00B\x00-\x004\x002\x003\x009\x00-\x008\x00C\x007\x009\x00-\x00D\x006\x00D\x00C\x00A\x00D\x00C\x005\x002\x00B\x00A\x00A\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14469</id>
        <msg>WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Elevated.HostDeviceInfos&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Elevated\.HostDeviceInfos\x22|\x27Elevated\.HostDeviceInfos\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Elevated\.HostDeviceInfos\x22|\x27Elevated\.HostDeviceInfos\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14470</id>
        <msg>WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|l|00|e|00|v|00|a|00|t|00|e|00|d|00|.|00|H|00|o|00|s|00|t|00|D|00|e|00|v|00|i|00|c|00|e|00|I|00|n|00|f|00|o|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00H\x00o\x00s\x00t\x00D\x00e\x00v\x00i\x00c\x00e\x00I\x00n\x00f\x00o\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00H\x00o\x00s\x00t\x00D\x00e\x00v\x00i\x00c\x00e\x00I\x00n\x00f\x00o\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14471</id>
        <msg>WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;bea48e3e-5990-4f52-ad0c-4fee8b00b3dd&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bea48e3e-5990-4f52-ad0c-4fee8b00b3dd\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14472</id>
        <msg>WEB-ACTIVEX VMWare unspecified 16 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b|00|e|00|a|00|4|00|8|00|e|00|3|00|e|00|-|00|5|00|9|00|9|00|0|00|-|00|4|00|f|00|5|00|2|00|-|00|a|00|d|00|0|00|c|00|-|00|4|00|f|00|e|00|e|00|8|00|b|00|0|00|0|00|b|00|3|00|d|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*b\x00e\x00a\x004\x008\x00e\x003\x00e\x00-\x005\x009\x009\x000\x00-\x004\x00f\x005\x002\x00-\x00a\x00d\x000\x00c\x00-\x004\x00f\x00e\x00e\x008\x00b\x000\x000\x00b\x003\x00d\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14473</id>
        <msg>WEB-ACTIVEX VMWare unspecified 16 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;bf337b95-a08a-43ba-b395-001bb11e51cd&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bf337b95-a08a-43ba-b395-001bb11e51cd\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14474</id>
        <msg>WEB-ACTIVEX VMWare unspecified 17 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b|00|f|00|3|00|3|00|7|00|b|00|9|00|5|00|-|00|a|00|0|00|8|00|a|00|-|00|4|00|3|00|b|00|a|00|-|00|b|00|3|00|9|00|5|00|-|00|0|00|0|00|1|00|b|00|b|00|1|00|1|00|e|00|5|00|1|00|c|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*b\x00f\x003\x003\x007\x00b\x009\x005\x00-\x00a\x000\x008\x00a\x00-\x004\x003\x00b\x00a\x00-\x00b\x003\x009\x005\x00-\x000\x000\x001\x00b\x00b\x001\x001\x00e\x005\x001\x00c\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14475</id>
        <msg>WEB-ACTIVEX VMWare unspecified 17 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C0A9F3A2-C933-42E5-8ED4-FC7E9A55686F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C0A9F3A2-C933-42E5-8ED4-FC7E9A55686F\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14476</id>
        <msg>WEB-ACTIVEX reconfig.GuestInfo ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|0|00|A|00|9|00|F|00|3|00|A|00|2|00|-|00|C|00|9|00|3|00|3|00|-|00|4|00|2|00|E|00|5|00|-|00|8|00|E|00|D|00|4|00|-|00|F|00|C|00|7|00|E|00|9|00|A|00|5|00|5|00|6|00|8|00|6|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x000\x00A\x009\x00F\x003\x00A\x002\x00-\x00C\x009\x003\x003\x00-\x004\x002\x00E\x005\x00-\x008\x00E\x00D\x004\x00-\x00F\x00C\x007\x00E\x009\x00A\x005\x005\x006\x008\x006\x00F\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14477</id>
        <msg>WEB-ACTIVEX reconfig.GuestInfo ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;reconfig.GuestInfo&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22reconfig\.GuestInfo\x22|\x27reconfig\.GuestInfo\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22reconfig\.GuestInfo\x22|\x27reconfig\.GuestInfo\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14478</id>
        <msg>WEB-ACTIVEX reconfig.GuestInfo ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|e|00|c|00|o|00|n|00|f|00|i|00|g|00|.|00|G|00|u|00|e|00|s|00|t|00|I|00|n|00|f|00|o|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00G\x00u\x00e\x00s\x00t\x00I\x00n\x00f\x00o\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00e\x00c\x00o\x00n\x00f\x00i\x00g\x00.\x00G\x00u\x00e\x00s\x00t\x00I\x00n\x00f\x00o\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14479</id>
        <msg>WEB-ACTIVEX reconfig.GuestInfo ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c0f98577-fc80-4d0a-86b2-6d4e045edf8e&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*c0f98577-fc80-4d0a-86b2-6d4e045edf8e\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14480</id>
        <msg>WEB-ACTIVEX VmappPropFrame Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c|00|0|00|f|00|9|00|8|00|5|00|7|00|7|00|-|00|f|00|c|00|8|00|0|00|-|00|4|00|d|00|0|00|a|00|-|00|8|00|6|00|b|00|2|00|-|00|6|00|d|00|4|00|e|00|0|00|4|00|5|00|e|00|d|00|f|00|8|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*c\x000\x00f\x009\x008\x005\x007\x007\x00-\x00f\x00c\x008\x000\x00-\x004\x00d\x000\x00a\x00-\x008\x006\x00b\x002\x00-\x006\x00d\x004\x00e\x000\x004\x005\x00e\x00d\x00f\x008\x00e\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14481</id>
        <msg>WEB-ACTIVEX VmappPropFrame Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VmappPropFrame&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VmappPropFrame\x22|\x27Vmappsdk\.VmappPropFrame\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VmappPropFrame\x22|\x27Vmappsdk\.VmappPropFrame\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14482</id>
        <msg>WEB-ACTIVEX VmappPropFrame Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|m|00|a|00|p|00|p|00|P|00|r|00|o|00|p|00|F|00|r|00|a|00|m|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00F\x00r\x00a\x00m\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00F\x00r\x00a\x00m\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14483</id>
        <msg>WEB-ACTIVEX VmappPropFrame Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C2FBF309-56F6-409E-B9D7-DBBC190AD51A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C2FBF309-56F6-409E-B9D7-DBBC190AD51A\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14484</id>
        <msg>WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|2|00|F|00|B|00|F|00|3|00|0|00|9|00|-|00|5|00|6|00|F|00|6|00|-|00|4|00|0|00|9|00|E|00|-|00|B|00|9|00|D|00|7|00|-|00|D|00|B|00|B|00|C|00|1|00|9|00|0|00|A|00|D|00|5|00|1|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x002\x00F\x00B\x00F\x003\x000\x009\x00-\x005\x006\x00F\x006\x00-\x004\x000\x009\x00E\x00-\x00B\x009\x00D\x007\x00-\x00D\x00B\x00B\x00C\x001\x009\x000\x00A\x00D\x005\x001\x00A\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14485</id>
        <msg>WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VhdCvtCom.VhdConverter&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VhdCvtCom\.VhdConverter\x22|\x27VhdCvtCom\.VhdConverter\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VhdCvtCom\.VhdConverter\x22|\x27VhdCvtCom\.VhdConverter\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14486</id>
        <msg>WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|h|00|d|00|C|00|v|00|t|00|C|00|o|00|m|00|.|00|V|00|h|00|d|00|C|00|o|00|n|00|v|00|e|00|r|00|t|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00V\x00h\x00d\x00C\x00o\x00n\x00v\x00e\x00r\x00t\x00e\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00V\x00h\x00d\x00C\x00o\x00n\x00v\x00e\x00r\x00t\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14487</id>
        <msg>WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ce55ac6b-d0fa-4be6-bc90-c318e7383cdd&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*ce55ac6b-d0fa-4be6-bc90-c318e7383cdd\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14488</id>
        <msg>WEB-ACTIVEX VMSwitchCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c|00|e|00|5|00|5|00|a|00|c|00|6|00|b|00|-|00|d|00|0|00|f|00|a|00|-|00|4|00|b|00|e|00|6|00|-|00|b|00|c|00|9|00|0|00|-|00|c|00|3|00|1|00|8|00|e|00|7|00|3|00|8|00|3|00|c|00|d|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*c\x00e\x005\x005\x00a\x00c\x006\x00b\x00-\x00d\x000\x00f\x00a\x00-\x004\x00b\x00e\x006\x00-\x00b\x00c\x009\x000\x00-\x00c\x003\x001\x008\x00e\x007\x003\x008\x003\x00c\x00d\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14489</id>
        <msg>WEB-ACTIVEX VMSwitchCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VMSwitchCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VMSwitchCtl\x22|\x27Vmappsdk\.VMSwitchCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VMSwitchCtl\x22|\x27Vmappsdk\.VMSwitchCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14490</id>
        <msg>WEB-ACTIVEX VMSwitchCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|S|00|w|00|i|00|t|00|c|00|h|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00S\x00w\x00i\x00t\x00c\x00h\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00S\x00w\x00i\x00t\x00c\x00h\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14491</id>
        <msg>WEB-ACTIVEX VMSwitchCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d1084c98-79f2-461d-81b8-7888228e77cc&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*d1084c98-79f2-461d-81b8-7888228e77cc\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14492</id>
        <msg>WEB-ACTIVEX VMWare unspecified 18 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|1|00|0|00|8|00|4|00|c|00|9|00|8|00|-|00|7|00|9|00|f|00|2|00|-|00|4|00|6|00|1|00|d|00|-|00|8|00|1|00|b|00|8|00|-|00|7|00|8|00|8|00|8|00|2|00|2|00|8|00|e|00|7|00|7|00|c|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x001\x000\x008\x004\x00c\x009\x008\x00-\x007\x009\x00f\x002\x00-\x004\x006\x001\x00d\x00-\x008\x001\x00b\x008\x00-\x007\x008\x008\x008\x002\x002\x008\x00e\x007\x007\x00c\x00c\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14493</id>
        <msg>WEB-ACTIVEX VMWare unspecified 18 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d1d1d84a-318e-4bce-9d4b-9d6664c99bd0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*d1d1d84a-318e-4bce-9d4b-9d6664c99bd0\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14494</id>
        <msg>WEB-ACTIVEX VmdbUtil Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|1|00|d|00|1|00|d|00|8|00|4|00|a|00|-|00|3|00|1|00|8|00|e|00|-|00|4|00|b|00|c|00|e|00|-|00|9|00|d|00|4|00|b|00|-|00|9|00|d|00|6|00|6|00|6|00|4|00|c|00|9|00|9|00|b|00|d|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x001\x00d\x001\x00d\x008\x004\x00a\x00-\x003\x001\x008\x00e\x00-\x004\x00b\x00c\x00e\x00-\x009\x00d\x004\x00b\x00-\x009\x00d\x006\x006\x006\x004\x00c\x009\x009\x00b\x00d\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14495</id>
        <msg>WEB-ACTIVEX VmdbUtil Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbUtil&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbUtil\x22|\x27vmdbCOM\.VmdbUtil\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbUtil\x22|\x27vmdbCOM\.VmdbUtil\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14496</id>
        <msg>WEB-ACTIVEX VmdbUtil Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|U|00|t|00|i|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00t\x00i\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00t\x00i\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14497</id>
        <msg>WEB-ACTIVEX VmdbUtil Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d344ef7e-e559-48b4-8b16-07950bf1f191&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*d344ef7e-e559-48b4-8b16-07950bf1f191\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14498</id>
        <msg>WEB-ACTIVEX VMWare unspecified 19 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|3|00|4|00|4|00|e|00|f|00|7|00|e|00|-|00|e|00|5|00|5|00|9|00|-|00|4|00|8|00|b|00|4|00|-|00|8|00|b|00|1|00|6|00|-|00|0|00|7|00|9|00|5|00|0|00|b|00|f|00|1|00|f|00|1|00|9|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x003\x004\x004\x00e\x00f\x007\x00e\x00-\x00e\x005\x005\x009\x00-\x004\x008\x00b\x004\x00-\x008\x00b\x001\x006\x00-\x000\x007\x009\x005\x000\x00b\x00f\x001\x00f\x001\x009\x001\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14499</id>
        <msg>WEB-ACTIVEX VMWare unspecified 19 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D428A135-8494-41DE-A4B5-8BB1B632E8DC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D428A135-8494-41DE-A4B5-8BB1B632E8DC\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14500</id>
        <msg>WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|2|00|8|00|A|00|1|00|3|00|5|00|-|00|8|00|4|00|9|00|4|00|-|00|4|00|1|00|D|00|E|00|-|00|A|00|4|00|B|00|5|00|-|00|8|00|B|00|B|00|1|00|B|00|6|00|3|00|2|00|E|00|8|00|D|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x004\x002\x008\x00A\x001\x003\x005\x00-\x008\x004\x009\x004\x00-\x004\x001\x00D\x00E\x00-\x00A\x004\x00B\x005\x00-\x008\x00B\x00B\x001\x00B\x006\x003\x002\x00E\x008\x00D\x00C\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14501</id>
        <msg>WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VMwareVpcCvt.VpcC&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VMwareVpcCvt\.VpcC\x22|\x27VMwareVpcCvt\.VpcC\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VMwareVpcCvt\.VpcC\x22|\x27VMwareVpcCvt\.VpcC\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14502</id>
        <msg>WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|M|00|w|00|a|00|r|00|e|00|V|00|p|00|c|00|C|00|v|00|t|00|.|00|V|00|p|00|c|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00M\x00w\x00a\x00r\x00e\x00V\x00p\x00c\x00C\x00v\x00t\x00.\x00V\x00p\x00c\x00C\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00M\x00w\x00a\x00r\x00e\x00V\x00p\x00c\x00C\x00v\x00t\x00.\x00V\x00p\x00c\x00C\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14503</id>
        <msg>WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d6e9ab14-5437-4507-8f53-60ded2db142c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*d6e9ab14-5437-4507-8f53-60ded2db142c\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14504</id>
        <msg>WEB-ACTIVEX VmdbCnxUtil Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|6|00|e|00|9|00|a|00|b|00|1|00|4|00|-|00|5|00|4|00|3|00|7|00|-|00|4|00|5|00|0|00|7|00|-|00|8|00|f|00|5|00|3|00|-|00|6|00|0|00|d|00|e|00|d|00|2|00|d|00|b|00|1|00|4|00|2|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x006\x00e\x009\x00a\x00b\x001\x004\x00-\x005\x004\x003\x007\x00-\x004\x005\x000\x007\x00-\x008\x00f\x005\x003\x00-\x006\x000\x00d\x00e\x00d\x002\x00d\x00b\x001\x004\x002\x00c\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14505</id>
        <msg>WEB-ACTIVEX VmdbCnxUtil Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbCnxUtil&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbCnxUtil\x22|\x27vmdbCOM\.VmdbCnxUtil\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbCnxUtil\x22|\x27vmdbCOM\.VmdbCnxUtil\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14506</id>
        <msg>WEB-ACTIVEX VmdbCnxUtil Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|C|00|n|00|x|00|U|00|t|00|i|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00C\x00n\x00x\x00U\x00t\x00i\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00C\x00n\x00x\x00U\x00t\x00i\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14507</id>
        <msg>WEB-ACTIVEX VmdbCnxUtil Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D9902D56-1F2A-47D6-89AA-08F49A40AE8C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D9902D56-1F2A-47D6-89AA-08F49A40AE8C\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14508</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|9|00|0|00|2|00|D|00|5|00|6|00|-|00|1|00|F|00|2|00|A|00|-|00|4|00|7|00|D|00|6|00|-|00|8|00|9|00|A|00|A|00|-|00|0|00|8|00|F|00|4|00|9|00|A|00|4|00|0|00|A|00|E|00|8|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x009\x009\x000\x002\x00D\x005\x006\x00-\x001\x00F\x002\x00A\x00-\x004\x007\x00D\x006\x00-\x008\x009\x00A\x00A\x00-\x000\x008\x00F\x004\x009\x00A\x004\x000\x00A\x00E\x008\x00C\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14509</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmc2vmx.CoVPCDrive&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmc2vmx\.CoVPCDrive\x22|\x27Vmc2vmx\.CoVPCDrive\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmc2vmx\.CoVPCDrive\x22|\x27Vmc2vmx\.CoVPCDrive\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14510</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|c|00|2|00|v|00|m|00|x|00|.|00|C|00|o|00|V|00|P|00|C|00|D|00|r|00|i|00|v|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00D\x00r\x00i\x00v\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00D\x00r\x00i\x00v\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14511</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;da52e304-436f-420e-8cf4-9f785c2e5dc7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*da52e304-436f-420e-8cf4-9f785c2e5dc7\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14512</id>
        <msg>WEB-ACTIVEX VMWare unspecified 20 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|a|00|5|00|2|00|e|00|3|00|0|00|4|00|-|00|4|00|3|00|6|00|f|00|-|00|4|00|2|00|0|00|e|00|-|00|8|00|c|00|f|00|4|00|-|00|9|00|f|00|7|00|8|00|5|00|c|00|2|00|e|00|5|00|d|00|c|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00a\x005\x002\x00e\x003\x000\x004\x00-\x004\x003\x006\x00f\x00-\x004\x002\x000\x00e\x00-\x008\x00c\x00f\x004\x00-\x009\x00f\x007\x008\x005\x00c\x002\x00e\x005\x00d\x00c\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14513</id>
        <msg>WEB-ACTIVEX VMWare unspecified 20 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;dd3705d3-53b0-4d2d-961e-64fc7495b8cd&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*dd3705d3-53b0-4d2d-961e-64fc7495b8cd\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14514</id>
        <msg>WEB-ACTIVEX VMClientVM Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|d|00|3|00|7|00|0|00|5|00|d|00|3|00|-|00|5|00|3|00|b|00|0|00|-|00|4|00|d|00|2|00|d|00|-|00|9|00|6|00|1|00|e|00|-|00|6|00|4|00|f|00|c|00|7|00|4|00|9|00|5|00|b|00|8|00|c|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00d\x003\x007\x000\x005\x00d\x003\x00-\x005\x003\x00b\x000\x00-\x004\x00d\x002\x00d\x00-\x009\x006\x001\x00e\x00-\x006\x004\x00f\x00c\x007\x004\x009\x005\x00b\x008\x00c\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14515</id>
        <msg>WEB-ACTIVEX VMClientVM Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VMClientVM&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VMClientVM\x22|\x27vmdbCOM\.VMClientVM\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VMClientVM\x22|\x27vmdbCOM\.VMClientVM\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14516</id>
        <msg>WEB-ACTIVEX VMClientVM Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|C|00|l|00|i|00|e|00|n|00|t|00|V|00|M|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00V\x00M\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00C\x00l\x00i\x00e\x00n\x00t\x00V\x00M\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14517</id>
        <msg>WEB-ACTIVEX VMClientVM Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;deab0eb8-05d4-49b5-a9c6-31b031d26d99&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*deab0eb8-05d4-49b5-a9c6-31b031d26d99\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14518</id>
        <msg>WEB-ACTIVEX VMWare unspecified 21 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|e|00|a|00|b|00|0|00|e|00|b|00|8|00|-|00|0|00|5|00|d|00|4|00|-|00|4|00|9|00|b|00|5|00|-|00|a|00|9|00|c|00|6|00|-|00|3|00|1|00|b|00|0|00|3|00|1|00|d|00|2|00|6|00|d|00|9|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00e\x00a\x00b\x000\x00e\x00b\x008\x00-\x000\x005\x00d\x004\x00-\x004\x009\x00b\x005\x00-\x00a\x009\x00c\x006\x00-\x003\x001\x00b\x000\x003\x001\x00d\x002\x006\x00d\x009\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14519</id>
        <msg>WEB-ACTIVEX VMWare unspecified 21 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DFC76A6B-4873-458C-AB00-40B1FC028001&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DFC76A6B-4873-458C-AB00-40B1FC028001\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14520</id>
        <msg>WEB-ACTIVEX Elevated.VMXCreator ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|F|00|C|00|7|00|6|00|A|00|6|00|B|00|-|00|4|00|8|00|7|00|3|00|-|00|4|00|5|00|8|00|C|00|-|00|A|00|B|00|0|00|0|00|-|00|4|00|0|00|B|00|1|00|F|00|C|00|0|00|2|00|8|00|0|00|0|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00F\x00C\x007\x006\x00A\x006\x00B\x00-\x004\x008\x007\x003\x00-\x004\x005\x008\x00C\x00-\x00A\x00B\x000\x000\x00-\x004\x000\x00B\x001\x00F\x00C\x000\x002\x008\x000\x000\x001\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14521</id>
        <msg>WEB-ACTIVEX Elevated.VMXCreator ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Elevated.VMXCreator&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Elevated\.VMXCreator\x22|\x27Elevated\.VMXCreator\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Elevated\.VMXCreator\x22|\x27Elevated\.VMXCreator\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14522</id>
        <msg>WEB-ACTIVEX Elevated.VMXCreator ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|l|00|e|00|v|00|a|00|t|00|e|00|d|00|.|00|V|00|M|00|X|00|C|00|r|00|e|00|a|00|t|00|o|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00V\x00M\x00X\x00C\x00r\x00e\x00a\x00t\x00o\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00l\x00e\x00v\x00a\x00t\x00e\x00d\x00.\x00V\x00M\x00X\x00C\x00r\x00e\x00a\x00t\x00o\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14523</id>
        <msg>WEB-ACTIVEX Elevated.VMXCreator ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;dfd8b167-5652-4962-a162-9a227825afaa&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*dfd8b167-5652-4962-a162-9a227825afaa\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14524</id>
        <msg>WEB-ACTIVEX VMWare unspecified 22 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|f|00|d|00|8|00|b|00|1|00|6|00|7|00|-|00|5|00|6|00|5|00|2|00|-|00|4|00|9|00|6|00|2|00|-|00|a|00|1|00|6|00|2|00|-|00|9|00|a|00|2|00|2|00|7|00|8|00|2|00|5|00|a|00|f|00|a|00|a|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00f\x00d\x008\x00b\x001\x006\x007\x00-\x005\x006\x005\x002\x00-\x004\x009\x006\x002\x00-\x00a\x001\x006\x002\x00-\x009\x00a\x002\x002\x007\x008\x002\x005\x00a\x00f\x00a\x00a\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14525</id>
        <msg>WEB-ACTIVEX VMWare unspecified 22 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;dfef4b09-1b0a-4529-9775-ac437d6a93b3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*dfef4b09-1b0a-4529-9775-ac437d6a93b3\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14526</id>
        <msg>WEB-ACTIVEX HotfixWz Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|f|00|e|00|f|00|4|00|b|00|0|00|9|00|-|00|1|00|b|00|0|00|a|00|-|00|4|00|5|00|2|00|9|00|-|00|9|00|7|00|7|00|5|00|-|00|a|00|c|00|4|00|3|00|7|00|d|00|6|00|a|00|9|00|3|00|b|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00f\x00e\x00f\x004\x00b\x000\x009\x00-\x001\x00b\x000\x00a\x00-\x004\x005\x002\x009\x00-\x009\x007\x007\x005\x00-\x00a\x00c\x004\x003\x007\x00d\x006\x00a\x009\x003\x00b\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14527</id>
        <msg>WEB-ACTIVEX HotfixWz Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappcfg.HotfixWz&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappcfg\.HotfixWz\x22|\x27vmappcfg\.HotfixWz\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappcfg\.HotfixWz\x22|\x27vmappcfg\.HotfixWz\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14528</id>
        <msg>WEB-ACTIVEX HotfixWz Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|c|00|f|00|g|00|.|00|H|00|o|00|t|00|f|00|i|00|x|00|W|00|z|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00c\x00f\x00g\x00.\x00H\x00o\x00t\x00f\x00i\x00x\x00W\x00z\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00c\x00f\x00g\x00.\x00H\x00o\x00t\x00f\x00i\x00x\x00W\x00z\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14529</id>
        <msg>WEB-ACTIVEX HotfixWz Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;dff44aec-2370-469d-8a22-df82448bff64&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*dff44aec-2370-469d-8a22-df82448bff64\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14530</id>
        <msg>WEB-ACTIVEX VmdbUpdates Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|f|00|f|00|4|00|4|00|a|00|e|00|c|00|-|00|2|00|3|00|7|00|0|00|-|00|4|00|6|00|9|00|d|00|-|00|8|00|a|00|2|00|2|00|-|00|d|00|f|00|8|00|2|00|4|00|4|00|8|00|b|00|f|00|f|00|6|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*d\x00f\x00f\x004\x004\x00a\x00e\x00c\x00-\x002\x003\x007\x000\x00-\x004\x006\x009\x00d\x00-\x008\x00a\x002\x002\x00-\x00d\x00f\x008\x002\x004\x004\x008\x00b\x00f\x00f\x006\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14531</id>
        <msg>WEB-ACTIVEX VmdbUpdates Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmdbCOM.VmdbUpdates&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmdbCOM\.VmdbUpdates\x22|\x27vmdbCOM\.VmdbUpdates\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmdbCOM\.VmdbUpdates\x22|\x27vmdbCOM\.VmdbUpdates\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14532</id>
        <msg>WEB-ACTIVEX VmdbUpdates Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|U|00|p|00|d|00|a|00|t|00|e|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00p\x00d\x00a\x00t\x00e\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00U\x00p\x00d\x00a\x00t\x00e\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14533</id>
        <msg>WEB-ACTIVEX VmdbUpdates Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e2d82f32-b4b0-4763-80d6-87323173d571&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*e2d82f32-b4b0-4763-80d6-87323173d571\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14534</id>
        <msg>WEB-ACTIVEX VMListCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|2|00|d|00|8|00|2|00|f|00|3|00|2|00|-|00|b|00|4|00|b|00|0|00|-|00|4|00|7|00|6|00|3|00|-|00|8|00|0|00|d|00|6|00|-|00|8|00|7|00|3|00|2|00|3|00|1|00|7|00|3|00|d|00|5|00|7|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x002\x00d\x008\x002\x00f\x003\x002\x00-\x00b\x004\x00b\x000\x00-\x004\x007\x006\x003\x00-\x008\x000\x00d\x006\x00-\x008\x007\x003\x002\x003\x001\x007\x003\x00d\x005\x007\x001\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14535</id>
        <msg>WEB-ACTIVEX VMListCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VMListCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VMListCtl\x22|\x27Vmappsdk\.VMListCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VMListCtl\x22|\x27Vmappsdk\.VMListCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14536</id>
        <msg>WEB-ACTIVEX VMListCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|M|00|L|00|i|00|s|00|t|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00L\x00i\x00s\x00t\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00M\x00L\x00i\x00s\x00t\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14537</id>
        <msg>WEB-ACTIVEX VMListCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e3aa8d10-02e2-4615-b524-908a3b8716e9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*e3aa8d10-02e2-4615-b524-908a3b8716e9\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14538</id>
        <msg>WEB-ACTIVEX CheckedListViewWnd Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|3|00|a|00|a|00|8|00|d|00|1|00|0|00|-|00|0|00|2|00|e|00|2|00|-|00|4|00|6|00|1|00|5|00|-|00|b|00|5|00|2|00|4|00|-|00|9|00|0|00|8|00|a|00|3|00|b|00|8|00|7|00|1|00|6|00|e|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x003\x00a\x00a\x008\x00d\x001\x000\x00-\x000\x002\x00e\x002\x00-\x004\x006\x001\x005\x00-\x00b\x005\x002\x004\x00-\x009\x000\x008\x00a\x003\x00b\x008\x007\x001\x006\x00e\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14539</id>
        <msg>WEB-ACTIVEX CheckedListViewWnd Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.CheckedListViewWnd&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.CheckedListViewWnd\x22|\x27Vmappsdk\.CheckedListViewWnd\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.CheckedListViewWnd\x22|\x27Vmappsdk\.CheckedListViewWnd\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14540</id>
        <msg>WEB-ACTIVEX CheckedListViewWnd Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|C|00|h|00|e|00|c|00|k|00|e|00|d|00|L|00|i|00|s|00|t|00|V|00|i|00|e|00|w|00|W|00|n|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00h\x00e\x00c\x00k\x00e\x00d\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x00W\x00n\x00d\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00h\x00e\x00c\x00k\x00e\x00d\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x00W\x00n\x00d\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14541</id>
        <msg>WEB-ACTIVEX CheckedListViewWnd Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e54b2aa7-52ab-431c-a1fa-3f807ee3578d&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*e54b2aa7-52ab-431c-a1fa-3f807ee3578d\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14542</id>
        <msg>WEB-ACTIVEX VMWare unspecified 23 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|5|00|4|00|b|00|2|00|a|00|a|00|7|00|-|00|5|00|2|00|a|00|b|00|-|00|4|00|3|00|1|00|c|00|-|00|a|00|1|00|f|00|a|00|-|00|3|00|f|00|8|00|0|00|7|00|e|00|e|00|3|00|5|00|7|00|8|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x005\x004\x00b\x002\x00a\x00a\x007\x00-\x005\x002\x00a\x00b\x00-\x004\x003\x001\x00c\x00-\x00a\x001\x00f\x00a\x00-\x003\x00f\x008\x000\x007\x00e\x00e\x003\x005\x007\x008\x00d\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14543</id>
        <msg>WEB-ACTIVEX VMWare unspecified 23 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e669547d-ae52-459f-9c07-cc5f17b4b16f&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*e669547d-ae52-459f-9c07-cc5f17b4b16f\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14544</id>
        <msg>WEB-ACTIVEX VmdbTreeCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|6|00|6|00|9|00|5|00|4|00|7|00|d|00|-|00|a|00|e|00|5|00|2|00|-|00|4|00|5|00|9|00|f|00|-|00|9|00|c|00|0|00|7|00|-|00|c|00|c|00|5|00|f|00|1|00|7|00|b|00|4|00|b|00|1|00|6|00|f|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x006\x006\x009\x005\x004\x007\x00d\x00-\x00a\x00e\x005\x002\x00-\x004\x005\x009\x00f\x00-\x009\x00c\x000\x007\x00-\x00c\x00c\x005\x00f\x001\x007\x00b\x004\x00b\x001\x006\x00f\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14545</id>
        <msg>WEB-ACTIVEX VmdbTreeCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.vmdbTreeCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.vmdbTreeCtl\x22|\x27vmappsdk\.vmdbTreeCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.vmdbTreeCtl\x22|\x27vmappsdk\.vmdbTreeCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14546</id>
        <msg>WEB-ACTIVEX VmdbTreeCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|v|00|m|00|d|00|b|00|T|00|r|00|e|00|e|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00v\x00m\x00d\x00b\x00T\x00r\x00e\x00e\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00v\x00m\x00d\x00b\x00T\x00r\x00e\x00e\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14547</id>
        <msg>WEB-ACTIVEX VmdbTreeCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;eb80211b-ef44-463c-adab-b75ccd68c163&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*eb80211b-ef44-463c-adab-b75ccd68c163\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14548</id>
        <msg>WEB-ACTIVEX Nwz Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|b|00|8|00|0|00|2|00|1|00|1|00|b|00|-|00|e|00|f|00|4|00|4|00|-|00|4|00|6|00|3|00|c|00|-|00|a|00|d|00|a|00|b|00|-|00|b|00|7|00|5|00|c|00|c|00|d|00|6|00|8|00|c|00|1|00|6|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x00b\x008\x000\x002\x001\x001\x00b\x00-\x00e\x00f\x004\x004\x00-\x004\x006\x003\x00c\x00-\x00a\x00d\x00a\x00b\x00-\x00b\x007\x005\x00c\x00c\x00d\x006\x008\x00c\x001\x006\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14549</id>
        <msg>WEB-ACTIVEX Nwz Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmhwcfg.Nwz&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmhwcfg\.Nwz\x22|\x27vmhwcfg\.Nwz\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmhwcfg\.Nwz\x22|\x27vmhwcfg\.Nwz\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14550</id>
        <msg>WEB-ACTIVEX Nwz Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|h|00|w|00|c|00|f|00|g|00|.|00|N|00|w|00|z|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00h\x00w\x00c\x00f\x00g\x00.\x00N\x00w\x00z\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00h\x00w\x00c\x00f\x00g\x00.\x00N\x00w\x00z\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14551</id>
        <msg>WEB-ACTIVEX Nwz Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EBA250D3-CEE2-4185-8563-1080F50BB733&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EBA250D3-CEE2-4185-8563-1080F50BB733\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14552</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|B|00|A|00|2|00|5|00|0|00|D|00|3|00|-|00|C|00|E|00|E|00|2|00|-|00|4|00|1|00|8|00|5|00|-|00|8|00|5|00|6|00|3|00|-|00|1|00|0|00|8|00|0|00|F|00|5|00|0|00|B|00|B|00|7|00|3|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x00B\x00A\x002\x005\x000\x00D\x003\x00-\x00C\x00E\x00E\x002\x00-\x004\x001\x008\x005\x00-\x008\x005\x006\x003\x00-\x001\x000\x008\x000\x00F\x005\x000\x00B\x00B\x007\x003\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14553</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmc2vmx.CoVPCDrives&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmc2vmx\.CoVPCDrives\x22|\x27Vmc2vmx\.CoVPCDrives\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmc2vmx\.CoVPCDrives\x22|\x27Vmc2vmx\.CoVPCDrives\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14554</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|c|00|2|00|v|00|m|00|x|00|.|00|C|00|o|00|V|00|P|00|C|00|D|00|r|00|i|00|v|00|e|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00D\x00r\x00i\x00v\x00e\x00s\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00c\x002\x00v\x00m\x00x\x00.\x00C\x00o\x00V\x00P\x00C\x00D\x00r\x00i\x00v\x00e\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14555</id>
        <msg>WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ec24c86e-34dd-45f3-928d-ecb7c2b3afb4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*ec24c86e-34dd-45f3-928d-ecb7c2b3afb4\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14556</id>
        <msg>WEB-ACTIVEX MksCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|c|00|2|00|4|00|c|00|8|00|6|00|e|00|-|00|3|00|4|00|d|00|d|00|-|00|4|00|5|00|f|00|3|00|-|00|9|00|2|00|8|00|d|00|-|00|e|00|c|00|b|00|7|00|c|00|2|00|b|00|3|00|a|00|f|00|b|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x00c\x002\x004\x00c\x008\x006\x00e\x00-\x003\x004\x00d\x00d\x00-\x004\x005\x00f\x003\x00-\x009\x002\x008\x00d\x00-\x00e\x00c\x00b\x007\x00c\x002\x00b\x003\x00a\x00f\x00b\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14557</id>
        <msg>WEB-ACTIVEX MksCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vmappsdk.MksCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vmappsdk\.MksCtl\x22|\x27vmappsdk\.MksCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vmappsdk\.MksCtl\x22|\x27vmappsdk\.MksCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14558</id>
        <msg>WEB-ACTIVEX MksCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|M|00|k|00|s|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00M\x00k\x00s\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)v\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00M\x00k\x00s\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14559</id>
        <msg>WEB-ACTIVEX MksCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ec891881-be63-45cf-97c9-34615aa209c1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*ec891881-be63-45cf-97c9-34615aa209c1\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14560</id>
        <msg>WEB-ACTIVEX VmappPropPath Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|c|00|8|00|9|00|1|00|8|00|8|00|1|00|-|00|b|00|e|00|6|00|3|00|-|00|4|00|5|00|c|00|f|00|-|00|9|00|7|00|c|00|9|00|-|00|3|00|4|00|6|00|1|00|5|00|a|00|a|00|2|00|0|00|9|00|c|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x00c\x008\x009\x001\x008\x008\x001\x00-\x00b\x00e\x006\x003\x00-\x004\x005\x00c\x00f\x00-\x009\x007\x00c\x009\x00-\x003\x004\x006\x001\x005\x00a\x00a\x002\x000\x009\x00c\x001\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14561</id>
        <msg>WEB-ACTIVEX VmappPropPath Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.VmappPropPath&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.VmappPropPath\x22|\x27Vmappsdk\.VmappPropPath\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.VmappPropPath\x22|\x27Vmappsdk\.VmappPropPath\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14562</id>
        <msg>WEB-ACTIVEX VmappPropPath Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|V|00|m|00|a|00|p|00|p|00|P|00|r|00|o|00|p|00|P|00|a|00|t|00|h|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00P\x00a\x00t\x00h\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00V\x00m\x00a\x00p\x00p\x00P\x00r\x00o\x00p\x00P\x00a\x00t\x00h\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14563</id>
        <msg>WEB-ACTIVEX VmappPropPath Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;edaf3a1f-942e-4062-89b0-5276060dff93&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*edaf3a1f-942e-4062-89b0-5276060dff93\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14564</id>
        <msg>WEB-ACTIVEX VMWare unspecified 24 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|d|00|a|00|f|00|3|00|a|00|1|00|f|00|-|00|9|00|4|00|2|00|e|00|-|00|4|00|0|00|6|00|2|00|-|00|8|00|9|00|b|00|0|00|-|00|5|00|2|00|7|00|6|00|0|00|6|00|0|00|d|00|f|00|f|00|9|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x00d\x00a\x00f\x003\x00a\x001\x00f\x00-\x009\x004\x002\x00e\x00-\x004\x000\x006\x002\x00-\x008\x009\x00b\x000\x00-\x005\x002\x007\x006\x000\x006\x000\x00d\x00f\x00f\x009\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14565</id>
        <msg>WEB-ACTIVEX VMWare unspecified 24 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;edc2cfe2-97c9-41c3-80e9-9bb55b5a1ade&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*edc2cfe2-97c9-41c3-80e9-9bb55b5a1ade\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14566</id>
        <msg>WEB-ACTIVEX PolicyCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|d|00|c|00|2|00|c|00|f|00|e|00|2|00|-|00|9|00|7|00|c|00|9|00|-|00|4|00|1|00|c|00|3|00|-|00|8|00|0|00|e|00|9|00|-|00|9|00|b|00|b|00|5|00|5|00|b|00|5|00|a|00|1|00|a|00|d|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*e\x00d\x00c\x002\x00c\x00f\x00e\x002\x00-\x009\x007\x00c\x009\x00-\x004\x001\x00c\x003\x00-\x008\x000\x00e\x009\x00-\x009\x00b\x00b\x005\x005\x00b\x005\x00a\x001\x00a\x00d\x00e\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14567</id>
        <msg>WEB-ACTIVEX PolicyCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.PolicyCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.PolicyCtl\x22|\x27Vmappsdk\.PolicyCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.PolicyCtl\x22|\x27Vmappsdk\.PolicyCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14568</id>
        <msg>WEB-ACTIVEX PolicyCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|P|00|o|00|l|00|i|00|c|00|y|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00P\x00o\x00l\x00i\x00c\x00y\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00P\x00o\x00l\x00i\x00c\x00y\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14569</id>
        <msg>WEB-ACTIVEX PolicyCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f1bee71f-bf84-4a3c-a967-f1c9d21c6100&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*f1bee71f-bf84-4a3c-a967-f1c9d21c6100\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14570</id>
        <msg>WEB-ACTIVEX VmdbParseError Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|1|00|b|00|e|00|e|00|7|00|1|00|f|00|-|00|b|00|f|00|8|00|4|00|-|00|4|00|a|00|3|00|c|00|-|00|a|00|9|00|6|00|7|00|-|00|f|00|1|00|c|00|9|00|d|00|2|00|1|00|c|00|6|00|1|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x001\x00b\x00e\x00e\x007\x001\x00f\x00-\x00b\x00f\x008\x004\x00-\x004\x00a\x003\x00c\x00-\x00a\x009\x006\x007\x00-\x00f\x001\x00c\x009\x00d\x002\x001\x00c\x006\x001\x000\x000\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14571</id>
        <msg>WEB-ACTIVEX VmdbParseError Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VmdbCOM.VmdbParseError&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VmdbCOM\.VmdbParseError\x22|\x27VmdbCOM\.VmdbParseError\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VmdbCOM\.VmdbParseError\x22|\x27VmdbCOM\.VmdbParseError\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14572</id>
        <msg>WEB-ACTIVEX VmdbParseError Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|m|00|d|00|b|00|P|00|a|00|r|00|s|00|e|00|E|00|r|00|r|00|o|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00P\x00a\x00r\x00s\x00e\x00E\x00r\x00r\x00o\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00m\x00d\x00b\x00P\x00a\x00r\x00s\x00e\x00E\x00r\x00r\x00o\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14573</id>
        <msg>WEB-ACTIVEX VmdbParseError Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f665fa34-efa7-4dff-bee6-ad27fa396c2b&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*f665fa34-efa7-4dff-bee6-ad27fa396c2b\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14574</id>
        <msg>WEB-ACTIVEX NavigationCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|6|00|6|00|5|00|f|00|a|00|3|00|4|00|-|00|e|00|f|00|a|00|7|00|-|00|4|00|d|00|f|00|f|00|-|00|b|00|e|00|e|00|6|00|-|00|a|00|d|00|2|00|7|00|f|00|a|00|3|00|9|00|6|00|c|00|2|00|b|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x006\x006\x005\x00f\x00a\x003\x004\x00-\x00e\x00f\x00a\x007\x00-\x004\x00d\x00f\x00f\x00-\x00b\x00e\x00e\x006\x00-\x00a\x00d\x002\x007\x00f\x00a\x003\x009\x006\x00c\x002\x00b\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14575</id>
        <msg>WEB-ACTIVEX NavigationCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.NavigationCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.NavigationCtl\x22|\x27Vmappsdk\.NavigationCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.NavigationCtl\x22|\x27Vmappsdk\.NavigationCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14576</id>
        <msg>WEB-ACTIVEX NavigationCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|N|00|a|00|v|00|i|00|g|00|a|00|t|00|i|00|o|00|n|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00N\x00a\x00v\x00i\x00g\x00a\x00t\x00i\x00o\x00n\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00N\x00a\x00v\x00i\x00g\x00a\x00t\x00i\x00o\x00n\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14577</id>
        <msg>WEB-ACTIVEX NavigationCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f76e4799-379b-4362-bcc4-68b753d10744&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*f76e4799-379b-4362-bcc4-68b753d10744\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14578</id>
        <msg>WEB-ACTIVEX VMList Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|7|00|6|00|e|00|4|00|7|00|9|00|9|00|-|00|3|00|7|00|9|00|b|00|-|00|4|00|3|00|6|00|2|00|-|00|b|00|c|00|c|00|4|00|-|00|6|00|8|00|b|00|7|00|5|00|3|00|d|00|1|00|0|00|7|00|4|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x007\x006\x00e\x004\x007\x009\x009\x00-\x003\x007\x009\x00b\x00-\x004\x003\x006\x002\x00-\x00b\x00c\x00c\x004\x00-\x006\x008\x00b\x007\x005\x003\x00d\x001\x000\x007\x004\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14579</id>
        <msg>WEB-ACTIVEX VMList Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VmdbCOM.VMList&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VmdbCOM\.VMList\x22|\x27VmdbCOM\.VMList\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VmdbCOM\.VMList\x22|\x27VmdbCOM\.VMList\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14580</id>
        <msg>WEB-ACTIVEX VMList Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|d|00|b|00|C|00|O|00|M|00|.|00|V|00|M|00|L|00|i|00|s|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00L\x00i\x00s\x00t\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00d\x00b\x00C\x00O\x00M\x00.\x00V\x00M\x00L\x00i\x00s\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14581</id>
        <msg>WEB-ACTIVEX VMList Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;fcac0ad0-ff50-4dba-8c79-f17102e15c02&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*fcac0ad0-ff50-4dba-8c79-f17102e15c02\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14582</id>
        <msg>WEB-ACTIVEX VMWare unspecified 25 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|c|00|a|00|c|00|0|00|a|00|d|00|0|00|-|00|f|00|f|00|5|00|0|00|-|00|4|00|d|00|b|00|a|00|-|00|8|00|c|00|7|00|9|00|-|00|f|00|1|00|7|00|1|00|0|00|2|00|e|00|1|00|5|00|c|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x00c\x00a\x00c\x000\x00a\x00d\x000\x00-\x00f\x00f\x005\x000\x00-\x004\x00d\x00b\x00a\x00-\x008\x00c\x007\x009\x00-\x00f\x001\x007\x001\x000\x002\x00e\x001\x005\x00c\x000\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14583</id>
        <msg>WEB-ACTIVEX VMWare unspecified 25 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;fd1e7da6-fbda-49aa-9488-4a1fc2ec7826&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*fd1e7da6-fbda-49aa-9488-4a1fc2ec7826\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14584</id>
        <msg>WEB-ACTIVEX VMWare unspecified 26 ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|d|00|1|00|e|00|7|00|d|00|a|00|6|00|-|00|f|00|b|00|d|00|a|00|-|00|4|00|9|00|a|00|a|00|-|00|9|00|4|00|8|00|8|00|-|00|4|00|a|00|1|00|f|00|c|00|2|00|e|00|c|00|7|00|8|00|2|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x00d\x001\x00e\x007\x00d\x00a\x006\x00-\x00f\x00b\x00d\x00a\x00-\x004\x009\x00a\x00a\x00-\x009\x004\x008\x008\x00-\x004\x00a\x001\x00f\x00c\x002\x00e\x00c\x007\x008\x002\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14585</id>
        <msg>WEB-ACTIVEX VMWare unspecified 26 ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;fd99f74c-9d06-415e-8c60-a249d16f1d77&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*fd99f74c-9d06-415e-8c60-a249d16f1d77\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14586</id>
        <msg>WEB-ACTIVEX CurrentVMCtl Class ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|d|00|9|00|9|00|f|00|7|00|4|00|c|00|-|00|9|00|d|00|0|00|6|00|-|00|4|00|1|00|5|00|e|00|-|00|8|00|c|00|6|00|0|00|-|00|a|00|2|00|4|00|9|00|d|00|1|00|6|00|f|00|1|00|d|00|7|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*f\x00d\x009\x009\x00f\x007\x004\x00c\x00-\x009\x00d\x000\x006\x00-\x004\x001\x005\x00e\x00-\x008\x00c\x006\x000\x00-\x00a\x002\x004\x009\x00d\x001\x006\x00f\x001\x00d\x007\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14587</id>
        <msg>WEB-ACTIVEX CurrentVMCtl Class ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Vmappsdk.CurrentVMCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Vmappsdk\.CurrentVMCtl\x22|\x27Vmappsdk\.CurrentVMCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Vmappsdk\.CurrentVMCtl\x22|\x27Vmappsdk\.CurrentVMCtl\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14588</id>
        <msg>WEB-ACTIVEX CurrentVMCtl Class ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|a|00|p|00|p|00|s|00|d|00|k|00|.|00|C|00|u|00|r|00|r|00|e|00|n|00|t|00|V|00|M|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00u\x00r\x00r\x00e\x00n\x00t\x00V\x00M\x00C\x00t\x00l\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00a\x00p\x00p\x00s\x00d\x00k\x00.\x00C\x00u\x00r\x00r\x00e\x00n\x00t\x00V\x00M\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14589</id>
        <msg>WEB-ACTIVEX CurrentVMCtl Class ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FDE6485C-53E6-4E1F-BBFD-12D92384ECD2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FDE6485C-53E6-4E1F-BBFD-12D92384ECD2\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14590</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX clsid access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|E|00|6|00|4|00|8|00|5|00|C|00|-|00|5|00|3|00|E|00|6|00|-|00|4|00|E|00|1|00|F|00|-|00|B|00|B|00|F|00|D|00|-|00|1|00|2|00|D|00|9|00|2|00|3|00|8|00|4|00|E|00|C|00|D|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00D\x00E\x006\x004\x008\x005\x00C\x00-\x005\x003\x00E\x006\x00-\x004\x00E\x001\x00F\x00-\x00B\x00B\x00F\x00D\x00-\x001\x002\x00D\x009\x002\x003\x008\x004\x00E\x00C\x00D\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14591</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX clsid unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VhdCvtCom.DiskLibHelper&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VhdCvtCom\.DiskLibHelper\x22|\x27VhdCvtCom\.DiskLibHelper\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VhdCvtCom\.DiskLibHelper\x22|\x27VhdCvtCom\.DiskLibHelper\x27)\s*\)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14592</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX function call access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3696</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|h|00|d|00|C|00|v|00|t|00|C|00|o|00|m|00|.|00|D|00|i|00|s|00|k|00|L|00|i|00|b|00|H|00|e|00|l|00|p|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00D\x00i\x00s\x00k\x00L\x00i\x00b\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00h\x00d\x00C\x00v\x00t\x00C\x00o\x00m\x00.\x00D\x00i\x00s\x00k\x00L\x00i\x00b\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14593</id>
        <msg>WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX function call unicode access</msg>
        <url>www.vmware.com/security/advisories/VMSA-2008-0014.html</url>
      </rule>
      <rule>
        <bugtraq>31096</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2BCEAECE-6121-4E78-816C-8CD3121361B0&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2BCEAECE-6121-4E78-816C-8CD3121361B0\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ExecutePreferredApplication)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2BCEAECE-6121-4E78-816C-8CD3121361B0\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ExecutePreferredApplication))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14594</id>
        <msg>WEB-ACTIVEX Peachtree Accounting 2004 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31096</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|B|00|C|00|E|00|A|00|E|00|C|00|E|00|-|00|6|00|1|00|2|00|1|00|-|00|4|00|E|00|7|00|8|00|-|00|8|00|1|00|6|00|C|00|-|00|8|00|C|00|D|00|3|00|1|00|2|00|1|00|3|00|6|00|1|00|B|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00B\x00C\x00E\x00A\x00E\x00C\x00E\x00-\x006\x001\x002\x001\x00-\x004\x00E\x007\x008\x00-\x008\x001\x006\x00C\x00-\x008\x00C\x00D\x003\x001\x002\x001\x003\x006\x001\x00B\x000\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14595</id>
        <msg>WEB-ACTIVEX Peachtree Accounting 2004 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31200</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C945E31A-102E-4A0D-8854-D599D7AED5FA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C945E31A-102E-4A0D-8854-D599D7AED5FA\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Archive)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C945E31A-102E-4A0D-8854-D599D7AED5FA\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Archive))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14596</id>
        <msg>WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31200</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|9|00|4|00|5|00|E|00|3|00|1|00|A|00|-|00|1|00|0|00|2|00|E|00|-|00|4|00|A|00|0|00|D|00|-|00|8|00|8|00|5|00|4|00|-|00|D|00|5|00|9|00|9|00|D|00|7|00|A|00|E|00|D|00|5|00|F|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x009\x004\x005\x00E\x003\x001\x00A\x00-\x001\x000\x002\x00E\x00-\x004\x00A\x000\x00D\x00-\x008\x008\x005\x004\x00-\x00D\x005\x009\x009\x00D\x007\x00A\x00E\x00D\x005\x00F\x00A\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14597</id>
        <msg>WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31200</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VSFlexGrid8.VSFlexGridADO&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VSFlexGrid8\.VSFlexGridADO\x22|\x27VSFlexGrid8\.VSFlexGridADO\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Archive\s*|.*(?P=v)\s*\.\s*Archive\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VSFlexGrid8\.VSFlexGridADO\x22|\x27VSFlexGrid8\.VSFlexGridADO\x27)\s*\)(\s*\.\s*Archive\s*|.*(?P=n)\s*\.\s*Archive\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14598</id>
        <msg>WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31200</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|S|00|F|00|l|00|e|00|x|00|G|00|r|00|i|00|d|00|8|00|.|00|V|00|S|00|F|00|l|00|e|00|x|00|G|00|r|00|i|00|d|00|A|00|D|00|O|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x008\x00.\x00V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00A\x00D\x00O\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x008\x00.\x00V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00A\x00D\x00O\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14599</id>
        <msg>WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31227</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8569D715-FF88-44BA-8D1D-AD3E59543DDE&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8569D715-FF88-44BA-8D1D-AD3E59543DDE\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Pages.Save|PrintReport|Canvas.Save)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8569D715-FF88-44BA-8D1D-AD3E59543DDE\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Pages.Save|PrintReport|Canvas.Save))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14603</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31227</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|5|00|6|00|9|00|D|00|7|00|1|00|5|00|-|00|F|00|F|00|8|00|8|00|-|00|4|00|4|00|B|00|A|00|-|00|8|00|D|00|1|00|D|00|-|00|A|00|D|00|3|00|E|00|5|00|9|00|5|00|4|00|3|00|D|00|D|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x005\x006\x009\x00D\x007\x001\x005\x00-\x00F\x00F\x008\x008\x00-\x004\x004\x00B\x00A\x00-\x008\x00D\x001\x00D\x00-\x00A\x00D\x003\x00E\x005\x009\x005\x004\x003\x00D\x00D\x00E\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14604</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31227</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DDActiveReportsViewer2.ARViewer2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DDActiveReportsViewer2\.ARViewer2\x22|\x27DDActiveReportsViewer2\.ARViewer2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Pages.Save|PrintReport|Canvas.Save)\s*|.*(?P=v)\s*\.\s*(Pages.Save|PrintReport|Canvas.Save)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DDActiveReportsViewer2\.ARViewer2\x22|\x27DDActiveReportsViewer2\.ARViewer2\x27)\s*\)(\s*\.\s*(Pages.Save|PrintReport|Canvas.Save)\s*|.*(?P=n)\s*\.\s*(Pages.Save|PrintReport|Canvas.Save)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14605</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31227</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|D|00|A|00|c|00|t|00|i|00|v|00|e|00|R|00|e|00|p|00|o|00|r|00|t|00|s|00|V|00|i|00|e|00|w|00|e|00|r|00|2|00|.|00|A|00|R|00|V|00|i|00|e|00|w|00|e|00|r|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00D\x00A\x00c\x00t\x00i\x00v\x00e\x00R\x00e\x00p\x00o\x00r\x00t\x00s\x00V\x00i\x00e\x00w\x00e\x00r\x002\x00.\x00A\x00R\x00V\x00i\x00e\x00w\x00e\x00r\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00D\x00A\x00c\x00t\x00i\x00v\x00e\x00R\x00e\x00p\x00o\x00r\x00t\x00s\x00V\x00i\x00e\x00w\x00e\x00r\x002\x00.\x00A\x00R\x00V\x00i\x00e\x00w\x00e\x00r\x002\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14606</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23635</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2139</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server,established; dsize:&gt;61; content:&quot;|00 06 09|~&quot;; depth:4; offset:16; pcre:&quot;/^.{4}\x00\x00\x00(\xF0|\xEF|\xF5).{36}/smiR&quot;; pcre:!&quot;/^_[^_]{1,64}_[^_]{1,64}_/smiR&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>14607</id>
        <msg>EXPLOIT CA Brightstor SUN RPC malformed string buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3892</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;38DB77F9-058D-4955-98AA-4A9F3B6A5B06&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*38DB77F9-058D-4955-98AA-4A9F3B6A5B06\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GuestInfo)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|\x26\x23039\x3b|)\s*clsid\s*\x3a\s*{?\s*38DB77F9-058D-4955-98AA-4A9F3B6A5B06\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|\x26\x23039\x3b|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GuestInfo))\s*\(/Osi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14611</id>
        <msg>WEB-ACTIVEX VMWare VMCtl Class ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3892</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|8|00|D|00|B|00|7|00|7|00|F|00|9|00|-|00|0|00|5|00|8|00|D|00|-|00|4|00|9|00|5|00|5|00|-|00|9|00|8|00|A|00|A|00|-|00|4|00|A|00|9|00|F|00|3|00|B|00|6|00|A|00|5|00|B|00|0|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x008\x00D\x00B\x007\x007\x00F\x009\x00-\x000\x005\x008\x00D\x00-\x004\x009\x005\x005\x00-\x009\x008\x00A\x00A\x00-\x004\x00A\x009\x00F\x003\x00B\x006\x00A\x005\x00B\x000\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14612</id>
        <msg>WEB-ACTIVEX VMWare VMCtl Class ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3892</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VmCOM.VmCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VmCOM\.VmCtl\x22|\x27VmCOM\.VmCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GuestInfo\s*|.*(?P=v)\s*\.\s*GuestInfo\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VmCOM\.VmCtl\x22|\x27VmCOM\.VmCtl\x27)\s*\)(\s*\.\s*GuestInfo\s*|.*(?P=n)\s*\.\s*GuestInfo\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14613</id>
        <msg>WEB-ACTIVEX VMWare VMCtl Class ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>30934</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3892</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|m|00|C|00|O|00|M|00|.|00|V|00|m|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00m\x00C\x00O\x00M\x00.\x00V\x00m\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00m\x00C\x00O\x00M\x00.\x00V\x00m\x00C\x00t\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14614</id>
        <msg>WEB-ACTIVEX VMWare VMCtl Class ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;67A5F8DC-1A4B-4D66-9F24-A704AD929EEE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67A5F8DC-1A4B-4D66-9F24-A704AD929EEE\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14631</id>
        <msg>WEB-ACTIVEX SystemRequirementsLab ActiveX clsid access</msg>
        <url>www.systemrequirementslab.com/bulletins/security_bulletin_1.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|A|00|5|00|F|00|8|00|D|00|C|00|-|00|1|00|A|00|4|00|B|00|-|00|4|00|D|00|6|00|6|00|-|00|9|00|F|00|2|00|4|00|-|00|A|00|7|00|0|00|4|00|A|00|D|00|9|00|2|00|9|00|E|00|E|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x007\x00A\x005\x00F\x008\x00D\x00C\x00-\x001\x00A\x004\x00B\x00-\x004\x00D\x006\x006\x00-\x009\x00F\x002\x004\x00-\x00A\x007\x000\x004\x00A\x00D\x009\x002\x009\x00E\x00E\x00E\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14632</id>
        <msg>WEB-ACTIVEX SystemRequirementsLab ActiveX clsid unicode access</msg>
        <url>www.systemrequirementslab.com/bulletins/security_bulletin_1.html</url>
      </rule>
      <rule>
        <bugtraq>29279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E48BB416-C578-4A62-84C9-5E3389ABE5FC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E48BB416-C578-4A62-84C9-5E3389ABE5FC\s*}?\s*(?P=q3)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14633</id>
        <msg>WEB-ACTIVEX PhotoStockPlus ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/956391</url>
      </rule>
      <rule>
        <bugtraq>29279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|4|00|8|00|B|00|B|00|4|00|1|00|6|00|-|00|C|00|5|00|7|00|8|00|-|00|4|00|A|00|6|00|2|00|-|00|8|00|4|00|C|00|9|00|-|00|5|00|E|00|3|00|3|00|8|00|9|00|A|00|B|00|E|00|5|00|F|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q4&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x004\x008\x00B\x00B\x004\x001\x006\x00-\x00C\x005\x007\x008\x00-\x004\x00A\x006\x002\x00-\x008\x004\x00C\x009\x00-\x005\x00E\x003\x003\x008\x009\x00A\x00B\x00E\x005\x00F\x00C\x00(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14634</id>
        <msg>WEB-ACTIVEX PhotoStockPlus ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/956391</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FA91DF8D-53AB-455D-AB20-F2F023E498D3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FA91DF8D-53AB-455D-AB20-F2F023E498D3\s*}?\s*(?P=q5)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14635</id>
        <msg>WEB-ACTIVEX Microsoft RSClientPrint ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|A|00|9|00|1|00|D|00|F|00|8|00|D|00|-|00|5|00|3|00|A|00|B|00|-|00|4|00|5|00|5|00|D|00|-|00|A|00|B|00|2|00|0|00|-|00|F|00|2|00|F|00|0|00|2|00|3|00|E|00|4|00|9|00|8|00|D|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00A\x009\x001\x00D\x00F\x008\x00D\x00-\x005\x003\x00A\x00B\x00-\x004\x005\x005\x00D\x00-\x00A\x00B\x002\x000\x00-\x00F\x002\x00F\x000\x002\x003\x00E\x004\x009\x008\x00D\x003\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14636</id>
        <msg>WEB-ACTIVEX Microsoft RSClientPrint ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>31632</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;507813C3-0B26-47AD-A8C0-D483C7A21FA7&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*507813C3-0B26-47AD-A8C0-D483C7A21FA7\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddString|Post)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*507813C3-0B26-47AD-A8C0-D483C7A21FA7\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddString|Post))\s*\(/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14637</id>
        <msg>WEB-ACTIVEX Microsoft PicturePusher ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31632</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|0|00|7|00|8|00|1|00|3|00|C|00|3|00|-|00|0|00|B|00|2|00|6|00|-|00|4|00|7|00|A|00|D|00|-|00|A|00|8|00|C|00|0|00|-|00|D|00|4|00|8|00|3|00|C|00|7|00|A|00|2|00|1|00|F|00|A|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x000\x007\x008\x001\x003\x00C\x003\x00-\x000\x00B\x002\x006\x00-\x004\x007\x00A\x00D\x00-\x00A\x008\x00C\x000\x00-\x00D\x004\x008\x003\x00C\x007\x00A\x002\x001\x00F\x00A\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14638</id>
        <msg>WEB-ACTIVEX Microsoft PicturePusher ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31632</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Microsoft.DIG.PicturePusherControl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Microsoft\.DIG\.PicturePusherControl\x22|\x27Microsoft\.DIG\.PicturePusherControl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(AddString|Post)\s*|.*(?P=v)\s*\.\s*(AddString|Post)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Microsoft\.DIG\.PicturePusherControl\x22|\x27Microsoft\.DIG\.PicturePusherControl\x27)\s*\)(\s*\.\s*(AddString|Post)\s*|.*(?P=n)\s*\.\s*(AddString|Post)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14639</id>
        <msg>WEB-ACTIVEX Microsoft PicturePusher ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31632</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|i|00|c|00|r|00|o|00|s|00|o|00|f|00|t|00|.|00|D|00|I|00|G|00|.|00|P|00|i|00|c|00|t|00|u|00|r|00|e|00|P|00|u|00|s|00|h|00|e|00|r|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00D\x00I\x00G\x00.\x00P\x00i\x00c\x00t\x00u\x00r\x00e\x00P\x00u\x00s\x00h\x00e\x00r\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00D\x00I\x00G\x00.\x00P\x00i\x00c\x00t\x00u\x00r\x00e\x00P\x00u\x00s\x00h\x00e\x00r\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14640</id>
        <msg>WEB-ACTIVEX Microsoft PicturePusher ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14647, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14647</id>
        <msg>NETBIOS-DG SMB Search Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14648, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14648</id>
        <msg>NETBIOS-DG SMB Search unicode Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14649, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14649</id>
        <msg>NETBIOS SMB Search Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14650, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14650</id>
        <msg>NETBIOS SMB Search unicode Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14651, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14651</id>
        <msg>NETBIOS-DG SMB Search andx Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14652, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14652</id>
        <msg>NETBIOS-DG SMB Search unicode andx Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14653, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14653</id>
        <msg>NETBIOS SMB Search andx Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4038</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14654, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14654</id>
        <msg>NETBIOS SMB Search unicode andx Search filename size integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-063.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:set,dce.spoolss.4.call; flowbits:noalert; metadata: engine shared, soid 3|14661, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14661</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss EnumJobs attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14709, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14709</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX unicode little endian attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14711, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14711</id>
        <msg>NETBIOS SMB spoolss EnumJobs response little endian attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14712, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14712</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX little endian attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14713, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14713</id>
        <msg>NETBIOS SMB spoolss EnumJobs response attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14714, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14714</id>
        <msg>NETBIOS SMB spoolss EnumJobs response unicode attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14715, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14715</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14716, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14716</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX unicode attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14717, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14717</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX unicode little endian andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14718, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14718</id>
        <msg>NETBIOS SMB spoolss EnumJobs response unicode little endian andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14719, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14719</id>
        <msg>NETBIOS SMB spoolss EnumJobs response little endian andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14720, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14720</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX little endian andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14721, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14721</id>
        <msg>NETBIOS SMB spoolss EnumJobs response andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14722, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14722</id>
        <msg>NETBIOS SMB spoolss EnumJobs response unicode andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14723, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14723</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-1446</cve>
        <filter1>tcp $HOME_NET [139,445] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:isset,dce.spoolss.4.call; metadata: engine shared, soid 3|14724, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14724</id>
        <msg>NETBIOS SMB spoolss EnumJobs response WriteAndX unicode andx attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-3479</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|14725, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14725</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP mqqm QMGetRemoteQueueName overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-065.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-3479</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|14726, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14726</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP mqqm QMGetRemoteQueueName overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-065.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-3466</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|14737, service dcerpc, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14737</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP host-integration bind attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-059.mspx</url>
      </rule>
      <rule>
        <bugtraq>31783</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FFB6CC68-702D-4FE2-A8E7-4DE23835F0D2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FFB6CC68-702D-4FE2-A8E7-4DE23835F0D2\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14744</id>
        <msg>WEB-ACTIVEX Hummingbird HostExplorer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31783</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|F|00|B|00|6|00|C|00|C|00|6|00|8|00|-|00|7|00|0|00|2|00|D|00|-|00|4|00|F|00|E|00|2|00|-|00|A|00|8|00|E|00|7|00|-|00|4|00|D|00|E|00|2|00|3|00|8|00|3|00|5|00|F|00|0|00|D|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00F\x00B\x006\x00C\x00C\x006\x008\x00-\x007\x000\x002\x00D\x00-\x004\x00F\x00E\x002\x00-\x00A\x008\x00E\x007\x00-\x004\x00D\x00E\x002\x003\x008\x003\x005\x00F\x000\x00D\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14745</id>
        <msg>WEB-ACTIVEX Hummingbird HostExplorer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A662DA7E-CCB7-4743-B71A-D817F6D575DF&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A662DA7E-CCB7-4743-B71A-D817F6D575DF\s*}?\s*(?P=q3)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAs)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A662DA7E-CCB7-4743-B71A-D817F6D575DF\s*}?\s*(?P=q4)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveAs))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14746</id>
        <msg>WEB-ACTIVEX Autodesk DWF Viewer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|6|00|6|00|2|00|D|00|A|00|7|00|E|00|-|00|C|00|C|00|B|00|7|00|-|00|4|00|7|00|4|00|3|00|-|00|B|00|7|00|1|00|A|00|-|00|D|00|8|00|1|00|7|00|F|00|6|00|D|00|5|00|7|00|5|00|D|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q5&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x006\x006\x002\x00D\x00A\x007\x00E\x00-\x00C\x00C\x00B\x007\x00-\x004\x007\x004\x003\x00-\x00B\x007\x001\x00A\x00-\x00D\x008\x001\x007\x00F\x006\x00D\x005\x007\x005\x00D\x00F\x00(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14747</id>
        <msg>WEB-ACTIVEX Autodesk DWF Viewer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;89EC7921-729B-4116-A819-DF86A4A5776B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*89EC7921-729B-4116-A819-DF86A4A5776B\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(ApplyPatch)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|\x26\x23039\x3b|)\s*clsid\s*\x3a\s*{?\s*89EC7921-729B-4116-A819-DF86A4A5776B\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|\x27|\x26\x23039\x3b|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(ApplyPatch))\s*\(/Osi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14748</id>
        <msg>WEB-ACTIVEX Autodesk LiveUpdate ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|9|00|E|00|C|00|7|00|9|00|2|00|1|00|-|00|7|00|2|00|9|00|B|00|-|00|4|00|1|00|1|00|6|00|-|00|A|00|8|00|1|00|9|00|-|00|D|00|F|00|8|00|6|00|A|00|4|00|A|00|5|00|7|00|7|00|6|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x009\x00E\x00C\x007\x009\x002\x001\x00-\x007\x002\x009\x00B\x00-\x004\x001\x001\x006\x00-\x00A\x008\x001\x009\x00-\x00D\x00F\x008\x006\x00A\x004\x00A\x005\x007\x007\x006\x00B\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14749</id>
        <msg>WEB-ACTIVEX Autodesk LiveUpdate ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LiveUpdate.UpdateEngine&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LiveUpdate\.UpdateEngine\x22|\x27LiveUpdate\.UpdateEngine\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*ApplyPatch\s*|.*(?P=v)\s*\.\s*ApplyPatch\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LiveUpdate\.UpdateEngine\x22|\x27LiveUpdate\.UpdateEngine\x27)\s*\)(\s*\.\s*ApplyPatch\s*|.*(?P=n)\s*\.\s*ApplyPatch\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14750</id>
        <msg>WEB-ACTIVEX Autodesk LiveUpdate ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31490</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|i|00|v|00|e|00|U|00|p|00|d|00|a|00|t|00|e|00|.|00|U|00|p|00|d|00|a|00|t|00|e|00|E|00|n|00|g|00|i|00|n|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)L\x00i\x00v\x00e\x00U\x00p\x00d\x00a\x00t\x00e\x00.\x00U\x00p\x00d\x00a\x00t\x00e\x00E\x00n\x00g\x00i\x00n\x00e\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)L\x00i\x00v\x00e\x00U\x00p\x00d\x00a\x00t\x00e\x00.\x00U\x00p\x00d\x00a\x00t\x00e\x00E\x00n\x00g\x00i\x00n\x00e\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14751</id>
        <msg>WEB-ACTIVEX Autodesk LiveUpdate ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31435</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0F517994-A6FA-4F39-BD4B-EC2DF00AEEF1&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0F517994-A6FA-4F39-BD4B-EC2DF00AEEF1\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(CanUninstall)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0F517994-A6FA-4F39-BD4B-EC2DF00AEEF1\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(CanUninstall))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14752</id>
        <msg>WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31435</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|F|00|5|00|1|00|7|00|9|00|9|00|4|00|-|00|A|00|6|00|F|00|A|00|-|00|4|00|F|00|3|00|9|00|-|00|B|00|D|00|4|00|B|00|-|00|E|00|C|00|2|00|D|00|F|00|0|00|0|00|A|00|E|00|E|00|F|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q13&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00F\x005\x001\x007\x009\x009\x004\x00-\x00A\x006\x00F\x00A\x00-\x004\x00F\x003\x009\x00-\x00B\x00D\x004\x00B\x00-\x00E\x00C\x002\x00D\x00F\x000\x000\x00A\x00E\x00E\x00F\x001\x00(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14753</id>
        <msg>WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31435</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AxNalServer.CAxNalWebInterface&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AxNalServer\.CAxNalWebInterface\x22|\x27AxNalServer\.CAxNalWebInterface\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*CanUninstall\s*|.*(?P=v)\s*\.\s*CanUninstall\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AxNalServer\.CAxNalWebInterface\x22|\x27AxNalServer\.CAxNalWebInterface\x27)\s*\)(\s*\.\s*CanUninstall\s*|.*(?P=n)\s*\.\s*CanUninstall\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14754</id>
        <msg>WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31435</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|x|00|N|00|a|00|l|00|S|00|e|00|r|00|v|00|e|00|r|00|.|00|C|00|A|00|x|00|N|00|a|00|l|00|W|00|e|00|b|00|I|00|n|00|t|00|e|00|r|00|f|00|a|00|c|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)A\x00x\x00N\x00a\x00l\x00S\x00e\x00r\x00v\x00e\x00r\x00.\x00C\x00A\x00x\x00N\x00a\x00l\x00W\x00e\x00b\x00I\x00n\x00t\x00e\x00r\x00f\x00a\x00c\x00e\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)A\x00x\x00N\x00a\x00l\x00S\x00e\x00r\x00v\x00e\x00r\x00.\x00C\x00A\x00x\x00N\x00a\x00l\x00W\x00e\x00b\x00I\x00n\x00t\x00e\x00r\x00f\x00a\x00c\x00e\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14755</id>
        <msg>WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3f0eecce-e138-11d1-8712-0060083d83f5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3f0eecce-e138-11d1-8712-0060083d83f5\s*}?\s*(?P=q21)(\s|&gt;).*(?P=id1)\s*\.\s*(url|toolbar|enableZoomPastMax)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3f0eecce-e138-11d1-8712-0060083d83f5\s*}?\s*(?P=q22)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\s*\.\s*(url|toolbar|enableZoomPastMax))\s*=/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14760</id>
        <msg>WEB-ACTIVEX iseemedia LPViewer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|f|00|0|00|e|00|e|00|c|00|c|00|e|00|-|00|e|00|1|00|3|00|8|00|-|00|1|00|1|00|d|00|1|00|-|00|8|00|7|00|1|00|2|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|3|00|d|00|8|00|3|00|f|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q23&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00f\x000\x00e\x00e\x00c\x00c\x00e\x00-\x00e\x001\x003\x008\x00-\x001\x001\x00d\x001\x00-\x008\x007\x001\x002\x00-\x000\x000\x006\x000\x000\x008\x003\x00d\x008\x003\x00f\x005\x00(}\x00)?(?P=q23)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14761</id>
        <msg>WEB-ACTIVEX iseemedia LPViewer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LPViewer.LPViewer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LPViewer\.LPViewer\x22|\x27LPViewer\.LPViewer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(url|toolbar|enableZoomPastMax)\s*|.*(?P=v)\s*\.\s*(url|toolbar|enableZoomPastMax)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LPViewer\.LPViewer\x22|\x27LPViewer\.LPViewer\x27)\s*\)(\s*\.\s*(url|toolbar|enableZoomPastMax)\s*|.*(?P=n)\s*\.\s*(url|toolbar|enableZoomPastMax))\s*=/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14762</id>
        <msg>WEB-ACTIVEX iseemedia LPViewer ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|P|00|V|00|i|00|e|00|w|00|e|00|r|00|.|00|L|00|P|00|V|00|i|00|e|00|w|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q24&gt;\x22|\x27|)L\x00P\x00V\x00i\x00e\x00w\x00e\x00r\x00.\x00L\x00P\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q24)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q25&gt;\x22|\x27|)L\x00P\x00V\x00i\x00e\x00w\x00e\x00r\x00.\x00L\x00P\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q25)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14763</id>
        <msg>WEB-ACTIVEX iseemedia LPViewer ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4250</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|14782, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14782</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4250</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|14783, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14783</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4250</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;|04 00|&quot;; byte_test:1,!&amp;,16,2,relative; content:&quot;|C8|O2Kp|16 D3 01 12|xZG|BF|n|E1 88|&quot;; within:16; distance:22; pcre:&quot;/^.{28}(\x00\x1f|\x00\x20)/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:6; pcre:&quot;/^.{2}/sR&quot;; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align; pcre:&quot;/\x00\.\x00\.\x00[\x2f\x5c]/R&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>14896</id>
        <msg>NETBIOS-DG SMB v4 srvsvc NetrpPathCononicalize unicode path cononicalization stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</url>
      </rule>
      <rule>
        <bugtraq>26950</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6506</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HPRulesEngine.ContentCollection&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22HPRulesEngine\.ContentCollection\x22|\x27HPRulesEngine\.ContentCollection\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SaveToFile|LoadFromFile)\s*|.*(?P=v)\s*\.\s*(SaveToFile|LoadFromFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22HPRulesEngine\.ContentCollection\x22|\x27HPRulesEngine\.ContentCollection\x27)\s*\)(\s*\.\s*(SaveToFile|LoadFromFile)\s*|.*(?P=n)\s*\.\s*(SaveToFile|LoadFromFile)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14897</id>
        <msg>WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26950</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6506</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;H|00|P|00|R|00|u|00|l|00|e|00|s|00|E|00|n|00|g|00|i|00|n|00|e|00|.|00|C|00|o|00|n|00|t|00|e|00|n|00|t|00|C|00|o|00|l|00|l|00|e|00|c|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)H\x00P\x00R\x00u\x00l\x00e\x00s\x00E\x00n\x00g\x00i\x00n\x00e\x00.\x00C\x00o\x00n\x00t\x00e\x00n\x00t\x00C\x00o\x00l\x00l\x00e\x00c\x00t\x00i\x00o\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)H\x00P\x00R\x00u\x00l\x00e\x00s\x00E\x00n\x00g\x00i\x00n\x00e\x00.\x00C\x00o\x00n\x00t\x00e\x00n\x00t\x00C\x00o\x00l\x00l\x00e\x00c\x00t\x00i\x00o\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14898</id>
        <msg>WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; byte_test:4,&gt;,16777215,24,relative,dce; pcre:&quot;/^.{16}(([\x01\x02\x03\x04\xC8]\x00|\x2C\x01)\x00{2}|\x00{2}(\x00[\x01\x02\x03\x04]|\x01\x2C))/sR&quot;; content:&quot;|05 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>14900</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; byte_test:4,&gt;,16777215,24,relative,dce; pcre:&quot;/^.{16}(([\x01\x02\x03\x04\xC8]\x00|\x2C\x01)\x00{2}|\x00{2}(\x00[\x01\x02\x03\x04]|\x01\x2C))/sR&quot;; content:&quot;|04 00|&quot;; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>14988</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31984</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BDF3E9D2-5F7A-4F4A-A914-7498C862EA6A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BDF3E9D2-5F7A-4F4A-A914-7498C862EA6A\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(savePageAsBitmap)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BDF3E9D2-5F7A-4F4A-A914-7498C862EA6A\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(savePageAsBitmap))\s*\(/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14993</id>
        <msg>WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31984</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|D|00|F|00|3|00|E|00|9|00|D|00|2|00|-|00|5|00|F|00|7|00|A|00|-|00|4|00|F|00|4|00|A|00|-|00|A|00|9|00|1|00|4|00|-|00|7|00|4|00|9|00|8|00|C|00|8|00|6|00|2|00|E|00|A|00|6|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00D\x00F\x003\x00E\x009\x00D\x002\x00-\x005\x00F\x007\x00A\x00-\x004\x00F\x004\x00A\x00-\x00A\x009\x001\x004\x00-\x007\x004\x009\x008\x00C\x008\x006\x002\x00E\x00A\x006\x00A\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14994</id>
        <msg>WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31984</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VSPDFEditorX.VSPDFEdit&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VSPDFEditorX\.VSPDFEdit(\.\d)?\x22|\x27VSPDFEditorX\.VSPDFEdit(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*savePageAsBitmap\s*|.*(?P=v)\s*\.\s*savePageAsBitmap\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VSPDFEditorX\.VSPDFEdit(\.\d)?\x22|\x27VSPDFEditorX\.VSPDFEdit(\.\d)?\x27)\s*\)(\s*\.\s*savePageAsBitmap\s*|.*(?P=n)\s*\.\s*savePageAsBitmap\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14995</id>
        <msg>WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31984</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|S|00|P|00|D|00|F|00|E|00|d|00|i|00|t|00|o|00|r|00|X|00|.|00|V|00|S|00|P|00|D|00|F|00|E|00|d|00|i|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00S\x00P\x00D\x00F\x00E\x00d\x00i\x00t\x00o\x00r\x00X\x00.\x00V\x00S\x00P\x00D\x00F\x00E\x00d\x00i\x00t\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00S\x00P\x00D\x00F\x00E\x00d\x00i\x00t\x00o\x00r\x00X\x00.\x00V\x00S\x00P\x00D\x00F\x00E\x00d\x00i\x00t\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14996</id>
        <msg>WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31996</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4800</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7233D6F8-AD31-440F-BAF0-9E7A292A53DA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7233D6F8-AD31-440F-BAF0-9E7A292A53DA\s*}?\s*(?P=q9)(\s|&gt;).*(?P=id1)\s*\.\s*(GetEntryPointForThread)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7233D6F8-AD31-440F-BAF0-9E7A292A53DA\s*}?\s*(?P=q10)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(GetEntryPointForThread))\s*\(/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14999</id>
        <msg>WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31996</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4800</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|2|00|3|00|3|00|D|00|6|00|F|00|8|00|-|00|A|00|D|00|3|00|1|00|-|00|4|00|4|00|0|00|F|00|-|00|B|00|A|00|F|00|0|00|-|00|9|00|E|00|7|00|A|00|2|00|9|00|2|00|A|00|5|00|3|00|D|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q11&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x002\x003\x003\x00D\x006\x00F\x008\x00-\x00A\x00D\x003\x001\x00-\x004\x004\x000\x00F\x00-\x00B\x00A\x00F\x000\x00-\x009\x00E\x007\x00A\x002\x009\x002\x00A\x005\x003\x00D\x00A\x00(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15000</id>
        <msg>WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31996</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4800</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CrashHangExt.Utils&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CrashHangExt\.Utils(\.\d)?\x22|\x27CrashHangExt\.Utils(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GetEntryPointForThread\s*|.*(?P=v)\s*\.\s*GetEntryPointForThread\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CrashHangExt\.Utils(\.\d)?\x22|\x27CrashHangExt\.Utils(\.\d)?\x27)\s*\)(\s*\.\s*GetEntryPointForThread\s*|.*(?P=n)\s*\.\s*GetEntryPointForThread\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15001</id>
        <msg>WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31996</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4800</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|r|00|a|00|s|00|h|00|H|00|a|00|n|00|g|00|E|00|x|00|t|00|.|00|U|00|t|00|i|00|l|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)C\x00r\x00a\x00s\x00h\x00H\x00a\x00n\x00g\x00E\x00x\x00t\x00.\x00U\x00t\x00i\x00l\x00s\x00(\.\x00\d\x00)?(?P=q12)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)C\x00r\x00a\x00s\x00h\x00H\x00a\x00n\x00g\x00E\x00x\x00t\x00.\x00U\x00t\x00i\x00l\x00s\x00(\.\x00\d\x00)?(?P=q13)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15002</id>
        <msg>WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3352B5B9-82E8-4FFD-9EB1-1A3E60056904&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3352B5B9-82E8-4FFD-9EB1-1A3E60056904\s*}?\s*(?P=q14)(\s|&gt;).*(?P=id1)\s*\.\s*(WriteFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3352B5B9-82E8-4FFD-9EB1-1A3E60056904\s*}?\s*(?P=q15)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(WriteFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15003</id>
        <msg>WEB-ACTIVEX Chilkat Crypt 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|5|00|2|00|B|00|5|00|B|00|9|00|-|00|8|00|2|00|E|00|8|00|-|00|4|00|F|00|F|00|D|00|-|00|9|00|E|00|B|00|1|00|-|00|1|00|A|00|3|00|E|00|6|00|0|00|0|00|5|00|6|00|9|00|0|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q16&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x003\x005\x002\x00B\x005\x00B\x009\x00-\x008\x002\x00E\x008\x00-\x004\x00F\x00F\x00D\x00-\x009\x00E\x00B\x001\x00-\x001\x00A\x003\x00E\x006\x000\x000\x005\x006\x009\x000\x004\x00(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15004</id>
        <msg>WEB-ACTIVEX Chilkat Crypt 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ChilkatCrypt2.ChilkatCrypt2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ChilkatCrypt2\.ChilkatCrypt2(\.\d)?\x22|\x27ChilkatCrypt2\.ChilkatCrypt2(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*WriteFile\s*|.*(?P=v)\s*\.\s*WriteFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ChilkatCrypt2\.ChilkatCrypt2(\.\d)?\x22|\x27ChilkatCrypt2\.ChilkatCrypt2(\.\d)?\x27)\s*\)(\s*\.\s*WriteFile\s*|.*(?P=n)\s*\.\s*WriteFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15005</id>
        <msg>WEB-ACTIVEX Chilkat Crypt 2 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|h|00|i|00|l|00|k|00|a|00|t|00|C|00|r|00|y|00|p|00|t|00|2|00|.|00|C|00|h|00|i|00|l|00|k|00|a|00|t|00|C|00|r|00|y|00|p|00|t|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)C\x00h\x00i\x00l\x00k\x00a\x00t\x00C\x00r\x00y\x00p\x00t\x002\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00C\x00r\x00y\x00p\x00t\x002\x00(\.\x00\d\x00)?(?P=q17)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q18&gt;\x22|\x27|)C\x00h\x00i\x00l\x00k\x00a\x00t\x00C\x00r\x00y\x00p\x00t\x002\x00.\x00C\x00h\x00i\x00l\x00k\x00a\x00t\x00C\x00r\x00y\x00p\x00t\x002\x00(\.\x00\d\x00)?(?P=q18)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15006</id>
        <msg>WEB-ACTIVEX Chilkat Crypt 2 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2000-0834</cve>
        <filter1>tcp any [139,445] -&gt; any any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15009, policy balanced-ips drop, policy security-ips drop, service netbios-ns;</filter2>
        <id>15009</id>
        <msg>NETBIOS possible SMB replay attempt - overlapping encryption keys detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-4033</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15011, service http, policy security-ips drop;</filter2>
        <id>15011</id>
        <msg>WEB-CLIENT Microsoft XML core services cross-domain information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4250</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15015, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15015</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrUseAdd/NetrUseGetInfo/NetrUseDel overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-067.mspx</url>
      </rule>
      <rule>
        <bugtraq>32186</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4387</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B01952B0-AF66-11D1-B10D-0060086F6D97&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B01952B0-AF66-11D1-B10D-0060086F6D97\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15069</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui mdrmsap ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32186</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4387</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|1|00|9|00|5|00|2|00|B|00|0|00|-|00|A|00|F|00|6|00|6|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|1|00|0|00|D|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|6|00|F|00|6|00|D|00|9|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x000\x001\x009\x005\x002\x00B\x000\x00-\x00A\x00F\x006\x006\x00-\x001\x001\x00D\x001\x00-\x00B\x001\x000\x00D\x00-\x000\x000\x006\x000\x000\x008\x006\x00F\x006\x00D\x009\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15070</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui mdrmsap ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15084, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15084</id>
        <msg>WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15086, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15086</id>
        <msg>WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2000-0834</cve>
        <filter1>tcp any $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15124, policy balanced-ips drop, policy security-ips drop, service http;</filter2>
        <id>15124</id>
        <msg>NETBIOS Web-based NTLM replay attack attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15127</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15128</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15129</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15130</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15131</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15132</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15133</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.sql.query; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>15134</id>
        <msg>NETBIOS SMB sp_replwritetovarbin vulnerable function unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15135</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15136</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15137</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15138</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15139</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;sp_replwritetovarbin&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15140</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15141</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flowbits:isset,smb.tree.create.sql.query; content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; distance:0; metadata:policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>15142</id>
        <msg>NETBIOS-DG SMB sp_replwritetovarbin vulnerable function unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2004-1050</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;IFRAME &quot;; nocase; content:&quot;file|3A|//&quot;; distance:0; nocase; pcre:&quot;/&lt;IFRAME\s+[^&gt;]*?src\s*=\s*(\x22|\x27|)file\x3a\x2f\x2f[^\x22\x27\s&gt;]{400}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15147</id>
        <msg>WEB-CLIENT Microsoft IE malformed iframe buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10726</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0728</cve>
        <filter1>tcp $HOME_NET any -&gt; $HOME_NET 2702</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|15148, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15148</id>
        <msg>DOS Microsoft SMS remote control client message length denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>32901</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D8089245-3211-40F6-819B-9E5E92CD61A2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D8089245-3211-40F6-819B-9E5E92CD61A2\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15173</id>
        <msg>WEB-ACTIVEX Phoenician Casino ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32901</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|8|00|0|00|8|00|9|00|2|00|4|00|5|00|-|00|3|00|2|00|1|00|1|00|-|00|4|00|0|00|F|00|6|00|-|00|8|00|1|00|9|00|B|00|-|00|9|00|E|00|5|00|E|00|9|00|2|00|C|00|D|00|6|00|1|00|A|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x008\x000\x008\x009\x002\x004\x005\x00-\x003\x002\x001\x001\x00-\x004\x000\x00F\x006\x00-\x008\x001\x009\x00B\x00-\x009\x00E\x005\x00E\x009\x002\x00C\x00D\x006\x001\x00A\x002\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15174</id>
        <msg>WEB-ACTIVEX Phoenician Casino ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32901</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FlashAX.FlashXControl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22FlashAX\.FlashXControl(\.\d)?\x22|\x27FlashAX\.FlashXControl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22FlashAX\.FlashXControl(\.\d)?\x22|\x27FlashAX\.FlashXControl(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15175</id>
        <msg>WEB-ACTIVEX Phoenician Casino ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>32901</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|l|00|a|00|s|00|h|00|A|00|X|00|.|00|F|00|l|00|a|00|s|00|h|00|X|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)F\x00l\x00a\x00s\x00h\x00A\x00X\x00.\x00F\x00l\x00a\x00s\x00h\x00X\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)F\x00l\x00a\x00s\x00h\x00A\x00X\x00.\x00F\x00l\x00a\x00s\x00h\x00X\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15176</id>
        <msg>WEB-ACTIVEX Phoenician Casino ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32965</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;74D05D43-3236-11D4-BDCD-00C04F9A3B61&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*74D05D43-3236-11D4-BDCD-00C04F9A3B61\s*}?\s*(?P=q5)(\s|&gt;).*(?P=id1)\s*\.\s*(notifyOnLoadNative)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*74D05D43-3236-11D4-BDCD-00C04F9A3B61\s*}?\s*(?P=q6)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(notifyOnLoadNative))\s*\(/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15177</id>
        <msg>WEB-ACTIVEX Trend Micro HouseCall ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32965</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|4|00|D|00|0|00|5|00|D|00|4|00|3|00|-|00|3|00|2|00|3|00|6|00|-|00|1|00|1|00|D|00|4|00|-|00|B|00|D|00|C|00|D|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|9|00|A|00|3|00|B|00|6|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q7&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x004\x00D\x000\x005\x00D\x004\x003\x00-\x003\x002\x003\x006\x00-\x001\x001\x00D\x004\x00-\x00B\x00D\x00C\x00D\x00-\x000\x000\x00C\x000\x004\x00F\x009\x00A\x003\x00B\x006\x001\x00(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15178</id>
        <msg>WEB-ACTIVEX Trend Micro HouseCall ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32965</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;XSCAN.XscanCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22XSCAN\.XscanCtrl(\.\d)?\x22|\x27XSCAN\.XscanCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*notifyOnLoadNative\s*|.*(?P=v)\s*\.\s*notifyOnLoadNative\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22XSCAN\.XscanCtrl(\.\d)?\x22|\x27XSCAN\.XscanCtrl(\.\d)?\x27)\s*\)(\s*\.\s*notifyOnLoadNative\s*|.*(?P=n)\s*\.\s*notifyOnLoadNative\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15179</id>
        <msg>WEB-ACTIVEX Trend Micro HouseCall ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>32965</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;X|00|S|00|C|00|A|00|N|00|.|00|X|00|s|00|c|00|a|00|n|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)X\x00S\x00C\x00A\x00N\x00.\x00X\x00s\x00c\x00a\x00n\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q8)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)X\x00S\x00C\x00A\x00N\x00.\x00X\x00s\x00c\x00a\x00n\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q9)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15180</id>
        <msg>WEB-ACTIVEX Trend Micro HouseCall ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0297D24A-F425-47EE-9F3B-A459BCE593E3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0297D24A-F425-47EE-9F3B-A459BCE593E3\s*}?\s*(?P=q10)(\s|&gt;).*(?P=id1)\s*\.\s*(Get)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0297D24A-F425-47EE-9F3B-A459BCE593E3\s*}?\s*(?P=q11)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(Get))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15181</id>
        <msg>WEB-ACTIVEX SaschArt SasCam Webcam Server ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|2|00|9|00|7|00|D|00|2|00|4|00|A|00|-|00|F|00|4|00|2|00|5|00|-|00|4|00|7|00|E|00|E|00|-|00|9|00|F|00|3|00|B|00|-|00|A|00|4|00|5|00|9|00|B|00|C|00|E|00|5|00|9|00|3|00|E|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q12&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x002\x009\x007\x00D\x002\x004\x00A\x00-\x00F\x004\x002\x005\x00-\x004\x007\x00E\x00E\x00-\x009\x00F\x003\x00B\x00-\x00A\x004\x005\x009\x00B\x00C\x00E\x005\x009\x003\x00E\x003\x00(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15182</id>
        <msg>WEB-ACTIVEX SaschArt SasCam Webcam Server ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2315B059-EDD7-4C66-933C-ECFF5B9DD593&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2315B059-EDD7-4C66-933C-ECFF5B9DD593\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddTab)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2315B059-EDD7-4C66-933C-ECFF5B9DD593\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddTab))\s*\(/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15192</id>
        <msg>WEB-ACTIVEX SizerOne ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|3|00|1|00|5|00|B|00|0|00|5|00|9|00|-|00|E|00|D|00|D|00|7|00|-|00|4|00|C|00|6|00|6|00|-|00|9|00|3|00|3|00|C|00|-|00|E|00|C|00|F|00|F|00|5|00|B|00|9|00|D|00|D|00|5|00|9|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x003\x001\x005\x00B\x000\x005\x009\x00-\x00E\x00D\x00D\x007\x00-\x004\x00C\x006\x006\x00-\x009\x003\x003\x00C\x00-\x00E\x00C\x00F\x00F\x005\x00B\x009\x00D\x00D\x005\x009\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15193</id>
        <msg>WEB-ACTIVEX SizerOne ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TabOne.TabOne&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TabOne\.TabOne(\.\d)?\x22|\x27TabOne\.TabOne(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddTab\s*|.*(?P=v)\s*\.\s*AddTab\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TabOne\.TabOne(\.\d)?\x22|\x27TabOne\.TabOne(\.\d)?\x27)\s*\)(\s*\.\s*AddTab\s*|.*(?P=n)\s*\.\s*AddTab\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15194</id>
        <msg>WEB-ACTIVEX SizerOne ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|a|00|b|00|O|00|n|00|e|00|.|00|T|00|a|00|b|00|O|00|n|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)T\x00a\x00b\x00O\x00n\x00e\x00.\x00T\x00a\x00b\x00O\x00n\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)T\x00a\x00b\x00O\x00n\x00e\x00.\x00T\x00a\x00b\x00O\x00n\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15195</id>
        <msg>WEB-ACTIVEX SizerOne ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15196, policy security-ips drop;</filter2>
        <id>15196</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15197, policy security-ips drop;</filter2>
        <id>15197</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15198, policy security-ips drop;</filter2>
        <id>15198</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE unicode param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15199, policy security-ips drop;</filter2>
        <id>15199</id>
        <msg>NETBIOS SMB NT Trans NT CREATE param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15200, policy security-ips drop;</filter2>
        <id>15200</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15201, policy security-ips drop;</filter2>
        <id>15201</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15202, policy security-ips drop;</filter2>
        <id>15202</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE unicode andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15203, policy security-ips drop;</filter2>
        <id>15203</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15204, policy security-ips drop;</filter2>
        <id>15204</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE unicode max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15205, policy security-ips drop;</filter2>
        <id>15205</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15206, policy security-ips drop;</filter2>
        <id>15206</id>
        <msg>NETBIOS SMB NT Trans NT CREATE max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15207, policy security-ips drop;</filter2>
        <id>15207</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15208, policy security-ips drop;</filter2>
        <id>15208</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE unicode andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15209, policy security-ips drop;</filter2>
        <id>15209</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15210, policy security-ips drop;</filter2>
        <id>15210</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4834</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15211, policy security-ips drop;</filter2>
        <id>15211</id>
        <msg>NETBIOS-DG SMB NT Trans NT CREATE andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15212, policy security-ips drop;</filter2>
        <id>15212</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15213, policy security-ips drop;</filter2>
        <id>15213</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15214, policy security-ips drop;</filter2>
        <id>15214</id>
        <msg>NETBIOS SMB Trans2 OPEN2 max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15215, policy security-ips drop;</filter2>
        <id>15215</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15216, policy security-ips drop;</filter2>
        <id>15216</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15217, policy security-ips drop;</filter2>
        <id>15217</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15218, policy security-ips drop;</filter2>
        <id>15218</id>
        <msg>NETBIOS SMB Trans2 OPEN2 andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15219, policy security-ips drop;</filter2>
        <id>15219</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode andx max_param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15220, policy security-ips drop;</filter2>
        <id>15220</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15221, policy security-ips drop;</filter2>
        <id>15221</id>
        <msg>NETBIOS SMB Trans2 OPEN2 param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15222, policy security-ips drop;</filter2>
        <id>15222</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15223, policy security-ips drop;</filter2>
        <id>15223</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15224, policy security-ips drop;</filter2>
        <id>15224</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15225, policy security-ips drop;</filter2>
        <id>15225</id>
        <msg>NETBIOS SMB Trans2 OPEN2 andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15226, policy security-ips drop;</filter2>
        <id>15226</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4835</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15227, policy security-ips drop;</filter2>
        <id>15227</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode andx param_count underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-001.mspx</url>
      </rule>
      <rule>
        <bugtraq>33233</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00E7C7F8-71E2-498A-AB28-A3D72FC74485&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00E7C7F8-71E2-498A-AB28-A3D72FC74485\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00E7C7F8-71E2-498A-AB28-A3D72FC74485\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15228</id>
        <msg>WEB-ACTIVEX Ciansoft PDFBuilderX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33233</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|E|00|7|00|C|00|7|00|F|00|8|00|-|00|7|00|1|00|E|00|2|00|-|00|4|00|9|00|8|00|A|00|-|00|A|00|B|00|2|00|8|00|-|00|A|00|3|00|D|00|7|00|2|00|F|00|C|00|7|00|4|00|4|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x00E\x007\x00C\x007\x00F\x008\x00-\x007\x001\x00E\x002\x00-\x004\x009\x008\x00A\x00-\x00A\x00B\x002\x008\x00-\x00A\x003\x00D\x007\x002\x00F\x00C\x007\x004\x004\x008\x005\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15229</id>
        <msg>WEB-ACTIVEX Ciansoft PDFBuilderX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33272</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DD44C0EA-B2CF-31D1-8DD3-444553540000&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DD44C0EA-B2CF-31D1-8DD3-444553540000\s*}?\s*(?P=q27)(\s|&gt;).*(?P=id1)\s*\.\s*(DoSaveHTMLFile|DoSaveFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q28&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DD44C0EA-B2CF-31D1-8DD3-444553540000\s*}?\s*(?P=q28)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\.(DoSaveHTMLFile|DoSaveFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15232</id>
        <msg>WEB-ACTIVEX Easy Grid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33272</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|D|00|4|00|4|00|C|00|0|00|E|00|A|00|-|00|B|00|2|00|C|00|F|00|-|00|3|00|1|00|D|00|1|00|-|00|8|00|D|00|D|00|3|00|-|00|4|00|4|00|4|00|5|00|5|00|3|00|5|00|4|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q29&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00D\x004\x004\x00C\x000\x00E\x00A\x00-\x00B\x002\x00C\x00F\x00-\x003\x001\x00D\x001\x00-\x008\x00D\x00D\x003\x00-\x004\x004\x004\x005\x005\x003\x005\x004\x000\x000\x000\x000\x00(}\x00)?(?P=q29)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15233</id>
        <msg>WEB-ACTIVEX Easy Grid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33272</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EasyGrid.SGCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EasyGrid\.SGCtrl(\.\d)?\x22|\x27EasyGrid\.SGCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoSaveHTMLFile|DoSaveFile)\s*|.*(?P=v)\s*\.\s*(DoSaveHTMLFile|DoSaveFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EasyGrid\.SGCtrl(\.\d)?\x22|\x27EasyGrid\.SGCtrl(\.\d)?\x27)\s*\)(\s*\.\s*(DoSaveHTMLFile|DoSaveFile)\s*|.*(?P=n)\s*\.\s*(DoSaveHTMLFile|DoSaveFile)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15234</id>
        <msg>WEB-ACTIVEX Easy Grid ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33272</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|a|00|s|00|y|00|G|00|r|00|i|00|d|00|.|00|S|00|G|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00a\x00s\x00y\x00G\x00r\x00i\x00d\x00.\x00S\x00G\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00a\x00s\x00y\x00G\x00r\x00i\x00d\x00.\x00S\x00G\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15235</id>
        <msg>WEB-ACTIVEX Easy Grid ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33408</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;917623D1-D8E5-11D2-BE8B-00104B06BDE3&quot;; nocase; pcre:&quot;/&lt;object\s+[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*917623D1-D8E5-11D2-BE8B-00104B06BDE3\s*}?\s*(?P=q1)(\s|&gt;)/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15243</id>
        <msg>WEB-ACTIVEX AXIS Camera ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33408</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|1|00|7|00|6|00|2|00|3|00|D|00|1|00|-|00|D|00|8|00|E|00|5|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|E|00|8|00|B|00|-|00|0|00|0|00|1|00|0|00|4|00|B|00|0|00|6|00|B|00|D|00|E|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x001\x007\x006\x002\x003\x00D\x001\x00-\x00D\x008\x00E\x005\x00-\x001\x001\x00D\x002\x00-\x00B\x00E\x008\x00B\x00-\x000\x000\x001\x000\x004\x00B\x000\x006\x00B\x00D\x00E\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15244</id>
        <msg>WEB-ACTIVEX AXIS Camera ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33408</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CamImage.CamImage&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CamImage\.CamImage(\.\d)?\x22|\x27CamImage\.CamImage(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*image_pan_tilt\s*|.*(?P=v)\s*\.\s*image_pan_tilt\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CamImage\.CamImage(\.\d)?\x22|\x27CamImage\.CamImage(\.\d)?\x27)\s*\)(\s*\.\s*image_pan_tilt\s*|.*(?P=n)\s*\.\s*image_pan_tilt)\s*=/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15245</id>
        <msg>WEB-ACTIVEX AXIS Camera ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33408</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|a|00|m|00|I|00|m|00|a|00|g|00|e|00|.|00|C|00|a|00|m|00|I|00|m|00|a|00|g|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00a\x00m\x00I\x00m\x00a\x00g\x00e\x00.\x00C\x00a\x00m\x00I\x00m\x00a\x00g\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00a\x00m\x00I\x00m\x00a\x00g\x00e\x00.\x00C\x00a\x00m\x00I\x00m\x00a\x00g\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15246</id>
        <msg>WEB-ACTIVEX AXIS Camera ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33345</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0B8F9DC9-A99C-40AD-BE40-88DDE92BAC41&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0B8F9DC9-A99C-40AD-BE40-88DDE92BAC41\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0B8F9DC9-A99C-40AD-BE40-88DDE92BAC41\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15247</id>
        <msg>WEB-ACTIVEX JamDTA ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33345</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|B|00|8|00|F|00|9|00|D|00|C|00|9|00|-|00|A|00|9|00|9|00|C|00|-|00|4|00|0|00|A|00|D|00|-|00|B|00|E|00|4|00|0|00|-|00|8|00|8|00|D|00|D|00|E|00|9|00|2|00|B|00|A|00|C|00|4|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00B\x008\x00F\x009\x00D\x00C\x009\x00-\x00A\x009\x009\x00C\x00-\x004\x000\x00A\x00D\x00-\x00B\x00E\x004\x000\x00-\x008\x008\x00D\x00D\x00E\x009\x002\x00B\x00A\x00C\x004\x001\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15248</id>
        <msg>WEB-ACTIVEX JamDTA ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33349</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E3462D53-47A6-11D8-8EF6-DAE89272743C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E3462D53-47A6-11D8-8EF6-DAE89272743C\s*}?\s*(?P=q9)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveMaskToFile|StartVideoSaving)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E3462D53-47A6-11D8-8EF6-DAE89272743C\s*}?\s*(?P=q10)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SaveMaskToFile|StartVideoSaving))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15249</id>
        <msg>WEB-ACTIVEX SmartVMD ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33349</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|3|00|4|00|6|00|2|00|D|00|5|00|3|00|-|00|4|00|7|00|A|00|6|00|-|00|1|00|1|00|D|00|8|00|-|00|8|00|E|00|F|00|6|00|-|00|D|00|A|00|E|00|8|00|9|00|2|00|7|00|2|00|7|00|4|00|3|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q11&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x003\x004\x006\x002\x00D\x005\x003\x00-\x004\x007\x00A\x006\x00-\x001\x001\x00D\x008\x00-\x008\x00E\x00F\x006\x00-\x00D\x00A\x00E\x008\x009\x002\x007\x002\x007\x004\x003\x00C\x00(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15250</id>
        <msg>WEB-ACTIVEX SmartVMD ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33318</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;67E66985-F81A-11D6-BC0F-F7B40157DC26&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67E66985-F81A-11D6-BC0F-F7B40157DC26\s*}?\s*(?P=q12)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToBMP)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*67E66985-F81A-11D6-BC0F-F7B40157DC26\s*}?\s*(?P=q13)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(SaveToBMP))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15251</id>
        <msg>WEB-ACTIVEX MetaProducts MetaTreeX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33318</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|E|00|6|00|6|00|9|00|8|00|5|00|-|00|F|00|8|00|1|00|A|00|-|00|1|00|1|00|D|00|6|00|-|00|B|00|C|00|0|00|F|00|-|00|F|00|7|00|B|00|4|00|0|00|1|00|5|00|7|00|D|00|C|00|2|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q14&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x007\x00E\x006\x006\x009\x008\x005\x00-\x00F\x008\x001\x00A\x00-\x001\x001\x00D\x006\x00-\x00B\x00C\x000\x00F\x00-\x00F\x007\x00B\x004\x000\x001\x005\x007\x00D\x00C\x002\x006\x00(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15252</id>
        <msg>WEB-ACTIVEX MetaProducts MetaTreeX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33318</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SaveToBMP.MetaTreeX&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SaveToBMP\.MetaTreeX(\.\d)?\x22|\x27SaveToBMP\.MetaTreeX(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveToBMP\s*|.*(?P=v)\s*\.\s*SaveToBMP\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SaveToBMP\.MetaTreeX(\.\d)?\x22|\x27SaveToBMP\.MetaTreeX(\.\d)?\x27)\s*\)(\s*\.\s*SaveToBMP\s*|.*(?P=n)\s*\.\s*SaveToBMP\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15253</id>
        <msg>WEB-ACTIVEX MetaProducts MetaTreeX ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33318</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|a|00|v|00|e|00|T|00|o|00|B|00|M|00|P|00|.|00|M|00|e|00|t|00|a|00|T|00|r|00|e|00|e|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)S\x00a\x00v\x00e\x00T\x00o\x00B\x00M\x00P\x00.\x00M\x00e\x00t\x00a\x00T\x00r\x00e\x00e\x00X\x00(\.\x00\d\x00)?(?P=q15)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)S\x00a\x00v\x00e\x00T\x00o\x00B\x00M\x00P\x00.\x00M\x00e\x00t\x00a\x00T\x00r\x00e\x00e\x00X\x00(\.\x00\d\x00)?(?P=q16)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15254</id>
        <msg>WEB-ACTIVEX MetaProducts MetaTreeX ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33469</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|T|00|A|00|u|00|d|00|i|00|o|00|F|00|i|00|l|00|e|00|2|00|.|00|A|00|u|00|d|00|i|00|o|00|F|00|i|00|l|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q30&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00F\x00i\x00l\x00e\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00F\x00i\x00l\x00e\x00(\.\x00\d\x00)?(?P=q30)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q31&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00F\x00i\x00l\x00e\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00F\x00i\x00l\x00e\x00(\.\x00\d\x00)?(?P=q31)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15265</id>
        <msg>WEB-ACTIVEX NCTAudioFile2 ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/292713</url>
      </rule>
      <rule>
        <bugtraq>33451</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0298</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;14D09688-CFA7-11D5-995A-005004CE563B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*14D09688-CFA7-11D5-995A-005004CE563B\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*14D09688-CFA7-11D5-995A-005004CE563B\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15266</id>
        <msg>WEB-ACTIVEX MW6 Technologies Barcode ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33451</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0298</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|4|00|D|00|0|00|9|00|6|00|8|00|8|00|-|00|C|00|F|00|A|00|7|00|-|00|1|00|1|00|D|00|5|00|-|00|9|00|9|00|5|00|A|00|-|00|0|00|0|00|5|00|0|00|0|00|4|00|C|00|E|00|5|00|6|00|3|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x004\x00D\x000\x009\x006\x008\x008\x00-\x00C\x00F\x00A\x007\x00-\x001\x001\x00D\x005\x00-\x009\x009\x005\x00A\x00-\x000\x000\x005\x000\x000\x004\x00C\x00E\x005\x006\x003\x00B\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15267</id>
        <msg>WEB-ACTIVEX MW6 Technologies Barcode ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33451</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0298</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Barcode.MW6Barcode&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Barcode\.MW6Barcode(\.\d)?\x22|\x27Barcode\.MW6Barcode(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF)\s*|.*(?P=v)\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Barcode\.MW6Barcode(\.\d)?\x22|\x27Barcode\.MW6Barcode(\.\d)?\x27)\s*\)(\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF)\s*|.*(?P=n)\s*\.\s*(Supplement|SaveAsBMP|SaveAsWMF))\s*=/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15268</id>
        <msg>WEB-ACTIVEX MW6 Technologies Barcode ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33451</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0298</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|a|00|r|00|c|00|o|00|d|00|e|00|.|00|M|00|W|00|6|00|B|00|a|00|r|00|c|00|o|00|d|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)B\x00a\x00r\x00c\x00o\x00d\x00e\x00.\x00M\x00W\x006\x00B\x00a\x00r\x00c\x00o\x00d\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)B\x00a\x00r\x00c\x00o\x00d\x00e\x00.\x00M\x00W\x006\x00B\x00a\x00r\x00c\x00o\x00d\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15269</id>
        <msg>WEB-ACTIVEX MW6 Technologies Barcode ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4926</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;90D2A875-5024-4CCD-80AA-C8A353DB2B45&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*90D2A875-5024-4CCD-80AA-C8A353DB2B45\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAsWMF|SaveAsBMP)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*90D2A875-5024-4CCD-80AA-C8A353DB2B45\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveAsWMF|SaveAsBMP))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15270</id>
        <msg>WEB-ACTIVEX MW6 Technologies PDF417 ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4926</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|0|00|D|00|2|00|A|00|8|00|7|00|5|00|-|00|5|00|0|00|2|00|4|00|-|00|4|00|C|00|C|00|D|00|-|00|8|00|0|00|A|00|A|00|-|00|C|00|8|00|A|00|3|00|5|00|3|00|D|00|B|00|2|00|B|00|4|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x000\x00D\x002\x00A\x008\x007\x005\x00-\x005\x000\x002\x004\x00-\x004\x00C\x00C\x00D\x00-\x008\x000\x00A\x00A\x00-\x00C\x008\x00A\x003\x005\x003\x00D\x00B\x002\x00B\x004\x005\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15271</id>
        <msg>WEB-ACTIVEX MW6 Technologies PDF417 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4926</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MW6PDF417.PDF417&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MW6PDF417\.PDF417(\.\d)?\x22|\x27MW6PDF417\.PDF417(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=v)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MW6PDF417\.PDF417(\.\d)?\x22|\x27MW6PDF417\.PDF417(\.\d)?\x27)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=n)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15272</id>
        <msg>WEB-ACTIVEX MW6 Technologies PDF417 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4926</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|W|00|6|00|P|00|D|00|F|00|4|00|1|00|7|00|.|00|P|00|D|00|F|00|4|00|1|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)M\x00W\x006\x00P\x00D\x00F\x004\x001\x007\x00.\x00P\x00D\x00F\x004\x001\x007\x00(\.\x00\d\x00)?(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)M\x00W\x006\x00P\x00D\x00F\x004\x001\x007\x00.\x00P\x00D\x00F\x004\x001\x007\x00(\.\x00\d\x00)?(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15273</id>
        <msg>WEB-ACTIVEX MW6 Technologies PDF417 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4925</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DE7DA0B5-7D7B-4CEA-8739-65CF600D511E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DE7DA0B5-7D7B-4CEA-8739-65CF600D511E\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAsWMF|SaveAsBMP)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DE7DA0B5-7D7B-4CEA-8739-65CF600D511E\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SaveAsWMF|SaveAsBMP))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15274</id>
        <msg>WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4925</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|E|00|7|00|D|00|A|00|0|00|B|00|5|00|-|00|7|00|D|00|7|00|B|00|-|00|4|00|C|00|E|00|A|00|-|00|8|00|7|00|3|00|9|00|-|00|6|00|5|00|C|00|F|00|6|00|0|00|0|00|D|00|5|00|1|00|1|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q13&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00E\x007\x00D\x00A\x000\x00B\x005\x00-\x007\x00D\x007\x00B\x00-\x004\x00C\x00E\x00A\x00-\x008\x007\x003\x009\x00-\x006\x005\x00C\x00F\x006\x000\x000\x00D\x005\x001\x001\x00E\x00(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15275</id>
        <msg>WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4925</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DATAMATRIX.MW6DataMatrix&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DATAMATRIX\.MW6DataMatrix(\.\d)?\x22|\x27DATAMATRIX\.MW6DataMatrix(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=v)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DATAMATRIX\.MW6DataMatrix(\.\d)?\x22|\x27DATAMATRIX\.MW6DataMatrix(\.\d)?\x27)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=n)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15276</id>
        <msg>WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4925</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|A|00|T|00|A|00|M|00|A|00|T|00|R|00|I|00|X|00|.|00|M|00|W|00|6|00|D|00|a|00|t|00|a|00|M|00|a|00|t|00|r|00|i|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)D\x00A\x00T\x00A\x00M\x00A\x00T\x00R\x00I\x00X\x00.\x00M\x00W\x006\x00D\x00a\x00t\x00a\x00M\x00a\x00t\x00r\x00i\x00x\x00(\.\x00\d\x00)?(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)D\x00A\x00T\x00A\x00M\x00A\x00T\x00R\x00I\x00X\x00.\x00M\x00W\x006\x00D\x00a\x00t\x00a\x00M\x00a\x00t\x00r\x00i\x00x\x00(\.\x00\d\x00)?(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15277</id>
        <msg>WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4923</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F359732D-D020-40ED-83FF-F381EFE36B54&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F359732D-D020-40ED-83FF-F381EFE36B54\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveAsWMF|SaveAsBMP)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F359732D-D020-40ED-83FF-F381EFE36B54\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(SaveAsWMF|SaveAsBMP))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15278</id>
        <msg>WEB-ACTIVEX MW6 Technologies Aztec ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4923</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|3|00|5|00|9|00|7|00|3|00|2|00|D|00|-|00|D|00|0|00|2|00|0|00|-|00|4|00|0|00|E|00|D|00|-|00|8|00|3|00|F|00|F|00|-|00|F|00|3|00|8|00|1|00|E|00|F|00|E|00|3|00|6|00|B|00|5|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q18&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x003\x005\x009\x007\x003\x002\x00D\x00-\x00D\x000\x002\x000\x00-\x004\x000\x00E\x00D\x00-\x008\x003\x00F\x00F\x00-\x00F\x003\x008\x001\x00E\x00F\x00E\x003\x006\x00B\x005\x004\x00(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15279</id>
        <msg>WEB-ACTIVEX MW6 Technologies Aztec ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4923</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AZTEC.MW6Aztec&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AZTEC\.MW6Aztec(\.\d)?\x22|\x27AZTEC\.MW6Aztec(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=v)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AZTEC\.MW6Aztec(\.\d)?\x22|\x27AZTEC\.MW6Aztec(\.\d)?\x27)\s*\)(\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*|.*(?P=n)\s*\.\s*(SaveAsWMF|SaveAsBMP)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15280</id>
        <msg>WEB-ACTIVEX MW6 Technologies Aztec ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4923</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|Z|00|T|00|E|00|C|00|.|00|M|00|W|00|6|00|A|00|z|00|t|00|e|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q19&gt;\x22|\x27|)A\x00Z\x00T\x00E\x00C\x00.\x00M\x00W\x006\x00A\x00z\x00t\x00e\x00c\x00(\.\x00\d\x00)?(?P=q19)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)A\x00Z\x00T\x00E\x00C\x00.\x00M\x00W\x006\x00A\x00z\x00t\x00e\x00c\x00(\.\x00\d\x00)?(?P=q20)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15281</id>
        <msg>WEB-ACTIVEX MW6 Technologies Aztec ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;34A261F9-FC34-47F8-A35C-75FB73BB1358&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m15&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m15)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q32&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*34A261F9-FC34-47F8-A35C-75FB73BB1358\s*}?\s*(?P=q32)(\s|&gt;).*(?P=id1)\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q33&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*34A261F9-FC34-47F8-A35C-75FB73BB1358\s*}?\s*(?P=q33)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m16&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m16)(\s|&gt;).*(?P=id2)\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15284</id>
        <msg>WEB-ACTIVEX NCTAudioGrabber2 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/656593</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|4|00|A|00|2|00|6|00|1|00|F|00|9|00|-|00|F|00|C|00|3|00|4|00|-|00|4|00|7|00|F|00|8|00|-|00|A|00|3|00|5|00|C|00|-|00|7|00|5|00|F|00|B|00|7|00|3|00|B|00|B|00|1|00|3|00|5|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q34&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x004\x00A\x002\x006\x001\x00F\x009\x00-\x00F\x00C\x003\x004\x00-\x004\x007\x00F\x008\x00-\x00A\x003\x005\x00C\x00-\x007\x005\x00F\x00B\x007\x003\x00B\x00B\x001\x003\x005\x008\x00(}\x00)?(?P=q34)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15285</id>
        <msg>WEB-ACTIVEX NCTAudioGrabber2 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/656593</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCTAudioGrabber2.AudioGrabber2&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCTAudioGrabber2\.AudioGrabber2(\.\d)?\x22|\x27NCTAudioGrabber2\.AudioGrabber2(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript)\s*|.*(?P=v)\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCTAudioGrabber2\.AudioGrabber2(\.\d)?\x22|\x27NCTAudioGrabber2\.AudioGrabber2(\.\d)?\x27)\s*\)(\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript)\s*|.*(?P=n)\s*\.\s*(cddbServerAddress|cddbAgentName|cddbUserEmail|cddbCGIScript))\s*=/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15286</id>
        <msg>WEB-ACTIVEX NCTAudioGrabber2 ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/656593</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|T|00|A|00|u|00|d|00|i|00|o|00|G|00|r|00|a|00|b|00|b|00|e|00|r|00|2|00|.|00|A|00|u|00|d|00|i|00|o|00|G|00|r|00|a|00|b|00|b|00|e|00|r|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q35&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00G\x00r\x00a\x00b\x00b\x00e\x00r\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00G\x00r\x00a\x00b\x00b\x00e\x00r\x002\x00(\.\x00\d\x00)?(?P=q35)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q36&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00G\x00r\x00a\x00b\x00b\x00e\x00r\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00G\x00r\x00a\x00b\x00b\x00e\x00r\x002\x00(\.\x00\d\x00)?(?P=q36)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15287</id>
        <msg>WEB-ACTIVEX NCTAudioGrabber2 ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/656593</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m17&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m17)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q37&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C\s*}?\s*(?P=q37)(\s|&gt;).*(?P=id1)\s*\.\s*(GetAudioInformation|SetAudioInformation)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q38&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C\s*}?\s*(?P=q38)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m18&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m18)(\s|&gt;).*(?P=id2)\.(GetAudioInformation|SetAudioInformation))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15288</id>
        <msg>WEB-ACTIVEX NCTAudioInformation2 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/669265</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|A|00|F|00|A|00|1|00|E|00|7|00|3|00|-|00|4|00|8|00|4|00|2|00|-|00|4|00|B|00|E|00|C|00|-|00|B|00|C|00|4|00|6|00|-|00|4|00|8|00|C|00|6|00|2|00|E|00|1|00|C|00|5|00|C|00|9|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q39&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00A\x00F\x00A\x001\x00E\x007\x003\x00-\x004\x008\x004\x002\x00-\x004\x00B\x00E\x00C\x00-\x00B\x00C\x004\x006\x00-\x004\x008\x00C\x006\x002\x00E\x001\x00C\x005\x00C\x009\x00C\x00(}\x00)?(?P=q39)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15289</id>
        <msg>WEB-ACTIVEX NCTAudioInformation2 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/669265</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCTAudioInformation2.AudioInformation2&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCTAudioInformation2\.AudioInformation2(\.\d)?\x22|\x27NCTAudioInformation2\.AudioInformation2(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(GetAudioInformation|SetAudioInformation)\s*|.*(?P=v)\s*\.\s*(GetAudioInformation|SetAudioInformation)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCTAudioInformation2\.AudioInformation2(\.\d)?\x22|\x27NCTAudioInformation2\.AudioInformation2(\.\d)?\x27)\s*\)(\s*\.\s*(GetAudioInformation|SetAudioInformation)\s*|.*(?P=n)\s*\.\s*(GetAudioInformation|SetAudioInformation)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15290</id>
        <msg>WEB-ACTIVEX NCTAudioInformation2 ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/669265</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|T|00|A|00|u|00|d|00|i|00|o|00|I|00|n|00|f|00|o|00|r|00|m|00|a|00|t|00|i|00|o|00|n|00|2|00|.|00|A|00|u|00|d|00|i|00|o|00|I|00|n|00|f|00|o|00|r|00|m|00|a|00|t|00|i|00|o|00|n|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q40&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00I\x00n\x00f\x00o\x00r\x00m\x00a\x00t\x00i\x00o\x00n\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00I\x00n\x00f\x00o\x00r\x00m\x00a\x00t\x00i\x00o\x00n\x002\x00(\.\x00\d\x00)?(?P=q40)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q41&gt;\x22|\x27|)N\x00C\x00T\x00A\x00u\x00d\x00i\x00o\x00I\x00n\x00f\x00o\x00r\x00m\x00a\x00t\x00i\x00o\x00n\x002\x00.\x00A\x00u\x00d\x00i\x00o\x00I\x00n\x00f\x00o\x00r\x00m\x00a\x00t\x00i\x00o\x00n\x002\x00(\.\x00\d\x00)?(?P=q41)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15291</id>
        <msg>WEB-ACTIVEX NCTAudioInformation2 ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/669265</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1E216240-1B7D-11CF-9D53-00AA003C9CB6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1E216240-1B7D-11CF-9D53-00AA003C9CB6\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15307</id>
        <msg>WEB-ACTIVEX Microsoft Animation Control ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|E|00|2|00|1|00|6|00|2|00|4|00|0|00|-|00|1|00|B|00|7|00|D|00|-|00|1|00|1|00|C|00|F|00|-|00|9|00|D|00|5|00|3|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|3|00|C|00|9|00|C|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00E\x002\x001\x006\x002\x004\x000\x00-\x001\x00B\x007\x00D\x00-\x001\x001\x00C\x00F\x00-\x009\x00D\x005\x003\x00-\x000\x000\x00A\x00A\x000\x000\x003\x00C\x009\x00C\x00B\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15308</id>
        <msg>WEB-ACTIVEX Microsoft Animation Control ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ComCtl2.Animation&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ComCtl2\.Animation(\.\d)?\x22|\x27ComCtl2\.Animation(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ComCtl2\.Animation(\.\d)?\x22|\x27ComCtl2\.Animation(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15309</id>
        <msg>WEB-ACTIVEX Microsoft Animation Control ActiveX function call access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|o|00|m|00|C|00|t|00|l|00|2|00|.|00|A|00|n|00|i|00|m|00|a|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)C\x00o\x00m\x00C\x00t\x00l\x002\x00.\x00A\x00n\x00i\x00m\x00a\x00t\x00i\x00o\x00n\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00o\x00m\x00C\x00t\x00l\x002\x00.\x00A\x00n\x00i\x00m\x00a\x00t\x00i\x00o\x00n\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15310</id>
        <msg>WEB-ACTIVEX Microsoft Animation Control ActiveX function call unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <bugtraq>33663</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0305</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4788DE08-3552-49EA-AC8C-233DA52523B9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4788DE08-3552-49EA-AC8C-233DA52523B9\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15311</id>
        <msg>WEB-ACTIVEX Research In Motion AxLoader ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <bugtraq>33663</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0305</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|8|00|8|00|D|00|E|00|0|00|8|00|-|00|3|00|5|00|5|00|2|00|-|00|4|00|9|00|E|00|A|00|-|00|A|00|C|00|8|00|C|00|-|00|2|00|3|00|3|00|D|00|A|00|5|00|2|00|5|00|2|00|3|00|B|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x007\x008\x008\x00D\x00E\x000\x008\x00-\x003\x005\x005\x002\x00-\x004\x009\x00E\x00A\x00-\x00A\x00C\x008\x00C\x00-\x002\x003\x003\x00D\x00A\x005\x002\x005\x002\x003\x00B\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15312</id>
        <msg>WEB-ACTIVEX Research In Motion AxLoader ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <bugtraq>33663</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0305</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RIM.AxLoader&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22RIM\.AxLoader(\.\d)?\x22|\x27RIM\.AxLoader(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RIM\.AxLoader(\.\d)?\x22|\x27RIM\.AxLoader(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15313</id>
        <msg>WEB-ACTIVEX Research In Motion AxLoader ActiveX function call access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <bugtraq>33663</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0305</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;R|00|I|00|M|00|.|00|A|00|x|00|L|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)R\x00I\x00M\x00.\x00A\x00x\x00L\x00o\x00a\x00d\x00e\x00r\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)R\x00I\x00M\x00.\x00A\x00x\x00L\x00o\x00a\x00d\x00e\x00r\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15314</id>
        <msg>WEB-ACTIVEX Research In Motion AxLoader ActiveX function call unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1\s*}?\s*(?P=q9)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15315</id>
        <msg>WEB-ACTIVEX Akamai DownloadManager ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|F|00|B|00|B|00|3|00|F|00|3|00|B|00|-|00|0|00|A|00|5|00|A|00|-|00|4|00|1|00|0|00|6|00|-|00|B|00|E|00|5|00|3|00|-|00|D|00|F|00|E|00|1|00|E|00|2|00|3|00|4|00|0|00|C|00|B|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00F\x00B\x00B\x003\x00F\x003\x00B\x00-\x000\x00A\x005\x00A\x00-\x004\x001\x000\x006\x00-\x00B\x00E\x005\x003\x00-\x00D\x00F\x00E\x001\x00E\x002\x003\x004\x000\x00C\x00B\x001\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15316</id>
        <msg>WEB-ACTIVEX Akamai DownloadManager ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MANAGER.DLMCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MANAGER\.DLMCtrl(\.\d)?\x22|\x27MANAGER\.DLMCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MANAGER\.DLMCtrl(\.\d)?\x22|\x27MANAGER\.DLMCtrl(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15317</id>
        <msg>WEB-ACTIVEX Akamai DownloadManager ActiveX function call access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|A|00|N|00|A|00|G|00|E|00|R|00|.|00|D|00|L|00|M|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q11&gt;\x22|\x27|)M\x00A\x00N\x00A\x00G\x00E\x00R\x00.\x00D\x00L\x00M\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q11)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)M\x00A\x00N\x00A\x00G\x00E\x00R\x00.\x00D\x00L\x00M\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q12)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15318</id>
        <msg>WEB-ACTIVEX Akamai DownloadManager ActiveX function call unicode access</msg>
        <url>support.microsoft.com/kb/960715</url>
      </rule>
      <rule>
        <bugtraq>33726</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F85B4A10-B530-4D68-A714-7415838FD174&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F85B4A10-B530-4D68-A714-7415838FD174\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SelectDevice)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F85B4A10-B530-4D68-A714-7415838FD174\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SelectDevice))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15330</id>
        <msg>WEB-ACTIVEX Nokia Phoenix Service 1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33726</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|8|00|5|00|B|00|4|00|A|00|1|00|0|00|-|00|B|00|5|00|3|00|0|00|-|00|4|00|D|00|6|00|8|00|-|00|A|00|7|00|1|00|4|00|-|00|7|00|4|00|1|00|5|00|8|00|3|00|8|00|F|00|D|00|1|00|7|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x008\x005\x00B\x004\x00A\x001\x000\x00-\x00B\x005\x003\x000\x00-\x004\x00D\x006\x008\x00-\x00A\x007\x001\x004\x00-\x007\x004\x001\x005\x008\x003\x008\x00F\x00D\x001\x007\x004\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15331</id>
        <msg>WEB-ACTIVEX Nokia Phoenix Service 1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33726</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;929A0D77-044A-497F-8FDF-8EDE81F6251A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*929A0D77-044A-497F-8FDF-8EDE81F6251A\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(SelectDevice)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*929A0D77-044A-497F-8FDF-8EDE81F6251A\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SelectDevice))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15332</id>
        <msg>WEB-ACTIVEX Nokia Phoenix Service 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33726</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|2|00|9|00|A|00|0|00|D|00|7|00|7|00|-|00|0|00|4|00|4|00|A|00|-|00|4|00|9|00|7|00|F|00|-|00|8|00|F|00|D|00|F|00|-|00|8|00|E|00|D|00|E|00|8|00|1|00|F|00|6|00|2|00|5|00|1|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x002\x009\x00A\x000\x00D\x007\x007\x00-\x000\x004\x004\x00A\x00-\x004\x009\x007\x00F\x00-\x008\x00F\x00D\x00F\x00-\x008\x00E\x00D\x00E\x008\x001\x00F\x006\x002\x005\x001\x00A\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15333</id>
        <msg>WEB-ACTIVEX Nokia Phoenix Service 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33535</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0465</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B5576893-F948-4E0F-9BE1-A37CB56D66FF&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B5576893-F948-4E0F-9BE1-A37CB56D66FF\s*}?\s*(?P=q22)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveDoc)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q23&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B5576893-F948-4E0F-9BE1-A37CB56D66FF\s*}?\s*(?P=q23)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\.(SaveDoc))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15346</id>
        <msg>WEB-ACTIVEX Synactis ALL In-The-Box ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33535</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0465</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|5|00|5|00|7|00|6|00|8|00|9|00|3|00|-|00|F|00|9|00|4|00|8|00|-|00|4|00|E|00|0|00|F|00|-|00|9|00|B|00|E|00|1|00|-|00|A|00|3|00|7|00|C|00|B|00|5|00|6|00|D|00|6|00|6|00|F|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q24&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x005\x005\x007\x006\x008\x009\x003\x00-\x00F\x009\x004\x008\x00-\x004\x00E\x000\x00F\x00-\x009\x00B\x00E\x001\x00-\x00A\x003\x007\x00C\x00B\x005\x006\x00D\x006\x006\x00F\x00F\x00(}\x00)?(?P=q24)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15347</id>
        <msg>WEB-ACTIVEX Synactis ALL In-The-Box ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33535</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0465</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;All_In_The_Box.AllBox&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22All_In_The_Box\.AllBox(\.\d)?\x22|\x27All_In_The_Box\.AllBox(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveDoc\s*|.*(?P=v)\s*\.\s*SaveDoc\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22All_In_The_Box\.AllBox(\.\d)?\x22|\x27All_In_The_Box\.AllBox(\.\d)?\x27)\s*\)(\s*\.\s*SaveDoc\s*|.*(?P=n)\s*\.\s*SaveDoc\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15348</id>
        <msg>WEB-ACTIVEX Synactis ALL In-The-Box ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33535</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0465</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|l|00|l|00|_|00|I|00|n|00|_|00|T|00|h|00|e|00|_|00|B|00|o|00|x|00|.|00|A|00|l|00|l|00|B|00|o|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q25&gt;\x22|\x27|)A\x00l\x00l\x00_\x00I\x00n\x00_\x00T\x00h\x00e\x00_\x00B\x00o\x00x\x00.\x00A\x00l\x00l\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q25)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q26&gt;\x22|\x27|)A\x00l\x00l\x00_\x00I\x00n\x00_\x00T\x00h\x00e\x00_\x00B\x00o\x00x\x00.\x00A\x00l\x00l\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q26)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15349</id>
        <msg>WEB-ACTIVEX Synactis ALL In-The-Box ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33515</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0389</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;441E9D47-9F52-11D6-9672-0080C88B3613&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*441E9D47-9F52-11D6-9672-0080C88B3613\s*}?\s*(?P=q27)(\s|&gt;).*(?P=id1)\s*\.\s*(WriteIniFileString|ShellExecute)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q28&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*441E9D47-9F52-11D6-9672-0080C88B3613\s*}?\s*(?P=q28)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\.(WriteIniFileString|ShellExecute))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15350</id>
        <msg>WEB-ACTIVEX Web on Windows ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33515</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0389</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|1|00|E|00|9|00|D|00|4|00|7|00|-|00|9|00|F|00|5|00|2|00|-|00|1|00|1|00|D|00|6|00|-|00|9|00|6|00|7|00|2|00|-|00|0|00|0|00|8|00|0|00|C|00|8|00|8|00|B|00|3|00|6|00|1|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q29&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x001\x00E\x009\x00D\x004\x007\x00-\x009\x00F\x005\x002\x00-\x001\x001\x00D\x006\x00-\x009\x006\x007\x002\x00-\x000\x000\x008\x000\x00C\x008\x008\x00B\x003\x006\x001\x003\x00(}\x00)?(?P=q29)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15351</id>
        <msg>WEB-ACTIVEX Web on Windows ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33515</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0389</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;All_In_The_Box.AllBox&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22All_In_The_Box\.AllBox(\.\d)?\x22|\x27All_In_The_Box\.AllBox(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(WriteIniFileString|ShellExecute)\s*|.*(?P=v)\s*\.\s*(WriteIniFileString|ShellExecute)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22All_In_The_Box\.AllBox(\.\d)?\x22|\x27All_In_The_Box\.AllBox(\.\d)?\x27)\s*\)(\s*\.\s*(WriteIniFileString|ShellExecute)\s*|.*(?P=n)\s*\.\s*(WriteIniFileString|ShellExecute)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15352</id>
        <msg>WEB-ACTIVEX Web on Windows ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33515</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0389</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|l|00|l|00|_|00|I|00|n|00|_|00|T|00|h|00|e|00|_|00|B|00|o|00|x|00|.|00|A|00|l|00|l|00|B|00|o|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q30&gt;\x22|\x27|)A\x00l\x00l\x00_\x00I\x00n\x00_\x00T\x00h\x00e\x00_\x00B\x00o\x00x\x00.\x00A\x00l\x00l\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q30)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q31&gt;\x22|\x27|)A\x00l\x00l\x00_\x00I\x00n\x00_\x00T\x00h\x00e\x00_\x00B\x00o\x00x\x00.\x00A\x00l\x00l\x00B\x00o\x00x\x00(\.\x00\d\x00)?(?P=q31)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15353</id>
        <msg>WEB-ACTIVEX Web on Windows ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33867</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9A077D0D-B4A6-4EC0-B6CF-98526DF589E4&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9A077D0D-B4A6-4EC0-B6CF-98526DF589E4\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9A077D0D-B4A6-4EC0-B6CF-98526DF589E4\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(DeleteFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15372</id>
        <msg>WEB-ACTIVEX iDefense COMRaider ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33867</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|A|00|0|00|7|00|7|00|D|00|0|00|D|00|-|00|B|00|4|00|A|00|6|00|-|00|4|00|E|00|C|00|0|00|-|00|B|00|6|00|C|00|F|00|-|00|9|00|8|00|5|00|2|00|6|00|D|00|F|00|5|00|8|00|9|00|E|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00A\x000\x007\x007\x00D\x000\x00D\x00-\x00B\x004\x00A\x006\x00-\x004\x00E\x00C\x000\x00-\x00B\x006\x00C\x00F\x00-\x009\x008\x005\x002\x006\x00D\x00F\x005\x008\x009\x00E\x004\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15373</id>
        <msg>WEB-ACTIVEX iDefense COMRaider ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33867</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;vbDevKit.CVariantFileSystem&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22vbDevKit\.CVariantFileSystem(\.\d)?\x22|\x27vbDevKit\.CVariantFileSystem(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DeleteFile\s*|.*(?P=v)\s*\.\s*DeleteFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22vbDevKit\.CVariantFileSystem(\.\d)?\x22|\x27vbDevKit\.CVariantFileSystem(\.\d)?\x27)\s*\)(\s*\.\s*DeleteFile\s*|.*(?P=n)\s*\.\s*DeleteFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15374</id>
        <msg>WEB-ACTIVEX iDefense COMRaider ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33867</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;v|00|b|00|D|00|e|00|v|00|K|00|i|00|t|00|.|00|C|00|V|00|a|00|r|00|i|00|a|00|n|00|t|00|F|00|i|00|l|00|e|00|S|00|y|00|s|00|t|00|e|00|m|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)v\x00b\x00D\x00e\x00v\x00K\x00i\x00t\x00.\x00C\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00F\x00i\x00l\x00e\x00S\x00y\x00s\x00t\x00e\x00m\x00(\.\x00\d\x00)?(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)v\x00b\x00D\x00e\x00v\x00K\x00i\x00t\x00.\x00C\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00F\x00i\x00l\x00e\x00S\x00y\x00s\x00t\x00e\x00m\x00(\.\x00\d\x00)?(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15375</id>
        <msg>WEB-ACTIVEX iDefense COMRaider ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33920</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8FEFF364-6A5F-4966-A917-A3AC28411659&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8FEFF364-6A5F-4966-A917-A3AC28411659\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(SetExternalPlayer)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8FEFF364-6A5F-4966-A917-A3AC28411659\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SetExternalPlayer))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15376</id>
        <msg>WEB-ACTIVEX Sopcast SopCore ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33920</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|F|00|E|00|F|00|F|00|3|00|6|00|4|00|-|00|6|00|A|00|5|00|F|00|-|00|4|00|9|00|6|00|6|00|-|00|A|00|9|00|1|00|7|00|-|00|A|00|3|00|A|00|C|00|2|00|8|00|4|00|1|00|1|00|6|00|5|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q13&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00F\x00E\x00F\x00F\x003\x006\x004\x00-\x006\x00A\x005\x00F\x00-\x004\x009\x006\x006\x00-\x00A\x009\x001\x007\x00-\x00A\x003\x00A\x00C\x002\x008\x004\x001\x001\x006\x005\x009\x00(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15377</id>
        <msg>WEB-ACTIVEX Sopcast SopCore ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33920</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SOPCORE.SopCoreCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SOPCORE\.SopCoreCtrl(\.\d)?\x22|\x27SOPCORE\.SopCoreCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SetExternalPlayer\s*|.*(?P=v)\s*\.\s*SetExternalPlayer\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SOPCORE\.SopCoreCtrl(\.\d)?\x22|\x27SOPCORE\.SopCoreCtrl(\.\d)?\x27)\s*\)(\s*\.\s*SetExternalPlayer\s*|.*(?P=n)\s*\.\s*SetExternalPlayer\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15378</id>
        <msg>WEB-ACTIVEX Sopcast SopCore ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33920</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|O|00|P|00|C|00|O|00|R|00|E|00|.|00|S|00|o|00|p|00|C|00|o|00|r|00|e|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)S\x00O\x00P\x00C\x00O\x00R\x00E\x00.\x00S\x00o\x00p\x00C\x00o\x00r\x00e\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)S\x00O\x00P\x00C\x00O\x00R\x00E\x00.\x00S\x00o\x00p\x00C\x00o\x00r\x00e\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15379</id>
        <msg>WEB-ACTIVEX Sopcast SopCore ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33918</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0208</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00000032-9593-4264-8B29-930B3E4EDCCD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00000032-9593-4264-8B29-930B3E4EDCCD\s*}?\s*(?P=q16)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15380</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms v7 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33918</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0208</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|0|00|0|00|0|00|3|00|2|00|-|00|9|00|5|00|9|00|3|00|-|00|4|00|2|00|6|00|4|00|-|00|8|00|B|00|2|00|9|00|-|00|9|00|3|00|0|00|B|00|3|00|E|00|4|00|E|00|D|00|C|00|C|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q17&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x000\x000\x000\x003\x002\x00-\x009\x005\x009\x003\x00-\x004\x002\x006\x004\x00-\x008\x00B\x002\x009\x00-\x009\x003\x000\x00B\x003\x00E\x004\x00E\x00D\x00C\x00C\x00D\x00(}\x00)?(?P=q17)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15381</id>
        <msg>WEB-ACTIVEX HP Virtual Rooms v7 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-0094</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 137</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15387, policy security-ips drop;</filter2>
        <id>15387</id>
        <msg>NETBIOS udp WINS WPAD registration attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-008.mspx</url>
      </rule>
      <rule>
        <bugtraq>34250</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|01 00 00 00|&quot;; content:&quot; EMF&quot;; within:4; distance:36; byte_jump:4,-40,relative,little; content:&quot;F|00 00 00|,|00 00 00| |00 00 00|&quot;; within:12; distance:-8; content:&quot;F|00 00 00|&quot;; distance:0; content:&quot;|08|@|00 06|&quot;; within:4; distance:12; byte_test:4,&gt;,4261412864,28,relative,little; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15430</id>
        <msg>WEB-CLIENT Microsoft EMF+ GpFont.SetData buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2000-0834</cve>
        <filter1>tcp any [139,445] -&gt; any any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15453, policy balanced-ips drop, policy security-ips drop, service netbios-ns;</filter2>
        <id>15453</id>
        <msg>NETBIOS SMB replay attempt via NTLMSSP - overlapping encryption keys detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1128</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,ppt.download; metadata: engine shared, soid 3|15498, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15498</id>
        <msg>WEB-CLIENT Microsoft PowerPoint CString atom overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0221</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15500, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15500</id>
        <msg>WEB-CLIENT Microsoft PowerPoint LinkedSlide memory corruption</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0224</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15501, service http, policy security-ips drop;</filter2>
        <id>15501</id>
        <msg>WEB-CLIENT Microsoft Powerpoint ParaBuildAtom memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0224</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15502, service http, policy security-ips drop;</filter2>
        <id>15502</id>
        <msg>WEB-CLIENT Microsoft Powerpoint DiagramBuildContainer memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1130</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15505, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15505</id>
        <msg>WEB-CLIENT Microsoft PowerPoint HashCode10Atom memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1131</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15506, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15506</id>
        <msg>WEB-CLIENT Microsoft PowerPoint CurrentUserAtom remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0605</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:3,4; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>15512</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rpcss2 _RemoteGetClassObject attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0605</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:3,4; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>15513</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP rpcss2 _RemoteGetClassObject attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1533</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,works.download; metadata: engine shared, soid 3|15526, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15526</id>
        <msg>EXPLOIT Microsoft Works 4.x converter font name buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-024.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1138</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15527, service ldap, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15527</id>
        <msg>EXPLOIT Microsoft Active Directory LDAP denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-018.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-0230</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15528, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15528</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss RpcSetPrinterDataEx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-022.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1532</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15540, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15540</id>
        <msg>WEB-CLIENT Microsoft IE DOM memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;648A5600-2C6E-101B-82B6-000000000014&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*648A5600-2C6E-101B-82B6-000000000014\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15543</id>
        <msg>WEB-ACTIVEX Microsoft Communications Control v6 ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|4|00|8|00|A|00|5|00|6|00|0|00|0|00|-|00|2|00|C|00|6|00|E|00|-|00|1|00|0|00|1|00|B|00|-|00|8|00|2|00|B|00|6|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|1|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x004\x008\x00A\x005\x006\x000\x000\x00-\x002\x00C\x006\x00E\x00-\x001\x000\x001\x00B\x00-\x008\x002\x00B\x006\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x001\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15544</id>
        <msg>WEB-ACTIVEX Microsoft Communications Control v6 ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MSCOMMLib.MSComm&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MSCOMMLib\.MSComm(\.\d)?\x22|\x27MSCOMMLib\.MSComm(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MSCOMMLib\.MSComm(\.\d)?\x22|\x27MSCOMMLib\.MSComm(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15545</id>
        <msg>WEB-ACTIVEX Microsoft Communications Control v6 ActiveX function call access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|S|00|C|00|O|00|M|00|M|00|L|00|i|00|b|00|.|00|M|00|S|00|C|00|o|00|m|00|m|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)M\x00S\x00C\x00O\x00M\x00M\x00L\x00i\x00b\x00.\x00M\x00S\x00C\x00o\x00m\x00m\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)M\x00S\x00C\x00O\x00M\x00M\x00L\x00i\x00b\x00.\x00M\x00S\x00C\x00o\x00m\x00m\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15546</id>
        <msg>WEB-ACTIVEX Microsoft Communications Control v6 ActiveX function call unicode access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4C39376E-FA9D-4349-BACC-D305C1750EF3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4C39376E-FA9D-4349-BACC-D305C1750EF3\s*}?\s*(?P=q5)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15547</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|C|00|3|00|9|00|3|00|7|00|6|00|E|00|-|00|F|00|A|00|9|00|D|00|-|00|4|00|3|00|4|00|9|00|-|00|B|00|A|00|C|00|C|00|-|00|D|00|3|00|0|00|5|00|C|00|1|00|7|00|5|00|0|00|E|00|F|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x00C\x003\x009\x003\x007\x006\x00E\x00-\x00F\x00A\x009\x00D\x00-\x004\x003\x004\x009\x00-\x00B\x00A\x00C\x00C\x00-\x00D\x003\x000\x005\x00C\x001\x007\x005\x000\x00E\x00F\x003\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15548</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EPUWalControl.EPUImageControl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EPUWalControl\.EPUImageControl(\.\d)?\x22|\x27EPUWalControl\.EPUImageControl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EPUWalControl\.EPUImageControl(\.\d)?\x22|\x27EPUWalControl\.EPUImageControl(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15549</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX function call access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|P|00|U|00|W|00|a|00|l|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|.|00|E|00|P|00|U|00|I|00|m|00|a|00|g|00|e|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)E\x00P\x00U\x00W\x00a\x00l\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00E\x00P\x00U\x00I\x00m\x00a\x00g\x00e\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)E\x00P\x00U\x00W\x00a\x00l\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00E\x00P\x00U\x00I\x00m\x00a\x00g\x00e\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(\.\x00\d\x00)?(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15550</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX function call unicode access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C3EB1670-84E0-4EDA-B570-0B51AAE81679&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C3EB1670-84E0-4EDA-B570-0B51AAE81679\s*}?\s*(?P=q9)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15551</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 2 ActiveX clsid access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|3|00|E|00|B|00|1|00|6|00|7|00|0|00|-|00|8|00|4|00|E|00|0|00|-|00|4|00|E|00|D|00|A|00|-|00|B|00|5|00|7|00|0|00|-|00|0|00|B|00|5|00|1|00|A|00|A|00|E|00|8|00|1|00|6|00|7|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x003\x00E\x00B\x001\x006\x007\x000\x00-\x008\x004\x00E\x000\x00-\x004\x00E\x00D\x00A\x00-\x00B\x005\x007\x000\x00-\x000\x00B\x005\x001\x00A\x00A\x00E\x008\x001\x006\x007\x009\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15552</id>
        <msg>WEB-ACTIVEX eBay Picture Uploads control 2 ActiveX clsid unicode access</msg>
        <url>support.microsoft.com/kb/969898</url>
      </rule>
      <rule>
        <bugtraq>35256</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F6908F83-ADA6-11D0-87AA-00AA00198702&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F6908F83-ADA6-11D0-87AA-00AA00198702\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Accept)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F6908F83-ADA6-11D0-87AA-00AA00198702\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Accept))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15557</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EnjoySAP ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>35256</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|6|00|9|00|0|00|8|00|F|00|8|00|3|00|-|00|A|00|D|00|A|00|6|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|7|00|A|00|A|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|1|00|9|00|8|00|7|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x006\x009\x000\x008\x00F\x008\x003\x00-\x00A\x00D\x00A\x006\x00-\x001\x001\x00D\x000\x00-\x008\x007\x00A\x00A\x00-\x000\x000\x00A\x00A\x000\x000\x001\x009\x008\x007\x000\x002\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15558</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EnjoySAP ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;011B3619-FE63-4814-8A84-15A194CE9CE3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*011B3619-FE63-4814-8A84-15A194CE9CE3\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15588</id>
        <msg>WEB-ACTIVEX Microsoft Video 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|1|00|1|00|B|00|3|00|6|00|1|00|9|00|-|00|F|00|E|00|6|00|3|00|-|00|4|00|8|00|1|00|4|00|-|00|8|00|A|00|8|00|4|00|-|00|1|00|5|00|A|00|1|00|9|00|4|00|C|00|E|00|9|00|C|00|E|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x001\x001\x00B\x003\x006\x001\x009\x00-\x00F\x00E\x006\x003\x00-\x004\x008\x001\x004\x00-\x008\x00A\x008\x004\x00-\x001\x005\x00A\x001\x009\x004\x00C\x00E\x009\x00C\x00E\x003\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15589</id>
        <msg>WEB-ACTIVEX Microsoft Video 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1DF7D126-4050-47F0-A7CF-4C4CA9241333&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1DF7D126-4050-47F0-A7CF-4C4CA9241333\s*}?\s*(?P=q3)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15590</id>
        <msg>WEB-ACTIVEX Microsoft Video 10 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|D|00|F|00|7|00|D|00|1|00|2|00|6|00|-|00|4|00|0|00|5|00|0|00|-|00|4|00|7|00|F|00|0|00|-|00|A|00|7|00|C|00|F|00|-|00|4|00|C|00|4|00|C|00|A|00|9|00|2|00|4|00|1|00|3|00|3|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q4&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00D\x00F\x007\x00D\x001\x002\x006\x00-\x004\x000\x005\x000\x00-\x004\x007\x00F\x000\x00-\x00A\x007\x00C\x00F\x00-\x004\x00C\x004\x00C\x00A\x009\x002\x004\x001\x003\x003\x003\x00(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15591</id>
        <msg>WEB-ACTIVEX Microsoft Video 10 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2C63E4EB-4CEA-41B8-919C-E947EA19A77C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2C63E4EB-4CEA-41B8-919C-E947EA19A77C\s*}?\s*(?P=q5)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15592</id>
        <msg>WEB-ACTIVEX Microsoft Video 11 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|C|00|6|00|3|00|E|00|4|00|E|00|B|00|-|00|4|00|C|00|E|00|A|00|-|00|4|00|1|00|B|00|8|00|-|00|9|00|1|00|9|00|C|00|-|00|E|00|9|00|4|00|7|00|E|00|A|00|1|00|9|00|A|00|7|00|7|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00C\x006\x003\x00E\x004\x00E\x00B\x00-\x004\x00C\x00E\x00A\x00-\x004\x001\x00B\x008\x00-\x009\x001\x009\x00C\x00-\x00E\x009\x004\x007\x00E\x00A\x001\x009\x00A\x007\x007\x00C\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15593</id>
        <msg>WEB-ACTIVEX Microsoft Video 11 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;334125C0-77E5-11D3-B653-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*334125C0-77E5-11D3-B653-00C04F79498E\s*}?\s*(?P=q7)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15594</id>
        <msg>WEB-ACTIVEX Microsoft Video 12 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|4|00|1|00|2|00|5|00|C|00|0|00|-|00|7|00|7|00|E|00|5|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|3|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x003\x004\x001\x002\x005\x00C\x000\x00-\x007\x007\x00E\x005\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x003\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15595</id>
        <msg>WEB-ACTIVEX Microsoft Video 12 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;37B0353C-A4C8-11D2-B634-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*37B0353C-A4C8-11D2-B634-00C04F79498E\s*}?\s*(?P=q9)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15596</id>
        <msg>WEB-ACTIVEX Microsoft Video 13 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|7|00|B|00|0|00|3|00|5|00|3|00|C|00|-|00|A|00|4|00|C|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|6|00|3|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x007\x00B\x000\x003\x005\x003\x00C\x00-\x00A\x004\x00C\x008\x00-\x001\x001\x00D\x002\x00-\x00B\x006\x003\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15597</id>
        <msg>WEB-ACTIVEX Microsoft Video 13 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;37B03543-A4C8-11D2-B634-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*37B03543-A4C8-11D2-B634-00C04F79498E\s*}?\s*(?P=q11)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15598</id>
        <msg>WEB-ACTIVEX Microsoft Video 14 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|7|00|B|00|0|00|3|00|5|00|4|00|3|00|-|00|A|00|4|00|C|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|6|00|3|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q12&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x007\x00B\x000\x003\x005\x004\x003\x00-\x00A\x004\x00C\x008\x00-\x001\x001\x00D\x002\x00-\x00B\x006\x003\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15599</id>
        <msg>WEB-ACTIVEX Microsoft Video 14 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;37B03544-A4C8-11D2-B634-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*37B03544-A4C8-11D2-B634-00C04F79498E\s*}?\s*(?P=q13)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15600</id>
        <msg>WEB-ACTIVEX Microsoft Video 15 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|7|00|B|00|0|00|3|00|5|00|4|00|4|00|-|00|A|00|4|00|C|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|6|00|3|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q14&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x007\x00B\x000\x003\x005\x004\x004\x00-\x00A\x004\x00C\x008\x00-\x001\x001\x00D\x002\x00-\x00B\x006\x003\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15601</id>
        <msg>WEB-ACTIVEX Microsoft Video 15 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;418008F3-CF67-4668-9628-10DC52BE1D08&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*418008F3-CF67-4668-9628-10DC52BE1D08\s*}?\s*(?P=q15)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15602</id>
        <msg>WEB-ACTIVEX Microsoft Video 16 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|8|00|0|00|0|00|8|00|F|00|3|00|-|00|C|00|F|00|6|00|7|00|-|00|4|00|6|00|6|00|8|00|-|00|9|00|6|00|2|00|8|00|-|00|1|00|0|00|D|00|C|00|5|00|2|00|B|00|E|00|1|00|D|00|0|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q16&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x001\x008\x000\x000\x008\x00F\x003\x00-\x00C\x00F\x006\x007\x00-\x004\x006\x006\x008\x00-\x009\x006\x002\x008\x00-\x001\x000\x00D\x00C\x005\x002\x00B\x00E\x001\x00D\x000\x008\x00(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15603</id>
        <msg>WEB-ACTIVEX Microsoft Video 16 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4A5869CF-929D-4040-AE03-FCAFC5B9CD42&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4A5869CF-929D-4040-AE03-FCAFC5B9CD42\s*}?\s*(?P=q17)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15604</id>
        <msg>WEB-ACTIVEX Microsoft Video 17 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|A|00|5|00|8|00|6|00|9|00|C|00|F|00|-|00|9|00|2|00|9|00|D|00|-|00|4|00|0|00|4|00|0|00|-|00|A|00|E|00|0|00|3|00|-|00|F|00|C|00|A|00|F|00|C|00|5|00|B|00|9|00|C|00|D|00|4|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q18&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x00A\x005\x008\x006\x009\x00C\x00F\x00-\x009\x002\x009\x00D\x00-\x004\x000\x004\x000\x00-\x00A\x00E\x000\x003\x00-\x00F\x00C\x00A\x00F\x00C\x005\x00B\x009\x00C\x00D\x004\x002\x00(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15605</id>
        <msg>WEB-ACTIVEX Microsoft Video 17 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;577FAA18-4518-445E-8F70-1473F8CF4BA4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*577FAA18-4518-445E-8F70-1473F8CF4BA4\s*}?\s*(?P=q19)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15606</id>
        <msg>WEB-ACTIVEX Microsoft Video 18 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|7|00|7|00|F|00|A|00|A|00|1|00|8|00|-|00|4|00|5|00|1|00|8|00|-|00|4|00|4|00|5|00|E|00|-|00|8|00|F|00|7|00|0|00|-|00|1|00|4|00|7|00|3|00|F|00|8|00|C|00|F|00|4|00|B|00|A|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q20&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x007\x007\x00F\x00A\x00A\x001\x008\x00-\x004\x005\x001\x008\x00-\x004\x004\x005\x00E\x00-\x008\x00F\x007\x000\x00-\x001\x004\x007\x003\x00F\x008\x00C\x00F\x004\x00B\x00A\x004\x00(}\x00)?(?P=q20)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15607</id>
        <msg>WEB-ACTIVEX Microsoft Video 18 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;59DC47A8-116C-11D3-9D8E-00C04F72D980&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*59DC47A8-116C-11D3-9D8E-00C04F72D980\s*}?\s*(?P=q21)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15608</id>
        <msg>WEB-ACTIVEX Microsoft Video 19 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|9|00|D|00|C|00|4|00|7|00|A|00|8|00|-|00|1|00|1|00|6|00|C|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|D|00|8|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|2|00|D|00|9|00|8|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q22&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x009\x00D\x00C\x004\x007\x00A\x008\x00-\x001\x001\x006\x00C\x00-\x001\x001\x00D\x003\x00-\x009\x00D\x008\x00E\x00-\x000\x000\x00C\x000\x004\x00F\x007\x002\x00D\x009\x008\x000\x00(}\x00)?(?P=q22)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15609</id>
        <msg>WEB-ACTIVEX Microsoft Video 19 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0149EEDF-D08F-4142-8D73-D23903D21E90&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q23&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0149EEDF-D08F-4142-8D73-D23903D21E90\s*}?\s*(?P=q23)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15610</id>
        <msg>WEB-ACTIVEX Microsoft Video 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|1|00|4|00|9|00|E|00|E|00|D|00|F|00|-|00|D|00|0|00|8|00|F|00|-|00|4|00|1|00|4|00|2|00|-|00|8|00|D|00|7|00|3|00|-|00|D|00|2|00|3|00|9|00|0|00|3|00|D|00|2|00|1|00|E|00|9|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q24&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x001\x004\x009\x00E\x00E\x00D\x00F\x00-\x00D\x000\x008\x00F\x00-\x004\x001\x004\x002\x00-\x008\x00D\x007\x003\x00-\x00D\x002\x003\x009\x000\x003\x00D\x002\x001\x00E\x009\x000\x00(}\x00)?(?P=q24)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15611</id>
        <msg>WEB-ACTIVEX Microsoft Video 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7F9CB14D-48E4-43B6-9346-1AEBC39C64D3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7F9CB14D-48E4-43B6-9346-1AEBC39C64D3\s*}?\s*(?P=q25)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15612</id>
        <msg>WEB-ACTIVEX Microsoft Video 20 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|F|00|9|00|C|00|B|00|1|00|4|00|D|00|-|00|4|00|8|00|E|00|4|00|-|00|4|00|3|00|B|00|6|00|-|00|9|00|3|00|4|00|6|00|-|00|1|00|A|00|E|00|B|00|C|00|3|00|9|00|C|00|6|00|4|00|D|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q26&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00F\x009\x00C\x00B\x001\x004\x00D\x00-\x004\x008\x00E\x004\x00-\x004\x003\x00B\x006\x00-\x009\x003\x004\x006\x00-\x001\x00A\x00E\x00B\x00C\x003\x009\x00C\x006\x004\x00D\x003\x00(}\x00)?(?P=q26)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15613</id>
        <msg>WEB-ACTIVEX Microsoft Video 20 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;823535A0-0318-11D3-9D8E-00C04F72D980&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*823535A0-0318-11D3-9D8E-00C04F72D980\s*}?\s*(?P=q27)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15614</id>
        <msg>WEB-ACTIVEX Microsoft Video 21 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|2|00|3|00|5|00|3|00|5|00|A|00|0|00|-|00|0|00|3|00|1|00|8|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|D|00|8|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|2|00|D|00|9|00|8|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q28&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x002\x003\x005\x003\x005\x00A\x000\x00-\x000\x003\x001\x008\x00-\x001\x001\x00D\x003\x00-\x009\x00D\x008\x00E\x00-\x000\x000\x00C\x000\x004\x00F\x007\x002\x00D\x009\x008\x000\x00(}\x00)?(?P=q28)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15615</id>
        <msg>WEB-ACTIVEX Microsoft Video 21 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8872FF1B-98FA-4D7A-8D93-C9F1055F85BB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q29&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8872FF1B-98FA-4D7A-8D93-C9F1055F85BB\s*}?\s*(?P=q29)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15616</id>
        <msg>WEB-ACTIVEX Microsoft Video 22 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|8|00|7|00|2|00|F|00|F|00|1|00|B|00|-|00|9|00|8|00|F|00|A|00|-|00|4|00|D|00|7|00|A|00|-|00|8|00|D|00|9|00|3|00|-|00|C|00|9|00|F|00|1|00|0|00|5|00|5|00|F|00|8|00|5|00|B|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q30&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x008\x007\x002\x00F\x00F\x001\x00B\x00-\x009\x008\x00F\x00A\x00-\x004\x00D\x007\x00A\x00-\x008\x00D\x009\x003\x00-\x00C\x009\x00F\x001\x000\x005\x005\x00F\x008\x005\x00B\x00B\x00(}\x00)?(?P=q30)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15617</id>
        <msg>WEB-ACTIVEX Microsoft Video 22 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8A674B4C-1F63-11D3-B64C-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q31&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8A674B4C-1F63-11D3-B64C-00C04F79498E\s*}?\s*(?P=q31)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15618</id>
        <msg>WEB-ACTIVEX Microsoft Video 23 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|A|00|6|00|7|00|4|00|B|00|4|00|C|00|-|00|1|00|F|00|6|00|3|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|4|00|C|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q32&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00A\x006\x007\x004\x00B\x004\x00C\x00-\x001\x00F\x006\x003\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x004\x00C\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q32)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15619</id>
        <msg>WEB-ACTIVEX Microsoft Video 23 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8A674B4D-1F63-11D3-B64C-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q33&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8A674B4D-1F63-11D3-B64C-00C04F79498E\s*}?\s*(?P=q33)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15620</id>
        <msg>WEB-ACTIVEX Microsoft Video 24 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|A|00|6|00|7|00|4|00|B|00|4|00|D|00|-|00|1|00|F|00|6|00|3|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|4|00|C|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q34&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00A\x006\x007\x004\x00B\x004\x00D\x00-\x001\x00F\x006\x003\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x004\x00C\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q34)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15621</id>
        <msg>WEB-ACTIVEX Microsoft Video 24 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9CD64701-BDF3-4D14-8E03-F12983D86664&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q35&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9CD64701-BDF3-4D14-8E03-F12983D86664\s*}?\s*(?P=q35)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15622</id>
        <msg>WEB-ACTIVEX Microsoft Video 25 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|C|00|D|00|6|00|4|00|7|00|0|00|1|00|-|00|B|00|D|00|F|00|3|00|-|00|4|00|D|00|1|00|4|00|-|00|8|00|E|00|0|00|3|00|-|00|F|00|1|00|2|00|9|00|8|00|3|00|D|00|8|00|6|00|6|00|6|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q36&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00C\x00D\x006\x004\x007\x000\x001\x00-\x00B\x00D\x00F\x003\x00-\x004\x00D\x001\x004\x00-\x008\x00E\x000\x003\x00-\x00F\x001\x002\x009\x008\x003\x00D\x008\x006\x006\x006\x004\x00(}\x00)?(?P=q36)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15623</id>
        <msg>WEB-ACTIVEX Microsoft Video 25 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9E77AAC4-35E5-42A1-BDC2-8F3FF399847C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q37&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9E77AAC4-35E5-42A1-BDC2-8F3FF399847C\s*}?\s*(?P=q37)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15624</id>
        <msg>WEB-ACTIVEX Microsoft Video 26 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|E|00|7|00|7|00|A|00|A|00|C|00|4|00|-|00|3|00|5|00|E|00|5|00|-|00|4|00|2|00|A|00|1|00|-|00|B|00|D|00|C|00|2|00|-|00|8|00|F|00|3|00|F|00|F|00|3|00|9|00|9|00|8|00|4|00|7|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q38&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x00E\x007\x007\x00A\x00A\x00C\x004\x00-\x003\x005\x00E\x005\x00-\x004\x002\x00A\x001\x00-\x00B\x00D\x00C\x002\x00-\x008\x00F\x003\x00F\x00F\x003\x009\x009\x008\x004\x007\x00C\x00(}\x00)?(?P=q38)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15625</id>
        <msg>WEB-ACTIVEX Microsoft Video 26 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q39&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980\s*}?\s*(?P=q39)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15626</id>
        <msg>WEB-ACTIVEX Microsoft Video 27 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|1|00|A|00|2|00|B|00|1|00|C|00|4|00|-|00|0|00|E|00|3|00|A|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|D|00|8|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|2|00|D|00|9|00|8|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q40&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x001\x00A\x002\x00B\x001\x00C\x004\x00-\x000\x00E\x003\x00A\x00-\x001\x001\x00D\x003\x00-\x009\x00D\x008\x00E\x00-\x000\x000\x00C\x000\x004\x00F\x007\x002\x00D\x009\x008\x000\x00(}\x00)?(?P=q40)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15627</id>
        <msg>WEB-ACTIVEX Microsoft Video 27 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A2E3074E-6C3D-11D3-B653-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q41&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A2E3074E-6C3D-11D3-B653-00C04F79498E\s*}?\s*(?P=q41)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15628</id>
        <msg>WEB-ACTIVEX Microsoft Video 28 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|2|00|E|00|3|00|0|00|7|00|4|00|E|00|-|00|6|00|C|00|3|00|D|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|3|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q42&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x002\x00E\x003\x000\x007\x004\x00E\x00-\x006\x00C\x003\x00D\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x003\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q42)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15629</id>
        <msg>WEB-ACTIVEX Microsoft Video 28 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A2E30750-6C3D-11D3-B653-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q43&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A2E30750-6C3D-11D3-B653-00C04F79498E\s*}?\s*(?P=q43)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15630</id>
        <msg>WEB-ACTIVEX Microsoft Video 29 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|2|00|E|00|3|00|0|00|7|00|5|00|0|00|-|00|6|00|C|00|3|00|D|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|3|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q44&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x002\x00E\x003\x000\x007\x005\x000\x00-\x006\x00C\x003\x00D\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x003\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q44)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15631</id>
        <msg>WEB-ACTIVEX Microsoft Video 29 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0369B4E5-45B6-11D3-B650-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q45&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0369B4E5-45B6-11D3-B650-00C04F79498E\s*}?\s*(?P=q45)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15632</id>
        <msg>WEB-ACTIVEX Microsoft Video 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|3|00|6|00|9|00|B|00|4|00|E|00|5|00|-|00|4|00|5|00|B|00|6|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|0|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q46&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x003\x006\x009\x00B\x004\x00E\x005\x00-\x004\x005\x00B\x006\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x000\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q46)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15633</id>
        <msg>WEB-ACTIVEX Microsoft Video 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q47&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE\s*}?\s*(?P=q47)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15634</id>
        <msg>WEB-ACTIVEX Microsoft Video 30 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|8|00|D|00|C|00|F|00|3|00|D|00|5|00|-|00|0|00|7|00|8|00|0|00|-|00|4|00|E|00|F|00|4|00|-|00|8|00|A|00|8|00|3|00|-|00|2|00|C|00|F|00|F|00|A|00|A|00|C|00|B|00|8|00|A|00|C|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q48&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x008\x00D\x00C\x00F\x003\x00D\x005\x00-\x000\x007\x008\x000\x00-\x004\x00E\x00F\x004\x00-\x008\x00A\x008\x003\x00-\x002\x00C\x00F\x00F\x00A\x00A\x00C\x00B\x008\x00A\x00C\x00E\x00(}\x00)?(?P=q48)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15635</id>
        <msg>WEB-ACTIVEX Microsoft Video 30 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AD8E510D-217F-409B-8076-29C5E73B98E8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q49&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AD8E510D-217F-409B-8076-29C5E73B98E8\s*}?\s*(?P=q49)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15636</id>
        <msg>WEB-ACTIVEX Microsoft Video 31 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|D|00|8|00|E|00|5|00|1|00|0|00|D|00|-|00|2|00|1|00|7|00|F|00|-|00|4|00|0|00|9|00|B|00|-|00|8|00|0|00|7|00|6|00|-|00|2|00|9|00|C|00|5|00|E|00|7|00|3|00|B|00|9|00|8|00|E|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q50&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00D\x008\x00E\x005\x001\x000\x00D\x00-\x002\x001\x007\x00F\x00-\x004\x000\x009\x00B\x00-\x008\x000\x007\x006\x00-\x002\x009\x00C\x005\x00E\x007\x003\x00B\x009\x008\x00E\x008\x00(}\x00)?(?P=q50)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15637</id>
        <msg>WEB-ACTIVEX Microsoft Video 31 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2494</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B0EDF163-910A-11D2-B632-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B0EDF163-910A-11D2-B632-00C04F79498E\s*}?\s*(?P=q9)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15638</id>
        <msg>WEB-ACTIVEX Microsoft Video 32 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2494</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|E|00|D|00|F|00|1|00|6|00|3|00|-|00|9|00|1|00|0|00|A|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|6|00|3|00|2|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x000\x00E\x00D\x00F\x001\x006\x003\x00-\x009\x001\x000\x00A\x00-\x001\x001\x00D\x002\x00-\x00B\x006\x003\x002\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15639</id>
        <msg>WEB-ACTIVEX Microsoft Video 32 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B64016F3-C9A2-4066-96F0-BD9563314726&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q53&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B64016F3-C9A2-4066-96F0-BD9563314726\s*}?\s*(?P=q53)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15640</id>
        <msg>WEB-ACTIVEX Microsoft Video 33 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|6|00|4|00|0|00|1|00|6|00|F|00|3|00|-|00|C|00|9|00|A|00|2|00|-|00|4|00|0|00|6|00|6|00|-|00|9|00|6|00|F|00|0|00|-|00|B|00|D|00|9|00|5|00|6|00|3|00|3|00|1|00|4|00|7|00|2|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q54&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x006\x004\x000\x001\x006\x00F\x003\x00-\x00C\x009\x00A\x002\x00-\x004\x000\x006\x006\x00-\x009\x006\x00F\x000\x00-\x00B\x00D\x009\x005\x006\x003\x003\x001\x004\x007\x002\x006\x00(}\x00)?(?P=q54)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15641</id>
        <msg>WEB-ACTIVEX Microsoft Video 33 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BB530C63-D9DF-4B49-9439-63453962E598&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q55&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BB530C63-D9DF-4B49-9439-63453962E598\s*}?\s*(?P=q55)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15642</id>
        <msg>WEB-ACTIVEX Microsoft Video 34 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|B|00|5|00|3|00|0|00|C|00|6|00|3|00|-|00|D|00|9|00|D|00|F|00|-|00|4|00|B|00|4|00|9|00|-|00|9|00|4|00|3|00|9|00|-|00|6|00|3|00|4|00|5|00|3|00|9|00|6|00|2|00|E|00|5|00|9|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q56&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00B\x005\x003\x000\x00C\x006\x003\x00-\x00D\x009\x00D\x00F\x00-\x004\x00B\x004\x009\x00-\x009\x004\x003\x009\x00-\x006\x003\x004\x005\x003\x009\x006\x002\x00E\x005\x009\x008\x00(}\x00)?(?P=q56)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15643</id>
        <msg>WEB-ACTIVEX Microsoft Video 34 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C531D9FD-9685-4028-8B68-6E1232079F1E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q57&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C531D9FD-9685-4028-8B68-6E1232079F1E\s*}?\s*(?P=q57)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15644</id>
        <msg>WEB-ACTIVEX Microsoft Video 35 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|3|00|1|00|D|00|9|00|F|00|D|00|-|00|9|00|6|00|8|00|5|00|-|00|4|00|0|00|2|00|8|00|-|00|8|00|B|00|6|00|8|00|-|00|6|00|E|00|1|00|2|00|3|00|2|00|0|00|7|00|9|00|F|00|1|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q58&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x003\x001\x00D\x009\x00F\x00D\x00-\x009\x006\x008\x005\x00-\x004\x000\x002\x008\x00-\x008\x00B\x006\x008\x00-\x006\x00E\x001\x002\x003\x002\x000\x007\x009\x00F\x001\x00E\x00(}\x00)?(?P=q58)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15645</id>
        <msg>WEB-ACTIVEX Microsoft Video 35 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C5702CCC-9B79-11D3-B654-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q59&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C5702CCC-9B79-11D3-B654-00C04F79498E\s*}?\s*(?P=q59)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15646</id>
        <msg>WEB-ACTIVEX Microsoft Video 36 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|7|00|0|00|2|00|C|00|C|00|C|00|-|00|9|00|B|00|7|00|9|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q60&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x007\x000\x002\x00C\x00C\x00C\x00-\x009\x00B\x007\x009\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q60)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15647</id>
        <msg>WEB-ACTIVEX Microsoft Video 36 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C5702CCD-9B79-11D3-B654-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q61&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C5702CCD-9B79-11D3-B654-00C04F79498E\s*}?\s*(?P=q61)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15648</id>
        <msg>WEB-ACTIVEX Microsoft Video 37 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|7|00|0|00|2|00|C|00|C|00|D|00|-|00|9|00|B|00|7|00|9|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q62&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x007\x000\x002\x00C\x00C\x00D\x00-\x009\x00B\x007\x009\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q62)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15649</id>
        <msg>WEB-ACTIVEX Microsoft Video 37 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C5702CCE-9B79-11D3-B654-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q63&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C5702CCE-9B79-11D3-B654-00C04F79498E\s*}?\s*(?P=q63)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15650</id>
        <msg>WEB-ACTIVEX Microsoft Video 38 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|7|00|0|00|2|00|C|00|C|00|E|00|-|00|9|00|B|00|7|00|9|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q64&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x007\x000\x002\x00C\x00C\x00E\x00-\x009\x00B\x007\x009\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q64)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15651</id>
        <msg>WEB-ACTIVEX Microsoft Video 38 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C5702CCF-9B79-11D3-B654-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q65&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C5702CCF-9B79-11D3-B654-00C04F79498E\s*}?\s*(?P=q65)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15652</id>
        <msg>WEB-ACTIVEX Microsoft Video 39 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|7|00|0|00|2|00|C|00|C|00|F|00|-|00|9|00|B|00|7|00|9|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q66&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x007\x000\x002\x00C\x00C\x00F\x00-\x009\x00B\x007\x009\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q66)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15653</id>
        <msg>WEB-ACTIVEX Microsoft Video 39 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0369B4E6-45B6-11D3-B650-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q67&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0369B4E6-45B6-11D3-B650-00C04F79498E\s*}?\s*(?P=q67)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15654</id>
        <msg>WEB-ACTIVEX Microsoft Video 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|3|00|6|00|9|00|B|00|4|00|E|00|6|00|-|00|4|00|5|00|B|00|6|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|0|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q68&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x003\x006\x009\x00B\x004\x00E\x006\x00-\x004\x005\x00B\x006\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x000\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q68)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15655</id>
        <msg>WEB-ACTIVEX Microsoft Video 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C5702CD0-9B79-11D3-B654-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q69&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C5702CD0-9B79-11D3-B654-00C04F79498E\s*}?\s*(?P=q69)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15656</id>
        <msg>WEB-ACTIVEX Microsoft Video 40 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|5|00|7|00|0|00|2|00|C|00|D|00|0|00|-|00|9|00|B|00|7|00|9|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|6|00|5|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q70&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x005\x007\x000\x002\x00C\x00D\x000\x00-\x009\x00B\x007\x009\x00-\x001\x001\x00D\x003\x00-\x00B\x006\x005\x004\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q70)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15657</id>
        <msg>WEB-ACTIVEX Microsoft Video 40 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q71&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7\s*}?\s*(?P=q71)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15658</id>
        <msg>WEB-ACTIVEX Microsoft Video 41 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|6|00|B|00|1|00|4|00|B|00|3|00|2|00|-|00|7|00|6|00|A|00|A|00|-|00|4|00|A|00|8|00|6|00|-|00|A|00|7|00|A|00|C|00|-|00|5|00|C|00|7|00|9|00|A|00|A|00|F|00|5|00|8|00|D|00|A|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q72&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x006\x00B\x001\x004\x00B\x003\x002\x00-\x007\x006\x00A\x00A\x00-\x004\x00A\x008\x006\x00-\x00A\x007\x00A\x00C\x00-\x005\x00C\x007\x009\x00A\x00A\x00F\x005\x008\x00D\x00A\x007\x00(}\x00)?(?P=q72)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15659</id>
        <msg>WEB-ACTIVEX Microsoft Video 41 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CAAFDD83-CEFC-4E3D-BA03-175F17A24F91&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q73&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CAAFDD83-CEFC-4E3D-BA03-175F17A24F91\s*}?\s*(?P=q73)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15660</id>
        <msg>WEB-ACTIVEX Microsoft Video 42 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|A|00|A|00|F|00|D|00|D|00|8|00|3|00|-|00|C|00|E|00|F|00|C|00|-|00|4|00|E|00|3|00|D|00|-|00|B|00|A|00|0|00|3|00|-|00|1|00|7|00|5|00|F|00|1|00|7|00|A|00|2|00|4|00|F|00|9|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q74&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00A\x00A\x00F\x00D\x00D\x008\x003\x00-\x00C\x00E\x00F\x00C\x00-\x004\x00E\x003\x00D\x00-\x00B\x00A\x000\x003\x00-\x001\x007\x005\x00F\x001\x007\x00A\x002\x004\x00F\x009\x001\x00(}\x00)?(?P=q74)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15661</id>
        <msg>WEB-ACTIVEX Microsoft Video 42 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D02AAC50-027E-11D3-9D8E-00C04F72D980&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q75&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D02AAC50-027E-11D3-9D8E-00C04F72D980\s*}?\s*(?P=q75)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15662</id>
        <msg>WEB-ACTIVEX Microsoft Video 43 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|0|00|2|00|A|00|A|00|C|00|5|00|0|00|-|00|0|00|2|00|7|00|E|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|D|00|8|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|2|00|D|00|9|00|8|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q76&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x000\x002\x00A\x00A\x00C\x005\x000\x00-\x000\x002\x007\x00E\x00-\x001\x001\x00D\x003\x00-\x009\x00D\x008\x00E\x00-\x000\x000\x00C\x000\x004\x00F\x007\x002\x00D\x009\x008\x000\x00(}\x00)?(?P=q76)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15663</id>
        <msg>WEB-ACTIVEX Microsoft Video 43 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F9769A06-7ACA-4E39-9CFB-97BB35F0E77E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q77&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F9769A06-7ACA-4E39-9CFB-97BB35F0E77E\s*}?\s*(?P=q77)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15664</id>
        <msg>WEB-ACTIVEX Microsoft Video 44 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|9|00|7|00|6|00|9|00|A|00|0|00|6|00|-|00|7|00|A|00|C|00|A|00|-|00|4|00|E|00|3|00|9|00|-|00|9|00|C|00|F|00|B|00|-|00|9|00|7|00|B|00|B|00|3|00|5|00|F|00|0|00|E|00|7|00|7|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q78&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x009\x007\x006\x009\x00A\x000\x006\x00-\x007\x00A\x00C\x00A\x00-\x004\x00E\x003\x009\x00-\x009\x00C\x00F\x00B\x00-\x009\x007\x00B\x00B\x003\x005\x00F\x000\x00E\x007\x007\x00E\x00(}\x00)?(?P=q78)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15665</id>
        <msg>WEB-ACTIVEX Microsoft Video 44 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FA7C375B-66A7-4280-879D-FD459C84BB02&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q79&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FA7C375B-66A7-4280-879D-FD459C84BB02\s*}?\s*(?P=q79)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15666</id>
        <msg>WEB-ACTIVEX Microsoft Video 45 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|A|00|7|00|C|00|3|00|7|00|5|00|B|00|-|00|6|00|6|00|A|00|7|00|-|00|4|00|2|00|8|00|0|00|-|00|8|00|7|00|9|00|D|00|-|00|F|00|D|00|4|00|5|00|9|00|C|00|8|00|4|00|B|00|B|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q80&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00A\x007\x00C\x003\x007\x005\x00B\x00-\x006\x006\x00A\x007\x00-\x004\x002\x008\x000\x00-\x008\x007\x009\x00D\x00-\x00F\x00D\x004\x005\x009\x00C\x008\x004\x00B\x00B\x000\x002\x00(}\x00)?(?P=q80)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15667</id>
        <msg>WEB-ACTIVEX Microsoft Video 45 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;055CB2D7-2969-45CD-914B-76890722F112&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q81&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*055CB2D7-2969-45CD-914B-76890722F112\s*}?\s*(?P=q81)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15668</id>
        <msg>WEB-ACTIVEX Microsoft Video 5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|5|00|5|00|C|00|B|00|2|00|D|00|7|00|-|00|2|00|9|00|6|00|9|00|-|00|4|00|5|00|C|00|D|00|-|00|9|00|1|00|4|00|B|00|-|00|7|00|6|00|8|00|9|00|0|00|7|00|2|00|2|00|F|00|1|00|1|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q82&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x005\x005\x00C\x00B\x002\x00D\x007\x00-\x002\x009\x006\x009\x00-\x004\x005\x00C\x00D\x00-\x009\x001\x004\x00B\x00-\x007\x006\x008\x009\x000\x007\x002\x002\x00F\x001\x001\x002\x00(}\x00)?(?P=q82)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15669</id>
        <msg>WEB-ACTIVEX Microsoft Video 5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <bugtraq>35558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0955AC62-BF2E-4CBA-A2B9-A63F772D46CF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0955AC62-BF2E-4CBA-A2B9-A63F772D46CF\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15670</id>
        <msg>WEB-ACTIVEX Microsoft Video 6 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <bugtraq>35558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|9|00|5|00|5|00|A|00|C|00|6|00|2|00|-|00|B|00|F|00|2|00|E|00|-|00|4|00|C|00|B|00|A|00|-|00|A|00|2|00|B|00|9|00|-|00|A|00|6|00|3|00|F|00|7|00|7|00|2|00|D|00|4|00|6|00|C|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x009\x005\x005\x00A\x00C\x006\x002\x00-\x00B\x00F\x002\x00E\x00-\x004\x00C\x00B\x00A\x00-\x00A\x002\x00B\x009\x00-\x00A\x006\x003\x00F\x007\x007\x002\x00D\x004\x006\x00C\x00F\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15671</id>
        <msg>WEB-ACTIVEX Microsoft Video 6 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;15D6504A-5494-499C-886C-973C9E53B9F1&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15672</id>
        <msg>WEB-ACTIVEX Microsoft Video 7 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1BE49F30-0E1B-11D3-9D8E-00C04F72D980&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q87&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1BE49F30-0E1B-11D3-9D8E-00C04F72D980\s*}?\s*(?P=q87)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15674</id>
        <msg>WEB-ACTIVEX Microsoft Video 8 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|B|00|E|00|4|00|9|00|F|00|3|00|0|00|-|00|0|00|E|00|1|00|B|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|D|00|8|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|2|00|D|00|9|00|8|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q88&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00B\x00E\x004\x009\x00F\x003\x000\x00-\x000\x00E\x001\x00B\x00-\x001\x001\x00D\x003\x00-\x009\x00D\x008\x00E\x00-\x000\x000\x00C\x000\x004\x00F\x007\x002\x00D\x009\x008\x000\x00(}\x00)?(?P=q88)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15675</id>
        <msg>WEB-ACTIVEX Microsoft Video 8 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1C15D484-911D-11D2-B632-00C04F79498E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q89&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*1C15D484-911D-11D2-B632-00C04F79498E\s*}?\s*(?P=q89)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15676</id>
        <msg>WEB-ACTIVEX Microsoft Video 9 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|C|00|1|00|5|00|D|00|4|00|8|00|4|00|-|00|9|00|1|00|1|00|D|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|6|00|3|00|2|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|7|00|9|00|4|00|9|00|8|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q90&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x00C\x001\x005\x00D\x004\x008\x004\x00-\x009\x001\x001\x00D\x00-\x001\x001\x00D\x002\x00-\x00B\x006\x003\x002\x00-\x000\x000\x00C\x000\x004\x00F\x007\x009\x004\x009\x008\x00E\x00(}\x00)?(?P=q90)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15677</id>
        <msg>WEB-ACTIVEX Microsoft Video 9 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2004-0540</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>flow:to_server; content:&quot;0|17 A0 03 02 01 02 A1 10|0|0E 1B 06|krbtgt|1B 04|A123&quot;; content:&quot;|0F|n|FB C0|&quot;; distance:0; metadata:policy security-ips drop, service kerberos; classtype:attempted-user;</filter2>
        <id>15701</id>
        <msg>SPECIFIC-THREATS Microsoft Windows 2000 domain authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>35396</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-1761</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:19; dce_stub_data; byte_test:4,=,1,0,relative,dce; byte_test:4,&gt;,64000,8,relative,dce; byte_test:4,=,0,12,relative,dce; byte_test:4,&gt;,64000,16,relative,dce; content:&quot;|05 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-dos;</filter2>
        <id>15702</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x13 overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35396</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-1761</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:59; dce_stub_data; content:&quot;|00 00 00 00 00 00 00 00|&quot;; within:8; distance:8; content:&quot;|05 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-dos;</filter2>
        <id>15710</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x3B null strings attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2000-0834</cve>
        <filter1>tcp any 23 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15847, policy balanced-ips drop, policy security-ips drop, service telnet;</filter2>
        <id>15847</id>
        <msg>NETBIOS Telnet-based NTLM replay attack attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1923</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15848, service netbios-ns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15848</id>
        <msg>EXPLOIT WINS replication request memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1924</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15849, service netbios-ns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15849</id>
        <msg>EXPLOIT WINS replication inform2 request memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-1536</cve>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; detection_filter:track by_dst, count 12, seconds 60; metadata: engine shared, soid 3|15851, service http, policy balanced-ips alert, policy security-ips alert;</filter2>
        <id>15851</id>
        <msg>DOS Microsoft ASP.NET bad request denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>35970</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15854, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15854</id>
        <msg>WEB-CLIENT Microsoft Windows AVIFile media file processing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15857, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15857</id>
        <msg>WEB-CLIENT Microsoft Windows AVIFile media file invalid header length</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-038.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1544</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15860, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15860</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrGetJoinInformation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1929</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15861, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15861</id>
        <msg>WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX clsid access </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1929</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15863, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15863</id>
        <msg>WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX function call access </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2627</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3895DD35-7573-11D2-8FED-00606730D3AA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3895DD35-7573-11D2-8FED-00606730D3AA\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Run)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3895DD35-7573-11D2-8FED-00606730D3AA\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Run))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15878</id>
        <msg>WEB-ACTIVEX AcerCtrls.APlunch ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/485961</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2627</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|8|00|9|00|5|00|D|00|D|00|3|00|5|00|-|00|7|00|5|00|7|00|3|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|F|00|E|00|D|00|-|00|0|00|0|00|6|00|0|00|6|00|7|00|3|00|0|00|D|00|3|00|A|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x008\x009\x005\x00D\x00D\x003\x005\x00-\x007\x005\x007\x003\x00-\x001\x001\x00D\x002\x00-\x008\x00F\x00E\x00D\x00-\x000\x000\x006\x000\x006\x007\x003\x000\x00D\x003\x00A\x00A\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15879</id>
        <msg>WEB-ACTIVEX AcerCtrls.APlunch ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/485961</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|11 11 12 12 12 0B 0D 14 15 14 12 15 10 12 12 11 01 03 03 03 04 03 04 08 04 04 08 11 0B 0A 0B 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 11 FF C4 01 A2 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15894</id>
        <msg>SPECIFIC-THREATS Microsoft Color Management Module remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-016.mspx</url>
      </rule>
      <rule>
        <bugtraq>35558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BDATuner.MPEG2TuneRequest&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22BDATuner\.MPEG2TuneRequest(\.\d)?\x22|\x27BDATuner\.MPEG2TuneRequest(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BDATuner\.MPEG2TuneRequest(\.\d)?\x22|\x27BDATuner\.MPEG2TuneRequest(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15904</id>
        <msg>WEB-ACTIVEX Microsoft Video 6 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <bugtraq>35558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|D|00|A|00|T|00|u|00|n|00|e|00|r|00|.|00|M|00|P|00|E|00|G|00|2|00|T|00|u|00|n|00|e|00|R|00|e|00|q|00|u|00|e|00|s|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)B\x00D\x00A\x00T\x00u\x00n\x00e\x00r\x00.\x00M\x00P\x00E\x00G\x002\x00T\x00u\x00n\x00e\x00R\x00e\x00q\x00u\x00e\x00s\x00t\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)B\x00D\x00A\x00T\x00u\x00n\x00e\x00r\x00.\x00M\x00P\x00E\x00G\x002\x00T\x00u\x00n\x00e\x00R\x00e\x00q\x00u\x00e\x00s\x00t\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15905</id>
        <msg>WEB-ACTIVEX Microsoft Video 6 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/972890.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2499</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.mp3; metadata: engine shared, soid 3|15920, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15920</id>
        <msg>WEB-CLIENT Microsoft mp3 malformed APIC header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-047.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.wma&quot;; nocase; http_uri; flowbits:set,http.wma; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15921</id>
        <msg>WEB-CLIENT Microsoft media format file download request</msg>
      </rule>
      <rule>
        <bugtraq>1474</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2519</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|D|00|3|00|6|00|0|00|2|00|0|00|1|00|-|00|F|00|F|00|F|00|5|00|-|00|1|00|1|00|d|00|1|00|-|00|8|00|D|00|0|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|5|00|9|00|B|00|C|00|0|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00D\x003\x006\x000\x002\x000\x001\x00-\x00F\x00F\x00F\x005\x00-\x001\x001\x00d\x001\x00-\x008\x00D\x000\x003\x00-\x000\x000\x00A\x000\x00C\x009\x005\x009\x00B\x00C\x000\x00A\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15923</id>
        <msg>WEB-ACTIVEX DHTML Editing ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>1474</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2519</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DHTMLSafe.DHTMLSafe&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DHTMLSafe\.DHTMLSafe(\.\d)?\x22|\x27DHTMLSafe\.DHTMLSafe(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*LoadURL\s*|.*(?P=v)\s*\.\s*LoadURL\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DHTMLSafe\.DHTMLSafe(\.\d)?\x22|\x27DHTMLSafe\.DHTMLSafe(\.\d)?\x27)\s*\)(\s*\.\s*LoadURL\s*|.*(?P=n)\s*\.\s*LoadURL\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15924</id>
        <msg>WEB-ACTIVEX DHTML Editing ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>1474</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2519</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|H|00|T|00|M|00|L|00|S|00|a|00|f|00|e|00|.|00|D|00|H|00|T|00|M|00|L|00|S|00|a|00|f|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00H\x00T\x00M\x00L\x00S\x00a\x00f\x00e\x00.\x00D\x00H\x00T\x00M\x00L\x00S\x00a\x00f\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00H\x00T\x00M\x00L\x00S\x00a\x00f\x00e\x00.\x00D\x00H\x00T\x00M\x00L\x00S\x00a\x00f\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15925</id>
        <msg>WEB-ACTIVEX DHTML Editing ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>36234</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D22DE742-04CD-4B5C-A8A3-82AB3DAEC43D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D22DE742-04CD-4B5C-A8A3-82AB3DAEC43D\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15926</id>
        <msg>WEB-ACTIVEX PPStream PPSMediaList ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>36234</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|2|00|2|00|D|00|E|00|7|00|4|00|2|00|-|00|0|00|4|00|C|00|D|00|-|00|4|00|B|00|5|00|C|00|-|00|A|00|8|00|A|00|3|00|-|00|8|00|2|00|A|00|B|00|3|00|D|00|A|00|E|00|C|00|4|00|3|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x002\x002\x00D\x00E\x007\x004\x002\x00-\x000\x004\x00C\x00D\x00-\x004\x00B\x005\x00C\x00-\x00A\x008\x00A\x003\x00-\x008\x002\x00A\x00B\x003\x00D\x00A\x00E\x00C\x004\x003\x00D\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15927</id>
        <msg>WEB-ACTIVEX PPStream PPSMediaList ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36234</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PPSMEDIALIST.PPSMediaListCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PPSMEDIALIST\.PPSMediaListCtrl(\.\d)?\x22|\x27PPSMEDIALIST\.PPSMediaListCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PPSMEDIALIST\.PPSMediaListCtrl(\.\d)?\x22|\x27PPSMEDIALIST\.PPSMediaListCtrl(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15928</id>
        <msg>WEB-ACTIVEX PPStream PPSMediaList ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>36234</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|P|00|S|00|M|00|E|00|D|00|I|00|A|00|L|00|I|00|S|00|T|00|.|00|P|00|P|00|S|00|M|00|e|00|d|00|i|00|a|00|L|00|i|00|s|00|t|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)P\x00P\x00S\x00M\x00E\x00D\x00I\x00A\x00L\x00I\x00S\x00T\x00.\x00P\x00P\x00S\x00M\x00e\x00d\x00i\x00a\x00L\x00i\x00s\x00t\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00P\x00S\x00M\x00E\x00D\x00I\x00A\x00L\x00I\x00S\x00T\x00.\x00P\x00P\x00S\x00M\x00e\x00d\x00i\x00a\x00L\x00i\x00s\x00t\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15929</id>
        <msg>WEB-ACTIVEX PPStream PPSMediaList ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-3103</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMBr|00 00 00|&quot;; isdataat:6,relative; content:!&quot;|00 00|&quot;; within:2; distance:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>15930</id>
        <msg>NETBIOS Microsoft Windows SMB malformed process ID high field remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-050.mspx</url>
      </rule>
      <rule>
        <bugtraq>24796</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-3028</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [389,3268]</filter1>
        <filter2>flow:to_server,established; content:&quot;|04 00 0A 01 00 0A 01 03 02 01|d|02 01|&lt;|01 01 00 A1 0B FF|bjectclass0|84 00 00 00 17 04 15|supportedCapabilities&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service ldap; classtype:attempted-dos;</filter2>
        <id>15944</id>
        <msg>SPECIFIC-THREATS Microsoft Windows Active Directory crafted LDAP request denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>25287</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,rss.download; content:&quot;&amp;lt|3B|&quot;; fast_pattern; nocase; content:&quot;&lt;title&gt;&quot;; nocase; pcre:&quot;/\x3ctitle\x3e[^\x3c]*\x26lt\x3b[^\x3c]*(&gt;|\x26gt\x3b)/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15946</id>
        <msg>WEB-CLIENT Microsoft Windows Vista Feed Headlines Gagdet code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2005-1665</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|15959, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15959</id>
        <msg>DOS Microsoft ASP.NET viewstate DoS attempt</msg>
        <url>osvdb.org/show/osvdb/16195</url>
      </rule>
      <rule>
        <bugtraq>10213</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0214</cve>
        <filter1>tcp $EXTERNAL_NET [139,445] -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 F5 01 00 00 00 00 00 00 F5 01 00 00|A|00|A|00|A|00|A|00|A|00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-user;</filter2>
        <id>15965</id>
        <msg>SPECIFIC-THREATS Microsoft Explorer long share name buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11342</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0847</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /fsc/secured|5C|fsc.aspx HTTP/1.1&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15985</id>
        <msg>SPECIFIC-THREATS Microsoft ASP.NET canonicalization exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>10113</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0119</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A| Negotiate YIIAEwYGKwYBBQUCoAkwB6EFIwMDAQc=|0D 0A|&quot;; http_header; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15996</id>
        <msg>SPECIFIC-THREATS Microsoft Negotiate SSP buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18920</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2006-1300</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;app|5F|code&quot;; nocase; http_uri; pcre:&quot;/^\w+\s+[^\s]*app\x5fcode(\x255c|\x5c)/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>16048</id>
        <msg>WEB-CLIENT Microsoft ASP.NET application folder info disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>22702</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1754</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pub; content:&quot;|01 00 00 00 FF FF FF 7F 01 00 00 80 01 00 00 00 10 0E FE 7F 01 00 00 00 58 00 7C 96 18 CB 7C 96|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16051</id>
        <msg>SPECIFIC-THREATS Microsoft Publisher 2007 conversion library code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>27579</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0625</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;buf = buf + unescape|28 22|%u&quot;; nocase; content:&quot;5F810AFC-BB5F-4416-BE63-E01DD117BD6C&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16068</id>
        <msg>SPECIFIC-THREATS Yahoo Music Jukebox ActiveX exploit</msg>
      </rule>
      <rule>
        <bugtraq>16194</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0010</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;SPP_P|1D CD|P|3B D5 AF AF AF AF 19|6|A5|U4cz{|B1 04 1D E7 EF|jiI|8A|T|D1|s|FD 0C F7|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16089</id>
        <msg>SPECIFIC-THREATS Microsoft Windows embedded web font handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>20915</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;var xmlhttp=new ActiveXObject|28 22|Msxml2.XMLHTTP.4.0|22 29|&quot;; content:&quot;try{ xmlhttp.open|28 22 5C|0t|22|, |22|test.html|22 29 3B| } catch|28|e|29| {}|3B|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16090</id>
        <msg>SPECIFIC-THREATS Microsoft Core XML core services XMLHTTP control open method code execution attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;0&amp;|B2|u&quot;; within:4; flowbits:set,http.asf; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>16143</id>
        <msg>WEB-CLIENT Microsoft asf file download</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-2524</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16167, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16167</id>
        <msg>DOS Microsoft LSASS integer wrap denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-059.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2526</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16168, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16168</id>
        <msg>DOS Microsoft SMBv2 integer overflow denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2497</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,exe.download; metadata: engine shared, soid 3|16179, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16179</id>
        <msg>EXPLOIT Microsoft .NET MSIL CLR interface multiple instantiation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-061.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0090</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,exe.download; metadata: engine shared, soid 3|16182, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16182</id>
        <msg>EXPLOIT Microsoft .NET MSIL stack corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-061.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,exe.download; metadata: engine shared, soid 3|16183, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16183</id>
        <msg>WEB-CLIENT Microsoft .NET MSIL CombineImpl suspicious usage</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-061.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2502</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16184, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16184</id>
        <msg>EXPLOIT Microsoft GDI+ TIFF file parsing heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2503</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16185, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16185</id>
        <msg>EXPLOIT Microsoft GDI+ compressed TIFF file parsing remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3126</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16186, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16186</id>
        <msg>WEB-CLIENT Microsoft GDI+ interlaced PNG file parsing heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-0022</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,ppt.download; metadata: engine shared, soid 3|16188, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16188</id>
        <msg>WEB-CLIENT Microsoft Powerpoint bad text header txttype attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-1928</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16237, service ldap, policy security-ips drop;</filter2>
        <id>16237</id>
        <msg>DOS Microsoft Active Directory NTDSA stack space exhaustion attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-066.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2523</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16238, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16238</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-064.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2523</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16239, service netbios-dgm, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16239</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP llsrpc2 LlsrLicenseRequestW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-064.mspx</url>
      </rule>
      <rule>
        <bugtraq>35419</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32771:34000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 01 86 F3 00 00 00 01 00 00 00 0F 00 00 00 00|&quot;; depth:32; offset:16; isdataat:256,relative; metadata:policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>16285</id>
        <msg>RPC AIX ttdbserv function 15 buffer overflow attempt</msg>
        <url>www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4699&amp;myns=paix52&amp;mync=E</url>
      </rule>
      <rule>
        <bugtraq>37092</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B44D252D-98FC-4D5C-948C-BE868392A004&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B44D252D-98FC-4D5C-948C-BE868392A004\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BrowseAndSaveFile|RunCMD)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B44D252D-98FC-4D5C-948C-BE868392A004\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BrowseAndSaveFile|RunCMD))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16305</id>
        <msg>WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>37092</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|4|00|4|00|D|00|2|00|5|00|2|00|D|00|-|00|9|00|8|00|F|00|C|00|-|00|4|00|D|00|5|00|C|00|-|00|9|00|4|00|8|00|C|00|-|00|B|00|E|00|8|00|6|00|8|00|3|00|9|00|2|00|A|00|0|00|0|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x004\x004\x00D\x002\x005\x002\x00D\x00-\x009\x008\x00F\x00C\x00-\x004\x00D\x005\x00C\x00-\x009\x004\x008\x00C\x00-\x00B\x00E\x008\x006\x008\x003\x009\x002\x00A\x000\x000\x004\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16306</id>
        <msg>WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>37092</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Altiris.AeXNSConsoleUtilities&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Altiris\.AeXNSConsoleUtilities(\.\d)?\x22|\x27Altiris\.AeXNSConsoleUtilities(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(BrowseAndSaveFile|RunCMD)\s*|.*(?P=v)\s*\.\s*(BrowseAndSaveFile|RunCMD)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Altiris\.AeXNSConsoleUtilities(\.\d)?\x22|\x27Altiris\.AeXNSConsoleUtilities(\.\d)?\x27)\s*\)(\s*\.\s*(BrowseAndSaveFile|RunCMD)\s*|.*(?P=n)\s*\.\s*(BrowseAndSaveFile|RunCMD)\s*)\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16307</id>
        <msg>WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>37092</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|l|00|t|00|i|00|r|00|i|00|s|00|.|00|A|00|e|00|X|00|N|00|S|00|C|00|o|00|n|00|s|00|o|00|l|00|e|00|U|00|t|00|i|00|l|00|i|00|t|00|i|00|e|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00l\x00t\x00i\x00r\x00i\x00s\x00.\x00A\x00e\x00X\x00N\x00S\x00C\x00o\x00n\x00s\x00o\x00l\x00e\x00U\x00t\x00i\x00l\x00i\x00t\x00i\x00e\x00s\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00l\x00t\x00i\x00r\x00i\x00s\x00.\x00A\x00e\x00X\x00N\x00S\x00C\x00o\x00n\x00s\x00o\x00l\x00e\x00U\x00t\x00i\x00l\x00i\x00t\x00i\x00e\x00s\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16308</id>
        <msg>WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2503</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16327, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16327</id>
        <msg>EXPLOIT Microsoft Windows GDIplus TIFF RLE compressed data buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3677</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1812</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16329, service radius, policy security-ips drop;</filter2>
        <id>16329</id>
        <msg>EXPLOIT Microsoft Internet Authentication Service EAP-MSCHAPv2 authentication bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-071.mspx</url>
      </rule>
      <rule>
        <bugtraq>7517</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;execCommand|28 22|copy|22 29 3B|&quot;; nocase; content:&quot;2D360201-FFF5-11d1-8D03-00A0C959BC0A&quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16340</id>
        <msg>SPECIFIC-THREATS DHTML Editing ActiveX clsid access</msg>
        <nessus>11595</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>35970</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16342, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16342</id>
        <msg>WEB-CLIENT Microsoft Windows AVIFile truncated media file processing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16366, service http, policy security-ips drop;</filter2>
        <id>16366</id>
        <msg>EXPLOIT Microsoft embedded OpenType font engine LZX decompression buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-001.mspx</url>
      </rule>
      <rule>
        <bugtraq>35256</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;77F12F8A-F117-11D0-8CF1-00A0C91D9D87&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*77F12F8A-F117-11D0-8CF1-00A0C91D9D87\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Accept)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*77F12F8A-F117-11D0-8CF1-00A0C91D9D87\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Accept))/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>16379</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui sapirrfc ActiveX clsid access</msg>
        <url>service.sap.com/sap/support/notes/1286637</url>
      </rule>
      <rule>
        <bugtraq>35256</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|7|00|F|00|1|00|2|00|F|00|8|00|A|00|-|00|F|00|1|00|1|00|7|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|C|00|F|00|1|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|D|00|9|00|D|00|8|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x007\x00F\x001\x002\x00F\x008\x00A\x00-\x00F\x001\x001\x007\x00-\x001\x001\x00D\x000\x00-\x008\x00C\x00F\x001\x00-\x000\x000\x00A\x000\x00C\x009\x001\x00D\x009\x00D\x008\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>16380</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui sapirrfc ActiveX clsid unicode access</msg>
        <url>service.sap.com/sap/support/notes/1286637</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0020</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16395, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16395</id>
        <msg>NETBIOS SMB COPY command oversized pathname attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-0021</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16396, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16396</id>
        <msg>NETBIOS SMB server srvnet.sys driver race condition attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0029</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16409, service http, policy balanced-ips alert, policy security-ips alert;</filter2>
        <id>16409</id>
        <msg>WEB-CLIENT Microsoft PowerPoint improper filename remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0030</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16410, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16410</id>
        <msg>WEB-CLIENT Microsoft PowerPoint file LinkedSlide10Atom record parsing heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16411, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16411</id>
        <msg>WEB-CLIENT Microsoft PowerPoint out of bounds value remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16412, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16412</id>
        <msg>WEB-CLIENT Microsoft PowerPoint invalid TextByteAtom remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0250</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16415, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16415</id>
        <msg>WEB-CLIENT Microsoft DirectShow memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0016</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16417, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16417</id>
        <msg>NETBIOS SMB Negotiate Protocol Response overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-006.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16419, service http, policy security-ips drop;</filter2>
        <id>16419</id>
        <msg>WEB-ACTIVEX Microsoft Data Analyzer 3.5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0032</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16421, service http, policy security-ips drop;</filter2>
        <id>16421</id>
        <msg>EXPLOIT Microsoft PowerPoint out of bounds value remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;72C24DD5-D70A-438B-8A42-98424B88AFB8&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16424</id>
        <msg>WEB-ACTIVEX Windows Script Host Shell Object ActiveX clsid access</msg>
        <url>www.exploit-db.com/exploits/11457</url>
      </rule>
      <rule>
        <bugtraq>30407</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3364</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5EFE8CB1-D095-11D1-88FC-0080C859833B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5EFE8CB1-D095-11D1-88FC-0080C859833B\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; content:&quot;&lt;PARAM&quot;; nocase; content:&quot;VALUE&quot;; distance:0; nocase; pcre:&quot;/&lt;PARAM[^&gt;]+VALUE\s*=\s*(?P&lt;q2&gt;\x22|\x27|)[^&gt;]{200}(?P=q2)/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16432</id>
        <msg>WEB-ACTIVEX Trend Micro Web Deployment ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0265</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.mswmm; flowbits:isset,http.msproducer; flowbits:isset,http.oless.v3; flowbits:isset,http.oless.v4; metadata: engine shared, soid 3|16472, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16472</id>
        <msg>WEB-CLIENT Microsoft Windows Movie Maker project file heap buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-016.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.mswmm&quot;; nocase; http_uri; flowbits:set,http.mswmm; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16473</id>
        <msg>WEB-CLIENT Microsoft Windows Movie Maker project file download request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; content:&quot;&gt;|00 03 00|&quot;; within:4; distance:16; flowbits:set,http.oless.v3; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16474</id>
        <msg>WEB-CLIENT Microsoft Compound File Binary v3 file download</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; content:&quot;&gt;|00 04 00|&quot;; within:4; distance:16; flowbits:set,http.oless.v4; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16475</id>
        <msg>WEB-CLIENT Microsoft Compound File Binary v4 file download</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.MSProducer&quot;; nocase; http_uri; flowbits:set,http.msproducer; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16476</id>
        <msg>WEB-CLIENT Microsoft .MSProducer file download request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.MSProducerZ&quot;; nocase; http_uri; flowbits:set,http.msproducer; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16477</id>
        <msg>WEB-CLIENT Microsoft .MSProducerZ file download request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.MSProducerBF&quot;; nocase; http_uri; flowbits:set,http.msproducer; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16478</id>
        <msg>WEB-CLIENT Microsoft .MSProducerBF file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0489</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16505, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16505</id>
        <msg>EXPLOIT Microsoft IE HTML parsing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0805</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16510, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16510</id>
        <msg>WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by CLSID</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0805</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16511, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16511</id>
        <msg>WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by ProgID</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0476</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16532, service netbios-ssn, policy security-ips drop;</filter2>
        <id>16532</id>
        <msg>NETBIOS SMB client TRANS response ring0 remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|16535, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16535</id>
        <msg>EXPLOIT  Microsoft Viso improper attribute code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0256</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|16536, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16536</id>
        <msg>EXPLOIT Microsoft Viso off-by-one in array index code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-028.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB|A0|&quot;; depth:5; offset:4; isdataat:66,relative; content:&quot;|06 00|&quot;; within:2; distance:64; flowbits:set,smb.query_sec_desc; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:misc-activity;</filter2>
        <id>16538</id>
        <msg>NETBIOS NT QUERY SECURITY DESC flowbit</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0269</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,smb.query_sec_desc; flowbits:unset,smb.query_sec_desc; metadata: engine shared, soid 3|16539, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16539</id>
        <msg>NETBIOS SMBv1 BytesNeeded ring0 buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0479</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:set,http.pub; flowbits:noalert;  metadata: engine shared, soid 3|16542, service http, policy security-ips drop;</filter2>
        <id>16542</id>
        <msg>EXPLOIT Microsoft Publisher 2007 and earlier stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0805</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16559, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16559</id>
        <msg>WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by CLSID / param tag</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0817</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16560, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16560</id>
        <msg>WEB-MISC Microsoft Sharepoint XSS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;38681fbd-d4cc-4a59-a527-b3136db711d3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*38681fbd-d4cc-4a59-a527-b3136db711d3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(TransferFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*38681fbd-d4cc-4a59-a527-b3136db711d3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(TransferFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16566</id>
        <msg>WEB-ACTIVEX Tumbleweed SecureTransport ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|8|00|6|00|8|00|1|00|f|00|b|00|d|00|-|00|d|00|4|00|c|00|c|00|-|00|4|00|a|00|5|00|9|00|-|00|a|00|5|00|2|00|7|00|-|00|b|00|3|00|1|00|3|00|6|00|d|00|b|00|7|00|1|00|1|00|d|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x008\x006\x008\x001\x00f\x00b\x00d\x00-\x00d\x004\x00c\x00c\x00-\x004\x00a\x005\x009\x00-\x00a\x005\x002\x007\x00-\x00b\x003\x001\x003\x006\x00d\x00b\x007\x001\x001\x00d\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16567</id>
        <msg>WEB-ACTIVEX Tumbleweed SecureTransport ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25903</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DEF37997-D9C9-4A4B-BF3C-88F99EACEEC2&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16568</id>
        <msg>WEB-ACTIVEX Altnet Download Manager ADM4 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24772</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3605</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2137278D-EF5C-11D3-96CE-0004AC965257&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2137278D-EF5C-11D3-96CE-0004AC965257\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(PrepareToPostHTML)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2137278D-EF5C-11D3-96CE-0004AC965257\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(PrepareToPostHTML))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16569</id>
        <msg>WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24772</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3605</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|1|00|3|00|7|00|2|00|7|00|8|00|D|00|-|00|E|00|F|00|5|00|C|00|-|00|1|00|1|00|D|00|3|00|-|00|9|00|6|00|C|00|E|00|-|00|0|00|0|00|0|00|4|00|A|00|C|00|9|00|6|00|5|00|2|00|5|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x001\x003\x007\x002\x007\x008\x00D\x00-\x00E\x00F\x005\x00C\x00-\x001\x001\x00D\x003\x00-\x009\x006\x00C\x00E\x00-\x000\x000\x000\x004\x00A\x00C\x009\x006\x005\x002\x005\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16570</id>
        <msg>WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24772</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3605</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;kweditcontrol.kwedit&quot;; fast_pattern:only; nocase; content:&quot;PrepareToPostHTML&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22kweditcontrol\.kwedit(\.\d)?\x22|\x27kweditcontrol\.kwedit(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22kweditcontrol\.kwedit(\.\d)?\x22|\x27kweditcontrol\.kwedit(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16571</id>
        <msg>WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24772</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3605</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;k|00|w|00|e|00|d|00|i|00|t|00|c|00|o|00|n|00|t|00|r|00|o|00|l|00|.|00|k|00|w|00|e|00|d|00|i|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)k\x00w\x00e\x00d\x00i\x00t\x00c\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00k\x00w\x00e\x00d\x00i\x00t\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)k\x00w\x00e\x00d\x00i\x00t\x00c\x00o\x00n\x00t\x00r\x00o\x00l\x00.\x00k\x00w\x00e\x00d\x00i\x00t\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16572</id>
        <msg>WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ActiveXObject|28|&quot;; nocase; content:&quot;unescape|28|&quot;; nocase; pcre:&quot;/new\s*ActiveXObject\(\s*unescape\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16573</id>
        <msg>WEB-ACTIVEX obfuscated ActiveX object instantiation via unescape</msg>
        <url>msdn.microsoft.com/en-us/library/7sw4ddf8(VS.85).aspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ActiveXObject|28|&quot;; nocase; content:&quot;String.fromCharCode|28|&quot;; fast_pattern; nocase; pcre:&quot;/new\s*ActiveXObject\(\s*String.fromCharCode\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16574</id>
        <msg>WEB-ACTIVEX obfuscated ActiveX object instantiation via fromCharCode</msg>
        <url>msdn.microsoft.com/en-us/library/7sw4ddf8(VS.85).aspx</url>
      </rule>
      <rule>
        <bugtraq>24596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3435</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid='clsid|3A|C26D9CA8-6747-11D5-AD4B-C01857C10000'&quot;; content:&quot;String&quot;; distance:0; content:&quot;unescape&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16575</id>
        <msg>SPECIFIC-THREATS RKD Software BarCode ActiveX buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-2552</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16577, service netbios-ssn, policy security-ips drop;</filter2>
        <id>16577</id>
        <msg>NETBIOS Microsoft Windows SMBv2 compound request DoS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>33469</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;object classid='clsid|3A|77829F14-D911-40FF-A2F0-D11DB8D6D0BC'&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16580</id>
        <msg>SPECIFIC-THREATS NCTAudioFile2 ActiveX clsid access via object tag</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ActiveXObject|28|'LPViewer.LPViewer.1'|29|&quot;; content:&quot;unescape&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16588</id>
        <msg>SPECIFIC-THREATS iseemedia LPViewer ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>31604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;url&quot;; content:&quot;toolbar&quot;; distance:0; content:&quot;enableZoomPastMax&quot;; distance:0; content:&quot;classid=|22|clsid|3A|{3F0EECCE-E138-11D1-8712-0060083D83F5}&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16589</id>
        <msg>SPECIFIC-THREATS iseemedia LPViewer ActiveX buffer overflows attempt</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|23| CLSID|3A|68AC0D5F-0424-11D5-822F-00C04F6BA8D9&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16590</id>
        <msg>SPECIFIC-THREATS EasyMail Objects ActiveX exploit attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid='clsid|3A|68AC0D5F-0424-11D5-822F-00C04F6BA8D9'&quot;; content:&quot;unescape|28 22|%&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16591</id>
        <msg>SPECIFIC-THREATS EasyMail Objects ActiveX exploit attempt - 2</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0815</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16593, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16593</id>
        <msg>WEB-CLIENT Microsoft VBE6.dll stack corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-031.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.CompleteInstallation|28|&quot;; content:&quot;String.fromCharCode&quot;; within:100; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16599</id>
        <msg>SPECIFIC-THREATS AtHocGov IWSAlerts ActiveX control buffer overflow attempt</msg>
        <url>www.fortiguard.com/encyclopedia/vulnerability/athocgov.iwsalerts.activex.buffer.overflow.html</url>
      </rule>
      <rule>
        <bugtraq>23239</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1819</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid=|27|clsid|3A|98C53984-8BF8-4D11-9B1C-C324FCA9CADE|27|&quot;; fast_pattern:only; content:&quot;unescape&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16608</id>
        <msg>SPECIFIC-THREATS HP Mercury Quality Center SPIDERLib ActiveX buffer overflow attempt</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872</url>
      </rule>
      <rule>
        <bugtraq>34228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.GetXMLValue&quot;; fast_pattern; content:&quot;String.fromCharCode&quot;; pcre:&quot;/String\x2EfromCharCode\s*\x28(?=[^\x29]*?0x\d+)[^\x29]*?\d{2}/&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16610</id>
        <msg>SPECIFIC-THREATS IBM Access Support ActiveX GetXMLValue method buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>40725</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1885</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;hcp|3A 2F 2F|&quot;; nocase; content:&quot;script&quot;; distance:0; nocase; content:&quot;defer&quot;; distance:0; nocase; pcre:&quot;/hcp\x3a\x2f\x2f[^\n]*(\x3c|\x253c)script(\s|\x2520|\x2f)+defer/iO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16665</id>
        <msg>WEB-CLIENT Microsoft Windows Help Centre escape sequence XSS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-042.mspx</url>
      </rule>
      <rule>
        <bugtraq>26904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;clsid|3A|22ACD16F-99EB-11D2-9BB3-00400561D975&quot;; fast_pattern:only; nocase; content:&quot;unescape|28|&quot;; content:&quot;|25|u&quot;; within:5; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16672</id>
        <msg>SPECIFIC-THREATS Symantec Backup Exec ActiveX control buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28268</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1472</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid|3D 22|clsid|3A|BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3|22|&quot;; content:&quot;unescape|28 22 25|u&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16675</id>
        <msg>SPECIFIC-THREATS CA BrightStor ListCtrl ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>34250</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2009-1217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|01 00 00 00|&quot;; content:&quot;|20|EMF&quot;; within:4; distance:36; content:&quot;|45 4D 46 2B 08 40|&quot;; pcre:&quot;/\x45\x4d\x46\x2b\x08\x40.(\x06|\x86).{28}([\xf4-\xff]\xff\xff(\xff|\x7f)|[\x00-\x06]\x00\x00\x80)/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>16679</id>
        <msg>WEB-MISC Microsoft Windows GDIplus integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17712</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;E5F5D008-DD2C-4D32-977D-1A0ADF03058B&quot;; nocase; content:&quot;ProductName&quot;; nocase; pcre:&quot;/\&lt;param\s*[^\&gt;]*?name\s*=\s*(?P&lt;q&gt;\x22|\x27|)?ProductName(?P=q)[^\&gt;]+?value\s*=\s*(\x22[^\x22]{500}|\x27[^\x27]{500}|[^\s\&gt;]{500})/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16687</id>
        <msg>WEB-ACTIVEX Juniper Networks SSL-VPN Client JuniperSetup ActiveX control buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34205</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-1072</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00 02 00 01 86 A3 00 00 00 02 00 00 00 09|&quot;; depth:28; byte_jump:4,4,relative,big; byte_jump:4,4,relative,big; byte_jump:4,32,relative,big; content:&quot;|00 00|&quot;; within:2; distance:1; byte_test:1,&amp;,0x20,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:misc-attack;</filter2>
        <id>16699</id>
        <msg>RPC Linux Kernel nfsd v2 udp CAP_MKNOD security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>34205</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-1072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00 02 00 01 86 A3 00 00 00 02 00 00 00 09|&quot;; depth:28; byte_jump:4,4,relative,big; byte_jump:4,4,relative,big; byte_jump:4,32,relative,big; content:&quot;|00 00|&quot;; within:2; distance:1; byte_test:1,&amp;,0x20,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:misc-attack;</filter2>
        <id>16700</id>
        <msg>RPC Linux Kernel nfsd v2 tcp CAP_MKNOD security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>34205</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-1072</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00 02 00 01 86 A3 00 00 00 03 00 00 00 0B|&quot;; depth:28; byte_jump:4,4,relative,big; byte_jump:4,4,relative,big; byte_jump:4,0,relative,big; byte_jump:4,0,relative,big; pcre:&quot;/^.\x00{3}(\x03|\x04)/sR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:misc-attack;</filter2>
        <id>16701</id>
        <msg>RPC Linux Kernel nfsd v3 udp CAP_MKNOD security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>34205</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-1072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00 02 00 01 86 A3 00 00 00 03 00 00 00 0B|&quot;; depth:28; byte_jump:4,4,relative,big; byte_jump:4,4,relative,big; byte_jump:4,0,relative,big; byte_jump:4,0,relative,big; pcre:&quot;/^.\x00{3}(\x03|\x04)/sR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:misc-attack;</filter2>
        <id>16702</id>
        <msg>RPC Linux Kernel nfsd v3 tcp CAP_MKNOD security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>37133</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4225</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|5E644C49-F8B0-4E9A-A2ED-5F176BB18CE6|27 3E 3C 2F|object|3E|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16704</id>
        <msg>SPECIFIC-THREATS CA eTrust PestPatrol 'ppctl.dll' ActiveX Initialize method overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3869</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; content:&quot;|00 01 87 88|&quot;; within:4; distance:4; fast_pattern; byte_jump:4,12,relative,big,align; byte_jump:4,4,relative,big,align; byte_jump:4,108,relative,big,align; byte_jump:4,0,relative,big,align; byte_jump:4,0,relative,big,align; content:&quot;|00 00 00 00 00 00 00 00|&quot;; distance:0; byte_test:4,!=,0,0,relative; byte_jump:4,0,relative,big,align; content:&quot;|00 00 00 11|&quot;; within:4; byte_jump:4,0,relative,big,align; isdataat:7; content:!&quot;|00 00 00 00 00 00 00 00|&quot;; within:8; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>16705</id>
        <msg>RPC Sun Solaris sadmind UDP array size buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3869</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 01 87 88|&quot;; within:4; distance:4; fast_pattern; byte_jump:4,12,relative,big,align; byte_jump:4,4,relative,big,align; byte_jump:4,108,relative,big,align; byte_jump:4,0,relative,big,align; byte_jump:4,0,relative,big,align; content:&quot;|00 00 00 00 00 00 00 00|&quot;; distance:0; byte_test:4,!=,0,0,relative; byte_jump:4,0,relative,big,align; content:&quot;|00 00 00 11|&quot;; within:4; byte_jump:4,0,relative,big,align; isdataat:7; content:!&quot;|00 00 00 00 00 00 00 00|&quot;; within:8; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>16706</id>
        <msg>RPC Sun Solaris sadmind TCP array size buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24328</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;classid|3D 27|clsid|3A|BA83FD38-CE14-4DA3-BEF5-96050D55F78A|27|&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 27 25|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16711</id>
        <msg>SPECIFIC-THREATS E-Book Systems FlipViewer FlipViewerX.dll ActiveX multiple buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1682</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;ActiveXObject|28 27|SoftArtisans|2E|FileManager|2E|1|27 29 3B|&quot;; content:&quot;unescape|28 27 25|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16714</id>
        <msg>SPECIFIC-THREATS SoftArtisans XFile FileManager ActiveX Control buffer overflow attempt</msg>
        <url>support.softartisans.com/Support-114.aspx</url>
      </rule>
      <rule>
        <bugtraq>33053</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-6898</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;clsid|3A|0297D24A-F425-47EE-9F3B-A459BCE593E3&quot;; nocase; content:&quot;unescape|28|&quot;; within:300; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16715</id>
        <msg>SPECIFIC-THREATS SaschArt SasCam Webcam Server ActiveX control exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>40884</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-2063</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16728, service netbios-ssn, policy security-ips drop;</filter2>
        <id>16728</id>
        <msg>NETBIOS Samba SMB1 chain_reply function memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;ActiveXObject|28 27|Enginecom.imagineLANEngine.1|27 29 3B|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16729</id>
        <msg>SPECIFIC-THREATS McAfee Remediation client ActiveX control buffer overflow attempt</msg>
        <url>www.fortiguard.com/encyclopedia/vulnerability/mcafee.remediation.client.enginecom.dll.activex.access.html</url>
      </rule>
      <rule>
        <bugtraq>28820</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1898</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6&quot;; fast_pattern:only; nocase; file_data; content:&quot;WksPictureInterface&quot;; pcre:&quot;/var num \x3D (-1|168430090)\x3B/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16740</id>
        <msg>SPECIFIC-THREATS Microsoft Works WkImgSrv.dll ActiveX control code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>28820</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1898</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6|27 3E 3C 2F|object|3E|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16741</id>
        <msg>SPECIFIC-THREATS Microsoft Works WkImgSrv.dll ActiveX control exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>31987</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;clsid:4A46B8CD-F7BD-11D4-B1D8-000102290E7C&quot;; fast_pattern:only; nocase; content:&quot;unescape|28|&quot;; nocase; content:&quot;%u&quot;; within:5; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16745</id>
        <msg>SPECIFIC-THREATS DjVu ActiveX control ImageURL property overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;74FFE28D-2378-11D5-990C-006094235084&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*74FFE28D-2378-11D5-990C-006094235084\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GetXMLValue)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*74FFE28D-2378-11D5-990C-006094235084\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GetXMLValue))/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16746</id>
        <msg>WEB-ACTIVEX IBM Access Support ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>34228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|4|00|F|00|F|00|E|00|2|00|8|00|D|00|-|00|2|00|3|00|7|00|8|00|-|00|1|00|1|00|D|00|5|00|-|00|9|00|9|00|0|00|C|00|-|00|0|00|0|00|6|00|0|00|9|00|4|00|2|00|3|00|5|00|0|00|8|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x004\x00F\x00F\x00E\x002\x008\x00D\x00-\x002\x003\x007\x008\x00-\x001\x001\x00D\x005\x00-\x009\x009\x000\x00C\x00-\x000\x000\x006\x000\x009\x004\x002\x003\x005\x000\x008\x004\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16747</id>
        <msg>WEB-ACTIVEX IBM Access Support ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>34228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IbmEgath.IbmEgathCtl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22IbmEgath\.IbmEgathCtl(\.\d)?\x22|\x27IbmEgath\.IbmEgathCtl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GetXMLValue\s*|.*(?P=v)\s*\.\s*GetXMLValue\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IbmEgath\.IbmEgathCtl(\.\d)?\x22|\x27IbmEgath\.IbmEgathCtl(\.\d)?\x27)\s*\)(\s*\.\s*GetXMLValue\s*|.*(?P=n)\s*\.\s*GetXMLValue\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16748</id>
        <msg>WEB-ACTIVEX IBM Access Support ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>34228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|b|00|m|00|E|00|g|00|a|00|t|00|h|00|.|00|I|00|b|00|m|00|E|00|g|00|a|00|t|00|h|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00b\x00m\x00E\x00g\x00a\x00t\x00h\x00.\x00I\x00b\x00m\x00E\x00g\x00a\x00t\x00h\x00C\x00t\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)I\x00b\x00m\x00E\x00g\x00a\x00t\x00h\x00.\x00I\x00b\x00m\x00E\x00g\x00a\x00t\x00h\x00C\x00t\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16749</id>
        <msg>WEB-ACTIVEX IBM Access Support ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C|PlughNTCommand|00|&quot;; within:17; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>16754</id>
        <msg>NETBIOS SMB /PlughNTCommand andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C|PlughNTCommand|00|&quot;; within:17; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>16755</id>
        <msg>NETBIOS SMB /PlughNTCommand create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C 00|P|00|l|00|u|00|g|00|h|00|N|00|T|00|C|00|o|00|m|00|m|00|a|00|n|00|d|00 00 00|&quot;; within:33; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>16756</id>
        <msg>NETBIOS SMB /PlughNTCommand unicode andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C 00|P|00|l|00|u|00|g|00|h|00|N|00|T|00|C|00|o|00|m|00|m|00|a|00|n|00|d|00 00 00|&quot;; within:33; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>16757</id>
        <msg>NETBIOS SMB /PlughNTCommand unicode create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C|PlughNTCommand|00|&quot;; within:17; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>16758</id>
        <msg>NETBIOS-DG SMB /PlughNTCommand andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C|PlughNTCommand|00|&quot;; within:17; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>16759</id>
        <msg>NETBIOS-DG SMB /PlughNTCommand create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C 00|P|00|l|00|u|00|g|00|h|00|N|00|T|00|C|00|o|00|m|00|m|00|a|00|n|00|d|00 00 00|&quot;; within:33; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>16760</id>
        <msg>NETBIOS-DG SMB /PlughNTCommand unicode andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-1394</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C 00|P|00|l|00|u|00|g|00|h|00|N|00|T|00|C|00|o|00|m|00|m|00|a|00|n|00|d|00 00 00|&quot;; within:33; distance:51; nocase; flowbits:set,smb.tree.create.timbuktu; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>16761</id>
        <msg>NETBIOS-DG SMB /PlughNTCommand unicode create tree attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.timbuktu; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; pcre:&quot;/^9\s(\S{101}|\S+\s(\S{349}|\S+\s\S{521}))/siR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16762</id>
        <msg>NETBIOS SMB Timbuktu Pro overflow WriteAndX andx attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.timbuktu; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; pcre:&quot;/^9\s(\S{101}|\S+\s(\S{349}|\S+\s\S{521}))/siR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16763</id>
        <msg>NETBIOS SMB Timbuktu Pro overflow WriteAndX attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.timbuktu; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;/&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; pcre:&quot;/^9\s(\S{101}|\S+\s(\S{349}|\S+\s\S{521}))/siR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16764</id>
        <msg>NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode andx attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.timbuktu; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB/&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_jump:2,23,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; pcre:&quot;/^9\s(\S{101}|\S+\s(\S{349}|\S+\s\S{521}))/siR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16765</id>
        <msg>NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smb.tree.create.timbuktu; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; pcre:&quot;/^9\s(\S{101}|\S+\s(\S{349}|\S+\s\S{521}))/siR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16766</id>
        <msg>NETBIOS SMB Timbuktu Pro overflow andx attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;17A54E7D-A9D4-11D8-9552-00E04CB09903&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*17A54E7D-A9D4-11D8-9552-00E04CB09903\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SceneURL)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*17A54E7D-A9D4-11D8-9552-00E04CB09903\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SceneURL))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16767</id>
        <msg>WEB-ACTIVEX AwingSoft Web3D Player ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|7|00|A|00|5|00|4|00|E|00|7|00|D|00|-|00|A|00|9|00|D|00|4|00|-|00|1|00|1|00|D|00|8|00|-|00|9|00|5|00|5|00|2|00|-|00|0|00|0|00|E|00|0|00|4|00|C|00|B|00|0|00|9|00|9|00|0|00|3|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x007\x00A\x005\x004\x00E\x007\x00D\x00-\x00A\x009\x00D\x004\x00-\x001\x001\x00D\x008\x00-\x009\x005\x005\x002\x00-\x000\x000\x00E\x000\x004\x00C\x00B\x000\x009\x009\x000\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16768</id>
        <msg>WEB-ACTIVEX AwingSoft Web3D Player ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WindsPlayerIE.View&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WindsPlayerIE\.View(\.\d)?\x22|\x27WindsPlayerIE\.View(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SceneURL\s*|.*(?P=v)\s*\.\s*SceneURL\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WindsPlayerIE\.View(\.\d)?\x22|\x27WindsPlayerIE\.View(\.\d)?\x27)\s*\)(\s*\.\s*SceneURL\s*|.*(?P=n)\s*\.\s*SceneURL\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16769</id>
        <msg>WEB-ACTIVEX AwingSoft Web3D Player ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|i|00|n|00|d|00|s|00|P|00|l|00|a|00|y|00|e|00|r|00|I|00|E|00|.|00|V|00|i|00|e|00|w|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00i\x00n\x00d\x00s\x00P\x00l\x00a\x00y\x00e\x00r\x00I\x00E\x00.\x00V\x00i\x00e\x00w\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)W\x00i\x00n\x00d\x00s\x00P\x00l\x00a\x00y\x00e\x00r\x00I\x00E\x00.\x00V\x00i\x00e\x00w\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16770</id>
        <msg>WEB-ACTIVEX AwingSoft Web3D Player ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4588</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;classid|3D 27|clsid|3A|17A54E7D-A9D4-11D8-9552-00E04CB09903|27|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16771</id>
        <msg>SPECIFIC-THREATS AwingSoft Web3D Player WindsPlayerIE.View.1 ActiveX SceneURL method overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36546</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B7ECFD41-BE62-11D2-B9A8-00104B138C8C&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B7ECFD41-BE62-11D2-B9A8-00104B138C8C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(JumpURL|JumpMappedID)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B7ECFD41-BE62-11D2-B9A8-00104B138C8C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(JumpURL|JumpMappedID))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16772</id>
        <msg>WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>36546</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|7|00|E|00|C|00|F|00|D|00|4|00|1|00|-|00|B|00|E|00|6|00|2|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|9|00|A|00|8|00|-|00|0|00|0|00|1|00|0|00|4|00|B|00|1|00|3|00|8|00|C|00|8|00|C|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x007\x00E\x00C\x00F\x00D\x004\x001\x00-\x00B\x00E\x006\x002\x00-\x001\x001\x00D\x002\x00-\x00B\x009\x00A\x008\x00-\x000\x000\x001\x000\x004\x00B\x001\x003\x008\x00C\x008\x00C\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16773</id>
        <msg>WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36546</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;KeyHelp.KeyCtrl&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22KeyHelp\.KeyCtrl(\.\d)?\x22|\x27KeyHelp\.KeyCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(JumpURL|JumpMappedID)\s*|.*(?P=v)\s*\.\s*(JumpURL|JumpMappedID)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22KeyHelp\.KeyCtrl(\.\d)?\x22|\x27KeyHelp\.KeyCtrl(\.\d)?\x27)\s*\)(\s*\.\s*(JumpURL|JumpMappedID)\s*|.*(?P=n)\s*\.\s*(JumpURL|JumpMappedID)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16774</id>
        <msg>WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>36546</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;K|00|e|00|y|00|H|00|e|00|l|00|p|00|.|00|K|00|e|00|y|00|C|00|t|00|r|00|l|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)K\x00e\x00y\x00H\x00e\x00l\x00p\x00.\x00K\x00e\x00y\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)K\x00e\x00y\x00H\x00e\x00l\x00p\x00.\x00K\x00e\x00y\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16775</id>
        <msg>WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36546</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;ActiveXObject|28 27|KeyHelp.KeyCtrl.1|27 29 3B|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16776</id>
        <msg>SPECIFIC-THREATS KeyWorks KeyHelp 'keyhelp.ocx' ActiveX control multiple method overflow attempt</msg>
        <url>osvdb.org/show/osvdb/58423</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;21E0CB95-1198-4945-A3D2-4BF804295F78&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*21E0CB95-1198-4945-A3D2-4BF804295F78\s*}?\s*(?P=q1)(\s|&gt;)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*21E0CB95-1198-4945-A3D2-4BF804295F78\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;))/siO&quot;; pcre:&quot;/\.(src|background|packagexml)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16783</id>
        <msg>WEB-ACTIVEX Autodesk iDrop ActiveX clsid access</msg>
        <url>securitytracker.com/id?1021969</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;idrop.idrop&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22idrop\.idrop(\.\d)?\x22|\x27idrop\.idrop(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22idrop\.idrop(\.\d)?\x22|\x27idrop\.idrop(\.\d)?\x27)\s*\)\s*=/smiO&quot;; pcre:&quot;/\.(src|background|packagexml)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16784</id>
        <msg>WEB-ACTIVEX Autodesk iDrop ActiveX function call access</msg>
        <url>securitytracker.com/id?1021969</url>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5002</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3D| new ActiveXObject|28 22|ChilkatCrypt2|2E|ChilkatCrypt2|22 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;|3D| unescape|3B|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16789</id>
        <msg>SPECIFIC-THREATS Chilkat Crypt 2 ActiveX WriteFile method arbitrary file overwrite attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>32073</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5002</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;classid|3D 27|clsid|3A|3352B5B9-82E8-4FFD-9EB1-1A3E60056904|27|&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 22 25|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16790</id>
        <msg>SPECIFIC-THREATS Chilkat Crypt 2 ActiveX WriteFile method arbitrary file overwrite attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>34310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4475</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AFBBE070-7340-11d2-AA6B-00E02924C34E&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AFBBE070-7340-11d2-AA6B-00E02924C34E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveViewToSessionFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AFBBE070-7340-11d2-AA6B-00E02924C34E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveViewToSessionFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16791</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>34310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4475</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|B|00|B|00|E|00|0|00|7|00|0|00|-|00|7|00|3|00|4|00|0|00|-|00|1|00|1|00|d|00|2|00|-|00|A|00|A|00|6|00|B|00|-|00|0|00|0|00|E|00|0|00|2|00|9|00|2|00|4|00|C|00|3|00|4|00|E|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00F\x00B\x00B\x00E\x000\x007\x000\x00-\x007\x003\x004\x000\x00-\x001\x001\x00d\x002\x00-\x00A\x00A\x006\x00B\x00-\x000\x000\x00E\x000\x002\x009\x002\x004\x00C\x003\x004\x00E\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16792</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>34310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4475</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EAIWeb.WebViewer3D&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EAIWeb\.WebViewer3D(\.\d)?\x22|\x27EAIWeb\.WebViewer3D(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveViewToSessionFile\s*|.*(?P=v)\s*\.\s*SaveViewToSessionFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EAIWeb\.WebViewer3D(\.\d)?\x22|\x27EAIWeb\.WebViewer3D(\.\d)?\x27)\s*\)(\s*\.\s*SaveViewToSessionFile\s*|.*(?P=n)\s*\.\s*SaveViewToSessionFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16793</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>34310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4475</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|A|00|I|00|W|00|e|00|b|00|.|00|W|00|e|00|b|00|V|00|i|00|e|00|w|00|e|00|r|00|3|00|D|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00A\x00I\x00W\x00e\x00b\x00.\x00W\x00e\x00b\x00V\x00i\x00e\x00w\x00e\x00r\x003\x00D\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00A\x00I\x00W\x00e\x00b\x00.\x00W\x00e\x00b\x00V\x00i\x00e\x00w\x00e\x00r\x003\x00D\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16794</id>
        <msg>WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>35083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3870</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; content:&quot;|00 01 87 88|&quot;; within:4; distance:4; fast_pattern; byte_jump:4,12,relative,big,align; byte_jump:4,4,relative,big,align; byte_jump:4,108,relative,big,align; byte_jump:4,0,relative,big,align; byte_jump:4,0,relative,big,align; byte_test:4,&gt;,0xFFFFFEFF,0,relative; metadata:policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>16796</id>
        <msg>RPC Sun Solaris sadmind UDP data length integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3870</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 01 87 88|&quot;; within:4; distance:4; fast_pattern; byte_jump:4,12,relative,big,align; byte_jump:4,4,relative,big,align; byte_jump:4,108,relative,big,align; byte_jump:4,0,relative,big,align; byte_jump:4,0,relative,big,align; byte_test:4,&gt;,0xFFFFFEFF,0,relative; metadata:policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>16797</id>
        <msg>RPC Sun Solaris sadmind TCP data length integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23071</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0348</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B727C217-2022-11D4-B2C6-0050DA1BD906&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B727C217-2022-11D4-B2C6-0050DA1BD906\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ApplicationType)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B727C217-2022-11D4-B2C6-0050DA1BD906\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(ApplicationType))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16802</id>
        <msg>WEB-ACTIVEX WinDVD IASystemInfo.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>23071</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0348</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|7|00|2|00|7|00|C|00|2|00|1|00|7|00|-|00|2|00|0|00|2|00|2|00|-|00|1|00|1|00|D|00|4|00|-|00|B|00|2|00|C|00|6|00|-|00|0|00|0|00|5|00|0|00|D|00|A|00|1|00|B|00|D|00|9|00|0|00|6|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x007\x002\x007\x00C\x002\x001\x007\x00-\x002\x000\x002\x002\x00-\x001\x001\x00D\x004\x00-\x00B\x002\x00C\x006\x00-\x000\x000\x005\x000\x00D\x00A\x001\x00B\x00D\x009\x000\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16803</id>
        <msg>WEB-ACTIVEX WinDVD IASystemInfo.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17037, service http, policy security-ips drop;</filter2>
        <id>17037</id>
        <msg>WEB-ACTIVEX MS Access multiple control instantiation memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1881</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17038, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17038</id>
        <msg>EXPLOIT Microsoft Access ACCWIZ library release after free attempt - 1</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1881</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17039, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17039</id>
        <msg>EXPLOIT Microsoft Access ACCWIZ library release after free attempt - 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2568</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46|&quot;; within:20; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17042</id>
        <msg>WEB-CLIENT Microsoft LNK shortcut download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-046.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2568</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pif&quot;; nocase; http_uri; pcre:&quot;/\.pif[\s\x3F\x3B]/Ui&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17043</id>
        <msg>WEB-CLIENT Microsoft PIF shortcut download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-046.mspx</url>
      </rule>
      <rule>
        <bugtraq>33247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4388</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3356DB7C-58A7-11D4-AA5C-006097314BF8&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3356DB7C-58A7-11D4-AA5C-006097314BF8\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3356DB7C-58A7-11D4-AA5C-006097314BF8\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17051</id>
        <msg>WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4388</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|5|00|6|00|D|00|B|00|7|00|C|00|-|00|5|00|8|00|A|00|7|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|A|00|5|00|C|00|-|00|0|00|0|00|6|00|0|00|9|00|7|00|3|00|1|00|4|00|B|00|F|00|8|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x003\x005\x006\x00D\x00B\x007\x00C\x00-\x005\x008\x00A\x007\x00-\x001\x001\x00D\x004\x00-\x00A\x00A\x005\x00C\x00-\x000\x000\x006\x000\x009\x007\x003\x001\x004\x00B\x00F\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17052</id>
        <msg>WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4388</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Launcher.LaunchObj&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Launcher\.LaunchObj(\.\d)?\x22|\x27Launcher\.LaunchObj(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx)\s*|.*(?P=v)\s*\.\s*(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Launcher\.LaunchObj(\.\d)?\x22|\x27Launcher\.LaunchObj(\.\d)?\x27)\s*\)(\s*\.\s*(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx)\s*|.*(?P=n)\s*\.\s*(installAppMgr|installAppMgr2|upgradeAsNeeded|upgradeAsNeededEx)\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17053</id>
        <msg>WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4388</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|a|00|u|00|n|00|c|00|h|00|e|00|r|00|.|00|L|00|a|00|u|00|n|00|c|00|h|00|O|00|b|00|j|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00.\x00L\x00a\x00u\x00n\x00c\x00h\x00O\x00b\x00j\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)L\x00a\x00u\x00n\x00c\x00h\x00e\x00r\x00.\x00L\x00a\x00u\x00n\x00c\x00h\x00O\x00b\x00j\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17054</id>
        <msg>WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>34400</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1350</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|02 00 00 00 00 00 00 00 40 09 B9 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17056</id>
        <msg>SPECIFIC-THREATS Novell NetIdentity Agent XTIERRPCPIPE remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>23412</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|9F1363DA-0220-462E-B923-9E3C9038896F|27|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17060</id>
        <msg>SPECIFIC-THREATS Roxio CinePlayer SonicDVDDashVRNav.dll ActiveX control buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23936</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1689</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BE39AEFD-5704-4bb5-B1DF-B7992454AB7E&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BE39AEFD-5704-4bb5-B1DF-B7992454AB7E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Get|Set)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BE39AEFD-5704-4bb5-B1DF-B7992454AB7E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Get|Set))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17061</id>
        <msg>WEB-ACTIVEX Symantec Norton Personal Firewall 2004 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>23936</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1689</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|E|00|3|00|9|00|A|00|E|00|F|00|D|00|-|00|5|00|7|00|0|00|4|00|-|00|4|00|b|00|b|00|5|00|-|00|B|00|1|00|D|00|F|00|-|00|B|00|7|00|9|00|9|00|2|00|4|00|5|00|4|00|A|00|B|00|7|00|E|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00E\x003\x009\x00A\x00E\x00F\x00D\x00-\x005\x007\x000\x004\x00-\x004\x00b\x00b\x005\x00-\x00B\x001\x00D\x00F\x00-\x00B\x007\x009\x009\x002\x004\x005\x004\x00A\x00B\x007\x00E\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17062</id>
        <msg>WEB-ACTIVEX Symantec Norton Personal Firewall 2004 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;54da0fb5-483a-4c53-810b-f131d50a8eb6&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*54da0fb5-483a-4c53-810b-f131d50a8eb6\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*54da0fb5-483a-4c53-810b-f131d50a8eb6\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Start))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17063</id>
        <msg>WEB-ACTIVEX Logitech Video Call 1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|4|00|d|00|a|00|0|00|f|00|b|00|5|00|-|00|4|00|8|00|3|00|a|00|-|00|4|00|c|00|5|00|3|00|-|00|8|00|1|00|0|00|b|00|-|00|f|00|1|00|3|00|1|00|d|00|5|00|0|00|a|00|8|00|e|00|b|00|6|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x004\x00d\x00a\x000\x00f\x00b\x005\x00-\x004\x008\x003\x00a\x00-\x004\x00c\x005\x003\x00-\x008\x001\x000\x00b\x00-\x00f\x001\x003\x001\x00d\x005\x000\x00a\x008\x00e\x00b\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17064</id>
        <msg>WEB-ACTIVEX Logitech Video Call 1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6577b09d-c39d-4e22-9913-c99803f9c388&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6577b09d-c39d-4e22-9913-c99803f9c388\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6577b09d-c39d-4e22-9913-c99803f9c388\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Start))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17065</id>
        <msg>WEB-ACTIVEX Logitech Video Call 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|5|00|7|00|7|00|b|00|0|00|9|00|d|00|-|00|c|00|3|00|9|00|d|00|-|00|4|00|e|00|2|00|2|00|-|00|9|00|9|00|1|00|3|00|-|00|c|00|9|00|9|00|8|00|0|00|3|00|f|00|9|00|c|00|3|00|8|00|8|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x005\x007\x007\x00b\x000\x009\x00d\x00-\x00c\x003\x009\x00d\x00-\x004\x00e\x002\x002\x00-\x009\x009\x001\x003\x00-\x00c\x009\x009\x008\x000\x003\x00f\x009\x00c\x003\x008\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17066</id>
        <msg>WEB-ACTIVEX Logitech Video Call 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;917b29f8-e72a-4761-8371-bf7fca27eb31&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*917b29f8-e72a-4761-8371-bf7fca27eb31\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*917b29f8-e72a-4761-8371-bf7fca27eb31\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Start))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17067</id>
        <msg>WEB-ACTIVEX Logitech Video Call 3 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|1|00|7|00|b|00|2|00|9|00|f|00|8|00|-|00|e|00|7|00|2|00|a|00|-|00|4|00|7|00|6|00|1|00|-|00|8|00|3|00|7|00|1|00|-|00|b|00|f|00|7|00|f|00|c|00|a|00|2|00|7|00|e|00|b|00|3|00|1|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x001\x007\x00b\x002\x009\x00f\x008\x00-\x00e\x007\x002\x00a\x00-\x004\x007\x006\x001\x00-\x008\x003\x007\x001\x00-\x00b\x00f\x007\x00f\x00c\x00a\x002\x007\x00e\x00b\x003\x001\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17068</id>
        <msg>WEB-ACTIVEX Logitech Video Call 3 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;bef0f488-3562-435f-8e89-79d94c9a528c&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bef0f488-3562-435f-8e89-79d94c9a528c\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bef0f488-3562-435f-8e89-79d94c9a528c\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Start))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17069</id>
        <msg>WEB-ACTIVEX Logitech Video Call 4 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b|00|e|00|f|00|0|00|f|00|4|00|8|00|8|00|-|00|3|00|5|00|6|00|2|00|-|00|4|00|3|00|5|00|f|00|-|00|8|00|e|00|8|00|9|00|-|00|7|00|9|00|d|00|9|00|4|00|c|00|9|00|a|00|5|00|2|00|8|00|c|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*b\x00e\x00f\x000\x00f\x004\x008\x008\x00-\x003\x005\x006\x002\x00-\x004\x003\x005\x00f\x00-\x008\x00e\x008\x009\x00-\x007\x009\x00d\x009\x004\x00c\x009\x00a\x005\x002\x008\x00c\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17070</id>
        <msg>WEB-ACTIVEX Logitech Video Call 4 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;bf4c7b03-f381-4544-9a33-cb6dad2a87cd&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bf4c7b03-f381-4544-9a33-cb6dad2a87cd\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*bf4c7b03-f381-4544-9a33-cb6dad2a87cd\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Start))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17071</id>
        <msg>WEB-ACTIVEX Logitech Video Call 5 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24254</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;b|00|f|00|4|00|c|00|7|00|b|00|0|00|3|00|-|00|f|00|3|00|8|00|1|00|-|00|4|00|5|00|4|00|4|00|-|00|9|00|a|00|3|00|3|00|-|00|c|00|b|00|6|00|d|00|a|00|d|00|2|00|a|00|8|00|7|00|c|00|d|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*b\x00f\x004\x00c\x007\x00b\x000\x003\x00-\x00f\x003\x008\x001\x00-\x004\x005\x004\x004\x00-\x009\x00a\x003\x003\x00-\x00c\x00b\x006\x00d\x00a\x00d\x002\x00a\x008\x007\x00c\x00d\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17072</id>
        <msg>WEB-ACTIVEX Logitech Video Call 5 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25785</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5A074B2B-F830-49de-A31B-5BB9D7F6B407&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5A074B2B-F830-49de-A31B-5BB9D7F6B407\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ShortFormat)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5A074B2B-F830-49de-A31B-5BB9D7F6B407\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(ShortFormat))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17073</id>
        <msg>WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25785</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|A|00|0|00|7|00|4|00|B|00|2|00|B|00|-|00|F|00|8|00|3|00|0|00|-|00|4|00|9|00|d|00|e|00|-|00|A|00|3|00|1|00|B|00|-|00|5|00|B|00|B|00|9|00|D|00|7|00|F|00|6|00|B|00|4|00|0|00|7|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x00A\x000\x007\x004\x00B\x002\x00B\x00-\x00F\x008\x003\x000\x00-\x004\x009\x00d\x00e\x00-\x00A\x003\x001\x00B\x00-\x005\x00B\x00B\x009\x00D\x007\x00F\x006\x00B\x004\x000\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17074</id>
        <msg>WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25785</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AskJeevesToolBar.SettingsPlugin&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AskJeevesToolBar\.SettingsPlugin(\.\d)?\x22|\x27AskJeevesToolBar\.SettingsPlugin(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*ShortFormat\s*|.*(?P=v)\s*\.\s*ShortFormat\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AskJeevesToolBar\.SettingsPlugin(\.\d)?\x22|\x27AskJeevesToolBar\.SettingsPlugin(\.\d)?\x27)\s*\)(\s*\.\s*ShortFormat\s*|.*(?P=n)\s*\.\s*ShortFormat)\s*=/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17075</id>
        <msg>WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25785</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|s|00|k|00|J|00|e|00|e|00|v|00|e|00|s|00|T|00|o|00|o|00|l|00|B|00|a|00|r|00|.|00|S|00|e|00|t|00|t|00|i|00|n|00|g|00|s|00|P|00|l|00|u|00|g|00|i|00|n|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00s\x00k\x00J\x00e\x00e\x00v\x00e\x00s\x00T\x00o\x00o\x00l\x00B\x00a\x00r\x00.\x00S\x00e\x00t\x00t\x00i\x00n\x00g\x00s\x00P\x00l\x00u\x00g\x00i\x00n\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00s\x00k\x00J\x00e\x00e\x00v\x00e\x00s\x00T\x00o\x00o\x00l\x00B\x00a\x00r\x00.\x00S\x00e\x00t\x00t\x00i\x00n\x00g\x00s\x00P\x00l\x00u\x00g\x00i\x00n\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17076</id>
        <msg>WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25785</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid|3D 27|clsid|3A|5A074B2B-F830-49DE-A31B-5BB9D7F6B407|27|&quot;; content:&quot;|3D| new String|28|&quot;; distance:0; content:!&quot;|29|&quot;; within:1000; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17077</id>
        <msg>SPECIFIC-THREATS Ask Toolbar AskJeevesToolBar.SettingsPlugin.1 ActiveX control buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26236</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5779</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DC07C721-79E0-4BD4-A89F-C90871946A31&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DC07C721-79E0-4BD4-A89F-C90871946A31\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(OpenURL)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DC07C721-79E0-4BD4-A89F-C90871946A31\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(OpenURL))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17078</id>
        <msg>WEB-ACTIVEX GOM Player GomWeb ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26236</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5779</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|C|00|0|00|7|00|C|00|7|00|2|00|1|00|-|00|7|00|9|00|E|00|0|00|-|00|4|00|B|00|D|00|4|00|-|00|A|00|8|00|9|00|F|00|-|00|C|00|9|00|0|00|8|00|7|00|1|00|9|00|4|00|6|00|A|00|3|00|1|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00C\x000\x007\x00C\x007\x002\x001\x00-\x007\x009\x00E\x000\x00-\x004\x00B\x00D\x004\x00-\x00A\x008\x009\x00F\x00-\x00C\x009\x000\x008\x007\x001\x009\x004\x006\x00A\x003\x001\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17079</id>
        <msg>WEB-ACTIVEX GOM Player GomWeb ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26236</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5779</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;GomWebCtrl.GomManager&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22GomWebCtrl\.GomManager(\.\d)?\x22|\x27GomWebCtrl\.GomManager(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*OpenURL\s*|.*(?P=v)\s*\.\s*OpenURL\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22GomWebCtrl\.GomManager(\.\d)?\x22|\x27GomWebCtrl\.GomManager(\.\d)?\x27)\s*\)(\s*\.\s*OpenURL\s*|.*(?P=n)\s*\.\s*OpenURL\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17080</id>
        <msg>WEB-ACTIVEX GOM Player GomWeb ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26236</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5779</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;G|00|o|00|m|00|W|00|e|00|b|00|C|00|t|00|r|00|l|00|.|00|G|00|o|00|m|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)G\x00o\x00m\x00W\x00e\x00b\x00C\x00t\x00r\x00l\x00.\x00G\x00o\x00m\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)G\x00o\x00m\x00W\x00e\x00b\x00C\x00t\x00r\x00l\x00.\x00G\x00o\x00m\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17081</id>
        <msg>WEB-ACTIVEX GOM Player GomWeb ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26288</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5603</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6EEFD7B1-B26C-440D-B55A-1EC677189F30&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6EEFD7B1-B26C-440D-B55A-1EC677189F30\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddRouteEntry)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6EEFD7B1-B26C-440D-B55A-1EC677189F30\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddRouteEntry))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17082</id>
        <msg>WEB-ACTIVEX SonicWALL SSL-VPN NeLaunchCtrl ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26288</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5603</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|E|00|F|00|D|00|7|00|B|00|1|00|-|00|B|00|2|00|6|00|C|00|-|00|4|00|4|00|0|00|D|00|-|00|B|00|5|00|5|00|A|00|-|00|1|00|E|00|C|00|6|00|7|00|7|00|1|00|8|00|9|00|F|00|3|00|0|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00E\x00E\x00F\x00D\x007\x00B\x001\x00-\x00B\x002\x006\x00C\x00-\x004\x004\x000\x00D\x00-\x00B\x005\x005\x00A\x00-\x001\x00E\x00C\x006\x007\x007\x001\x008\x009\x00F\x003\x000\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17083</id>
        <msg>WEB-ACTIVEX SonicWALL SSL-VPN NeLaunchCtrl ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29391</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0A5FD7C5-A45C-49FC-ADB5-9952547D5715&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0A5FD7C5-A45C-49FC-ADB5-9952547D5715\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(cachefolder)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0A5FD7C5-A45C-49FC-ADB5-9952547D5715\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(cachefolder))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17084</id>
        <msg>WEB-ACTIVEX Creative Software AutoUpdate Engine ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>29391</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|A|00|5|00|F|00|D|00|7|00|C|00|5|00|-|00|A|00|4|00|5|00|C|00|-|00|4|00|9|00|F|00|C|00|-|00|A|00|D|00|B|00|5|00|-|00|9|00|9|00|5|00|2|00|5|00|4|00|7|00|D|00|5|00|7|00|1|00|5|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00A\x005\x00F\x00D\x007\x00C\x005\x00-\x00A\x004\x005\x00C\x00-\x004\x009\x00F\x00C\x00-\x00A\x00D\x00B\x005\x00-\x009\x009\x005\x002\x005\x004\x007\x00D\x005\x007\x001\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17085</id>
        <msg>WEB-ACTIVEX Creative Software AutoUpdate Engine ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29391</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|0A5FD7C5-A45C-49FC-ADB5-9952547D5715|27|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17086</id>
        <msg>SPECIFIC-THREATS Creative Software AutoUpdate Engine CTSUEng.ocx ActiveX control buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>32313</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;433268D7-2CD4-43E6-AA24-2188672E7252&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*433268D7-2CD4-43E6-AA24-2188672E7252\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(OpenPDF)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*433268D7-2CD4-43E6-AA24-2188672E7252\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(OpenPDF))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17087</id>
        <msg>WEB-ACTIVEX VeryDOC PDF Viewer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32313</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|3|00|3|00|2|00|6|00|8|00|D|00|7|00|-|00|2|00|C|00|D|00|4|00|-|00|4|00|3|00|E|00|6|00|-|00|A|00|A|00|2|00|4|00|-|00|2|00|1|00|8|00|8|00|6|00|7|00|2|00|E|00|7|00|2|00|5|00|2|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x003\x003\x002\x006\x008\x00D\x007\x00-\x002\x00C\x00D\x004\x00-\x004\x003\x00E\x006\x00-\x00A\x00A\x002\x004\x00-\x002\x001\x008\x008\x006\x007\x002\x00E\x007\x002\x005\x002\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17088</id>
        <msg>WEB-ACTIVEX VeryDOC PDF Viewer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32313</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PDFVIEW.PdfviewCtrl&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PDFVIEW\.PdfviewCtrl(\.\d)?\x22|\x27PDFVIEW\.PdfviewCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*OpenPDF\s*|.*(?P=v)\s*\.\s*OpenPDF\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PDFVIEW\.PdfviewCtrl(\.\d)?\x22|\x27PDFVIEW\.PdfviewCtrl(\.\d)?\x27)\s*\)(\s*\.\s*OpenPDF\s*|.*(?P=n)\s*\.\s*OpenPDF\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17089</id>
        <msg>WEB-ACTIVEX VeryDOC PDF Viewer ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>32313</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|D|00|F|00|V|00|I|00|E|00|W|00|.|00|P|00|d|00|f|00|v|00|i|00|e|00|w|00|C|00|t|00|r|00|l|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00D\x00F\x00V\x00I\x00E\x00W\x00.\x00P\x00d\x00f\x00v\x00i\x00e\x00w\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)P\x00D\x00F\x00V\x00I\x00E\x00W\x00.\x00P\x00d\x00f\x00v\x00i\x00e\x00w\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17090</id>
        <msg>WEB-ACTIVEX VeryDOC PDF Viewer ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32313</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|433268D7-2CD4-43E6-AA24-2188672E7252|27|&quot;; content:&quot;unescape|28 27 25|u&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17091</id>
        <msg>SPECIFIC-THREATS VeryDOC PDF Viewer ActiveX control OpenPDF buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;63716E93-033D-48B0-8A2F-8E8473FD7AC7&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*63716E93-033D-48B0-8A2F-8E8473FD7AC7\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Download|DownloadAndInstall)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*63716E93-033D-48B0-8A2F-8E8473FD7AC7\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Download|DownloadAndInstall))/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17092</id>
        <msg>WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>36346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|3|00|7|00|1|00|6|00|E|00|9|00|3|00|-|00|0|00|3|00|3|00|D|00|-|00|4|00|8|00|B|00|0|00|-|00|8|00|A|00|2|00|F|00|-|00|8|00|E|00|8|00|4|00|7|00|3|00|F|00|D|00|7|00|A|00|C|00|7|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x003\x007\x001\x006\x00E\x009\x003\x00-\x000\x003\x003\x00D\x00-\x004\x008\x00B\x000\x00-\x008\x00A\x002\x00F\x00-\x008\x00E\x008\x004\x007\x003\x00F\x00D\x007\x00A\x00C\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17093</id>
        <msg>WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Altiris.AeXNSPkgDL&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Altiris\.AeXNSPkgDL(\.\d)?\x22|\x27Altiris\.AeXNSPkgDL(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Download|DownloadAndInstall)\s*|.*(?P=v)\s*\.\s*(Download|DownloadAndInstall)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Altiris\.AeXNSPkgDL(\.\d)?\x22|\x27Altiris\.AeXNSPkgDL(\.\d)?\x27)\s*\)(\s*\.\s*(Download|DownloadAndInstall)\s*|.*(?P=n)\s*\.\s*(Download|DownloadAndInstall)\s*)/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17094</id>
        <msg>WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>36346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|l|00|t|00|i|00|r|00|i|00|s|00|.|00|A|00|e|00|X|00|N|00|S|00|P|00|k|00|g|00|D|00|L|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00l\x00t\x00i\x00r\x00i\x00s\x00.\x00A\x00e\x00X\x00N\x00S\x00P\x00k\x00g\x00D\x00L\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00l\x00t\x00i\x00r\x00i\x00s\x00.\x00A\x00e\x00X\x00N\x00S\x00P\x00k\x00g\x00D\x00L\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17095</id>
        <msg>WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; flowbits:set,imagesource.redefine; flowbits:noalert; metadata: engine shared, soid 3|17113;</filter2>
        <id>17113</id>
        <msg>WEB-CLIENT Microsoft SilverLight ImageSource redefine flowbit</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1882</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.mp3; metadata: engine shared, soid 3|17117, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17117</id>
        <msg>EXPLOIT Microsoft MPEG Layer-3 audio heap corruption attempt</msg>
        <url>www.microsoft.com/technet/Bulletin/advisory/MS10-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1898</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17118, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17118</id>
        <msg>EXPLOIT Microsoft .NET CreateDelegate method arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-060.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-2550</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17125, service netbios-ssn, policy security-ips drop;</filter2>
        <id>17125</id>
        <msg>NETBIOS SMB Trans2 MaxDataCount overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-054.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-2551</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; flowbits:set,smb.small.packet; flowbits:noalert; metadata: engine shared, soid 3|17126, service netbios-ssn;</filter2>
        <id>17126</id>
        <msg>NETBIOS SMB large session length with small packet</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-2551</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-dos; flowbits:isset,smb.small.packet; flowbits:unset,smb.small.packet; metadata: engine shared, soid 3|17127, service netbios-ssn, policy security-ips drop;</filter2>
        <id>17127</id>
        <msg>NETBIOS BytesIndicated validation dos attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2564</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.mswmm; metadata: engine shared, soid 3|17135, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17135</id>
        <msg>EXPLOIT Microsoft Windows Movie Maker string size overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;classid|3D 27|clsid|3A|E68E401C-7DB0-4F3A-88E1-159882468A79|27|&quot;; content:&quot;defer&gt;&quot;; within:100; content:&quot;unescape|28 22 25|&quot;; within:50; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17160</id>
        <msg>SPECIFIC-THREATS Liquid XML Studio LtXmlComHelp8.dll ActiveX OpenFile buffer overflow attempt</msg>
        <url>secunia.com/advisories/38974</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E68E401C-7DB0-4F3A-88E1-159882468A79&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E68E401C-7DB0-4F3A-88E1-159882468A79\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(OpenFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E68E401C-7DB0-4F3A-88E1-159882468A79\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(OpenFile))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17161</id>
        <msg>WEB-ACTIVEX Liquid XML Studio ActiveX clsid access</msg>
        <url>secunia.com/advisories/38974</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|8|00|E|00|4|00|0|00|1|00|C|00|-|00|7|00|D|00|B|00|0|00|-|00|4|00|F|00|3|00|A|00|-|00|8|00|8|00|E|00|1|00|-|00|1|00|5|00|9|00|8|00|8|00|2|00|4|00|6|00|8|00|A|00|7|00|9|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x006\x008\x00E\x004\x000\x001\x00C\x00-\x007\x00D\x00B\x000\x00-\x004\x00F\x003\x00A\x00-\x008\x008\x00E\x001\x00-\x001\x005\x009\x008\x008\x002\x004\x006\x008\x00A\x007\x009\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17162</id>
        <msg>WEB-ACTIVEX Liquid XML Studio ActiveX clsid unicode access</msg>
        <url>secunia.com/advisories/38974</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LtXmlComHelp8.UnicodeFile&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LtXmlComHelp8\.UnicodeFile(\.\d)?\x22|\x27LtXmlComHelp8\.UnicodeFile(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*OpenFile\s*|.*(?P=v)\s*\.\s*OpenFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LtXmlComHelp8\.UnicodeFile(\.\d)?\x22|\x27LtXmlComHelp8\.UnicodeFile(\.\d)?\x27)\s*\)(\s*\.\s*OpenFile\s*|.*(?P=n)\s*\.\s*OpenFile\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17163</id>
        <msg>WEB-ACTIVEX Liquid XML Studio ActiveX function call access</msg>
        <url>secunia.com/advisories/38974</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|t|00|X|00|m|00|l|00|C|00|o|00|m|00|H|00|e|00|l|00|p|00|8|00|.|00|U|00|n|00|i|00|c|00|o|00|d|00|e|00|F|00|i|00|l|00|e|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)L\x00t\x00X\x00m\x00l\x00C\x00o\x00m\x00H\x00e\x00l\x00p\x008\x00.\x00U\x00n\x00i\x00c\x00o\x00d\x00e\x00F\x00i\x00l\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)L\x00t\x00X\x00m\x00l\x00C\x00o\x00m\x00H\x00e\x00l\x00p\x008\x00.\x00U\x00n\x00i\x00c\x00o\x00d\x00e\x00F\x00i\x00l\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17164</id>
        <msg>WEB-ACTIVEX Liquid XML Studio ActiveX function call unicode access</msg>
        <url>secunia.com/advisories/38974</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;07070bfd-c501-4899-934d-0b96a9f70795&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*07070bfd-c501-4899-934d-0b96a9f70795\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17167</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 1 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|7|00|0|00|7|00|0|00|b|00|f|00|d|00|-|00|c|00|5|00|0|00|1|00|-|00|4|00|8|00|9|00|9|00|-|00|9|00|3|00|4|00|d|00|-|00|0|00|b|00|9|00|6|00|a|00|9|00|f|00|7|00|0|00|7|00|9|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x007\x000\x007\x000\x00b\x00f\x00d\x00-\x00c\x005\x000\x001\x00-\x004\x008\x009\x009\x00-\x009\x003\x004\x00d\x00-\x000\x00b\x009\x006\x00a\x009\x00f\x007\x000\x007\x009\x005\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17168</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 1 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;26bac093-997c-4084-bad6-c35f5d67ea99&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*26bac093-997c-4084-bad6-c35f5d67ea99\s*}?\s*(?P=q3)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17169</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 2 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|6|00|b|00|a|00|c|00|0|00|9|00|3|00|-|00|9|00|9|00|7|00|c|00|-|00|4|00|0|00|8|00|4|00|-|00|b|00|a|00|d|00|6|00|-|00|c|00|3|00|5|00|f|00|5|00|d|00|6|00|7|00|e|00|a|00|9|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q4&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x006\x00b\x00a\x00c\x000\x009\x003\x00-\x009\x009\x007\x00c\x00-\x004\x000\x008\x004\x00-\x00b\x00a\x00d\x006\x00-\x00c\x003\x005\x00f\x005\x00d\x006\x007\x00e\x00a\x009\x009\x00(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17170</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 2 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;631F0C94-C02F-40AC-A31B-DDC39731FC81&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*631F0C94-C02F-40AC-A31B-DDC39731FC81\s*}?\s*(?P=q5)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17171</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 3 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|3|00|1|00|F|00|0|00|C|00|9|00|4|00|-|00|C|00|0|00|2|00|F|00|-|00|4|00|0|00|A|00|C|00|-|00|A|00|3|00|1|00|B|00|-|00|D|00|D|00|C|00|3|00|9|00|7|00|3|00|1|00|F|00|C|00|8|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x003\x001\x00F\x000\x00C\x009\x004\x00-\x00C\x000\x002\x00F\x00-\x004\x000\x00A\x00C\x00-\x00A\x003\x001\x00B\x00-\x00D\x00D\x00C\x003\x009\x007\x003\x001\x00F\x00C\x008\x001\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17172</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 3 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;68cdb19a-6305-4589-8c35-41e3502cd451&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*68cdb19a-6305-4589-8c35-41e3502cd451\s*}?\s*(?P=q7)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17173</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 4 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|c|00|d|00|b|00|1|00|9|00|a|00|-|00|6|00|3|00|0|00|5|00|-|00|4|00|5|00|8|00|9|00|-|00|8|00|c|00|3|00|5|00|-|00|4|00|1|00|e|00|3|00|5|00|0|00|2|00|c|00|d|00|4|00|5|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x008\x00c\x00d\x00b\x001\x009\x00a\x00-\x006\x003\x000\x005\x00-\x004\x005\x008\x009\x00-\x008\x00c\x003\x005\x00-\x004\x001\x00e\x003\x005\x000\x002\x00c\x00d\x004\x005\x001\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17174</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 4 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;81a81dd2-a261-442a-b9b1-df10a2542020&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*81a81dd2-a261-442a-b9b1-df10a2542020\s*}?\s*(?P=q9)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17175</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 5 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|1|00|a|00|8|00|1|00|d|00|d|00|2|00|-|00|a|00|2|00|6|00|1|00|-|00|4|00|4|00|2|00|a|00|-|00|b|00|9|00|b|00|1|00|-|00|d|00|f|00|1|00|0|00|a|00|2|00|5|00|4|00|2|00|0|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x001\x00a\x008\x001\x00d\x00d\x002\x00-\x00a\x002\x006\x001\x00-\x004\x004\x002\x00a\x00-\x00b\x009\x00b\x001\x00-\x00d\x00f\x001\x000\x00a\x002\x005\x004\x002\x000\x002\x000\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17176</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 5 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;45874228-a445-40dc-962b-ec15559b1741&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*45874228-a445-40dc-962b-ec15559b1741\s*}?\s*(?P=q11)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17177</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 6 ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3737</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|5|00|8|00|7|00|4|00|2|00|2|00|8|00|-|00|a|00|4|00|4|00|5|00|-|00|4|00|0|00|d|00|c|00|-|00|9|00|6|00|2|00|b|00|-|00|e|00|c|00|1|00|5|00|5|00|5|00|9|00|b|00|1|00|7|00|4|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q12&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x005\x008\x007\x004\x002\x002\x008\x00-\x00a\x004\x004\x005\x00-\x004\x000\x00d\x00c\x00-\x009\x006\x002\x00b\x00-\x00e\x00c\x001\x005\x005\x005\x009\x00b\x001\x007\x004\x001\x00(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17178</id>
        <msg>WEB-ACTIVEX Oracle Siebel Option Pack 6 ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/174089</url>
      </rule>
      <rule>
        <bugtraq>33408</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CamImage.CamImage&quot;; nocase; pcre:&quot;/(\x3d\s*new\s+ActiveXObject\s*\x28\s*(?P&lt;q1&gt;\x22|\x27)CamImage\.CamImage\.\d(?P=q1)\s*\x29|\x3d\s*CreateObject\s*\x28\s*(?P&lt;q2&gt;\x22|\x27)CamImage\.CamImage\.\d(?P=q2)\s*\x29)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17226</id>
        <msg>WEB-ACTIVEX AXIS Camera ActiveX initialization via script</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.wmv&quot;; nocase; http_uri; flowbits:set,http.wmv; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>17241</id>
        <msg>WEB-CLIENT Microsoft wmv file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0820</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17249, service ldap, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17249</id>
        <msg>EXPLOIT Microsoft LSASS integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2738</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17256, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17256</id>
        <msg>WEB-CLIENT Microsoft Windows uniscribe fonts parsing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>13248</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1191</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|1E 00 00 00|&quot;; fast_pattern; content:&quot;javascript&quot;; distance:0; nocase; pcre:&quot;/\x1e\x00\x00\x00.{4}[^\x00]*?\x40[^\x00]*?javascript/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17271</id>
        <msg>WEB-CLIENT Microsoft Windows Web View script injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>18993</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3656</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|A4 37 7A 00 81 00 00 00 00 00 82 00 00 00 00 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17285</id>
        <msg>WEB-CLIENT Microsoft Powerpoint PPT file parsing memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>20322</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3876</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|F2 03|&quot;; content:&quot;|AA AA AA 2F 00 C8 0F 0C 00 00 00 30 00 D2 0F 04 00|&quot;; within:17; distance:1; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17292</id>
        <msg>WEB-CLIENT Microsoft Powerpoint malformed data record code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>27658</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0105</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,works.download; content:&quot;|22 07 00 00 00 22 22 22 22 00 22 06 00 00 00 02 00 46 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17304</id>
        <msg>WEB-CLIENT Microsoft Works file converter file section header index table stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2008-1437</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;|49 44 45 44 38 55 45 47 47 53 39 6F 4F 72 2F 79 6A 45 77 6D 47 4C 76 57 4A 6A 56 4B 6B 6F 6D 6E 78 6E 2F 63 44 45 63 31 50 35|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:denial-of-service;</filter2>
        <id>17306</id>
        <msg>SPECIFIC-THREATS Microsoft Malware Protection Engine file processing denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>30552</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0120</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|26 00 00 00 7F 00 80 00 80 00 04 41 64 00 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17310</id>
        <msg>SPECIFIC-THREATS Microsoft Powerpoint Viewer Memory Allocation Code Execution</msg>
      </rule>
      <rule>
        <bugtraq>19389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3281</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.|7B|3050F4D8-98B5-11CF-BB82-00AA00BDCE0B|7D|&quot;; fast_pattern:only; nocase; pcre:&quot;/\x252e\x252e\x255c[^\s\x2e]*?\x2e\x7B3050F4D8-98B5-11CF-BB82-00AA00BDCE0B\x7d/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17316</id>
        <msg>WEB-CLIENT Microsoft Windows Folder GUID Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20495</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|F8 0F 04 00 00 00|&quot;; byte_test:4,&gt;,2,0,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17318</id>
        <msg>WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20495</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|FA 0F 04 00 00 00|&quot;; byte_test:4,&gt;,2147483646,0,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17319</id>
        <msg>WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20495</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|F9 0F 04 00 00 00|&quot;; byte_test:4,&gt;,2147483646,0,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17320</id>
        <msg>WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>25092</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6701</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,100,4,relative,dce; byte_test:4,&lt;,133,-4,relative,dce; content:&quot;N|00|e|00|t|00|W|00|a|00|r|00|e|00| |00|R|00|e|00|m|00|o|00|t|00|e|00| |00|P|00|r|00|i|00|n|00|t|00|e|00|r|00|s|00|&quot;; within:46; distance:20; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17321</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters name overflow attempt</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5005400.html</url>
      </rule>
      <rule>
        <bugtraq>16167</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0143</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,wmf.download; file_data; content:&quot;|00 09 00 00 03|&quot;; content:&quot;|04 00 00 00|&quot;; distance:0; pcre:&quot;/^(\x01|\x02)\x00\x09\x00{2}\x03/m&quot;; pcre:&quot;/\x04\x00{3}(\x26|\xff)/Rm&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17330</id>
        <msg>WEB-CLIENT Microsoft Windows GRE WMF Handling Memory Read Exception attempt</msg>
      </rule>
      <rule>
        <bugtraq>14214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;rXYZ&quot;; byte_test:4,&gt;,60,4,relative; content:&quot;gXYZ&quot;; within:4; distance:8; content:&quot;bXYZ&quot;; within:4; distance:8; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17347</id>
        <msg>WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;gXYZ&quot;; content:&quot;gXYZ&quot;; within:4; distance:8; content:&quot;bXYZ&quot;; within:4; distance:8; byte_test:4,&gt;,60,4,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17348</id>
        <msg>WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;bXYZ&quot;; content:&quot;gXYZ&quot;; within:4; distance:8; byte_test:4,&gt;,60,4,relative; content:&quot;bXYZ&quot;; within:4; distance:8; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17349</id>
        <msg>WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;.cnt&quot;; nocase; http_uri; pcre:&quot;/\x2Ecnt([\?\x5c\x2f]|$)/smiU&quot;; flowbits:set,MS_Help_content_file; flowbits:noalert; classtype:web-application-activity;</filter2>
        <id>17364</id>
        <msg>WEB-CLIENT Microsoft Help Workshop CNT Help contents</msg>
      </rule>
      <rule>
        <bugtraq>22100</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0352</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; flowbits:isset,MS_Help_content_file; content:&quot;Content-Type: text/plain&quot;; fast_pattern:only; file_data; pcre:&quot;/[^\n]{513}/Rsi&quot;; metadata:policy security-ips drop; classtype:web-application-attack;</filter2>
        <id>17365</id>
        <msg>WEB-CLIENT Microsoft Help Workshop CNT Help contents buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22135</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0427</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;HLP&quot;; nocase; pcre:&quot;/^\s*HLP\s*\x3d\s*[^\n]{257}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17366</id>
        <msg>WEB-CLIENT Microsoft Help Workshop HPJ OPTIONS section buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23382</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1912</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;|3F 5F 03 00|&quot;; depth:4; content:&quot;TTLBTREE|00 2E 06 00 00 7C 62|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17374</id>
        <msg>SPECIFIC-THREATS Microsoft Windows HLP File Handling heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28607</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1088</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|00 0B 00 00 00 CC E5 1A 00 41 41 41 41 00 00 00 00 03 02 01 22|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17382</id>
        <msg>SPECIFIC-THREATS Microsoft Project Invalid Memory Pointer Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>29158</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0119</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|00 00 03 68 1A 01 00 00 34 00 00 00 01 20 01 00|&quot;; content:&quot;|01 20 1D 01 00 00 02 20 1C 01 00 00 03 90 5A 05 00 00 00 78 00 78|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17383</id>
        <msg>SPECIFIC-THREATS Microsoft Publisher Object Handler Validation Code Execution attempted</msg>
      </rule>
      <rule>
        <bugtraq>24963</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4183</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|00 00 0A 00 00 00 00 00 00 00 00 00 00 80 00 80 20 20|&quot;; within:18; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17408</id>
        <msg>WEB-CLIENT Microsoft DirectX Targa image file heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12960</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0944</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;P|00|a|00|r|00|e|00|n|00|t|00|I|00|d|00|n|00|a|00|m|00|e|00 75 76|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17413</id>
        <msg>SPECIFIC-THREATS Microsoft Jet DB Engine Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25282</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2224</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|2E|substringData&quot;; pcre:&quot;/\x2esubstringData\s*\x28[^\x2c]*\x2c\s*0x7(f|F){6}[6-9AaBbCcDdEeFf]/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17421</id>
        <msg>WEB-CLIENT Microsoft OLE automation string manipulation overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2010-3332</cve>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; detection_filter:track by_src, count 100, seconds 30; metadata: engine shared, soid 3|17428, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17428</id>
        <msg>WEB-MISC Microsoft ASP.NET information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-070.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2010-3332</cve>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; detection_filter:track by_src, count 100, seconds 30; metadata: engine shared, soid 3|17429, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17429</id>
        <msg>WEB-MISC Microsoft ASP.NET information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-070.mspx</url>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:11; dce_stub_data; content:&quot;|5C 00 5C 00|&quot;; distance:16; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>17436</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:11; dce_stub_data; content:&quot;|5C 5C|&quot;; distance:16; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>17438</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>15063</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2128</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;RIFF&quot;; content:&quot;strn&quot;; distance:0; nocase; byte_test:4,&gt;,128,0,relative, little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17443</id>
        <msg>WEB-CLIENT Microsoft DirectShow AVI decoder buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FA3662C3-B8E8-11D6-A667-0010B556D978&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FA3662C3-B8E8-11D6-A667-0010B556D978\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetMetadata)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FA3662C3-B8E8-11D6-A667-0010B556D978\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetMetadata))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17464</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|A|00|3|00|6|00|6|00|2|00|C|00|3|00|-|00|B|00|8|00|E|00|8|00|-|00|1|00|1|00|D|00|6|00|-|00|A|00|6|00|6|00|7|00|-|00|0|00|0|00|1|00|0|00|B|00|5|00|5|00|6|00|D|00|9|00|7|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00A\x003\x006\x006\x002\x00C\x003\x00-\x00B\x008\x00E\x008\x00-\x001\x001\x00D\x006\x00-\x00A\x006\x006\x007\x00-\x000\x000\x001\x000\x00B\x005\x005\x006\x00D\x009\x007\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17465</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document|2E|location|2E|replace&quot;; content:&quot;|2E|exe&quot;; distance:0; nocase; content:&quot;|2E|pdf&quot;; distance:0; nocase; pcre:&quot;/document\x2Elocation\x2Ereplace\s*\x28\s*(\x22|\x27)[a-z0-9]+\.exe\?[a-z0-9]+\.pdf/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17467</id>
        <msg>WEB-CLIENT Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;launchURL&quot;; nocase; content:&quot;http|3A|&quot;; distance:0; pcre:&quot;/[^\n]*?[\x25\x22]\x2E(com|bat|cmd|exe)/Ri&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>17468</id>
        <msg>WEB-CLIENT Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>17325</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1591</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|80 80 00 00 C0 C0 C0 00 80 80 80 00 00 00 FF 00 00 FF 00 00 00 FF FF 00 FF 00 00 00 FF 00 FF 00 FF FF 00 00 FF FF FF 00 00 41 41 41 41 41 41 41|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17489</id>
        <msg>SPECIFIC-THREATS Microsoft Windows Help File Heap Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17926</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|74 03 9E 02 4A 02 9C 01 12 01 8B 00 3E 00 25 00 00 00 02 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17490</id>
        <msg>SPECIFIC-THREATS Microsoft Windows itss.dll CHM File Handling Heap Corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>20226</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4694</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|0F 00 10 04 36 00 00 00 0F 00 11 05 2E 00 00 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17496</id>
        <msg>WEB-CLIENT Microsoft Powerpoint malformed NamedShows record code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20226</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4694</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|0F 00 10 04 1E 02 00 00 EB 0A 11 06 2E 02 00 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17497</id>
        <msg>WEB-CLIENT Microsoft Powerpoint malformed NamedShows record code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>21688</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2006-6696</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.application&quot;; nocase; http_uri; flowbits:set,net.application; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17508</id>
        <msg>WEB-MISC Microsoft .NET Application download attempt</msg>
      </rule>
      <rule>
        <bugtraq>21688</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2006-6696</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; flowbits:isset,net.application; content:&quot;.manifest&quot;; nocase; http_uri; flowbits:set,manifest.application; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17509</id>
        <msg>WEB-MISC Microsoft .NET Manifest download attempt</msg>
      </rule>
      <rule>
        <bugtraq>21688</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2006-6696</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; flowbits:isset,manifest.application; content:&quot;.deploy&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17510</id>
        <msg>WEB-MISC Microsoft .NET Deploy download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;new ActiveXObject|28|&quot;; nocase; content:&quot;unescape|28|&quot;; within:20; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17571</id>
        <msg>WEB-ACTIVEX obfuscated instantiation of ActiveX object - likely malicious</msg>
      </rule>
      <rule>
        <bugtraq>32155</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2008-4029</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;|21|DOCTYPE &quot;; nocase; content:&quot;SYSTEM&quot;; distance:0; nocase; content:&quot;.parseError&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/&lt;\x21DOCTYPE\s+[^&gt;]*?SYSTEM[^&gt;]*?&gt;.*?\x2EparseError/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>17572</id>
        <msg>WEB-CLIENT Microsoft XML Core Services cross-site information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;24e04ebf-014d-471f-930e-7654b1193ba9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24e04ebf-014d-471f-930e-7654b1193ba9\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddTab)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24e04ebf-014d-471f-930e-7654b1193ba9\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddTab))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17575</id>
        <msg>WEB-ACTIVEX SizerOne 2 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|4|00|e|00|0|00|4|00|e|00|b|00|f|00|-|00|0|00|1|00|4|00|d|00|-|00|4|00|7|00|1|00|f|00|-|00|9|00|3|00|0|00|e|00|-|00|7|00|6|00|5|00|4|00|b|00|1|00|1|00|9|00|3|00|b|00|a|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x004\x00e\x000\x004\x00e\x00b\x00f\x00-\x000\x001\x004\x00d\x00-\x004\x007\x001\x00f\x00-\x009\x003\x000\x00e\x00-\x007\x006\x005\x004\x00b\x001\x001\x009\x003\x00b\x00a\x009\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17576</id>
        <msg>WEB-ACTIVEX SizerOne 2 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>12175</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CcErrDsp.ErrorDisplay&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CcErrDsp\.ErrorDisplay(\.\d)?\x22|\x27CcErrDsp\.ErrorDisplay(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DisplayError\s*|.*(?P=v)\s*\.\s*DisplayError\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CcErrDsp\.ErrorDisplay(\.\d)?\x22|\x27CcErrDsp\.ErrorDisplay(\.\d)?\x27)\s*\)(\s*\.\s*DisplayError\s*|.*(?P=n)\s*\.\s*DisplayError\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17582</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus CcErrDisp ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>12175</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|c|00|E|00|r|00|r|00|D|00|s|00|p|00|.|00|E|00|r|00|r|00|o|00|r|00|D|00|i|00|s|00|p|00|l|00|a|00|y|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q1&gt;\x22|\x27|)C\x00c\x00E\x00r\x00r\x00D\x00s\x00p\x00.\x00E\x00r\x00r\x00o\x00r\x00D\x00i\x00s\x00p\x00l\x00a\x00y\x00(\.\x00\d\x00)?(?P=q1)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q2&gt;\x22|\x27|)C\x00c\x00E\x00r\x00r\x00D\x00s\x00p\x00.\x00E\x00r\x00r\x00o\x00r\x00D\x00i\x00s\x00p\x00l\x00a\x00y\x00(\.\x00\d\x00)?(?P=q2)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17583</id>
        <msg>WEB-ACTIVEX Symantec Norton AntiVirus CcErrDisp ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21155</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6027</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CA8A9780-280D-11CF-A24D-444553540000&quot;; nocase; content:&quot;onClick=|22|checkversion|28|fn.value|29 22|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17587</id>
        <msg>SPECIFIC-THREATS AcroPDF.PDF ActiveX exploit attempt</msg>
        <url>www.adobe.com/support/security/advisories/apsa06-02.html</url>
      </rule>
      <rule>
        <bugtraq>19636</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4495</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4682C82A-B2FF-11D0-95A8-00A0C92B77A9&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17592</id>
        <msg>WEB-ACTIVEX Microsoft MyInfo.dll ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=16</url>
      </rule>
      <rule>
        <bugtraq>19636</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4495</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8E71888A-423F-11D2-876E-00A0C9082467&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17593</id>
        <msg>WEB-ACTIVEX Microsoft msdxm.ocx ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=16</url>
      </rule>
      <rule>
        <bugtraq>19636</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4495</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;606EF130-9852-11D3-97C6-0060084856D4&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17594</id>
        <msg>WEB-ACTIVEX Microsoft creator.dll 1 ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=16</url>
      </rule>
      <rule>
        <bugtraq>19636</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4495</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F849164D-9863-11D3-97C6-0060084856D4&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17595</id>
        <msg>WEB-ACTIVEX Microsoft creator.dll 2 ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=16</url>
      </rule>
      <rule>
        <bugtraq>19636</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4495</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3BC4F3A3-652A-11D1-B4D4-00C04FC2DB8D&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17596</id>
        <msg>WEB-ACTIVEX Microsoft ciodm.dll ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=16</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A009C90D-814B-11D3-BA3E-080009D22344&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A009C90D-814B-11D3-BA3E-080009D22344\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Execute)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A009C90D-814B-11D3-BA3E-080009D22344\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Execute))/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17614</id>
        <msg>WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX clsid access</msg>
        <url>securitytracker.com/alerts/2010/Mar/1023760.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|0|00|0|00|9|00|C|00|9|00|0|00|D|00|-|00|8|00|1|00|4|00|B|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|A|00|3|00|E|00|-|00|0|00|8|00|0|00|0|00|0|00|9|00|D|00|2|00|2|00|3|00|4|00|4|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x000\x000\x009\x00C\x009\x000\x00D\x00-\x008\x001\x004\x00B\x00-\x001\x001\x00D\x003\x00-\x00B\x00A\x003\x00E\x00-\x000\x008\x000\x000\x000\x009\x00D\x002\x002\x003\x004\x004\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17615</id>
        <msg>WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX clsid unicode access</msg>
        <url>securitytracker.com/alerts/2010/Mar/1023760.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SAPBExCommonResources.BExGlobal&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SAPBExCommonResources\.BExGlobal(\.\d)?\x22|\x27SAPBExCommonResources\.BExGlobal(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Execute\s*|.*(?P=v)\s*\.\s*Execute\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SAPBExCommonResources\.BExGlobal(\.\d)?\x22|\x27SAPBExCommonResources\.BExGlobal(\.\d)?\x27)\s*\)(\s*\.\s*Execute\s*|.*(?P=n)\s*\.\s*Execute\s*)/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17616</id>
        <msg>WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX function call access</msg>
        <url>securitytracker.com/alerts/2010/Mar/1023760.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|A|00|P|00|B|00|E|00|x|00|C|00|o|00|m|00|m|00|o|00|n|00|R|00|e|00|s|00|o|00|u|00|r|00|c|00|e|00|s|00|.|00|B|00|E|00|x|00|G|00|l|00|o|00|b|00|a|00|l|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00A\x00P\x00B\x00E\x00x\x00C\x00o\x00m\x00m\x00o\x00n\x00R\x00e\x00s\x00o\x00u\x00r\x00c\x00e\x00s\x00.\x00B\x00E\x00x\x00G\x00l\x00o\x00b\x00a\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00A\x00P\x00B\x00E\x00x\x00C\x00o\x00m\x00m\x00o\x00n\x00R\x00e\x00s\x00o\x00u\x00r\x00c\x00e\x00s\x00.\x00B\x00E\x00x\x00G\x00l\x00o\x00b\x00a\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17617</id>
        <msg>WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX function call unicode access</msg>
        <url>securitytracker.com/alerts/2010/Mar/1023760.html</url>
      </rule>
      <rule>
        <bugtraq>15352</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2123</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|C5 00 00 00 04 00 00 80 8D 00 83 00 8D 00 84 00 AF 01 10 01 AF 01 0F 01|&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17618</id>
        <msg>SPECIFIC-THREATS Microsoft Windows hraphics engine EMF rendering vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>16194</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0010</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|53 51 86 A4 50 1D CD 50 3B D5 D0 6C E3 D5 19 36 A5 55 34 63 7A 7B B1 04 1D E7 EF 6A 69 49 8A 54 D1 73 FD 0C F7 02 5E FA 70 4E E8 68 94 FF 14 1E DC 80 7B 58 96 D0 4A 7C DF F0 5C F0 50 88 73 8D|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17626</id>
        <msg>SPECIFIC-THREATS Microsoft Windows embedded web font handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33118</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2009-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB|75|&quot;; depth:5; offset:4; byte_jump:1,27,relative,multiplier 2; byte_jump:2,-2,relative,little; content:&quot;|5C 00 5C 00|&quot;; within:4; distance:2; content:&quot;|5C 00 00 00|&quot;; distance:0; pcre:&quot;/\x5c\x00\x5c\x00[^\x5c]*\x5c\x00\x00\x00/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-recon;</filter2>
        <id>17639</id>
        <msg>NETBIOS Samba Root File System access bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>34834</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0223</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.ppt; content:&quot;|FF 03 00 00 00 60 16 8F 10 00 00 00 00 5F 07 90 08 28 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17646</id>
        <msg>WEB-CLIENT Microsoft Powerpoint Legacy file format picture object code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>27756</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5711</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5C6698D9-7BE4-4122-8EC5-291D84DBD4A0&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 22 25|u&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17654</id>
        <msg>SPECIFIC-THREATS Facebook Photo Uploader ActiveX exploit attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>35970</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.avi; metadata: engine shared, soid 3|17694, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17694</id>
        <msg>WEB-CLIENT Microsoft Windows AVI file chunk length integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34833</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0220</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|17695, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17695</id>
        <msg>WEB-CLIENT Microsoft PowerPoint paragraph format array inner header overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15460</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-3644</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:48; dce_stub_data; byte_test:4,&gt;,65534,70,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-dos;</filter2>
        <id>17702</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrDfsCreateExitPoint dos attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/911052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|30 26 B2 75 8E 66 CF 11 A6 D9 00 AA 00 62 CE 6C|&quot;; content:&quot;|91 07 DC B7 B7 A9 CF 11 8E E6 00 C0 0C 20 53 65|&quot;; content:&quot;|E0 7D 90 35 15 E4 CF 11 A9 17 00 80 5F 5C 44 2B|&quot;; byte_test:2,&gt;,0xffc6,52,relative,little; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17711</id>
        <msg>WEB-CLIENT Microsoft Windows ASF parsing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-1924</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17721, service netbios-ns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17721</id>
        <msg>EXPLOIT WINS replication inform2 request memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0231</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17723, service netbios-ns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17723</id>
        <msg>NETBIOS possible SMB replay attempt - overlapping encryption keys detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0099</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;getElementById&quot;; nocase; content:&quot;setTimeout&quot;; fast_pattern; nocase; pcre:&quot;/\x2esrc\s*=\s*[\x22\x27]([^\x2e]+)\x2exml\x3f[\x22\x27]\s*\x2b.*\x2esrc\s*=\s*[\x22\x27]\1\x2exml\x3f[^\x22\x27]+[\x22\x27]\s\x2b/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17730</id>
        <msg>WEB-CLIENT Microsoft XML Core Services MIME Viewer memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>15067</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1987</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;FromAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17737</id>
        <msg>SPECIFIC-THREATS Microsoft collaboration data objects buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB2&quot;; depth:5; offset:4; content:&quot;|01 00|&quot;; within:2; distance:56; flowbits:set,smb.trans2.findfirst2; flowbits:noalert; metadata:service netbios-ssn; classtype:misc-activity;</filter2>
        <id>17745</id>
        <msg>NETBIOS SMB TRANS2 Find_First2 request attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0045</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,smb.trans2.findfirst2; content:&quot;|FF|SMB2&quot;; depth:5; offset:4; flowbits:unset,smb.trans2.findfirst2; byte_jump:1,27,relative,multiplier 2; byte_test:2,&gt;,1000,0,relative,little; byte_test:4,&gt;,300,75,relative,little; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17746</id>
        <msg>NETBIOS SMB client TRANS response Find_First2 filesize overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>34205</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-1072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00 02 00 01 86 A3 00 00 00 04 00 00 00 01|&quot;; depth:28; byte_jump:4,4,relative,big; byte_jump:4,4,relative,big; byte_jump:4,0,relative,big; content:&quot;|00 00 00 06 00 00 00|&quot;; byte_test:1,&gt;,2,0,relative; byte_test:1,&lt;,5,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:misc-attack;</filter2>
        <id>17749</id>
        <msg>RPC Linux Kernel nfsd v4 CAP_MKNOD security bypass attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3329</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17770, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17770</id>
        <msg>WEB-ACTIVEX Microsoft HtmlDlgHelper ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3331</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17772, service http, policy security-ips drop;</filter2>
        <id>17772</id>
        <msg>WEB-ACTIVEX Microsoft Scriptlet Component ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.exe; metadata: engine shared, soid 3|18064, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18064</id>
        <msg>EXPLOIT Microsoft .NET framework EntityObject execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-077.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2572</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|18065, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18065</id>
        <msg>EXPLOIT Microsoft PowerPoint converter bad indirection remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-088</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2573</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|18066, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18066</id>
        <msg>WEB-CLIENT Microsoft PowerPoint integer underflow heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-088</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3337</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18070, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18070</id>
        <msg>NETBIOS pptimpconv.dll access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2733</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18073, policy security-ips drop;</filter2>
        <id>18073</id>
        <msg>WEB-MISC Microsoft Forefront UAG arbitrary embedded scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3732</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B94C2238-346E-4C5E-9B36-8CC627F35574&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B94C2238-346E-4C5E-9B36-8CC627F35574\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(connect)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B94C2238-346E-4C5E-9B36-8CC627F35574\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(connect))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18097</id>
        <msg>WEB-ACTIVEX VMWare Remote Console Plug-In ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21108</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5198</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|Z|00|F|00|I|00|L|00|E|00|V|00|I|00|E|00|W|00|.|00|F|00|i|00|l|00|e|00|V|00|i|00|e|00|w|00|C|00|t|00|r|00|l|00|.|00|6|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)W\x00Z\x00F\x00I\x00L\x00E\x00V\x00I\x00E\x00W\x00.\x00F\x00i\x00l\x00e\x00V\x00i\x00e\x00w\x00C\x00t\x00r\x00l\x00.\x006\x001\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00Z\x00F\x00I\x00L\x00E\x00V\x00I\x00E\x00W\x00.\x00F\x00i\x00l\x00e\x00V\x00i\x00e\x00w\x00C\x00t\x00r\x00l\x00.\x006\x001\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18169</id>
        <msg>WEB-ACTIVEX WinZip FileView 6.1 ActiveX function call unicode access</msg>
        <url>www.winzip.com/wz7245.htm</url>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; content:&quot;^t|D1 05|0|00 00 00 10 00 00 00| |00 00 00 00 00 00 00|&quot;; within:20; distance:48; content:&quot;|05 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>18189</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt</msg>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; content:&quot;^t|D1 05|0|00 00 00 10 00 00 00| |00 00 00 00 00 00 00|&quot;; within:20; distance:48; content:&quot;|04 00|&quot;; metadata:policy security-ips drop, service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>18190</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt</msg>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; content:&quot;_t|D1 05|0|00 00 00 10 00 00 00| |00 00 00 00 00 00 00|&quot;; within:20; distance:68; content:&quot;|05 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>18191</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt</msg>
      </rule>
      <rule>
        <bugtraq>24198</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4fc742e0-4a10-11cf-8273-00aa004ae673; dce_opnum:5; dce_stub_data; content:&quot;_t|D1 05|0|00 00 00 10 00 00 00| |00 00 00 00 00 00 00|&quot;; within:20; distance:68; content:&quot;|04 00|&quot;; metadata:policy security-ips drop, service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>18192</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3340</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18197, service http, policy security-ips drop;</filter2>
        <id>18197</id>
        <msg>WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3340</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18198, service http, policy security-ips drop;</filter2>
        <id>18198</id>
        <msg>WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3340</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18199, service http, policy security-ips drop;</filter2>
        <id>18199</id>
        <msg>WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3144</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18203, service netbios-ssn, policy security-ips drop;</filter2>
        <id>18203</id>
        <msg>NETBIOS Windows Address Book smmscrpt.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-097.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3147</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18206, service netbios-ssn, policy security-ips drop;</filter2>
        <id>18206</id>
        <msg>NETBIOS Windows Address Book wab32res.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-096.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3147</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18207, service netbios-ssn, policy security-ips drop;</filter2>
        <id>18207</id>
        <msg>NETBIOS Windows Address Book msoeres32.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-096.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3966</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18209, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18209</id>
        <msg>NETBIOS Windows 7 Home peerdist.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-095.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3967</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18210, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18210</id>
        <msg>WEB-CLIENT Microsoft Movie Maker hhctrl.ocx dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-093.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3967</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18211, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18211</id>
        <msg>NETBIOS Microsoft Movie Maker hhctrl.ocx dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-093.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2742</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18215, service netbios-ssn, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18215</id>
        <msg>NETBIOS NETAPI RPC interface reboot attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-101.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3957</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18219, policy security-ips drop;</filter2>
        <id>18219</id>
        <msg>WEB-CLIENT Microsoft Windows ATMFD font driver remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-091.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18220, policy security-ips drop;</filter2>
        <id>18220</id>
        <msg>WEB-CLIENT Microsoft Windows ATMFD font driver malformed character glyph remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-091.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3954</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|18230, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18230</id>
        <msg>SPECIFIC-THREATS Microsoft Publisher memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-103.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|18231, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18231</id>
        <msg>WEB-CLIENT Microsoft Publisher oversized oti length attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-103.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-3964</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8082</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|18238, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18238</id>
        <msg>EXPLOIT Microsoft Sharepoint document conversion remote code excution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-104.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2745E5F5-D234-11D0-847A-00C04FD7BB08&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2745E5F5-D234-11D0-847A-00C04FD7BB08\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18241</id>
        <msg>WEB-ACTIVEX Microsoft WMI Administrator Tools Object Viewer ActiveX clsid access</msg>
        <url>secunia.com/advisories/42693/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AddContextRef&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AddContextRef(\.\d)?\x22|\x27AddContextRef(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AddContextRef(\.\d)?\x22|\x27AddContextRef(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18242</id>
        <msg>WEB-ACTIVEX Microsoft WMI Administrator Tools Object Viewer ActiveX function call access</msg>
        <url>secunia.com/advisories/42693/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FAXCOVER-VER005w&quot;; nocase; content:&quot;|87 00 00 00 4C 17 00 00 00 00 00 00 52 03 00 00|&quot;; within:100; fast_pattern; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18246</id>
        <msg>WEB-CLIENT Microsoft Windows Fax Services Cover Page Editor overflow attempt</msg>
        <url>www.vupen.com/english/advisories/2010/3327</url>
      </rule>
      <rule>
        <bugtraq>6665</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0027</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87|}&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:policy security-ips drop, service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2005</id>
        <msg>RPC portmap kcms_server request UDP</msg>
        <url>www.kb.cert.org/vuls/id/850785</url>
      </rule>
      <rule>
        <bugtraq>6665</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0027</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32771:34000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 87|}&quot;; depth:4; offset:16; byte_jump:4,20,relative,align; byte_jump:4,4,relative,align; content:&quot;/../&quot;; distance:0; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service sunrpc; classtype:misc-attack;</filter2>
        <id>2007</id>
        <msg>RPC kcms_server directory traversal attempt</msg>
        <url>www.kb.cert.org/vuls/id/850785</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>2103</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-admin</classtype>
        <filter1>tcp $HOME_NET !21:23 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; content:&quot;Microsoft Windows&quot;; content:&quot;|28|C|29| Copyright 1985-&quot;; distance:0; content:&quot;Microsoft Corp.&quot;; distance:0; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-admin;</filter2>
        <id>2123</id>
        <msg>ATTACK-RESPONSES Microsoft cmd.exe banner</msg>
        <nessus>11633</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; depth:5; offset:4; content:&quot;Documents and Settings|5C|All Users|5C|Start Menu|5C|Programs|5C|Startup|00|&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-recon;</filter2>
        <id>2176</id>
        <msg>NETBIOS SMB startup folder access</msg>
      </rule>
      <rule>
        <bugtraq>8458</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0715</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB%&quot;; depth:5; offset:4; nocase; content:&quot;&amp;|00|&quot;; within:2; distance:56; content:&quot;|5C 00|P|00|I|00|P|00|E|00 5C 00|&quot;; within:12; distance:5; nocase; content:&quot;|05|&quot;; within:1; content:&quot;|0B|&quot;; within:1; distance:1; byte_test:1,&amp;,1,0,relative; content:&quot;|B8|J|9F|M|1C|}|CF 11 86 1E 00| |AF|n|7C|W&quot;; within:16; distance:29; tag:session,5,packets; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>2252</id>
        <msg>NETBIOS SMB-DS DCERPC Remote Activation bind attempt</msg>
        <nessus>11835</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 87 88|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01 00 00 00 01|&quot;; within:8; distance:4; byte_jump:4,8,relative,align; content:&quot;|00 00 00 00|&quot;; within:4; metadata:policy security-ips drop, service sunrpc; classtype:misc-attack;</filter2>
        <id>2255</id>
        <msg>RPC sadmind query with root credentials attempt TCP</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 87 88|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01 00 00 00 01|&quot;; within:8; distance:4; byte_jump:4,8,relative,align; content:&quot;|00 00 00 00|&quot;; within:4; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:misc-attack;</filter2>
        <id>2256</id>
        <msg>RPC sadmind query with root credentials attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>8826</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0717</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>content:&quot;|04 00|&quot;; depth:2; byte_test:1,&gt;,15,2,relative; byte_jump:4,86,little,align,relative; byte_jump:4,8,little,align,relative; byte_test:4,&gt;,1024,0,little,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>2257</id>
        <msg>NETBIOS DCERPC Messenger Service buffer overflow attempt</msg>
        <nessus>11890</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>8826</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB%&quot;; depth:5; offset:4; nocase; content:&quot;&amp;|00|&quot;; within:2; distance:56; content:&quot;|5C 00|P|00|I|00|P|00|E|00 5C 00|&quot;; within:12; distance:5; nocase; content:&quot;|04 00|&quot;; within:2; byte_test:1,&gt;,15,2,relative; byte_jump:4,86,little,align,relative; byte_jump:4,8,little,align,relative; byte_test:4,&gt;,1024,0,little,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>2258</id>
        <msg>NETBIOS SMB-DS DCERPC Messenger Service buffer overflow attempt</msg>
        <nessus>11890</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>21220</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-6114</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:0; dce_stub_data; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>2349</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters attempt</msg>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>2401</id>
        <msg>NETBIOS SMB Session Setup andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>2403</id>
        <msg>NETBIOS SMB Session Setup unicode username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9707</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5746</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:from_client,established; content:&quot;.emf&quot;; http_uri; flowbits:set,http.emf; flowbits:noalert;  metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>2435</id>
        <msg>WEB-CLIENT Microsoft emf metafile access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-001.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:from_client,established; content:&quot;.wmf&quot;; nocase; http_uri; flowbits:set, wmf.download; flowbits:noalert;  metadata:service http; classtype:attempted-user;</filter2>
        <id>2436</id>
        <msg>WEB-CLIENT Microsoft wmf metafile access</msg>
      </rule>
      <rule>
        <bugtraq>10108</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0533</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:3919286a-b10c-11d0-9ba8-00c04fd92ef5; dce_opnum:9; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>2508</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP lsass DsRolerUpgradeDownlevelServer overflow attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10108</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0533</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,138,1024:]</filter1>
        <filter2>dce_iface:3919286a-b10c-11d0-9ba8-00c04fd92ef5; dce_opnum:9; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>2511</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP lsass DsRolerUpgradeDownlevelServer overflow attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:338cd001-2244-31f1-aaaa-900038001003; dce_opnum:24; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>2942</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP winreg InitiateSystemShutdown attempt</msg>
        <url>msdn.microsoft.com/library/default.asp?url=/library/en-us/shutdown/base/initiatesystemshutdown.asp</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3018</id>
        <msg>NETBIOS SMB NT Trans NT CREATE oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3019</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3020</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3021</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3022</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3023</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE andx oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3024</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-15,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; byte_test:4,&gt;,1024,36,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3025</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode andx oversized Security Descriptor attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3026</id>
        <msg>NETBIOS SMB NT Trans NT CREATE SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3027</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3028</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3029</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3030</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3031</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3032</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3033</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3034</id>
        <msg>NETBIOS SMB NT Trans NT CREATE DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3035</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3036</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3037</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3038</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3039</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1765</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;RIFF&quot;; nocase; content:&quot;anih&quot;; nocase; byte_test:4,&gt;,36,0,relative,little; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3079</id>
        <msg>WEB-CLIENT Microsoft ANI file parsing overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-017.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; pcre:&quot;/^.{27}/R&quot;; content:&quot;|07 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3135</id>
        <msg>NETBIOS SMB Trans2 QUERY_FILE_INFO attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|07 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3136</id>
        <msg>NETBIOS SMB Trans2 QUERY_FILE_INFO andx attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; pcre:&quot;/^.{27}/R&quot;; content:&quot;|07 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3137</id>
        <msg>NETBIOS SMB-DS Trans2 QUERY_FILE_INFO attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|07 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3138</id>
        <msg>NETBIOS SMB-DS Trans2 QUERY_FILE_INFO andx attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3139</id>
        <msg>NETBIOS SMB Trans2 FIND_FIRST2 attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3140</id>
        <msg>NETBIOS SMB Trans2 FIND_FIRST2 andx attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3141</id>
        <msg>NETBIOS SMB-DS Trans2 FIND_FIRST2 attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:29; flowbits:set,smb.trans2; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3142</id>
        <msg>NETBIOS SMB-DS Trans2 FIND_FIRST2 andx attempt</msg>
      </rule>
      <rule>
        <bugtraq>12484</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-0045</cve>
        <filter1>tcp $HOME_NET 139 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,smb.trans2; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; pcre:&quot;/^.{27}/R&quot;; flowbits:unset,smb.trans2; byte_test:2,&gt;,15,7,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3143</id>
        <msg>NETBIOS SMB Trans2 FIND_FIRST2 command response overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>12484</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-0045</cve>
        <filter1>tcp $HOME_NET 139 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,smb.trans2; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; flowbits:unset,smb.trans2; byte_test:2,&gt;,15,7,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3144</id>
        <msg>NETBIOS SMB Trans2 FIND_FIRST2 response andx overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>12484</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-0045</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,smb.trans2; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; flowbits:unset,smb.trans2; byte_test:2,&gt;,15,7,relative,little; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3146</id>
        <msg>NETBIOS SMB-DS Trans2 FIND_FIRST2 response andx overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-011.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0715</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:1; dce_stub_data; content:&quot;|01 10 08 00 CC CC CC CC|&quot;; distance:0; content:&quot;|5C 00 5C 00|&quot;; distance:0; byte_test:4,&gt;,256,-8,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>3158</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP ISystemActivator CoGetInstanceFromFile attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms03-039.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0715</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:1; dce_stub_data; content:&quot;|01 10 08 00 CC CC CC CC|&quot;; distance:0; content:&quot;|5C 00 5C 00|&quot;; distance:0; byte_test:4,&gt;,256,-8,relative; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>3159</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP ISystemActivator CoGetInstanceFromFile attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms03-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0059</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:975201B0-59CA-11D0-A8D5-00A0C90D8051; dce_opnum:4; dce_stub_data; byte_test:4,&gt;,128,8,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>3171</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msqueue function 4 overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0352</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:4; dce_stub_data; content:&quot;|01 10 08 00 CC CC CC CC|&quot;; distance:0; content:&quot;|5C 00 5C 00|&quot;; distance:0; byte_test:4,&gt;,256,-8,relative; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>3397</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP ISystemActivator RemoteCreateInstance attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-026.asp</url>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0352</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:4; dce_stub_data; content:&quot;|01 10 08 00 CC CC CC CC|&quot;; distance:0; content:&quot;|5C 00 5C 00|&quot;; distance:0; byte_test:4,&gt;,256,-8,relative; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>3398</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP ISystemActivator RemoteCreateInstance attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-026.asp</url>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0715</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4d9f4ab8-7d1c-11cf-861e-0020af6e7c57; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,256,52,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>3409</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP IActivation remoteactivation overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>13132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0063</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isnotset,http.hta; content:&quot;R|00|o|00|o|00|t|00| |00|E|00|n|00|t|00|r|00|y|00|&quot;; nocase; content:&quot;|D8 F4|P0|B5 98 CF 11 BB 82 00 AA 00 BD CE 0B|&quot;; within:16; distance:60; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3552</id>
        <msg>WEB-CLIENT OLE32 microsoft MSHTA masquerade attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-016.mspx</url>
      </rule>
      <rule>
        <bugtraq>14513</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1983</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:54; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>3967</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_QueryResConfList attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>14513</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1983</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:53; dce_stub_data; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,32,16,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>4072</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_DetectResourceConflict attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>8833</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0662</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4B106874-DD36-11D0-8B44-00A024DD9EFF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4B106874-DD36-11D0-8B44-00A024DD9EFF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4145</id>
        <msg>WEB-ACTIVEX Windows Trouble Shooter ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-042.mspx</url>
      </rule>
      <rule>
        <bugtraq>14515</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;DE4735F3-7532-4895-93DC-9A10C4257173&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*DE4735F3-7532-4895-93DC-9A10C4257173/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4146</id>
        <msg>WEB-ACTIVEX Share Point Portal Services Log Sink ActiveX Object Access</msg>
        <url>support.microsoft.com/default.aspx?scid=kb\;en-us\;KB837253</url>
      </rule>
      <rule>
        <bugtraq>5558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0647</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;99B42120-6EC7-11CF-A6C7-00AA00A47DD2&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*99B42120-6EC7-11CF-A6C7-00AA00A47DD2/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4147</id>
        <msg>WEB-ACTIVEX ActiveLabel ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>1474</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2519</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2D360201-FFF5-11d1-8D03-00A0C959BC0A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2D360201-FFF5-11d1-8D03-00A0C959BC0A\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(LoadURL)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2D360201-FFF5-11d1-8D03-00A0C959BC0A\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(LoadURL))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4148</id>
        <msg>WEB-ACTIVEX DHTML Editing ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>7384</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0CF32AA1-7571-11D0-93C4-00AA00A3DDEA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0CF32AA1-7571-11D0-93C4-00AA00A3DDEA/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4151</id>
        <msg>WEB-ACTIVEX System Monitor Source Properties ActiveX Object Access</msg>
      </rule>
      <rule>
        <bugtraq>619</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0669</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;06A7EC63-4E21-11D0-A112-00A0C90543AA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*06A7EC63-4E21-11D0-A112-00A0C90543AA/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4153</id>
        <msg>WEB-ACTIVEX Eyedog ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-032.mspx</url>
      </rule>
      <rule>
        <bugtraq>775</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-0329</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E449683-C509-11CF-AAFA-00AA00B6015C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E449683-C509-11CF-AAFA-00AA00B6015C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4154</id>
        <msg>WEB-ACTIVEX Active Setup ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-048.mspx</url>
      </rule>
      <rule>
        <bugtraq>1718</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0149</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;25336921-03F9-11CF-8FD0-00AA00686F13&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*25336921-03F9-11CF-8FD0-00AA00686F13/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4155</id>
        <msg>WEB-ACTIVEX htmlfile ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-015.mspx</url>
      </rule>
      <rule>
        <bugtraq>668</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-1484</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;8F0F5093-0A70-11D0-BCA9-00C04FD85AA6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8F0F5093-0A70-11D0-BCA9-00C04FD85AA6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4157</id>
        <msg>WEB-ACTIVEX MSN Setup BBS 4.71.0.10 ActiveX Object Access</msg>
      </rule>
      <rule>
        <bugtraq>5094</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00022613-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00022613-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4159</id>
        <msg>WEB-ACTIVEX Multimedia File Property Sheet ActiveX Object Access</msg>
      </rule>
      <rule>
        <bugtraq>8454</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0530</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;167701E3-FDCF-11D0-A48E-006097C549FF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*167701E3-FDCF-11D0-A48E-006097C549FF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4160</id>
        <msg>WEB-ACTIVEX Microsoft Windows Reporting Tool ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-032.mspx</url>
      </rule>
      <rule>
        <bugtraq>13946</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;FF2BBC4A-6881-4294-BE0C-17535B1FCCFA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FF2BBC4A-6881-4294-BE0C-17535B1FCCFA/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4161</id>
        <msg>WEB-ACTIVEX DigWebX MSN ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>13946</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;72770C4F-967D-4517-982B-92D6B9015649&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*72770C4F-967D-4517-982B-92D6B9015649/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4162</id>
        <msg>WEB-ACTIVEX DigWebX MSN ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>13946</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0519F3C1-0ED3-4EF1-98F5-CC3FB10218C7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0519F3C1-0ED3-4EF1-98F5-CC3FB10218C7/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4163</id>
        <msg>WEB-ACTIVEX DigWebX MSN ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>13946</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;13FA0C3E-6B1C-4D8B-88CD-6DA8E1CA7653&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*13FA0C3E-6B1C-4D8B-88CD-6DA8E1CA7653/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4164</id>
        <msg>WEB-ACTIVEX DigWebX MSN ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>12477</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D4A97620-8E8F-11CF-93CD-00AA00C08FDF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D4A97620-8E8F-11CF-93CD-00AA00C08FDF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4165</id>
        <msg>WEB-ACTIVEX Image Control 1.0 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>11367</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E5D419D6-A846-4514-9FAD-97E826C84822&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E5D419D6-A846-4514-9FAD-97E826C84822\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4167</id>
        <msg>WEB-ACTIVEX MSN Heartbeat ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-069.mspx</url>
      </rule>
      <rule>
        <bugtraq>9335</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;13709620-C279-11CE-A49E-444553540000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*13709620-C279-11CE-A49E-444553540000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4168</id>
        <msg>WEB-ACTIVEX Shell Automation Service ActiveX Object Access</msg>
      </rule>
      <rule>
        <bugtraq>671</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;50E5E3D1-C07E-11D0-B9FD-00A0249F6B00&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*50E5E3D1-C07E-11D0-B9FD-00A0249F6B00/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4171</id>
        <msg>WEB-ACTIVEX Registration Wizard ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F5BE8BD2-7DE6-11D0-91FE-00C04FD701A5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F5BE8BD2-7DE6-11D0-91FE-00C04FD701A5\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4172</id>
        <msg>WEB-ACTIVEX Microsoft Agent v1.5 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F107317A-A488-11d4-AA25-00C04F72DAEB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F107317A-A488-11d4-AA25-00C04F72DAEB/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4173</id>
        <msg>WEB-ACTIVEX MsnPUpld ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>8008</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;69DEAF94-AF66-11D3-BEC0-00105AA9B6AE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*69DEAF94-AF66-11D3-BEC0-00105AA9B6AE/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4174</id>
        <msg>WEB-ACTIVEX Symantec RuFSI registry Information Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-048.mspx</url>
      </rule>
      <rule>
        <bugtraq>5489</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0975</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;970C7E08-05A7-11D0-89AA-00A0C9054129&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*970C7E08-05A7-11D0-89AA-00A0C9054129/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4179</id>
        <msg>WEB-ACTIVEX DirectX Files Viewer ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-066.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;84926CA0-2941-101C-816F-0E6013114B7F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*84926CA0-2941-101C-816F-0E6013114B7F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4180</id>
        <msg>WEB-ACTIVEX Kodak Image Scan Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2002-0699</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;80CB7887-20DE-11D2-8D5C-00C04FC29D45&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*80CB7887-20DE-11D2-8D5C-00C04FC29D45/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4181</id>
        <msg>WEB-ACTIVEX Smartcard Enrollment ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-048.mspx</url>
      </rule>
      <rule>
        <bugtraq>4707</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0155</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;9088E688-063A-4806-A3DB-6522712FC061&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9088E688-063A-4806-A3DB-6522712FC061/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4182</id>
        <msg>WEB-ACTIVEX MSN Chat v4.5, 4.6 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-022.mspx</url>
      </rule>
      <rule>
        <bugtraq>13953</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1208</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;41B23C28-488E-4e5C-ACE2-BB0BBABE99E8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*41B23C28-488E-4e5C-ACE2-BB0BBABE99E8/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4183</id>
        <msg>WEB-ACTIVEX HTML Help ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-026.mspx</url>
      </rule>
      <rule>
        <bugtraq>5593</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0699</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;43F8F289-7A20-11D0-8F06-00C04FC295E1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*43F8F289-7A20-11D0-8F06-00C04FC295E1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4184</id>
        <msg>WEB-ACTIVEX Certificate Enrollment ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-048.mspx</url>
      </rule>
      <rule>
        <bugtraq>5554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0726</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;1fb464c8-09bb-4017-a2f5-eb742f04392f&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1fb464c8-09bb-4017-a2f5-eb742f04392f/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4185</id>
        <msg>WEB-ACTIVEX Terminal Services Advanced Client ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-046.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6D940285-9F11-11CE-83FD-02608C3EC08A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6D940285-9F11-11CE-83FD-02608C3EC08A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4186</id>
        <msg>WEB-ACTIVEX Kodak Image Editing ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <bugtraq>5554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0726</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;791fa017-2de3-492e-acc5-53c67a2b94d0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*791fa017-2de3-492e-acc5-53c67a2b94d0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4187</id>
        <msg>WEB-ACTIVEX Terminal Services Advanced Client ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-046.mspx</url>
      </rule>
      <rule>
        <bugtraq>11448</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0936</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D32C3BAD-5213-49BD-A7D5-E6DE6C0D8249&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D32C3BAD-5213-49BD-A7D5-E6DE6C0D8249/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4188</id>
        <msg>WEB-ACTIVEX RAV Online Scanner ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-048.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2003-0233</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;06DD38D3-D187-11CF-A80D-00C04FD74AD8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*06DD38D3-D187-11CF-A80D-00C04FD74AD8/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4189</id>
        <msg>WEB-ACTIVEX Third-Party Plugin ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-015.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E1A6B8A0-3603-101C-AC6E-040224009C02&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E1A6B8A0-3603-101C-AC6E-040224009C02/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4190</id>
        <msg>WEB-ACTIVEX Kodak Thumbnail Image ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;C3DFA998-A486-11d4-AA25-00C04F72DAEB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C3DFA998-A486-11d4-AA25-00C04F72DAEB/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4191</id>
        <msg>WEB-ACTIVEX MsnPUpld ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>669</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;130D7743-5F5A-11D1-B676-00A0C9697233&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*130D7743-5F5A-11D1-B676-00A0C9697233/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4192</id>
        <msg>WEB-ACTIVEX HHOpen ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6D940280-9F11-11CE-83FD-02608C3EC08A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6D940280-9F11-11CE-83FD-02608C3EC08A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4193</id>
        <msg>WEB-ACTIVEX Kodak Image Editing ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <bugtraq>13946</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;05E6787D-82D9-4D24-91DD-97FE8D199501&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*05E6787D-82D9-4D24-91DD-97FE8D199501/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4197</id>
        <msg>WEB-ACTIVEX DigWebX MSN ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;3BC4F3A7-652A-11D1-B4D4-00C04FC2DB8D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3BC4F3A7-652A-11D1-B4D4-00C04FC2DB8D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4200</id>
        <msg>WEB-ACTIVEX Index Server Scope Administration ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ECABAFC2-7F19-11D2-978E-0000F8757E2A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ECABAFC2-7F19-11D2-978E-0000F8757E2A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4201</id>
        <msg>WEB-ACTIVEX Queued Components Recorder ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;283807B8-2C60-11D0-A31D-00AA00B92C03&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*283807B8-2C60-11D0-A31D-00AA00B92C03/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4202</id>
        <msg>WEB-ACTIVEX DirectAnimation ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;250770F3-6AF2-11CF-A915-008029E31FCD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*250770F3-6AF2-11CF-A915-008029E31FCD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4203</id>
        <msg>WEB-ACTIVEX Microsoft Marquee Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D24D4453-1F01-11D1-8E63-006097D2DF48&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D24D4453-1F01-11D1-8E63-006097D2DF48/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4204</id>
        <msg>WEB-ACTIVEX Microsoft DT PolyLine Control 2 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;03CB9467-FD9D-42A8-82F9-8615B4223E6E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*03CB9467-FD9D-42A8-82F9-8615B4223E6E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4205</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Database Designer v7.0 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;598EBA02-B49A-11D2-A1C1-00609778EA66&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*598EBA02-B49A-11D2-A1C1-00609778EA66/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4206</id>
        <msg>WEB-ACTIVEX Microsoft MPEG-4 Video Decompressor Property Page ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;8FE7E181-BB96-11D2-A1CB-00609778EA66&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8FE7E181-BB96-11D2-A1CB-00609778EA66/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4207</id>
        <msg>WEB-ACTIVEX Microsoft MS Audio Decompressor Control Property Page ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4CFB5280-800B-4367-848F-5A13EBF27F1D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4CFB5280-800B-4367-848F-5A13EBF27F1D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4208</id>
        <msg>WEB-ACTIVEX LexRefStEsObject Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;B3E0E785-BD78-4366-9560-B7DABE2723BE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B3E0E785-BD78-4366-9560-B7DABE2723BE/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4209</id>
        <msg>WEB-ACTIVEX LexRefStFrObject Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4211</id>
        <msg>WEB-ACTIVEX Microsoft DDS Library Shape Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4FAAB301-CEF6-477C-9F58-F601039E9B78&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4FAAB301-CEF6-477C-9F58-F601039E9B78/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4212</id>
        <msg>WEB-ACTIVEX Microsoft DDS Generic Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6CBE0382-A879-4D2A-8EC3-1F2A43611BA8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6CBE0382-A879-4D2A-8EC3-1F2A43611BA8/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4213</id>
        <msg>WEB-ACTIVEX Microsoft DDS Picture Shape Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F117831B-C052-11D1-B1C0-00C04FC2F3EF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F117831B-C052-11D1-B1C0-00C04FC2F3EF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4214</id>
        <msg>WEB-ACTIVEX Microsoft TipGW Init ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;3050F667-98B5-11CF-BB82-00AA00BDCE0B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3050F667-98B5-11CF-BB82-00AA00BDCE0B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4215</id>
        <msg>WEB-ACTIVEX Microsoft HTML Popup Window ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;1AA06BA1-0E88-11D1-8391-00C04FBD7C09&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1AA06BA1-0E88-11D1-8391-00C04FBD7C09/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4216</id>
        <msg>WEB-ACTIVEX CLSID_CComAcctImport ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;7007ACCF-3202-11D1-AAD2-00805FC1270E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7007ACCF-3202-11D1-AAD2-00805FC1270E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4219</id>
        <msg>WEB-ACTIVEX Microsoft Network Connections Tray ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;992CFFA0-F557-101A-88EC-00DD010CCC48&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*992CFFA0-F557-101A-88EC-00DD010CCC48/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4220</id>
        <msg>WEB-ACTIVEX Microsoft Network and Dial-Up Connections ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020420-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020420-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4221</id>
        <msg>WEB-ACTIVEX Microsoft ProxyStub Dispatch ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ABBA001B-3075-11D6-88A4-00B0D0200F88&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ABBA001B-3075-11D6-88A4-00B0D0200F88/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4223</id>
        <msg>WEB-ACTIVEX Microsoft OpenCable Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;CE292861-FC88-11D0-9E69-00C04FD7C15B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CE292861-FC88-11D0-9E69-00C04FD7C15B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4224</id>
        <msg>WEB-ACTIVEX Microsoft VideoPort ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E227101-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E227101-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4225</id>
        <msg>WEB-ACTIVEX Microsoft Repository ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;7057E952-BD1B-11D1-8919-00C04FC2C836&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7057E952-BD1B-11D1-8919-00C04FC2C836/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4226</id>
        <msg>WEB-ACTIVEX Microsoft DocHost User Interface Handler ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;7007ACC7-3202-11D1-AAD2-00805FC1270E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7007ACC7-3202-11D1-AAD2-00805FC1270E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4227</id>
        <msg>WEB-ACTIVEX Microsoft Network Connections ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4622AD11-FF23-11D0-8D34-00A0C90F2719&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4622AD11-FF23-11D0-8D34-00A0C90F2719/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4228</id>
        <msg>WEB-ACTIVEX Microsoft Windows Start Menu ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;98CB4060-D3E7-42A1-8D65-949D34EBFE14&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*98CB4060-D3E7-42A1-8D65-949D34EBFE14/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4229</id>
        <msg>WEB-ACTIVEX MSAPP Export Support for Microsoft Access ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;47C6C527-6204-4F91-849D-66E234DEE015&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*47C6C527-6204-4F91-849D-66E234DEE015/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4230</id>
        <msg>WEB-ACTIVEX Search Assistant UI ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;35CEC8A3-2BE6-11D2-8773-92E220524153&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*35CEC8A3-2BE6-11D2-8773-92E220524153/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4231</id>
        <msg>WEB-ACTIVEX Microsoft SysTray ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;730F6CDC-2C86-11D2-8773-92E220524153&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*730F6CDC-2C86-11D2-8773-92E220524153/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4232</id>
        <msg>WEB-ACTIVEX Microsoft SysTray Invoker ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;2C10A98F-D64F-43B4-BED6-DD0E1BF2074C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*2C10A98F-D64F-43B4-BED6-DD0E1BF2074C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4233</id>
        <msg>WEB-ACTIVEX Microsoft Visual Database Tools Query Designer v7.0 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6F9F3481-84DD-4B14-B09C-6B4288ECCDE8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6F9F3481-84DD-4B14-B09C-6B4288ECCDE8/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4234</id>
        <msg>WEB-ACTIVEX Microsoft MSVTDGridCtrl7 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F0975AFE-5C7F-11D2-8B74-00104B2AFB41&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F0975AFE-5C7F-11D2-8B74-00104B2AFB41/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4236</id>
        <msg>WEB-ACTIVEX WMI ASDI Extension ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>15056</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2119</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>4245</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>15056</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2119</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>4246</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:11; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>4358</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;009541A0-3B81-101C-92F3-040224009C02&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*009541A0-3B81-101C-92F3-040224009C02/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4648</id>
        <msg>WEB-CLIENT wang image admin activex object access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <bugtraq>6666</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0003</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:d3fbb514-0e3b-11cb-8fad-08002b1d29c3; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>4754</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP locator nsi_binding_lookup_begin overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-001.mspx</url>
      </rule>
      <rule>
        <bugtraq>6666</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0003</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:d3fbb514-0e3b-11cb-8fad-08002b1d29c3; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>4755</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP locator nsi_binding_lookup_begin overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-001.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0002000D-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0002000D-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4890</id>
        <msg>WEB-ACTIVEX IAVIStream &amp; IAVIFile Proxy ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ECABAFC0-7F19-11D2-978E-0000F8757E2A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ECABAFC0-7F19-11D2-978E-0000F8757E2A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4891</id>
        <msg>WEB-ACTIVEX cfw Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ECABB0AB-7F19-11D2-978E-0000F8757E2A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ECABB0AB-7F19-11D2-978E-0000F8757E2A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4892</id>
        <msg>WEB-ACTIVEX MTSEvents Class ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;3050F4F5-98B5-11CF-BB82-00AA00BDCE0B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3050F4F5-98B5-11CF-BB82-00AA00BDCE0B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4893</id>
        <msg>WEB-ACTIVEX Trident HTMLEditor ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020421-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020421-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4894</id>
        <msg>WEB-ACTIVEX PSEnumVariant ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020422-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020422-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4895</id>
        <msg>WEB-ACTIVEX PSTypeInfo ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020423-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020423-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4896</id>
        <msg>WEB-ACTIVEX PSTypeLib ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020424-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020424-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4897</id>
        <msg>WEB-ACTIVEX PSOAInterface ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00020425-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00020425-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4898</id>
        <msg>WEB-ACTIVEX PSTypeComp ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;DF0B3D60-548F-101B-8E65-08002B2BD119&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*DF0B3D60-548F-101B-8E65-08002B2BD119/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4899</id>
        <msg>WEB-ACTIVEX ISupportErrorInfo Interface ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;2D2E24CB-0CD5-458F-86EA-3E6FA22C8E64&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*2D2E24CB-0CD5-458F-86EA-3E6FA22C8E64/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4901</id>
        <msg>WEB-ACTIVEX VMR Allocator Presenter 9 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;51B4ABF3-748F-4E3B-A276-C828330E926A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*51B4ABF3-748F-4E3B-A276-C828330E926A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4902</id>
        <msg>WEB-ACTIVEX Video Mixing Renderer 9 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E4979309-7A32-495E-8A92-7B014AAD4961&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E4979309-7A32-495E-8A92-7B014AAD4961/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4903</id>
        <msg>WEB-ACTIVEX VMR ImageSync 9 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;62EC9F22-5E30-11D2-97A1-00C04FB6DD9A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*62EC9F22-5E30-11D2-97A1-00C04FB6DD9A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4904</id>
        <msg>WEB-ACTIVEX Microsoft Repository Alias ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E2270FB-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E2270FB-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4905</id>
        <msg>WEB-ACTIVEX Microsoft Repository Object ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E227109-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E227109-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4906</id>
        <msg>WEB-ACTIVEX Microsoft Repository Interface Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710A-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710A-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4907</id>
        <msg>WEB-ACTIVEX Microsoft Repository Collection Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710B-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710B-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4908</id>
        <msg>WEB-ACTIVEX Microsoft Repository Method Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710C-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710C-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4909</id>
        <msg>WEB-ACTIVEX Microsoft Repository Property Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710D-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710D-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4910</id>
        <msg>WEB-ACTIVEX Microsoft Repository Relationship Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710E-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710E-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4911</id>
        <msg>WEB-ACTIVEX Microsoft Repository Type Library ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6E22710F-F799-11CF-9227-00AA00A1EB95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E22710F-F799-11CF-9227-00AA00A1EB95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4912</id>
        <msg>WEB-ACTIVEX Microsoft Repository Root ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;B1D4ED44-EE64-11D0-97E6-00C04FC30B4A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B1D4ED44-EE64-11D0-97E6-00C04FC30B4A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4913</id>
        <msg>WEB-ACTIVEX Microsoft Repository Workspace ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D675E22B-CAE9-11D2-AF7B-00C04F99179F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D675E22B-CAE9-11D2-AF7B-00C04F99179F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4914</id>
        <msg>WEB-ACTIVEX Microsoft Repository Script Definition ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00021401-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00021401-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4915</id>
        <msg>WEB-ACTIVEX Shortcut Handler ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>10514</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0549</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00000566-0000-0010-8000-00AA006D2EA4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00000566-0000-0010-8000-00AA006D2EA4/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4982</id>
        <msg>WEB-ACTIVEX Adodb.Stream ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>10514</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0549</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;CreateObject&quot;; nocase; content:&quot;Adodb.stream&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/CreateObject\(\s*\x22Adodb\.stream/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4983</id>
        <msg>WEB-ACTIVEX Adodb.Stream ActiveX Object Access CreateObject Function</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>12481</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0050</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:57674CD0-5200-11CE-A897-08002B2E9C6D; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>5485</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>5677</id>
        <msg>NETBIOS SMB Session Setup username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; metadata:policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>5682</id>
        <msg>NETBIOS SMB Session Setup unicode andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.hhp&quot;; nocase; http_uri; flowbits:set,http.hhp.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>5740</id>
        <msg>WEB-CLIENT Microsoft HTML help workshop file .hhp download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-0564</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.hhp.download; content:&quot;[&quot;; content:&quot;]&quot;; distance:0; content:&quot;file&quot;; distance:0; nocase; content:&quot;=&quot;; distance:0; pcre:&quot;/\x5B(OPTIONS|WINDOWS|MERGE FILES|MAP|ALIAS|TEXT\x20POPUPS|INFOTYPES|SUBSETS)\x5D.*?(Contents|Index|Compiled|Sample List|Full text search stop list)\x20file\s*\x3D[^\r\n]{200}/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>5741</id>
        <msg>WEB-CLIENT Microsoft HTML help workshop buffer overflow attempt</msg>
        <url>www.frsirt.com/english/advisories/2006/0446</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;1F7DD4F2-CAC3-11D0-A35B-00AA00BDCDFD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1F7DD4F2-CAC3-11D0-A35B-00AA00BDCDFD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6002</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS Rectilinear GDD Layout ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;1F7DD4F3-CAC3-11D0-A35B-00AA00BDCDFD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1F7DD4F3-CAC3-11D0-A35B-00AA00BDCDFD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6003</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS Rectilinear GDD Route ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;B0406342-B0C5-11d0-89A9-00A0C9054129&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B0406342-B0C5-11d0-89A9-00A0C9054129/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6004</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS Circular Auto Layout Logic 2 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;B0406343-B0C5-11d0-89A9-00A0C9054129&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B0406343-B0C5-11d0-89A9-00A0C9054129/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6005</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS Straight Line Routing Logic 2 ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D24D4450-1F01-11D1-8E63-006097D2DF48&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D24D4450-1F01-11D1-8E63-006097D2DF48/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6006</id>
        <msg>WEB-ACTIVEX Microsoft DT Icon Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4CECCEB1-8359-11D0-A34E-00AA00BDCDFD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4CECCEB1-8359-11D0-A34E-00AA00BDCDFD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6007</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS OrgChart GDD Layout ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;4CECCEB2-8359-11D0-A34E-00AA00BDCDFD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4CECCEB2-8359-11D0-A34E-00AA00BDCDFD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6008</id>
        <msg>WEB-ACTIVEX Microsoft DT DDS OrgChart GDD Route ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-013.mspx</url>
      </rule>
      <rule>
        <bugtraq>17462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0003</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;BD96C556-65A3-11D0-983A-00C04FC29E36&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*BD96C556-65A3-11D0-983A-00C04FC29E36/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6009</id>
        <msg>WEB-ACTIVEX RDS.Dataspace ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>17905</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1184</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; byte_test:4,&gt;,37,28,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6419</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW invalid uuid size attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17905</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1184</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; byte_test:4,&gt;,37,28,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6420</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid uuid size attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17905</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1184</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,37,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6431</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW invalid second uuid size attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17905</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1184</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,37,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6432</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid second uuid size attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17906</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0034</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&lt;,37,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6443</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17906</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0034</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:7; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&lt;,37,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6444</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17906</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0034</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:1; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&lt;,37,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6455</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContext heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>17906</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0034</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:906B0CE0-C70B-1067-B317-00DD010662DA; dce_opnum:1; dce_stub_data; pcre:&quot;/^.{28}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&lt;,37,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>6456</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContext heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-2383</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.Light&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.Light\x22|\x27DXImageTransform.Microsoft.Light\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.Light\x22|\x27DXImageTransform.Microsoft.Light\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6516</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-2383</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F9EFBEC2-4302-11D2-952A-00C04FA34F05&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F9EFBEC2-4302-11D2-952A-00C04FA34F05/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6517</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-2383</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|9|00|E|00|F|00|B|00|E|00|C|00|2|00|-|00|4|00|3|00|0|00|2|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|5|00|2|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|F|00|0|00|5|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x009\x00E\x00F\x00B\x00E\x00C\x002\x00-\x004\x003\x000\x002\x00-\x001\x001\x00D\x002\x00-\x009\x005\x002\x00A\x00-\x000\x000\x00C\x000\x004\x00F\x00A\x003\x004\x00F\x000\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6518</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.MMSpecialEffect2Inputs&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.MMSpecialEffect2Inputs\x22|\x27DXImageTransform.Microsoft.MMSpecialEffect2Inputs\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.MMSpecialEffect2Inputs\x22|\x27DXImageTransform.Microsoft.MMSpecialEffect2Inputs\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6682</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|5|00|3|00|3|00|5|00|9|00|C|00|1|00|-|00|3|00|9|00|E|00|1|00|-|00|4|00|9|00|1|00|b|00|-|00|9|00|9|00|5|00|1|00|-|00|4|00|6|00|4|00|F|00|D|00|8|00|A|00|B|00|0|00|7|00|1|00|C|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x005\x003\x003\x005\x009\x00C\x001\x00-\x003\x009\x00E\x001\x00-\x004\x009\x001\x00b\x00-\x009\x009\x005\x001\x00-\x004\x006\x004\x00F\x00D\x008\x00A\x00B\x000\x007\x001\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6683</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;353359C1-39E1-491b-9951-464FD8AB071C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*353359C1-39E1-491b-9951-464FD8AB071C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6684</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|6|00|3|00|3|00|4|00|4|00|D|00|8|00|-|00|7|00|0|00|D|00|3|00|-|00|4|00|0|00|3|00|2|00|-|00|9|00|B|00|3|00|2|00|-|00|7|00|A|00|3|00|C|00|A|00|D|00|5|00|0|00|9|00|1|00|A|00|5|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x006\x003\x003\x004\x004\x00D\x008\x00-\x007\x000\x00D\x003\x00-\x004\x000\x003\x002\x00-\x009\x00B\x003\x002\x00-\x007\x00A\x003\x00C\x00A\x00D\x005\x000\x009\x001\x00A\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6685</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C63344D8-70D3-4032-9B32-7A3CAD5091A5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C63344D8-70D3-4032-9B32-7A3CAD5091A5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6686</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.MMSpecialEffect1Input&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.MMSpecialEffect1Input\x22|\x27DXImageTransform.Microsoft.MMSpecialEffect1Input\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.MMSpecialEffect1Input\x22|\x27DXImageTransform.Microsoft.MMSpecialEffect1Input\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6687</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <bugtraq>18358</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2371</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:20610036-fa22-11cf-9823-00a0c911e5df; dce_opnum:10; dce_stub_data; byte_test:4,&gt;,34,68,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>6714</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences phonebook mode overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>18358</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2371</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:20610036-fa22-11cf-9823-00a0c911e5df; dce_opnum:10; dce_stub_data; pcre:&quot;/^.{68}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; byte_test:4,&gt;,258,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>6906</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences callback number overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>20704</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ADODB.Recordset&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22ADODB.Recordset\x22|\x27ADODB.Recordset\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22ADODB.Recordset\x22|\x27ADODB.Recordset\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7003</id>
        <msg>WEB-ACTIVEX ADODB.Recordset ActiveX function call access</msg>
        <url>osvdb.org/26834</url>
      </rule>
      <rule>
        <bugtraq>18769</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3357</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Internet.HHCtrl.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Internet.HHCtrl.1\x22|\x27Internet.HHCtrl.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Internet.HHCtrl.1\x22|\x27Internet.HHCtrl.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7004</id>
        <msg>WEB-ACTIVEX Internet.HHCtrl.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-046.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ASControls.InstallEngineCtl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22ASControls.InstallEngineCtl\x22|\x27ASControls.InstallEngineCtl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22ASControls.InstallEngineCtl\x22|\x27ASControls.InstallEngineCtl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7006</id>
        <msg>WEB-ACTIVEX ASControls.InstallEngineCtl ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AxDebugger.Document.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22AxDebugger.Document.1\x22|\x27AxDebugger.Document.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22AxDebugger.Document.1\x22|\x27AxDebugger.Document.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7007</id>
        <msg>WEB-ACTIVEX AxDebugger.Document.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAUserData&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAUserData\x22|\x27DirectAnimation.DAUserData\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAUserData\x22|\x27DirectAnimation.DAUserData\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7008</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAUserData ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.StructuredGraphicsControl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.StructuredGraphicsControl\x22|\x27DirectAnimation.StructuredGraphicsControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.StructuredGraphicsControl\x22|\x27DirectAnimation.StructuredGraphicsControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7009</id>
        <msg>WEB-ACTIVEX DirectAnimation.StructuredGraphicsControl ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HtmlDlgSafeHelper.HtmlDlgSafeHelper.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22HtmlDlgSafeHelper.HtmlDlgSafeHelper.1\x22|\x27HtmlDlgSafeHelper.HtmlDlgSafeHelper.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22HtmlDlgSafeHelper.HtmlDlgSafeHelper.1\x22|\x27HtmlDlgSafeHelper.HtmlDlgSafeHelper.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7010</id>
        <msg>WEB-ACTIVEX HtmlDlgSafeHelper.HtmlDlgSafeHelper.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HtmlDlgSafeHelper.HtmlDlgSafeHelper&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22HtmlDlgSafeHelper.HtmlDlgSafeHelper\x22|\x27HtmlDlgSafeHelper.HtmlDlgSafeHelper\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22HtmlDlgSafeHelper.HtmlDlgSafeHelper\x22|\x27HtmlDlgSafeHelper.HtmlDlgSafeHelper\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7011</id>
        <msg>WEB-ACTIVEX HtmlDlgSafeHelper.HtmlDlgSafeHelper ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Internet.PopupMenu.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Internet.PopupMenu.1\x22|\x27Internet.PopupMenu.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Internet.PopupMenu.1\x22|\x27Internet.PopupMenu.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7012</id>
        <msg>WEB-ACTIVEX Internet.PopupMenu.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Microsoft.ISCatAdm&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Microsoft.ISCatAdm\x22|\x27Microsoft.ISCatAdm\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Microsoft.ISCatAdm\x22|\x27Microsoft.ISCatAdm\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7013</id>
        <msg>WEB-ACTIVEX Microsoft.ISCatAdm ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>19114</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-3897</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NMSA.ASFSourceMediaDescription.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22NMSA.ASFSourceMediaDescription.1\x22|\x27NMSA.ASFSourceMediaDescription.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22NMSA.ASFSourceMediaDescription.1\x22|\x27NMSA.ASFSourceMediaDescription.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>7014</id>
        <msg>WEB-ACTIVEX NMSA.ASFSourceMediaDescription.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NMSA.MediaDescription&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22NMSA.MediaDescription\x22|\x27NMSA.MediaDescription\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22NMSA.MediaDescription\x22|\x27NMSA.MediaDescription\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7015</id>
        <msg>WEB-ACTIVEX NMSA.MediaDescription ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>18903</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-3512</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Object.Microsoft.DXTFilter&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Object.Microsoft.DXTFilter\x22|\x27Object.Microsoft.DXTFilter\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Object.Microsoft.DXTFilter\x22|\x27Object.Microsoft.DXTFilter\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>7016</id>
        <msg>WEB-ACTIVEX Object.Microsoft.DXTFilter ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>18900</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3510</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RDS.DataControl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22RDS.DataControl\x22|\x27RDS.DataControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22RDS.DataControl\x22|\x27RDS.DataControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7017</id>
        <msg>WEB-ACTIVEX RDS.DataControl ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Sysmon&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Sysmon\x22|\x27Sysmon\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Sysmon\x22|\x27Sysmon\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7018</id>
        <msg>WEB-ACTIVEX Sysmon ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>17462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0003</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RDS.DataSpace&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22RDS.DataSpace\x22|\x27RDS.DataSpace\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22RDS.DataSpace\x22|\x27RDS.DataSpace\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7026</id>
        <msg>WEB-ACTIVEX RDS.Dataspace ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03|&quot;; within:1; distance:27; content:&quot;|01 00 00 00|&quot;; within:4; distance:1; content:!&quot;|00|&quot;; within:25; distance:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>7035</id>
        <msg>NETBIOS SMB Trans mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03|&quot;; within:1; distance:27; content:!&quot;|00 00|&quot;; within:50; distance:9; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>7036</id>
        <msg>NETBIOS SMB Trans unicode mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03|&quot;; within:1; distance:27; content:&quot;|01 00 00 00|&quot;; within:4; distance:1; content:!&quot;|00|&quot;; within:25; distance:4; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>7039</id>
        <msg>NETBIOS SMB Trans andx mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03|&quot;; within:1; distance:27; content:!&quot;|00 00|&quot;; within:50; distance:9; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>7040</id>
        <msg>NETBIOS SMB Trans unicode andx mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03|&quot;; within:1; distance:27; content:&quot;|01 00 00 00|&quot;; within:4; distance:1; content:!&quot;|00|&quot;; within:25; distance:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>7041</id>
        <msg>NETBIOS-DG SMB Trans andx mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>19409</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3439</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:31; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>7209</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrPathCanonicalize overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-040.mspx</url>
      </rule>
      <rule>
        <bugtraq>19409</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3439</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:31; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|04 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>7210</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrPathCanonicalize overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-040.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BC0D69A8-0923-4EEE-9375-9239F5A38B92&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*BC0D69A8-0923-4EEE-9375-9239F5A38B92/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7425</id>
        <msg>WEB-ACTIVEX 9x8Resize ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|C|00|0|00|D|00|6|00|9|00|A|00|8|00|-|00|0|00|9|00|2|00|3|00|-|00|4|00|E|00|E|00|E|00|-|00|9|00|3|00|7|00|5|00|-|00|9|00|2|00|3|00|9|00|F|00|5|00|A|00|3|00|8|00|B|00|9|00|2|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x00C\x000\x00D\x006\x009\x00A\x008\x00-\x000\x009\x002\x003\x00-\x004\x00E\x00E\x00E\x00-\x009\x003\x007\x005\x00-\x009\x002\x003\x009\x00F\x005\x00A\x003\x008\x00B\x009\x002\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7426</id>
        <msg>WEB-ACTIVEX 9x8Resize ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C0D076C5-E4C6-4561-8BF4-80DA8DB819D7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C0D076C5-E4C6-4561-8BF4-80DA8DB819D7/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7427</id>
        <msg>WEB-ACTIVEX Allocator Fix ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|0|00|D|00|0|00|7|00|6|00|C|00|5|00|-|00|E|00|4|00|C|00|6|00|-|00|4|00|5|00|6|00|1|00|-|00|8|00|B|00|F|00|4|00|-|00|8|00|0|00|D|00|A|00|8|00|D|00|B|00|8|00|1|00|9|00|D|00|7|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x000\x00D\x000\x007\x006\x00C\x005\x00-\x00E\x004\x00C\x006\x00-\x004\x005\x006\x001\x00-\x008\x00B\x00F\x004\x00-\x008\x000\x00D\x00A\x008\x00D\x00B\x008\x001\x009\x00D\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7428</id>
        <msg>WEB-ACTIVEX Allocator Fix ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4F3E50BD-A9D7-4721-B0E1-00CB42A0A747&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4F3E50BD-A9D7-4721-B0E1-00CB42A0A747/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7429</id>
        <msg>WEB-ACTIVEX Bitmap ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|F|00|3|00|E|00|5|00|0|00|B|00|D|00|-|00|A|00|9|00|D|00|7|00|-|00|4|00|7|00|2|00|1|00|-|00|B|00|0|00|E|00|1|00|-|00|0|00|0|00|C|00|B|00|4|00|2|00|A|00|0|00|A|00|7|00|4|00|7|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x00F\x003\x00E\x005\x000\x00B\x00D\x00-\x00A\x009\x00D\x007\x00-\x004\x007\x002\x001\x00-\x00B\x000\x00E\x001\x00-\x000\x000\x00C\x00B\x004\x002\x00A\x000\x00A\x007\x004\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7430</id>
        <msg>WEB-ACTIVEX Bitmap ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;39A2C2A6-4778-11D2-9BDB-204C4F4F5020&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*39A2C2A6-4778-11D2-9BDB-204C4F4F5020/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7431</id>
        <msg>WEB-ACTIVEX DirectFrame.DirectControl.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|9|00|A|00|2|00|C|00|2|00|A|00|6|00|-|00|4|00|7|00|7|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|B|00|D|00|B|00|-|00|2|00|0|00|4|00|C|00|4|00|F|00|4|00|F|00|5|00|0|00|2|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x009\x00A\x002\x00C\x002\x00A\x006\x00-\x004\x007\x007\x008\x00-\x001\x001\x00D\x002\x00-\x009\x00B\x00D\x00B\x00-\x002\x000\x004\x00C\x004\x00F\x004\x00F\x005\x000\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7432</id>
        <msg>WEB-ACTIVEX DirectFrame.DirectControl.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1B544C24-FD0B-11CE-8C63-00AA0044B520&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1B544C24-FD0B-11CE-8C63-00AA0044B520/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7433</id>
        <msg>WEB-ACTIVEX DirectX Transform Wrapper Property Page ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|B|00|5|00|4|00|4|00|C|00|2|00|4|00|-|00|F|00|D|00|0|00|B|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|6|00|3|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|4|00|B|00|5|00|2|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x00B\x005\x004\x004\x00C\x002\x004\x00-\x00F\x00D\x000\x00B\x00-\x001\x001\x00C\x00E\x00-\x008\x00C\x006\x003\x00-\x000\x000\x00A\x00A\x000\x000\x004\x004\x00B\x005\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7434</id>
        <msg>WEB-ACTIVEX DirectX Transform Wrapper Property Page ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5DFB2651-9668-11D0-B17B-00C04FC2A0CA&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7435</id>
        <msg>WEB-ACTIVEX Dynamic Casts ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DATuple&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7436</id>
        <msg>WEB-ACTIVEX Dynamic Casts ActiveX function call</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6C68955E-F965-4249-8E18-F0977B1D2899&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6C68955E-F965-4249-8E18-F0977B1D2899/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7437</id>
        <msg>WEB-ACTIVEX Frame Eater ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|C|00|6|00|8|00|9|00|5|00|5|00|E|00|-|00|F|00|9|00|6|00|5|00|-|00|4|00|2|00|4|00|9|00|-|00|8|00|E|00|1|00|8|00|-|00|F|00|0|00|9|00|7|00|7|00|B|00|1|00|D|00|2|00|8|00|9|00|9|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x00C\x006\x008\x009\x005\x005\x00E\x00-\x00F\x009\x006\x005\x00-\x004\x002\x004\x009\x00-\x008\x00E\x001\x008\x00-\x00F\x000\x009\x007\x007\x00B\x001\x00D\x002\x008\x009\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7438</id>
        <msg>WEB-ACTIVEX Frame Eater ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0214</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;52A2AAAE-085D-4187-97EA-8C30DB990436&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*52A2AAAE-085D-4187-97EA-8C30DB990436\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7439</id>
        <msg>WEB-ACTIVEX HTML Help ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0214</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|2|00|A|00|2|00|A|00|A|00|A|00|E|00|-|00|0|00|8|00|5|00|D|00|-|00|4|00|1|00|8|00|7|00|-|00|9|00|7|00|E|00|A|00|-|00|8|00|C|00|3|00|0|00|D|00|B|00|9|00|9|00|0|00|4|00|3|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x002\x00A\x002\x00A\x00A\x00A\x00E\x00-\x000\x008\x005\x00D\x00-\x004\x001\x008\x007\x00-\x009\x007\x00E\x00A\x00-\x008\x00C\x003\x000\x00D\x00B\x009\x009\x000\x004\x003\x006\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7440</id>
        <msg>WEB-ACTIVEX HTML Help ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-008.mspx</url>
      </rule>
      <rule>
        <bugtraq>13953</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1208</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|B|00|2|00|3|00|C|00|2|00|8|00|-|00|4|00|8|00|8|00|E|00|-|00|4|00|e|00|5|00|C|00|-|00|A|00|C|00|E|00|2|00|-|00|B|00|B|00|0|00|B|00|B|00|A|00|B|00|E|00|9|00|9|00|E|00|8|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x001\x00B\x002\x003\x00C\x002\x008\x00-\x004\x008\x008\x00E\x00-\x004\x00e\x005\x00C\x00-\x00A\x00C\x00E\x002\x00-\x00B\x00B\x000\x00B\x00B\x00A\x00B\x00E\x009\x009\x00E\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7441</id>
        <msg>WEB-ACTIVEX HTML Help ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-026.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E8C31D11-6FD2-4659-AD75-155FA143F42B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E8C31D11-6FD2-4659-AD75-155FA143F42B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7442</id>
        <msg>WEB-ACTIVEX mmAEPlugIn.AEPlugIn.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|8|00|C|00|3|00|1|00|D|00|1|00|1|00|-|00|6|00|F|00|D|00|2|00|-|00|4|00|6|00|5|00|9|00|-|00|A|00|D|00|7|00|5|00|-|00|1|00|5|00|5|00|F|00|A|00|1|00|4|00|3|00|F|00|4|00|2|00|B|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x008\x00C\x003\x001\x00D\x001\x001\x00-\x006\x00F\x00D\x002\x00-\x004\x006\x005\x009\x00-\x00A\x00D\x007\x005\x00-\x001\x005\x005\x00F\x00A\x001\x004\x003\x00F\x004\x002\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7443</id>
        <msg>WEB-ACTIVEX mmAEPlugIn.AEPlugIn.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3DA2AA3E-3D96-11D2-9BD2-204C4F4F5020&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3DA2AA3E-3D96-11D2-9BD2-204C4F4F5020/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7444</id>
        <msg>WEB-ACTIVEX Mmedia.AsyncMHandler.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|D|00|A|00|2|00|A|00|A|00|3|00|E|00|-|00|3|00|D|00|9|00|6|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|B|00|D|00|2|00|-|00|2|00|0|00|4|00|C|00|4|00|F|00|4|00|F|00|5|00|0|00|2|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x00D\x00A\x002\x00A\x00A\x003\x00E\x00-\x003\x00D\x009\x006\x00-\x001\x001\x00D\x002\x00-\x009\x00B\x00D\x002\x00-\x002\x000\x004\x00C\x004\x00F\x004\x00F\x005\x000\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7445</id>
        <msg>WEB-ACTIVEX Mmedia.AsyncMHandler.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5B4B05EB-1F63-446B-AAD1-E10A34D650E0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*5B4B05EB-1F63-446B-AAD1-E10A34D650E0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7446</id>
        <msg>WEB-ACTIVEX Record Queue ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|B|00|4|00|B|00|0|00|5|00|E|00|B|00|-|00|1|00|F|00|6|00|3|00|-|00|4|00|4|00|6|00|B|00|-|00|A|00|A|00|D|00|1|00|-|00|E|00|1|00|0|00|A|00|3|00|4|00|D|00|6|00|5|00|0|00|E|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x00B\x004\x00B\x000\x005\x00E\x00B\x00-\x001\x00F\x006\x003\x00-\x004\x004\x006\x00B\x00-\x00A\x00A\x00D\x001\x00-\x00E\x001\x000\x00A\x003\x004\x00D\x006\x005\x000\x00E\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7447</id>
        <msg>WEB-ACTIVEX Record Queue ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CFFB1FC7-270D-4986-B299-FECF3F0E42DB&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CFFB1FC7-270D-4986-B299-FECF3F0E42DB/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7448</id>
        <msg>WEB-ACTIVEX ShotDetect ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|F|00|B|00|1|00|F|00|C|00|7|00|-|00|2|00|7|00|0|00|D|00|-|00|4|00|9|00|8|00|6|00|-|00|B|00|2|00|9|00|9|00|-|00|F|00|E|00|C|00|F|00|3|00|F|00|0|00|E|00|4|00|2|00|D|00|B|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x00F\x00F\x00B\x001\x00F\x00C\x007\x00-\x002\x007\x000\x00D\x00-\x004\x009\x008\x006\x00-\x00B\x002\x009\x009\x00-\x00F\x00E\x00C\x00F\x003\x00F\x000\x00E\x004\x002\x00D\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7449</id>
        <msg>WEB-ACTIVEX ShotDetect ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F44BB2D0-F070-463E-9433-B0CCF3CFD627&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F44BB2D0-F070-463E-9433-B0CCF3CFD627/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7450</id>
        <msg>WEB-ACTIVEX Stetch ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|4|00|4|00|B|00|B|00|2|00|D|00|0|00|-|00|F|00|0|00|7|00|0|00|-|00|4|00|6|00|3|00|E|00|-|00|9|00|4|00|3|00|3|00|-|00|B|00|0|00|C|00|C|00|F|00|3|00|C|00|F|00|D|00|6|00|2|00|7|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x004\x004\x00B\x00B\x002\x00D\x000\x00-\x00F\x000\x007\x000\x00-\x004\x006\x003\x00E\x00-\x009\x004\x003\x003\x00-\x00B\x000\x00C\x00C\x00F\x003\x00C\x00F\x00D\x006\x002\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7451</id>
        <msg>WEB-ACTIVEX Stetch ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CC45B0B0-72D8-4652-AE5F-5E3E266BE7ED&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CC45B0B0-72D8-4652-AE5F-5E3E266BE7ED/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7452</id>
        <msg>WEB-ACTIVEX WM Color Converter Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|C|00|4|00|5|00|B|00|0|00|B|00|0|00|-|00|7|00|2|00|D|00|8|00|-|00|4|00|6|00|5|00|2|00|-|00|A|00|E|00|5|00|F|00|-|00|5|00|E|00|3|00|E|00|2|00|6|00|6|00|B|00|E|00|7|00|E|00|D|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x00C\x004\x005\x00B\x000\x00B\x000\x00-\x007\x002\x00D\x008\x00-\x004\x006\x005\x002\x00-\x00A\x00E\x005\x00F\x00-\x005\x00E\x003\x00E\x002\x006\x006\x00B\x00E\x007\x00E\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7453</id>
        <msg>WEB-ACTIVEX WM Color Converter Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;44C79591-D0DE-49C4-BA3C-A45AB7003356&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*44C79591-D0DE-49C4-BA3C-A45AB7003356/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7454</id>
        <msg>WEB-ACTIVEX Wmm2ae.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|C|00|7|00|9|00|5|00|9|00|1|00|-|00|D|00|0|00|D|00|E|00|-|00|4|00|9|00|C|00|4|00|-|00|B|00|A|00|3|00|C|00|-|00|A|00|4|00|5|00|A|00|B|00|7|00|0|00|0|00|3|00|3|00|5|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x004\x00C\x007\x009\x005\x009\x001\x00-\x00D\x000\x00D\x00E\x00-\x004\x009\x00C\x004\x00-\x00B\x00A\x003\x00C\x00-\x00A\x004\x005\x00A\x00B\x007\x000\x000\x003\x003\x005\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7455</id>
        <msg>WEB-ACTIVEX Wmm2ae.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A2D4529E-84E0-4550-A2E0-C25D7C5CC0D0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A2D4529E-84E0-4550-A2E0-C25D7C5CC0D0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7456</id>
        <msg>WEB-ACTIVEX Wmm2fxa.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|2|00|D|00|4|00|5|00|2|00|9|00|E|00|-|00|8|00|4|00|E|00|0|00|-|00|4|00|5|00|5|00|0|00|-|00|A|00|2|00|E|00|0|00|-|00|C|00|2|00|5|00|D|00|7|00|C|00|5|00|C|00|C|00|0|00|D|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x002\x00D\x004\x005\x002\x009\x00E\x00-\x008\x004\x00E\x000\x00-\x004\x005\x005\x000\x00-\x00A\x002\x00E\x000\x00-\x00C\x002\x005\x00D\x007\x00C\x005\x00C\x00C\x000\x00D\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7457</id>
        <msg>WEB-ACTIVEX Wmm2fxa.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D74CA70F-2236-4BA8-A297-4B2A28C2363C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D74CA70F-2236-4BA8-A297-4B2A28C2363C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7458</id>
        <msg>WEB-ACTIVEX Wmm2fxb.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|7|00|4|00|C|00|A|00|7|00|0|00|F|00|-|00|2|00|2|00|3|00|6|00|-|00|4|00|B|00|A|00|8|00|-|00|A|00|2|00|9|00|7|00|-|00|4|00|B|00|2|00|A|00|2|00|8|00|C|00|2|00|3|00|6|00|3|00|C|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x007\x004\x00C\x00A\x007\x000\x00F\x00-\x002\x002\x003\x006\x00-\x004\x00B\x00A\x008\x00-\x00A\x002\x009\x007\x00-\x004\x00B\x002\x00A\x002\x008\x00C\x002\x003\x006\x003\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7459</id>
        <msg>WEB-ACTIVEX Wmm2fxb.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1CB1623E-BBEC-4E8D-B2DF-DC08C6F4627C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1CB1623E-BBEC-4E8D-B2DF-DC08C6F4627C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7460</id>
        <msg>WEB-ACTIVEX WMT Audio Analyzer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|C|00|B|00|1|00|6|00|2|00|3|00|E|00|-|00|B|00|B|00|E|00|C|00|-|00|4|00|E|00|8|00|D|00|-|00|B|00|2|00|D|00|F|00|-|00|D|00|C|00|0|00|8|00|C|00|6|00|F|00|4|00|6|00|2|00|7|00|C|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x00C\x00B\x001\x006\x002\x003\x00E\x00-\x00B\x00B\x00E\x00C\x00-\x004\x00E\x008\x00D\x00-\x00B\x002\x00D\x00F\x00-\x00D\x00C\x000\x008\x00C\x006\x00F\x004\x006\x002\x007\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7461</id>
        <msg>WEB-ACTIVEX WMT Audio Analyzer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2EA10031-0033-450E-8072-E27D9E768142&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*2EA10031-0033-450E-8072-E27D9E768142/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7462</id>
        <msg>WEB-ACTIVEX WMT Black Frame Generator ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|E|00|A|00|1|00|0|00|0|00|3|00|1|00|-|00|0|00|0|00|3|00|3|00|-|00|4|00|5|00|0|00|E|00|-|00|8|00|0|00|7|00|2|00|-|00|E|00|2|00|7|00|D|00|9|00|E|00|7|00|6|00|8|00|1|00|4|00|2|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*2\x00E\x00A\x001\x000\x000\x003\x001\x00-\x000\x000\x003\x003\x00-\x004\x005\x000\x00E\x00-\x008\x000\x007\x002\x00-\x00E\x002\x007\x00D\x009\x00E\x007\x006\x008\x001\x004\x002\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7463</id>
        <msg>WEB-ACTIVEX WMT Black Frame Generator ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C8F209F8-480E-454C-94A4-5392D88EBA0F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C8F209F8-480E-454C-94A4-5392D88EBA0F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7464</id>
        <msg>WEB-ACTIVEX WMT DeInterlace Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|8|00|F|00|2|00|0|00|9|00|F|00|8|00|-|00|4|00|8|00|0|00|E|00|-|00|4|00|5|00|4|00|C|00|-|00|9|00|4|00|A|00|4|00|-|00|5|00|3|00|9|00|2|00|D|00|8|00|8|00|E|00|B|00|A|00|0|00|F|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x008\x00F\x002\x000\x009\x00F\x008\x00-\x004\x008\x000\x00E\x00-\x004\x005\x004\x00C\x00-\x009\x004\x00A\x004\x00-\x005\x003\x009\x002\x00D\x008\x008\x00E\x00B\x00A\x000\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7465</id>
        <msg>WEB-ACTIVEX WMT DeInterlace Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A2EDA89A-0966-4B91-9C18-AB69F098187F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A2EDA89A-0966-4B91-9C18-AB69F098187F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7466</id>
        <msg>WEB-ACTIVEX WMT DeInterlace Prop Page ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|2|00|E|00|D|00|A|00|8|00|9|00|A|00|-|00|0|00|9|00|6|00|6|00|-|00|4|00|B|00|9|00|1|00|-|00|9|00|C|00|1|00|8|00|-|00|A|00|B|00|6|00|9|00|F|00|0|00|9|00|8|00|1|00|8|00|7|00|F|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x002\x00E\x00D\x00A\x008\x009\x00A\x00-\x000\x009\x006\x006\x00-\x004\x00B\x009\x001\x00-\x009\x00C\x001\x008\x00-\x00A\x00B\x006\x009\x00F\x000\x009\x008\x001\x008\x007\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7467</id>
        <msg>WEB-ACTIVEX WMT DeInterlace Prop Page ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AECF5D2E-7A18-4DD2-BDCD-29B6F615B448&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*AECF5D2E-7A18-4DD2-BDCD-29B6F615B448/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7468</id>
        <msg>WEB-ACTIVEX WMT DirectX Transform Wrapper ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|E|00|C|00|F|00|5|00|D|00|2|00|E|00|-|00|7|00|A|00|1|00|8|00|-|00|4|00|D|00|D|00|2|00|-|00|B|00|D|00|C|00|D|00|-|00|2|00|9|00|B|00|6|00|F|00|6|00|1|00|5|00|B|00|4|00|4|00|8|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x00E\x00C\x00F\x005\x00D\x002\x00E\x00-\x007\x00A\x001\x008\x00-\x004\x00D\x00D\x002\x00-\x00B\x00D\x00C\x00D\x00-\x002\x009\x00B\x006\x00F\x006\x001\x005\x00B\x004\x004\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7469</id>
        <msg>WEB-ACTIVEX WMT DirectX Transform Wrapper ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E476CBFF-E229-4524-B6B7-228A3129D1C7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E476CBFF-E229-4524-B6B7-228A3129D1C7/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7470</id>
        <msg>WEB-ACTIVEX WMT DV Extract Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|4|00|7|00|6|00|C|00|B|00|F|00|F|00|-|00|E|00|2|00|2|00|9|00|-|00|4|00|5|00|2|00|4|00|-|00|B|00|6|00|B|00|7|00|-|00|2|00|2|00|8|00|A|00|3|00|1|00|2|00|9|00|D|00|1|00|C|00|7|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x004\x007\x006\x00C\x00B\x00F\x00F\x00-\x00E\x002\x002\x009\x00-\x004\x005\x002\x004\x00-\x00B\x006\x00B\x007\x00-\x002\x002\x008\x00A\x003\x001\x002\x009\x00D\x001\x00C\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7471</id>
        <msg>WEB-ACTIVEX WMT DV Extract Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E188F7A3-A04E-413E-99D1-D79A45F70305&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E188F7A3-A04E-413E-99D1-D79A45F70305/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7472</id>
        <msg>WEB-ACTIVEX WMT FormatConversion Prop Page ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|1|00|8|00|8|00|F|00|7|00|A|00|3|00|-|00|A|00|0|00|4|00|E|00|-|00|4|00|1|00|3|00|E|00|-|00|9|00|9|00|D|00|1|00|-|00|D|00|7|00|9|00|A|00|4|00|5|00|F|00|7|00|0|00|3|00|0|00|5|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x001\x008\x008\x00F\x007\x00A\x003\x00-\x00A\x000\x004\x00E\x00-\x004\x001\x003\x00E\x00-\x009\x009\x00D\x001\x00-\x00D\x007\x009\x00A\x004\x005\x00F\x007\x000\x003\x000\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7473</id>
        <msg>WEB-ACTIVEX WMT FormatConversion Prop Page ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2D20D4BB-B47E-4FB7-83BD-E3C2EE250D26&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*2D20D4BB-B47E-4FB7-83BD-E3C2EE250D26/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7474</id>
        <msg>WEB-ACTIVEX WMT FormatConversion ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|D|00|2|00|0|00|D|00|4|00|B|00|B|00|-|00|B|00|4|00|7|00|E|00|-|00|4|00|F|00|B|00|7|00|-|00|8|00|3|00|B|00|D|00|-|00|E|00|3|00|C|00|2|00|E|00|E|00|2|00|5|00|0|00|D|00|2|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*2\x00D\x002\x000\x00D\x004\x00B\x00B\x00-\x00B\x004\x007\x00E\x00-\x004\x00F\x00B\x007\x00-\x008\x003\x00B\x00D\x00-\x00E\x003\x00C\x002\x00E\x00E\x002\x005\x000\x00D\x002\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7475</id>
        <msg>WEB-ACTIVEX WMT FormatConversion ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4D4C9FEF-ED80-47EA-A3FA-3215FDBB33AB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4D4C9FEF-ED80-47EA-A3FA-3215FDBB33AB/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7476</id>
        <msg>WEB-ACTIVEX WMT Import Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|D|00|4|00|C|00|9|00|F|00|E|00|F|00|-|00|E|00|D|00|8|00|0|00|-|00|4|00|7|00|E|00|A|00|-|00|A|00|3|00|F|00|A|00|-|00|3|00|2|00|1|00|5|00|F|00|D|00|B|00|B|00|3|00|3|00|A|00|B|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x00D\x004\x00C\x009\x00F\x00E\x00F\x00-\x00E\x00D\x008\x000\x00-\x004\x007\x00E\x00A\x00-\x00A\x003\x00F\x00A\x00-\x003\x002\x001\x005\x00F\x00D\x00B\x00B\x003\x003\x00A\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7477</id>
        <msg>WEB-ACTIVEX WMT Import Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C6CB1FE3-B05E-4F0E-818F-C83ED5A0332F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C6CB1FE3-B05E-4F0E-818F-C83ED5A0332F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7478</id>
        <msg>WEB-ACTIVEX WMT Interlacer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|6|00|C|00|B|00|1|00|F|00|E|00|3|00|-|00|B|00|0|00|5|00|E|00|-|00|4|00|F|00|0|00|E|00|-|00|8|00|1|00|8|00|F|00|-|00|C|00|8|00|3|00|E|00|D|00|5|00|A|00|0|00|3|00|3|00|2|00|F|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x006\x00C\x00B\x001\x00F\x00E\x003\x00-\x00B\x000\x005\x00E\x00-\x004\x00F\x000\x00E\x00-\x008\x001\x008\x00F\x00-\x00C\x008\x003\x00E\x00D\x005\x00A\x000\x003\x003\x002\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7479</id>
        <msg>WEB-ACTIVEX WMT Interlacer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;92883667-E95C-443D-AC96-4CACA27BEB6E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*92883667-E95C-443D-AC96-4CACA27BEB6E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7480</id>
        <msg>WEB-ACTIVEX WMT Log Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|2|00|8|00|8|00|3|00|6|00|6|00|7|00|-|00|E|00|9|00|5|00|C|00|-|00|4|00|4|00|3|00|D|00|-|00|A|00|C|00|9|00|6|00|-|00|4|00|C|00|A|00|C|00|A|00|2|00|7|00|B|00|E|00|B|00|6|00|E|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x002\x008\x008\x003\x006\x006\x007\x00-\x00E\x009\x005\x00C\x00-\x004\x004\x003\x00D\x00-\x00A\x00C\x009\x006\x00-\x004\x00C\x00A\x00C\x00A\x002\x007\x00B\x00E\x00B\x006\x00E\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7481</id>
        <msg>WEB-ACTIVEX WMT Log Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;01002B17-5D93-4551-81E4-831FEF780A53&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*01002B17-5D93-4551-81E4-831FEF780A53/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7482</id>
        <msg>WEB-ACTIVEX WMT MuxDeMux Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|1|00|0|00|0|00|2|00|B|00|1|00|7|00|-|00|5|00|D|00|9|00|3|00|-|00|4|00|5|00|5|00|1|00|-|00|8|00|1|00|E|00|4|00|-|00|8|00|3|00|1|00|F|00|E|00|F|00|7|00|8|00|0|00|A|00|5|00|3|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x001\x000\x000\x002\x00B\x001\x007\x00-\x005\x00D\x009\x003\x00-\x004\x005\x005\x001\x00-\x008\x001\x00E\x004\x00-\x008\x003\x001\x00F\x00E\x00F\x007\x008\x000\x00A\x005\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7483</id>
        <msg>WEB-ACTIVEX WMT MuxDeMux Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7F1232EE-44D7-4494-AB8B-CC61B10E21A5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7F1232EE-44D7-4494-AB8B-CC61B10E21A5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7484</id>
        <msg>WEB-ACTIVEX WMT Sample Info Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|F|00|1|00|2|00|3|00|2|00|E|00|E|00|-|00|4|00|4|00|D|00|7|00|-|00|4|00|4|00|9|00|4|00|-|00|A|00|B|00|8|00|B|00|-|00|C|00|C|00|6|00|1|00|B|00|1|00|0|00|E|00|2|00|1|00|A|00|5|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*7\x00F\x001\x002\x003\x002\x00E\x00E\x00-\x004\x004\x00D\x007\x00-\x004\x004\x009\x004\x00-\x00A\x00B\x008\x00B\x00-\x00C\x00C\x006\x001\x00B\x001\x000\x00E\x002\x001\x00A\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7485</id>
        <msg>WEB-ACTIVEX WMT Sample Info Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;679E132F-561B-42F8-846C-A70DBDC62999&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*679E132F-561B-42F8-846C-A70DBDC62999/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7486</id>
        <msg>WEB-ACTIVEX WMT Screen Capture Filter Task Page ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|9|00|E|00|1|00|3|00|2|00|F|00|-|00|5|00|6|00|1|00|B|00|-|00|4|00|2|00|F|00|8|00|-|00|8|00|4|00|6|00|C|00|-|00|A|00|7|00|0|00|D|00|B|00|D|00|C|00|6|00|2|00|9|00|9|00|9|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x007\x009\x00E\x001\x003\x002\x00F\x00-\x005\x006\x001\x00B\x00-\x004\x002\x00F\x008\x00-\x008\x004\x006\x00C\x00-\x00A\x007\x000\x00D\x00B\x00D\x00C\x006\x002\x009\x009\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7487</id>
        <msg>WEB-ACTIVEX WMT Screen Capture Filter Task Page ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;31087270-D348-432C-899E-2D2F38FF29A0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*31087270-D348-432C-899E-2D2F38FF29A0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7488</id>
        <msg>WEB-ACTIVEX WMT Screen capture Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|1|00|0|00|8|00|7|00|2|00|7|00|0|00|-|00|D|00|3|00|4|00|8|00|-|00|4|00|3|00|2|00|C|00|-|00|8|00|9|00|9|00|E|00|-|00|2|00|D|00|2|00|F|00|3|00|8|00|F|00|F|00|2|00|9|00|A|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x001\x000\x008\x007\x002\x007\x000\x00-\x00D\x003\x004\x008\x00-\x004\x003\x002\x00C\x00-\x008\x009\x009\x00E\x00-\x002\x00D\x002\x00F\x003\x008\x00F\x00F\x002\x009\x00A\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7489</id>
        <msg>WEB-ACTIVEX WMT Screen capture Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EF105BC3-C064-45F1-AD53-6D8A8578D01B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*EF105BC3-C064-45F1-AD53-6D8A8578D01B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7490</id>
        <msg>WEB-ACTIVEX WMT Switch Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|F|00|1|00|0|00|5|00|B|00|C|00|3|00|-|00|C|00|0|00|6|00|4|00|-|00|4|00|5|00|F|00|1|00|-|00|A|00|D|00|5|00|3|00|-|00|6|00|D|00|8|00|A|00|8|00|5|00|7|00|8|00|D|00|0|00|1|00|B|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x00F\x001\x000\x005\x00B\x00C\x003\x00-\x00C\x000\x006\x004\x00-\x004\x005\x00F\x001\x00-\x00A\x00D\x005\x003\x00-\x006\x00D\x008\x00A\x008\x005\x007\x008\x00D\x000\x001\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7491</id>
        <msg>WEB-ACTIVEX WMT Switch Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;930FD02C-BBE7-4EB9-91CF-FC45CC91E3E6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*930FD02C-BBE7-4EB9-91CF-FC45CC91E3E6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7492</id>
        <msg>WEB-ACTIVEX WMT Virtual Renderer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|3|00|0|00|F|00|D|00|0|00|2|00|C|00|-|00|B|00|B|00|E|00|7|00|-|00|4|00|E|00|B|00|9|00|-|00|9|00|1|00|C|00|F|00|-|00|F|00|C|00|4|00|5|00|C|00|C|00|9|00|1|00|E|00|3|00|E|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x003\x000\x00F\x00D\x000\x002\x00C\x00-\x00B\x00B\x00E\x007\x00-\x004\x00E\x00B\x009\x00-\x009\x001\x00C\x00F\x00-\x00F\x00C\x004\x005\x00C\x00C\x009\x001\x00E\x003\x00E\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7493</id>
        <msg>WEB-ACTIVEX WMT Virtual Renderer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C44C65C7-FDF1-453D-89A5-BCC28F5D69F9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C44C65C7-FDF1-453D-89A5-BCC28F5D69F9/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7494</id>
        <msg>WEB-ACTIVEX WMT Virtual Source ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|4|00|C|00|6|00|5|00|C|00|7|00|-|00|F|00|D|00|F|00|1|00|-|00|4|00|5|00|3|00|D|00|-|00|8|00|9|00|A|00|5|00|-|00|B|00|C|00|C|00|2|00|8|00|F|00|5|00|D|00|6|00|9|00|F|00|9|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x004\x00C\x006\x005\x00C\x007\x00-\x00F\x00D\x00F\x001\x00-\x004\x005\x003\x00D\x00-\x008\x009\x00A\x005\x00-\x00B\x00C\x00C\x002\x008\x00F\x005\x00D\x006\x009\x00F\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7495</id>
        <msg>WEB-ACTIVEX WMT Virtual Source ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EFEE43D6-BFE5-44B0-8063-AC3B2966AB2C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*EFEE43D6-BFE5-44B0-8063-AC3B2966AB2C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7496</id>
        <msg>WEB-ACTIVEX WMT Volume ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|F|00|E|00|E|00|4|00|3|00|D|00|6|00|-|00|B|00|F|00|E|00|5|00|-|00|4|00|4|00|B|00|0|00|-|00|8|00|0|00|6|00|3|00|-|00|A|00|C|00|3|00|B|00|2|00|9|00|6|00|6|00|A|00|B|00|2|00|C|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x00F\x00E\x00E\x004\x003\x00D\x006\x00-\x00B\x00F\x00E\x005\x00-\x004\x004\x00B\x000\x00-\x008\x000\x006\x003\x00-\x00A\x00C\x003\x00B\x002\x009\x006\x006\x00A\x00B\x002\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7497</id>
        <msg>WEB-ACTIVEX WMT Volume ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;41D2B841-7692-4C83-AFD3-F60E845341AF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*41D2B841-7692-4C83-AFD3-F60E845341AF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7498</id>
        <msg>WEB-ACTIVEX WM TV Out Smooth Picture Filter ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|D|00|2|00|B|00|8|00|4|00|1|00|-|00|7|00|6|00|9|00|2|00|-|00|4|00|C|00|8|00|3|00|-|00|A|00|F|00|D|00|3|00|-|00|F|00|6|00|0|00|E|00|8|00|4|00|5|00|3|00|4|00|1|00|A|00|F|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x001\x00D\x002\x00B\x008\x004\x001\x00-\x007\x006\x009\x002\x00-\x004\x00C\x008\x003\x00-\x00A\x00F\x00D\x003\x00-\x00F\x006\x000\x00E\x008\x004\x005\x003\x004\x001\x00A\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7499</id>
        <msg>WEB-ACTIVEX WM TV Out Smooth Picture Filter ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;586FB486-5560-4FF3-96DF-1118C96AF456&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*586FB486-5560-4FF3-96DF-1118C96AF456/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7500</id>
        <msg>WEB-ACTIVEX WM VIH2 Fix ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|8|00|6|00|F|00|B|00|4|00|8|00|6|00|-|00|5|00|5|00|6|00|0|00|-|00|4|00|F|00|F|00|3|00|-|00|9|00|6|00|D|00|F|00|-|00|1|00|1|00|1|00|8|00|C|00|9|00|6|00|A|00|F|00|4|00|5|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x008\x006\x00F\x00B\x004\x008\x006\x00-\x005\x005\x006\x000\x00-\x004\x00F\x00F\x003\x00-\x009\x006\x00D\x00F\x00-\x001\x001\x001\x008\x00C\x009\x006\x00A\x00F\x004\x005\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7501</id>
        <msg>WEB-ACTIVEX WM VIH2 Fix ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <bugtraq>19570</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E2E9CAE6-1E7B-4B8E-BABD-E9BF6292AC29&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E2E9CAE6-1E7B-4B8E-BABD-E9BF6292AC29\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7502</id>
        <msg>WEB-ACTIVEX tsuserex.ADsTSUserEx.1 ActiveX clsid access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=14</url>
      </rule>
      <rule>
        <bugtraq>19570</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|2|00|E|00|9|00|C|00|A|00|E|00|6|00|-|00|1|00|E|00|7|00|B|00|-|00|4|00|B|00|8|00|E|00|-|00|B|00|A|00|B|00|D|00|-|00|E|00|9|00|B|00|F|00|6|00|2|00|9|00|2|00|A|00|C|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x002\x00E\x009\x00C\x00A\x00E\x006\x00-\x001\x00E\x007\x00B\x00-\x004\x00B\x008\x00E\x00-\x00B\x00A\x00B\x00D\x00-\x00E\x009\x00B\x00F\x006\x002\x009\x002\x00A\x00C\x002\x009\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7503</id>
        <msg>WEB-ACTIVEX tsuserex.ADsTSUserEx.1 ActiveX clsid unicode access</msg>
        <url>www.xsec.org/index.php?module=Releases&amp;act=view&amp;type=1&amp;id=14</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/url_sp2.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;vb&quot;; nocase; http_header; content:&quot;wininet&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*vb\s+wininet/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7856</id>
        <msg>SPYWARE-PUT Trackware winsysba-a runtime detection - track surfing activity</msg>
        <url>secunia.com/virus_information/26844/winsysba-a/</url>
      </rule>
      <rule>
        <bugtraq>19265</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3961</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IsAppExpired&quot;; fast_pattern:only; nocase; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22IsAppExpired\x22|\x27IsAppExpired\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22IsAppExpired\x22|\x27IsAppExpired\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7862</id>
        <msg>WEB-ACTIVEX McSubMgr.IsAppExpired ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>19265</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3961</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IsOldAppInstalled&quot;; fast_pattern:only; nocase; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22IsOldAppInstalled\x22|\x27IsOldAppInstalled\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22IsOldAppInstalled\x22|\x27IsOldAppInstalled\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7863</id>
        <msg>WEB-ACTIVEX McSubMgr.IsOldAppInstalled ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>19265</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3961</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9be8d7b2-329c-442a-a4ac-aba9d7572602&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9be8d7b2-329c-442a-a4ac-aba9d7572602/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7864</id>
        <msg>WEB-ACTIVEX McSubMgr ActiveX CLSID access</msg>
      </rule>
      <rule>
        <bugtraq>19265</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3961</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|b|00|e|00|8|00|d|00|7|00|b|00|2|00|-|00|3|00|2|00|9|00|c|00|-|00|4|00|4|00|2|00|a|00|-|00|a|00|4|00|a|00|c|00|-|00|a|00|b|00|a|00|9|00|d|00|7|00|5|00|7|00|2|00|6|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x00b\x00e\x008\x00d\x007\x00b\x002\x00-\x003\x002\x009\x00c\x00-\x004\x004\x002\x00a\x00-\x00a\x004\x00a\x00c\x00-\x00a\x00b\x00a\x009\x00d\x007\x005\x007\x002\x006\x000\x002\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7865</id>
        <msg>WEB-ACTIVEX McSubMgr ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00000514-0000-0010-8000-00AA006D2EA4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*00000514-0000-0010-8000-00AA006D2EA4\s*}?\4.*\3\.(Execute)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00000514-0000-0010-8000-00AA006D2EA4\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(Execute)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7866</id>
        <msg>WEB-ACTIVEX ADODB.Connection ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-009.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|0|00|0|00|5|00|1|00|4|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|1|00|0|00|-|00|8|00|0|00|0|00|0|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|D|00|2|00|E|00|A|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x000\x000\x005\x001\x004\x00-\x000\x000\x000\x000\x00-\x000\x000\x001\x000\x00-\x008\x000\x000\x000\x00-\x000\x000\x00A\x00A\x000\x000\x006\x00D\x002\x00E\x00A\x004\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7867</id>
        <msg>WEB-ACTIVEX ADODB.Connection ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-009.mspx</url>
      </rule>
      <rule>
        <bugtraq>20704</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00000535-0000-0010-8000-00AA006D2EA4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*00000535-0000-0010-8000-00AA006D2EA4/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7868</id>
        <msg>WEB-ACTIVEX ADODB.Recordset ActiveX CLSID access</msg>
      </rule>
      <rule>
        <bugtraq>20704</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|0|00|0|00|5|00|3|00|5|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|1|00|0|00|-|00|8|00|0|00|0|00|0|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|D|00|2|00|E|00|A|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x000\x000\x000\x000\x005\x003\x005\x00-\x000\x000\x000\x000\x00-\x000\x000\x001\x000\x00-\x008\x000\x000\x000\x00-\x000\x000\x00A\x00A\x000\x000\x006\x00D\x002\x00E\x00A\x004\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7869</id>
        <msg>WEB-ACTIVEX ADODB.Recordset ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;03F998B2-0E00-11D3-A498-00104B6EB52E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*03F998B2-0E00-11D3-A498-00104B6EB52E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7878</id>
        <msg>WEB-ACTIVEX AxMetaStream.MetaStreamCtl ActiveX CLSID access</msg>
        <url>vil.nai.com/vil/content/v_137262.htm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|3|00|F|00|9|00|9|00|8|00|B|00|2|00|-|00|0|00|E|00|0|00|0|00|-|00|1|00|1|00|D|00|3|00|-|00|A|00|4|00|9|00|8|00|-|00|0|00|0|00|1|00|0|00|4|00|B|00|6|00|E|00|B|00|5|00|2|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x003\x00F\x009\x009\x008\x00B\x002\x00-\x000\x00E\x000\x000\x00-\x001\x001\x00D\x003\x00-\x00A\x004\x009\x008\x00-\x000\x000\x001\x000\x004\x00B\x006\x00E\x00B\x005\x002\x00E\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7879</id>
        <msg>WEB-ACTIVEX AxMetaStream.MetaStreamCtl ActiveX CLSID unicode access</msg>
        <url>vil.nai.com/vil/content/v_137262.htm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1B00725B-C455-4DE6-BFB6-AD540AD427CD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1B00725B-C455-4DE6-BFB6-AD540AD427CD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7880</id>
        <msg>WEB-ACTIVEX AxMetaStream.MetaStreamCtlSecondary ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|B|00|0|00|0|00|7|00|2|00|5|00|B|00|-|00|C|00|4|00|5|00|5|00|-|00|4|00|D|00|E|00|6|00|-|00|B|00|F|00|B|00|6|00|-|00|A|00|D|00|5|00|4|00|0|00|A|00|D|00|4|00|2|00|7|00|C|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x00B\x000\x000\x007\x002\x005\x00B\x00-\x00C\x004\x005\x005\x00-\x004\x00D\x00E\x006\x00-\x00B\x00F\x00B\x006\x00-\x00A\x00D\x005\x004\x000\x00A\x00D\x004\x002\x007\x00C\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7881</id>
        <msg>WEB-ACTIVEX AxMetaStream.MetaStreamCtlSecondary ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;68A499C7-F9B0-11D2-93D4-00A0C981B035&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*68A499C7-F9B0-11D2-93D4-00A0C981B035/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7882</id>
        <msg>WEB-ACTIVEX AccSync.AccSubNotHandler ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|A|00|4|00|9|00|9|00|C|00|7|00|-|00|F|00|9|00|B|00|0|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|3|00|D|00|4|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|8|00|1|00|B|00|0|00|3|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x008\x00A\x004\x009\x009\x00C\x007\x00-\x00F\x009\x00B\x000\x00-\x001\x001\x00D\x002\x00-\x009\x003\x00D\x004\x00-\x000\x000\x00A\x000\x00C\x009\x008\x001\x00B\x000\x003\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7883</id>
        <msg>WEB-ACTIVEX AccSync.AccSubNotHandler ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A8ABE123-FAC4-41C1-ABA3-051B6F112B83&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A8ABE123-FAC4-41C1-ABA3-051B6F112B83/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7884</id>
        <msg>WEB-ACTIVEX AolCalSvr.ACCalendarListCtrl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|8|00|A|00|B|00|E|00|1|00|2|00|3|00|-|00|F|00|A|00|C|00|4|00|-|00|4|00|1|00|C|00|1|00|-|00|A|00|B|00|A|00|3|00|-|00|0|00|5|00|1|00|B|00|6|00|F|00|1|00|1|00|2|00|B|00|8|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x008\x00A\x00B\x00E\x001\x002\x003\x00-\x00F\x00A\x00C\x004\x00-\x004\x001\x00C\x001\x00-\x00A\x00B\x00A\x003\x00-\x000\x005\x001\x00B\x006\x00F\x001\x001\x002\x00B\x008\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7885</id>
        <msg>WEB-ACTIVEX AolCalSvr.ACCalendarListCtrl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9F62797E-1249-4596-9FF7-AC6D851A542A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9F62797E-1249-4596-9FF7-AC6D851A542A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7886</id>
        <msg>WEB-ACTIVEX AolCalSvr.ACDictionary ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|F|00|6|00|2|00|7|00|9|00|7|00|E|00|-|00|1|00|2|00|4|00|9|00|-|00|4|00|5|00|9|00|6|00|-|00|9|00|F|00|F|00|7|00|-|00|A|00|C|00|6|00|D|00|8|00|5|00|1|00|A|00|5|00|4|00|2|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x00F\x006\x002\x007\x009\x007\x00E\x00-\x001\x002\x004\x009\x00-\x004\x005\x009\x006\x00-\x009\x00F\x00F\x007\x00-\x00A\x00C\x006\x00D\x008\x005\x001\x00A\x005\x004\x002\x00A\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7887</id>
        <msg>WEB-ACTIVEX AolCalSvr.ACDictionary ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18477169-4752-41DC-AB0F-C50EBA75641D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*18477169-4752-41DC-AB0F-C50EBA75641D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7890</id>
        <msg>WEB-ACTIVEX AOL.MemExpWz ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|4|00|7|00|7|00|1|00|6|00|9|00|-|00|4|00|7|00|5|00|2|00|-|00|4|00|1|00|D|00|C|00|-|00|A|00|B|00|0|00|F|00|-|00|C|00|5|00|0|00|E|00|B|00|A|00|7|00|5|00|6|00|4|00|1|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x008\x004\x007\x007\x001\x006\x009\x00-\x004\x007\x005\x002\x00-\x004\x001\x00D\x00C\x00-\x00A\x00B\x000\x00F\x00-\x00C\x005\x000\x00E\x00B\x00A\x007\x005\x006\x004\x001\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7891</id>
        <msg>WEB-ACTIVEX AOL.MemExpWz ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D9F99C6B-A3A6-11D4-AF64-444553546170&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D9F99C6B-A3A6-11D4-AF64-444553546170/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7892</id>
        <msg>WEB-ACTIVEX AOL Phobos Class ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|F|00|9|00|9|00|C|00|6|00|B|00|-|00|A|00|3|00|A|00|6|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|F|00|6|00|4|00|-|00|4|00|4|00|4|00|5|00|5|00|3|00|5|00|4|00|6|00|1|00|7|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x009\x00F\x009\x009\x00C\x006\x00B\x00-\x00A\x003\x00A\x006\x00-\x001\x001\x00D\x004\x00-\x00A\x00F\x006\x004\x00-\x004\x004\x004\x005\x005\x003\x005\x004\x006\x001\x007\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7893</id>
        <msg>WEB-ACTIVEX AOL Phobos Class ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D670D0B3-05AB-4115-9F87-D983EF1AC747&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D670D0B3-05AB-4115-9F87-D983EF1AC747/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7894</id>
        <msg>WEB-ACTIVEX AOL.PicDownloadCtrl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|6|00|7|00|0|00|D|00|0|00|B|00|3|00|-|00|0|00|5|00|A|00|B|00|-|00|4|00|1|00|1|00|5|00|-|00|9|00|F|00|8|00|7|00|-|00|D|00|9|00|8|00|3|00|E|00|F|00|1|00|A|00|C|00|7|00|4|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x006\x007\x000\x00D\x000\x00B\x003\x00-\x000\x005\x00A\x00B\x00-\x004\x001\x001\x005\x00-\x009\x00F\x008\x007\x00-\x00D\x009\x008\x003\x00E\x00F\x001\x00A\x00C\x007\x004\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7895</id>
        <msg>WEB-ACTIVEX AOL.PicDownloadCtrl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E0CB08CE-AB3D-4779-9C77-62A439BFE6C3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E0CB08CE-AB3D-4779-9C77-62A439BFE6C3/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7896</id>
        <msg>WEB-ACTIVEX AOL.PicEditCtrl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|0|00|C|00|B|00|0|00|8|00|C|00|E|00|-|00|A|00|B|00|3|00|D|00|-|00|4|00|7|00|7|00|9|00|-|00|9|00|C|00|7|00|7|00|-|00|6|00|2|00|A|00|4|00|3|00|9|00|B|00|F|00|E|00|6|00|C|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x000\x00C\x00B\x000\x008\x00C\x00E\x00-\x00A\x00B\x003\x00D\x00-\x004\x007\x007\x009\x00-\x009\x00C\x007\x007\x00-\x006\x002\x00A\x004\x003\x009\x00B\x00F\x00E\x006\x00C\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7897</id>
        <msg>WEB-ACTIVEX AOL.PicEditCtrl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7898</id>
        <msg>WEB-ACTIVEX AOL.PicSsvrCtrl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|1|00|B|00|0|00|9|00|0|00|6|00|6|00|-|00|C|00|9|00|5|00|C|00|-|00|4|00|E|00|F|00|6|00|-|00|8|00|D|00|F|00|D|00|-|00|3|00|D|00|D|00|0|00|A|00|F|00|E|00|6|00|1|00|0|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x001\x00B\x000\x009\x000\x006\x006\x00-\x00C\x009\x005\x00C\x00-\x004\x00E\x00F\x006\x00-\x008\x00D\x00F\x00D\x00-\x003\x00D\x00D\x000\x00A\x00F\x00E\x006\x001\x000\x00B\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7899</id>
        <msg>WEB-ACTIVEX AOL.PicSsvrCtrl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;98BFD494-F6AD-4794-9038-832C0654CC43&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*98BFD494-F6AD-4794-9038-832C0654CC43/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7900</id>
        <msg>WEB-ACTIVEX AOL.UPFCtrl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|8|00|B|00|F|00|D|00|4|00|9|00|4|00|-|00|F|00|6|00|A|00|D|00|-|00|4|00|7|00|9|00|4|00|-|00|9|00|0|00|3|00|8|00|-|00|8|00|3|00|2|00|C|00|0|00|6|00|5|00|4|00|C|00|C|00|4|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x008\x00B\x00F\x00D\x004\x009\x004\x00-\x00F\x006\x00A\x00D\x00-\x004\x007\x009\x004\x00-\x009\x000\x003\x008\x00-\x008\x003\x002\x00C\x000\x006\x005\x004\x00C\x00C\x004\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7901</id>
        <msg>WEB-ACTIVEX AOL.UPFCtrl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3134</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;229B78D5-38F5-11D5-9001-00C04F4C3B9F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*229B78D5-38F5-11D5-9001-00C04F4C3B9F\s*}?\s*(?P=q9)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7902</id>
        <msg>WEB-ACTIVEX CDDBControlAOL.CDDBAOLControl ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <bugtraq>23567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3134</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|9|00|B|00|7|00|8|00|D|00|5|00|-|00|3|00|8|00|F|00|5|00|-|00|1|00|1|00|D|00|5|00|-|00|9|00|0|00|0|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|4|00|C|00|3|00|B|00|9|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q10&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7903</id>
        <msg>WEB-ACTIVEX CDDBControlAOL.CDDBAOLControl ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/701121</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3DD53D40-7B8B-11D0-B013-00AA0059CE02&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3DD53D40-7B8B-11D0-B013-00AA0059CE02\s*}?\s*(?P=q13)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7904</id>
        <msg>WEB-ACTIVEX CDL Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|D|00|D|00|5|00|3|00|D|00|4|00|0|00|-|00|7|00|B|00|8|00|B|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|0|00|1|00|3|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|9|00|C|00|E|00|0|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q14&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7905</id>
        <msg>WEB-ACTIVEX CDL Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CD00020C-8B95-11D1-82DB-00C04FB1625D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CD00020C-8B95-11D1-82DB-00C04FB1625D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7906</id>
        <msg>WEB-ACTIVEX CDO.KnowledgeSearchFolder ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|D|00|0|00|0|00|0|00|2|00|0|00|C|00|-|00|8|00|B|00|9|00|5|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|2|00|D|00|B|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|B|00|1|00|6|00|2|00|5|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x00D\x000\x000\x000\x002\x000\x00C\x00-\x008\x00B\x009\x005\x00-\x001\x001\x00D\x001\x00-\x008\x002\x00D\x00B\x00-\x000\x000\x00C\x000\x004\x00F\x00B\x001\x006\x002\x005\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7907</id>
        <msg>WEB-ACTIVEX CDO.KnowledgeSearchFolder ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24188</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;421516C1-3CF8-11D2-952A-00C04FA34F05&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*421516C1-3CF8-11D2-952A-00C04FA34F05\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7908</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX clsid access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <bugtraq>24188</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|1|00|5|00|1|00|6|00|C|00|1|00|-|00|3|00|C|00|F|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|5|00|2|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|F|00|0|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7909</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX clsid unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ADC6CB86-424C-11D2-952A-00C04FA34F05&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ADC6CB86-424C-11D2-952A-00C04FA34F05/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7910</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.DropShadow ActiveX CLSID access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|D|00|C|00|6|00|C|00|B|00|8|00|6|00|-|00|4|00|2|00|4|00|C|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|5|00|2|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|F|00|0|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x00D\x00C\x006\x00C\x00B\x008\x006\x00-\x004\x002\x004\x00C\x00-\x001\x001\x00D\x002\x00-\x009\x005\x002\x00A\x00-\x000\x000\x00C\x000\x004\x00F\x00A\x003\x004\x00F\x000\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7911</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.DropShadow ActiveX CLSID unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8241F015-84D3-11d2-97E6-0000F803FF7A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8241F015-84D3-11d2-97E6-0000F803FF7A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7912</id>
        <msg>WEB-ACTIVEX DX3DTransform.Microsoft.Shapes ActiveX CLSID access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|2|00|4|00|1|00|F|00|0|00|1|00|5|00|-|00|8|00|4|00|D|00|3|00|-|00|1|00|1|00|d|00|2|00|-|00|9|00|7|00|E|00|6|00|-|00|0|00|0|00|0|00|0|00|F|00|8|00|0|00|3|00|F|00|F|00|7|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x002\x004\x001\x00F\x000\x001\x005\x00-\x008\x004\x00D\x003\x00-\x001\x001\x00d\x002\x00-\x009\x007\x00E\x006\x00-\x000\x000\x000\x000\x00F\x008\x000\x003\x00F\x00F\x007\x00A\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7913</id>
        <msg>WEB-ACTIVEX DX3DTransform.Microsoft.Shapes ActiveX CLSID unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <bugtraq>19340</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E673DCF2-C316-4C6F-AA96-4E4DC6DC291E&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E673DCF2-C316-4C6F-AA96-4E4DC6DC291E/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7914</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <bugtraq>19340</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|6|00|7|00|3|00|D|00|C|00|F|00|2|00|-|00|C|00|3|00|1|00|6|00|-|00|4|00|C|00|6|00|F|00|-|00|A|00|A|00|9|00|6|00|-|00|4|00|E|00|4|00|D|00|C|00|6|00|D|00|C|00|2|00|9|00|1|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x006\x007\x003\x00D\x00C\x00F\x002\x00-\x00C\x003\x001\x006\x00-\x004\x00C\x006\x00F\x00-\x00A\x00A\x009\x006\x00-\x004\x00E\x004\x00D\x00C\x006\x00D\x00C\x002\x009\x001\x00E\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7915</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FD853CD9-7F86-11D0-8252-00C04FD85AB4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FD853CD9-7F86-11D0-8252-00C04FD85AB4/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7916</id>
        <msg>WEB-ACTIVEX CLSID_IMimeInternational ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|8|00|5|00|3|00|C|00|D|00|9|00|-|00|7|00|F|00|8|00|6|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|2|00|5|00|2|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|8|00|5|00|A|00|B|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x00D\x008\x005\x003\x00C\x00D\x009\x00-\x007\x00F\x008\x006\x00-\x001\x001\x00D\x000\x00-\x008\x002\x005\x002\x00-\x000\x000\x00C\x000\x004\x00F\x00D\x008\x005\x00A\x00B\x004\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7917</id>
        <msg>WEB-ACTIVEX CLSID_IMimeInternational ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1853E19A-4E54-4190-8DEB-2E1CC947CD60&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*1853E19A-4E54-4190-8DEB-2E1CC947CD60/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7918</id>
        <msg>WEB-ACTIVEX CoAxTrackVideo Class ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|5|00|3|00|E|00|1|00|9|00|A|00|-|00|4|00|E|00|5|00|4|00|-|00|4|00|1|00|9|00|0|00|-|00|8|00|D|00|E|00|B|00|-|00|2|00|E|00|1|00|C|00|C|00|9|00|4|00|7|00|C|00|D|00|6|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x008\x005\x003\x00E\x001\x009\x00A\x00-\x004\x00E\x005\x004\x00-\x004\x001\x009\x000\x00-\x008\x00D\x00E\x00B\x00-\x002\x00E\x001\x00C\x00C\x009\x004\x007\x00C\x00D\x006\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7919</id>
        <msg>WEB-ACTIVEX CoAxTrackVideo Class ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F2C3FAAE-C8AC-11D0-BCDB-00C04FD8D5B6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F2C3FAAE-C8AC-11D0-BCDB-00C04FD8D5B6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7920</id>
        <msg>WEB-ACTIVEX DsPropertyPages.OU ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|2|00|C|00|3|00|F|00|A|00|A|00|E|00|-|00|C|00|8|00|A|00|C|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|C|00|D|00|B|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|8|00|D|00|5|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x002\x00C\x003\x00F\x00A\x00A\x00E\x00-\x00C\x008\x00A\x00C\x00-\x001\x001\x00D\x000\x00-\x00B\x00C\x00D\x00B\x00-\x000\x000\x00C\x000\x004\x00F\x00D\x008\x00D\x005\x00B\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7921</id>
        <msg>WEB-ACTIVEX DsPropertyPages.OU ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E31E87C4-86EA-4940-9B8A-5BD5D179A737&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E31E87C4-86EA-4940-9B8A-5BD5D179A737/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7922</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX CLSID access</msg>
        <url>osvdb.org/27057</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|3|00|1|00|E|00|8|00|7|00|C|00|4|00|-|00|8|00|6|00|E|00|A|00|-|00|4|00|9|00|4|00|0|00|-|00|9|00|B|00|8|00|A|00|-|00|5|00|B|00|D|00|5|00|D|00|1|00|7|00|9|00|A|00|7|00|3|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x003\x001\x00E\x008\x007\x00C\x004\x00-\x008\x006\x00E\x00A\x00-\x004\x009\x004\x000\x00-\x009\x00B\x008\x00A\x00-\x005\x00B\x00D\x005\x00D\x001\x007\x009\x00A\x007\x003\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7923</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX CLSID unicode access</msg>
        <url>osvdb.org/27057</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E71B4063-3E59-11D2-952A-00C04FA34F05&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E71B4063-3E59-11D2-952A-00C04FA34F05/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7924</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Shadow ActiveX CLSID access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|7|00|1|00|B|00|4|00|0|00|6|00|3|00|-|00|3|00|E|00|5|00|9|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|5|00|2|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|F|00|0|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x007\x001\x00B\x004\x000\x006\x003\x00-\x003\x00E\x005\x009\x00-\x001\x001\x00D\x002\x00-\x009\x005\x002\x00A\x00-\x000\x000\x00C\x000\x004\x00F\x00A\x003\x004\x00F\x000\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7925</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Shadow ActiveX CLSID unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7926</id>
        <msg>WEB-ACTIVEX DXTFilter ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|8|00|5|00|A|00|9|00|1|00|B|00|C|00|-|00|1|00|E|00|8|00|A|00|-|00|4|00|E|00|4|00|A|00|-|00|A|00|7|00|A|00|6|00|-|00|F|00|4|00|F|00|C|00|1|00|E|00|6|00|C|00|A|00|1|00|B|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x008\x005\x00A\x009\x001\x00B\x00C\x00-\x001\x00E\x008\x00A\x00-\x004\x00E\x004\x00A\x00-\x00A\x007\x00A\x006\x00-\x00F\x004\x00F\x00C\x001\x00E\x006\x00C\x00A\x001\x00B\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7927</id>
        <msg>WEB-ACTIVEX DXTFilter ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E7-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E7-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q11)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7928</id>
        <msg>WEB-ACTIVEX file or local Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|7|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q12&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q12)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7929</id>
        <msg>WEB-ACTIVEX file or local Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FEF10FA2-355E-4E06-9381-9B24D7F7CC88&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FEF10FA2-355E-4E06-9381-9B24D7F7CC88/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7930</id>
        <msg>WEB-ACTIVEX FolderItem2 ActiveX CLSID access</msg>
        <url>browserfun.blogspot.com/2006/07/mobb-15-folderitem-access.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|E|00|F|00|1|00|0|00|F|00|A|00|2|00|-|00|3|00|5|00|5|00|E|00|-|00|4|00|E|00|0|00|6|00|-|00|9|00|3|00|8|00|1|00|-|00|9|00|B|00|2|00|4|00|D|00|7|00|F|00|7|00|C|00|C|00|8|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x00E\x00F\x001\x000\x00F\x00A\x002\x00-\x003\x005\x005\x00E\x00-\x004\x00E\x000\x006\x00-\x009\x003\x008\x001\x00-\x009\x00B\x002\x004\x00D\x007\x00F\x007\x00C\x00C\x008\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7931</id>
        <msg>WEB-ACTIVEX FolderItem2 ActiveX CLSID unicode access</msg>
        <url>browserfun.blogspot.com/2006/07/mobb-15-folderitem-access.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;53C74826-AB99-4D33-ACA4-3117F51D3788&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*53C74826-AB99-4D33-ACA4-3117F51D3788/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7932</id>
        <msg>WEB-ACTIVEX FolderItems3 ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|3|00|C|00|7|00|4|00|8|00|2|00|6|00|-|00|A|00|B|00|9|00|9|00|-|00|4|00|D|00|3|00|3|00|-|00|A|00|C|00|A|00|4|00|-|00|3|00|1|00|1|00|7|00|F|00|5|00|1|00|D|00|3|00|7|00|8|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x003\x00C\x007\x004\x008\x002\x006\x00-\x00A\x00B\x009\x009\x00-\x004\x00D\x003\x003\x00-\x00A\x00C\x00A\x004\x00-\x003\x001\x001\x007\x00F\x005\x001\x00D\x003\x007\x008\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7933</id>
        <msg>WEB-ACTIVEX FolderItems3 ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9F8E6421-3D9B-11D2-952A-00C04FA34F05&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9F8E6421-3D9B-11D2-952A-00C04FA34F05/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7936</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Glow ActiveX CLSID access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|F|00|8|00|E|00|6|00|4|00|2|00|1|00|-|00|3|00|D|00|9|00|B|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|5|00|2|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|F|00|0|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x00F\x008\x00E\x006\x004\x002\x001\x00-\x003\x00D\x009\x00B\x00-\x001\x001\x00D\x002\x00-\x009\x005\x002\x00A\x00-\x000\x000\x00C\x000\x004\x00F\x00A\x003\x004\x00F\x000\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7937</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Glow ActiveX CLSID unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E4-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E4-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q5)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7938</id>
        <msg>WEB-ACTIVEX gopher Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|4|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7939</id>
        <msg>WEB-ACTIVEX gopher Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;623E2882-FC0E-11D1-9A77-0000F8756A10&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*623E2882-FC0E-11D1-9A77-0000F8756A10/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7940</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX CLSID access</msg>
        <url>osvdb.org/27109</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|2|00|3|00|E|00|2|00|8|00|8|00|2|00|-|00|F|00|C|00|0|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|A|00|7|00|7|00|-|00|0|00|0|00|0|00|0|00|F|00|8|00|7|00|5|00|6|00|A|00|1|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x002\x003\x00E\x002\x008\x008\x002\x00-\x00F\x00C\x000\x00E\x00-\x001\x001\x00D\x001\x00-\x009\x00A\x007\x007\x00-\x000\x000\x000\x000\x00F\x008\x007\x005\x006\x00A\x001\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7941</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX CLSID unicode access</msg>
        <url>osvdb.org/27109</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E2-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E2-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7942</id>
        <msg>WEB-ACTIVEX http Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|2|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7943</id>
        <msg>WEB-ACTIVEX http Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E5-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E5-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q7)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7944</id>
        <msg>WEB-ACTIVEX https Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|5|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7945</id>
        <msg>WEB-ACTIVEX https Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3A04D93B-1EDD-4F3F-A375-A03EC19572C4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3A04D93B-1EDD-4F3F-A375-A03EC19572C4/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7946</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MaskFilter ActiveX CLSID access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|A|00|0|00|4|00|D|00|9|00|3|00|B|00|-|00|1|00|E|00|D|00|D|00|-|00|4|00|F|00|3|00|F|00|-|00|A|00|3|00|7|00|5|00|-|00|A|00|0|00|3|00|E|00|C|00|1|00|9|00|5|00|7|00|2|00|C|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x00A\x000\x004\x00D\x009\x003\x00B\x00-\x001\x00E\x00D\x00D\x00-\x004\x00F\x003\x00F\x00-\x00A\x003\x007\x005\x00-\x00A\x000\x003\x00E\x00C\x001\x009\x005\x007\x002\x00C\x004\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7947</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.MaskFilter ActiveX CLSID unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF604EFE-8897-11D1-B944-00A0C90312E1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*AF604EFE-8897-11D1-B944-00A0C90312E1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7948</id>
        <msg>WEB-ACTIVEX Microsoft Common Browser Architecture ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|6|00|0|00|4|00|E|00|F|00|E|00|-|00|8|00|8|00|9|00|7|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|9|00|4|00|4|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|3|00|1|00|2|00|E|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x00F\x006\x000\x004\x00E\x00F\x00E\x00-\x008\x008\x009\x007\x00-\x001\x001\x00D\x001\x00-\x00B\x009\x004\x004\x00-\x000\x000\x00A\x000\x00C\x009\x000\x003\x001\x002\x00E\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7949</id>
        <msg>WEB-ACTIVEX Microsoft Common Browser Architecture ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B6FFC24C-7E13-11D0-9B47-00C04FC2F51D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B6FFC24C-7E13-11D0-9B47-00C04FC2F51D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7950</id>
        <msg>WEB-ACTIVEX Microsoft DirectAnimation Control ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|6|00|F|00|F|00|C|00|2|00|4|00|C|00|-|00|7|00|E|00|1|00|3|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|B|00|4|00|7|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|F|00|5|00|1|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x006\x00F\x00F\x00C\x002\x004\x00C\x00-\x007\x00E\x001\x003\x00-\x001\x001\x00D\x000\x00-\x009\x00B\x004\x007\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00F\x005\x001\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7951</id>
        <msg>WEB-ACTIVEX Microsoft DirectAnimation Control ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;69AD90EF-1C20-11D1-8801-00C04FC29D46&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*69AD90EF-1C20-11D1-8801-00C04FC29D46/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7952</id>
        <msg>WEB-ACTIVEX Microsoft DirectAnimation Windowed Control ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|9|00|A|00|D|00|9|00|0|00|E|00|F|00|-|00|1|00|C|00|2|00|0|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|8|00|0|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|9|00|D|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x009\x00A\x00D\x009\x000\x00E\x00F\x00-\x001\x00C\x002\x000\x00-\x001\x001\x00D\x001\x00-\x008\x008\x000\x001\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x009\x00D\x004\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7953</id>
        <msg>WEB-ACTIVEX Microsoft DirectAnimation Windowed Control ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>1999-0384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8BD21D30-EC42-11CE-9E0D-00AA006002F3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8BD21D30-EC42-11CE-9E0D-00AA006002F3/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7954</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ComboBox ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms99-001.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>1999-0384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|B|00|D|00|2|00|1|00|D|00|3|00|0|00|-|00|E|00|C|00|4|00|2|00|-|00|1|00|1|00|C|00|E|00|-|00|9|00|E|00|0|00|D|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|0|00|0|00|2|00|F|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x00B\x00D\x002\x001\x00D\x003\x000\x00-\x00E\x00C\x004\x002\x00-\x001\x001\x00C\x00E\x00-\x009\x00E\x000\x00D\x00-\x000\x000\x00A\x00A\x000\x000\x006\x000\x000\x002\x00F\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7955</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ComboBox ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms99-001.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8BD21D20-EC42-11CE-9E0D-00AA006002F3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8BD21D20-EC42-11CE-9E0D-00AA006002F3/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7956</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX CLSID access</msg>
        <url>osvdb.org/27372</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|B|00|D|00|2|00|1|00|D|00|2|00|0|00|-|00|E|00|C|00|4|00|2|00|-|00|1|00|1|00|C|00|E|00|-|00|9|00|E|00|0|00|D|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|0|00|0|00|2|00|F|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x00B\x00D\x002\x001\x00D\x002\x000\x00-\x00E\x00C\x004\x002\x00-\x001\x001\x00C\x00E\x00-\x009\x00E\x000\x00D\x00-\x000\x000\x00A\x00A\x000\x000\x006\x000\x000\x002\x00F\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7957</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX CLSID unicode access</msg>
        <url>osvdb.org/27372</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E6-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E6-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q9)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7958</id>
        <msg>WEB-ACTIVEX mk Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|6|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q10&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7959</id>
        <msg>WEB-ACTIVEX mk Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7849596A-48EA-486E-8937-A2A3009F31A9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7849596A-48EA-486E-8937-A2A3009F31A9/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7970</id>
        <msg>WEB-ACTIVEX PostBootReminder object ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|8|00|4|00|9|00|5|00|9|00|6|00|A|00|-|00|4|00|8|00|E|00|A|00|-|00|4|00|8|00|6|00|E|00|-|00|8|00|9|00|3|00|7|00|-|00|A|00|2|00|A|00|3|00|0|00|0|00|9|00|F|00|3|00|1|00|A|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*7\x008\x004\x009\x005\x009\x006\x00A\x00-\x004\x008\x00E\x00A\x00-\x004\x008\x006\x00E\x00-\x008\x009\x003\x007\x00-\x00A\x002\x00A\x003\x000\x000\x009\x00F\x003\x001\x00A\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7971</id>
        <msg>WEB-ACTIVEX PostBootReminder object ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F1029E5B-CB5B-11D0-8D59-00C04FD91AC0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F1029E5B-CB5B-11D0-8D59-00C04FD91AC0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7974</id>
        <msg>WEB-ACTIVEX Rendezvous Class ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|1|00|0|00|2|00|9|00|E|00|5|00|B|00|-|00|C|00|B|00|5|00|B|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|D|00|5|00|9|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|9|00|1|00|A|00|C|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x001\x000\x002\x009\x00E\x005\x00B\x00-\x00C\x00B\x005\x00B\x00-\x001\x001\x00D\x000\x00-\x008\x00D\x005\x009\x00-\x000\x000\x00C\x000\x004\x00F\x00D\x009\x001\x00A\x00C\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7975</id>
        <msg>WEB-ACTIVEX Rendezvous Class ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FBEB8A05-BEEE-4442-804E-409D6C4515E9&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FBEB8A05-BEEE-4442-804E-409D6C4515E9/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7976</id>
        <msg>WEB-ACTIVEX ShellFolder for CD Burning ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|B|00|E|00|B|00|8|00|A|00|0|00|5|00|-|00|B|00|E|00|E|00|E|00|-|00|4|00|4|00|4|00|2|00|-|00|8|00|0|00|4|00|E|00|-|00|4|00|0|00|9|00|D|00|6|00|C|00|4|00|5|00|1|00|5|00|E|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x00B\x00E\x00B\x008\x00A\x000\x005\x00-\x00B\x00E\x00E\x00E\x00-\x004\x004\x004\x002\x00-\x008\x000\x004\x00E\x00-\x004\x000\x009\x00D\x006\x00C\x004\x005\x001\x005\x00E\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7977</id>
        <msg>WEB-ACTIVEX ShellFolder for CD Burning ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F2175210-368C-11D0-AD81-00A0C90DC8D9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F2175210-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapshotPath|CompressedPath)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F2175210-368C-11D0-AD81-00A0C90DC8D9\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(SnapshotPath|CompressedPath))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>7981</id>
        <msg>WEB-ACTIVEX Snapshot Viewer General Property Page Object ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|2|00|1|00|7|00|5|00|2|00|1|00|0|00|-|00|3|00|6|00|8|00|C|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|D|00|8|00|1|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|D|00|C|00|8|00|D|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>7982</id>
        <msg>WEB-ACTIVEX Snapshot Viewer General Property Page Object ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;189504B8-50D1-4AA8-B4D6-95C8F58A6414&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*189504B8-50D1-4AA8-B4D6-95C8F58A6414/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7983</id>
        <msg>WEB-ACTIVEX SuperBuddy Class ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|9|00|5|00|0|00|4|00|B|00|8|00|-|00|5|00|0|00|D|00|1|00|-|00|4|00|A|00|A|00|8|00|-|00|B|00|4|00|D|00|6|00|-|00|9|00|5|00|C|00|8|00|F|00|5|00|8|00|A|00|6|00|4|00|1|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x008\x009\x005\x000\x004\x00B\x008\x00-\x005\x000\x00D\x001\x00-\x004\x00A\x00A\x008\x00-\x00B\x004\x00D\x006\x00-\x009\x005\x00C\x008\x00F\x005\x008\x00A\x006\x004\x001\x004\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7984</id>
        <msg>WEB-ACTIVEX SuperBuddy Class ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>19030</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3730</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E5DF9D10-3B52-11D1-83E8-00A0C90DC849&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7985</id>
        <msg>WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>19030</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3730</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|5|00|D|00|F|00|9|00|D|00|1|00|0|00|-|00|3|00|B|00|5|00|2|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|3|00|E|00|8|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|D|00|C|00|8|00|4|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x005\x00D\x00F\x009\x00D\x001\x000\x00-\x003\x00B\x005\x002\x00-\x001\x001\x00D\x001\x00-\x008\x003\x00E\x008\x00-\x000\x000\x00A\x000\x00C\x009\x000\x00D\x00C\x008\x004\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7986</id>
        <msg>WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-057.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;844F4806-E8A8-11D2-9652-00C04FC30871&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*844F4806-E8A8-11D2-9652-00C04FC30871/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7987</id>
        <msg>WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.2 ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|4|00|4|00|F|00|4|00|8|00|0|00|6|00|-|00|E|00|8|00|A|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|6|00|5|00|2|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|3|00|0|00|8|00|7|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x004\x004\x00F\x004\x008\x000\x006\x00-\x00E\x008\x00A\x008\x00-\x001\x001\x00D\x002\x00-\x009\x006\x005\x002\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x003\x000\x008\x007\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7988</id>
        <msg>WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.2 ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D2923B86-15F1-46FF-A19A-DE825F919576&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D2923B86-15F1-46FF-A19A-DE825F919576/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7989</id>
        <msg>WEB-ACTIVEX WIA FileSystem USD ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|2|00|9|00|2|00|3|00|B|00|8|00|6|00|-|00|1|00|5|00|F|00|1|00|-|00|4|00|6|00|F|00|F|00|-|00|A|00|1|00|9|00|A|00|-|00|D|00|E|00|8|00|2|00|5|00|F|00|9|00|1|00|9|00|5|00|7|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x002\x009\x002\x003\x00B\x008\x006\x00-\x001\x005\x00F\x001\x00-\x004\x006\x00F\x00F\x00-\x00A\x001\x009\x00A\x00-\x00D\x00E\x008\x002\x005\x00F\x009\x001\x009\x005\x007\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7990</id>
        <msg>WEB-ACTIVEX WIA FileSystem USD ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;33D9A761-90C8-11D0-BD43-00A0C911CE86&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*33D9A761-90C8-11D0-BD43-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7991</id>
        <msg>WEB-ACTIVEX ACM Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|D|00|9|00|A|00|7|00|6|00|1|00|-|00|9|00|0|00|C|00|8|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|D|00|4|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|1|00|C|00|E|00|8|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x003\x00D\x009\x00A\x007\x006\x001\x00-\x009\x000\x00C\x008\x00-\x001\x001\x00D\x000\x00-\x00B\x00D\x004\x003\x00-\x000\x000\x00A\x000\x00C\x009\x001\x001\x00C\x00E\x008\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7992</id>
        <msg>WEB-ACTIVEX ACM Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E846F0A0-D367-11D1-8286-00A0C9231C29&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E846F0A0-D367-11D1-8286-00A0C9231C29/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7993</id>
        <msg>WEB-ACTIVEX clbcatex.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|8|00|4|00|6|00|F|00|0|00|A|00|0|00|-|00|D|00|3|00|6|00|7|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|2|00|8|00|6|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|2|00|3|00|1|00|C|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x008\x004\x006\x00F\x000\x00A\x000\x00-\x00D\x003\x006\x007\x00-\x001\x001\x00D\x001\x00-\x008\x002\x008\x006\x00-\x000\x000\x00A\x000\x00C\x009\x002\x003\x001\x00C\x002\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7994</id>
        <msg>WEB-ACTIVEX clbcatex.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B4B3AECB-DFD6-11D1-9DAA-00805F85CFE3&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B4B3AECB-DFD6-11D1-9DAA-00805F85CFE3/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7995</id>
        <msg>WEB-ACTIVEX clbcatq.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|4|00|B|00|3|00|A|00|E|00|C|00|B|00|-|00|D|00|F|00|D|00|6|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|D|00|A|00|A|00|-|00|0|00|0|00|8|00|0|00|5|00|F|00|8|00|5|00|C|00|F|00|E|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x004\x00B\x003\x00A\x00E\x00C\x00B\x00-\x00D\x00F\x00D\x006\x00-\x001\x001\x00D\x001\x00-\x009\x00D\x00A\x00A\x00-\x000\x000\x008\x000\x005\x00F\x008\x005\x00C\x00F\x00E\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7996</id>
        <msg>WEB-ACTIVEX clbcatq.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8EE42293-C315-11D0-8D6F-00A0C9A06E1F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8EE42293-C315-11D0-8D6F-00A0C9A06E1F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7997</id>
        <msg>WEB-ACTIVEX CLSID_ApprenticeICW ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|E|00|E|00|4|00|2|00|2|00|9|00|3|00|-|00|C|00|3|00|1|00|5|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|D|00|6|00|F|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|A|00|0|00|6|00|E|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x00E\x00E\x004\x002\x002\x009\x003\x00-\x00C\x003\x001\x005\x00-\x001\x001\x00D\x000\x00-\x008\x00D\x006\x00F\x00-\x000\x000\x00A\x000\x00C\x009\x00A\x000\x006\x00E\x001\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7998</id>
        <msg>WEB-ACTIVEX CLSID_ApprenticeICW ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18AB439E-FCF4-40D4-90DA-F79BAA3B0655&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*18AB439E-FCF4-40D4-90DA-F79BAA3B0655/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7999</id>
        <msg>WEB-ACTIVEX CLSID_CDIDeviceActionConfigPage ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|A|00|B|00|4|00|3|00|9|00|E|00|-|00|F|00|C|00|F|00|4|00|-|00|4|00|0|00|D|00|4|00|-|00|9|00|0|00|D|00|A|00|-|00|F|00|7|00|9|00|B|00|A|00|A|00|3|00|B|00|0|00|6|00|5|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x008\x00A\x00B\x004\x003\x009\x00E\x00-\x00F\x00C\x00F\x004\x00-\x004\x000\x00D\x004\x00-\x009\x000\x00D\x00A\x00-\x00F\x007\x009\x00B\x00A\x00A\x003\x00B\x000\x006\x005\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8000</id>
        <msg>WEB-ACTIVEX CLSID_CDIDeviceActionConfigPage ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;67DCC487-AA48-11D1-8F4F-00C04FB611C7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*67DCC487-AA48-11D1-8F4F-00C04FB611C7/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8001</id>
        <msg>WEB-ACTIVEX CommunicationManager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|D|00|C|00|C|00|4|00|8|00|7|00|-|00|A|00|A|00|4|00|8|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|F|00|4|00|F|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|B|00|6|00|1|00|1|00|C|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x007\x00D\x00C\x00C\x004\x008\x007\x00-\x00A\x00A\x004\x008\x00-\x001\x001\x00D\x001\x00-\x008\x00F\x004\x00F\x00-\x000\x000\x00C\x000\x004\x00F\x00B\x006\x001\x001\x00C\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8002</id>
        <msg>WEB-ACTIVEX CommunicationManager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;52CA3BCF-3B9B-419E-A3D6-5D28C0B0B50C&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*52CA3BCF-3B9B-419E-A3D6-5D28C0B0B50C/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8003</id>
        <msg>WEB-ACTIVEX Content.mbcontent.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|2|00|C|00|A|00|3|00|B|00|C|00|F|00|-|00|3|00|B|00|9|00|B|00|-|00|4|00|1|00|9|00|E|00|-|00|A|00|3|00|D|00|6|00|-|00|5|00|D|00|2|00|8|00|C|00|0|00|B|00|0|00|B|00|5|00|0|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x002\x00C\x00A\x003\x00B\x00C\x00F\x00-\x003\x00B\x009\x00B\x00-\x004\x001\x009\x00E\x00-\x00A\x003\x00D\x006\x00-\x005\x00D\x002\x008\x00C\x000\x00B\x000\x00B\x005\x000\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8004</id>
        <msg>WEB-ACTIVEX Content.mbcontent.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FD78D554-4C6E-11D0-970D-00A0C9191601&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FD78D554-4C6E-11D0-970D-00A0C9191601/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8005</id>
        <msg>WEB-ACTIVEX DiskManagement.Connection ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|7|00|8|00|D|00|5|00|5|00|4|00|-|00|4|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|7|00|0|00|D|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|9|00|1|00|6|00|0|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x00D\x007\x008\x00D\x005\x005\x004\x00-\x004\x00C\x006\x00E\x00-\x001\x001\x00D\x000\x00-\x009\x007\x000\x00D\x00-\x000\x000\x00A\x000\x00C\x009\x001\x009\x001\x006\x000\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8006</id>
        <msg>WEB-ACTIVEX DiskManagement.Connection ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;860D28D0-8BF4-11CE-BE59-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*860D28D0-8BF4-11CE-BE59-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8007</id>
        <msg>WEB-ACTIVEX Dutch_Dutch Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|6|00|0|00|D|00|2|00|8|00|D|00|0|00|-|00|8|00|B|00|F|00|4|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|9|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x006\x000\x00D\x002\x008\x00D\x000\x00-\x008\x00B\x00F\x004\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x009\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8008</id>
        <msg>WEB-ACTIVEX Dutch_Dutch Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D99F7670-7F1A-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D99F7670-7F1A-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8009</id>
        <msg>WEB-ACTIVEX English_UK Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|9|00|F|00|7|00|6|00|7|00|0|00|-|00|7|00|F|00|1|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x009\x009\x00F\x007\x006\x007\x000\x00-\x007\x00F\x001\x00A\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8010</id>
        <msg>WEB-ACTIVEX English_UK Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EEED4C20-7F1B-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*EEED4C20-7F1B-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8011</id>
        <msg>WEB-ACTIVEX English_US Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|E|00|E|00|D|00|4|00|C|00|2|00|0|00|-|00|7|00|F|00|1|00|B|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x00E\x00E\x00D\x004\x00C\x002\x000\x00-\x007\x00F\x001\x00B\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8012</id>
        <msg>WEB-ACTIVEX English_US Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2A6EB050-7F1C-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*2A6EB050-7F1C-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8013</id>
        <msg>WEB-ACTIVEX French_French Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|A|00|6|00|E|00|B|00|0|00|5|00|0|00|-|00|7|00|F|00|1|00|C|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*2\x00A\x006\x00E\x00B\x000\x005\x000\x00-\x007\x00F\x001\x00C\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8014</id>
        <msg>WEB-ACTIVEX French_French Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;510A4910-7F1C-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*510A4910-7F1C-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8015</id>
        <msg>WEB-ACTIVEX German_German Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|1|00|0|00|A|00|4|00|9|00|1|00|0|00|-|00|7|00|F|00|1|00|C|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x001\x000\x00A\x004\x009\x001\x000\x00-\x007\x00F\x001\x00C\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8016</id>
        <msg>WEB-ACTIVEX German_German Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;33D9A760-90C8-11D0-BD43-00A0C911CE86&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*33D9A760-90C8-11D0-BD43-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8017</id>
        <msg>WEB-ACTIVEX ICM Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|D|00|9|00|A|00|7|00|6|00|0|00|-|00|9|00|0|00|C|00|8|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|D|00|4|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|1|00|C|00|E|00|8|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x003\x00D\x009\x00A\x007\x006\x000\x00-\x009\x000\x00C\x008\x00-\x001\x001\x00D\x000\x00-\x00B\x00D\x004\x003\x00-\x000\x000\x00A\x000\x00C\x009\x001\x001\x00C\x00E\x008\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8018</id>
        <msg>WEB-ACTIVEX ICM Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C7B6C04A-CBB5-11D0-BB4C-00C04FC2F410&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C7B6C04A-CBB5-11D0-BB4C-00C04FC2F410/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8021</id>
        <msg>WEB-ACTIVEX ISSimpleCommandCreator.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|7|00|B|00|6|00|C|00|0|00|4|00|A|00|-|00|C|00|B|00|B|00|5|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|B|00|4|00|C|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|F|00|4|00|1|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x007\x00B\x006\x00C\x000\x004\x00A\x00-\x00C\x00B\x00B\x005\x00-\x001\x001\x00D\x000\x00-\x00B\x00B\x004\x00C\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00F\x004\x001\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8022</id>
        <msg>WEB-ACTIVEX ISSimpleCommandCreator.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6D36CE10-7F1C-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6D36CE10-7F1C-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8023</id>
        <msg>WEB-ACTIVEX Italian_Italian Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|D|00|3|00|6|00|C|00|E|00|1|00|0|00|-|00|7|00|F|00|1|00|C|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x00D\x003\x006\x00C\x00E\x001\x000\x00-\x007\x00F\x001\x00C\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8024</id>
        <msg>WEB-ACTIVEX Italian_Italian Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3050F391-98B5-11CF-BB82-00AA00BDCE0B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3050F391-98B5-11CF-BB82-00AA00BDCE0B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8025</id>
        <msg>WEB-ACTIVEX Microsoft HTML Window Security Proxy ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|0|00|5|00|0|00|F|00|3|00|9|00|1|00|-|00|9|00|8|00|B|00|5|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|B|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|D|00|C|00|E|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x000\x005\x000\x00F\x003\x009\x001\x00-\x009\x008\x00B\x005\x00-\x001\x001\x00C\x00F\x00-\x00B\x00B\x008\x002\x00-\x000\x000\x00A\x00A\x000\x000\x00B\x00D\x00C\x00E\x000\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8026</id>
        <msg>WEB-ACTIVEX Microsoft HTML Window Security Proxy ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5D08B586-343A-11D0-AD46-00C04FD8FDFF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*5D08B586-343A-11D0-AD46-00C04FD8FDFF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8027</id>
        <msg>WEB-ACTIVEX Microsoft WBEM Event Subsystem ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|D|00|0|00|8|00|B|00|5|00|8|00|6|00|-|00|3|00|4|00|3|00|A|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|D|00|4|00|6|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|8|00|F|00|D|00|F|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x00D\x000\x008\x00B\x005\x008\x006\x00-\x003\x004\x003\x00A\x00-\x001\x001\x00D\x000\x00-\x00A\x00D\x004\x006\x00-\x000\x000\x00C\x000\x004\x00F\x00D\x008\x00F\x00D\x00F\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8028</id>
        <msg>WEB-ACTIVEX Microsoft WBEM Event Subsystem ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4EFE2452-168A-11D1-BC76-00C04FB9453B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4EFE2452-168A-11D1-BC76-00C04FB9453B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8029</id>
        <msg>WEB-ACTIVEX MidiOut Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|E|00|F|00|E|00|2|00|4|00|5|00|2|00|-|00|1|00|6|00|8|00|A|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|C|00|7|00|6|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|B|00|9|00|4|00|5|00|3|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x00E\x00F\x00E\x002\x004\x005\x002\x00-\x001\x006\x008\x00A\x00-\x001\x001\x00D\x001\x00-\x00B\x00C\x007\x006\x00-\x000\x000\x00C\x000\x004\x00F\x00B\x009\x004\x005\x003\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8030</id>
        <msg>WEB-ACTIVEX MidiOut Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;466D66FA-9616-11D2-9342-0000F875AE17&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*466D66FA-9616-11D2-9342-0000F875AE17/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8031</id>
        <msg>WEB-ACTIVEX Mslablti.MarshalableTI.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|6|00|6|00|D|00|6|00|6|00|F|00|A|00|-|00|9|00|6|00|1|00|6|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|3|00|4|00|2|00|-|00|0|00|0|00|0|00|0|00|F|00|8|00|7|00|5|00|A|00|E|00|1|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x006\x006\x00D\x006\x006\x00F\x00A\x00-\x009\x006\x001\x006\x00-\x001\x001\x00D\x002\x00-\x009\x003\x004\x002\x00-\x000\x000\x000\x000\x00F\x008\x007\x005\x00A\x00E\x001\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8032</id>
        <msg>WEB-ACTIVEX Mslablti.MarshalableTI.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ECABB0BF-7F19-11D2-978E-0000F8757E2A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*ECABB0BF-7F19-11D2-978E-0000F8757E2A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8033</id>
        <msg>WEB-ACTIVEX QC.MessageMover.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|C|00|A|00|B|00|B|00|0|00|B|00|F|00|-|00|7|00|F|00|1|00|9|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|7|00|8|00|E|00|-|00|0|00|0|00|0|00|0|00|F|00|8|00|7|00|5|00|7|00|E|00|2|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x00C\x00A\x00B\x00B\x000\x00B\x00F\x00-\x007\x00F\x001\x009\x00-\x001\x001\x00D\x002\x00-\x009\x007\x008\x00E\x00-\x000\x000\x000\x000\x00F\x008\x007\x005\x007\x00E\x002\x00A\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8034</id>
        <msg>WEB-ACTIVEX QC.MessageMover.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B0516FF0-7F1C-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B0516FF0-7F1C-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8035</id>
        <msg>WEB-ACTIVEX Spanish_Modern Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|5|00|1|00|6|00|F|00|F|00|0|00|-|00|7|00|F|00|1|00|C|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x000\x005\x001\x006\x00F\x00F\x000\x00-\x007\x00F\x001\x00C\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8036</id>
        <msg>WEB-ACTIVEX Spanish_Modern Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9478F640-7F1C-11CE-BE57-00AA0051FE20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9478F640-7F1C-11CE-BE57-00AA0051FE20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8037</id>
        <msg>WEB-ACTIVEX Swedish_Default Stemmer ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|4|00|7|00|8|00|F|00|6|00|4|00|0|00|-|00|7|00|F|00|1|00|C|00|-|00|1|00|1|00|C|00|E|00|-|00|B|00|E|00|5|00|7|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|1|00|F|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x004\x007\x008\x00F\x006\x004\x000\x00-\x007\x00F\x001\x00C\x00-\x001\x001\x00C\x00E\x00-\x00B\x00E\x005\x007\x00-\x000\x000\x00A\x00A\x000\x000\x005\x001\x00F\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8038</id>
        <msg>WEB-ACTIVEX Swedish_Default Stemmer ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;85BBD920-42A0-1069-A2E4-08002B30309D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*85BBD920-42A0-1069-A2E4-08002B30309D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8039</id>
        <msg>WEB-ACTIVEX syncui.dll ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|5|00|B|00|B|00|D|00|9|00|2|00|0|00|-|00|4|00|2|00|A|00|0|00|-|00|1|00|0|00|6|00|9|00|-|00|A|00|2|00|E|00|4|00|-|00|0|00|8|00|0|00|0|00|2|00|B|00|3|00|0|00|3|00|0|00|9|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x005\x00B\x00B\x00D\x009\x002\x000\x00-\x004\x002\x00A\x000\x00-\x001\x000\x006\x009\x00-\x00A\x002\x00E\x004\x00-\x000\x008\x000\x000\x002\x00B\x003\x000\x003\x000\x009\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8040</id>
        <msg>WEB-ACTIVEX syncui.dll ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;860BB310-5D01-11D0-BD3B-00A0C911CE86&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*860BB310-5D01-11D0-BD3B-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8041</id>
        <msg>WEB-ACTIVEX VFW Capture Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|6|00|0|00|B|00|B|00|3|00|1|00|0|00|-|00|5|00|D|00|0|00|1|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|D|00|3|00|B|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|1|00|C|00|E|00|8|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x006\x000\x00B\x00B\x003\x001\x000\x00-\x005\x00D\x000\x001\x00-\x001\x001\x00D\x000\x00-\x00B\x00D\x003\x00B\x00-\x000\x000\x00A\x000\x00C\x009\x001\x001\x00C\x00E\x008\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8042</id>
        <msg>WEB-ACTIVEX VFW Capture Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CC7BFB42-F175-11D1-A392-00E0291F3959&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CC7BFB42-F175-11D1-A392-00E0291F3959/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8043</id>
        <msg>WEB-ACTIVEX Video Effect Class Manager 1 Input ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|C|00|7|00|B|00|F|00|B|00|4|00|2|00|-|00|F|00|1|00|7|00|5|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|3|00|9|00|2|00|-|00|0|00|0|00|E|00|0|00|2|00|9|00|1|00|F|00|3|00|9|00|5|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x00C\x007\x00B\x00F\x00B\x004\x002\x00-\x00F\x001\x007\x005\x00-\x001\x001\x00D\x001\x00-\x00A\x003\x009\x002\x00-\x000\x000\x00E\x000\x002\x009\x001\x00F\x003\x009\x005\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8044</id>
        <msg>WEB-ACTIVEX Video Effect Class Manager 1 Input ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CC7BFB43-F175-11D1-A392-00E0291F3959&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*CC7BFB43-F175-11D1-A392-00E0291F3959/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8045</id>
        <msg>WEB-ACTIVEX Video Effect Class Manager 2 Input ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|C|00|7|00|B|00|F|00|B|00|4|00|3|00|-|00|F|00|1|00|7|00|5|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|3|00|9|00|2|00|-|00|0|00|0|00|E|00|0|00|2|00|9|00|1|00|F|00|3|00|9|00|5|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x00C\x007\x00B\x00F\x00B\x004\x003\x00-\x00F\x001\x007\x005\x00-\x001\x001\x00D\x001\x00-\x00A\x003\x009\x002\x00-\x000\x000\x00E\x000\x002\x009\x001\x00F\x003\x009\x005\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8046</id>
        <msg>WEB-ACTIVEX Video Effect Class Manager 2 Input ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;33D9A762-90C8-11D0-BD43-00A0C911CE86&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*33D9A762-90C8-11D0-BD43-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8047</id>
        <msg>WEB-ACTIVEX WaveIn Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|3|00|D|00|9|00|A|00|7|00|6|00|2|00|-|00|9|00|0|00|C|00|8|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|D|00|4|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|1|00|C|00|E|00|8|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*3\x003\x00D\x009\x00A\x007\x006\x002\x00-\x009\x000\x00C\x008\x00-\x001\x001\x00D\x000\x00-\x00B\x00D\x004\x003\x00-\x000\x000\x00A\x000\x00C\x009\x001\x001\x00C\x00E\x008\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8048</id>
        <msg>WEB-ACTIVEX WaveIn Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E0F158E1-CB04-11D0-BD4E-00A0C911CE86&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E0F158E1-CB04-11D0-BD4E-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8049</id>
        <msg>WEB-ACTIVEX WaveOut and DSound Class Manager ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|0|00|F|00|1|00|5|00|8|00|E|00|1|00|-|00|C|00|B|00|0|00|4|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|D|00|4|00|E|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|1|00|1|00|C|00|E|00|8|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x000\x00F\x001\x005\x008\x00E\x001\x00-\x00C\x00B\x000\x004\x00-\x001\x001\x00D\x000\x00-\x00B\x00D\x004\x00E\x00-\x000\x000\x00A\x000\x00C\x009\x001\x001\x00C\x00E\x008\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8050</id>
        <msg>WEB-ACTIVEX WaveOut and DSound Class Manager ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D2D588B5-D081-11D0-99E0-00C04FC2F8EC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D2D588B5-D081-11D0-99E0-00C04FC2F8EC/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8051</id>
        <msg>WEB-ACTIVEX WDM Instance Provider ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|2|00|D|00|5|00|8|00|8|00|B|00|5|00|-|00|D|00|0|00|8|00|1|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|9|00|E|00|0|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|F|00|8|00|E|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x002\x00D\x005\x008\x008\x00B\x005\x00-\x00D\x000\x008\x001\x00-\x001\x001\x00D\x000\x00-\x009\x009\x00E\x000\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00F\x008\x00E\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8052</id>
        <msg>WEB-ACTIVEX WDM Instance Provider ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>19738</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D7A7D7C3-D47F-11D0-89D3-00A0C90833E6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D7A7D7C3-D47F-11D0-89D3-00A0C90833E6/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8053</id>
        <msg>WEB-ACTIVEX DirectAnimation.PathControl ActiveX CLSID access</msg>
      </rule>
      <rule>
        <bugtraq>19738</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|7|00|A|00|7|00|D|00|7|00|C|00|3|00|-|00|D|00|4|00|7|00|F|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|9|00|D|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|8|00|3|00|3|00|E|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x007\x00A\x007\x00D\x007\x00C\x003\x00-\x00D\x004\x007\x00F\x00-\x001\x001\x00D\x000\x00-\x008\x009\x00D\x003\x00-\x000\x000\x00A\x000\x00C\x009\x000\x008\x003\x003\x00E\x006\x00/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8054</id>
        <msg>WEB-ACTIVEX DirectAnimation.PathControl ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>19738</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.PathControl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.PathControl\x22|\x27DirectAnimation.PathControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.PathControl\x22|\x27DirectAnimation.PathControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8055</id>
        <msg>WEB-ACTIVEX DirectAnimation.PathControl ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>10514</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0549</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|0|00|0|00|5|00|6|00|6|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|1|00|0|00|-|00|8|00|0|00|0|00|0|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|6|00|D|00|2|00|E|00|A|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x000\x000\x000\x000\x005\x006\x006\x00-\x000\x000\x000\x000\x00-\x000\x000\x001\x000\x00-\x008\x000\x000\x000\x00-\x000\x000\x00A\x00A\x000\x000\x006\x00D\x002\x00E\x00A\x004\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8062</id>
        <msg>WEB-ACTIVEX ADODB.Stream ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>10514</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0549</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ADODB.Stream&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22ADODB.Stream\x22|\x27ADODB.Stream\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22ADODB.Stream\x22|\x27ADODB.Stream\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8063</id>
        <msg>WEB-ACTIVEX ADODB.Stream ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>598</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1061</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;06290BD5-48AA-11D2-8432-006008C3FBFC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*06290BD5-48AA-11D2-8432-006008C3FBFC/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8064</id>
        <msg>WEB-ACTIVEX Scriptlet.Typelib ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS00-075.mspx</url>
      </rule>
      <rule>
        <bugtraq>598</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1061</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|6|00|2|00|9|00|0|00|B|00|D|00|5|00|-|00|4|00|8|00|A|00|A|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|4|00|3|00|2|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|C|00|3|00|F|00|B|00|F|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x006\x002\x009\x000\x00B\x00D\x005\x00-\x004\x008\x00A\x00A\x00-\x001\x001\x00D\x002\x00-\x008\x004\x003\x002\x00-\x000\x000\x006\x000\x000\x008\x00C\x003\x00F\x00B\x00F\x00C\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8065</id>
        <msg>WEB-ACTIVEX Scriptlet.Typelib ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS00-075.mspx</url>
      </rule>
      <rule>
        <bugtraq>8456</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0532</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F935DC22-1CF0-11D0-ADB9-00C04FD58A0B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F935DC22-1CF0-11D0-ADB9-00C04FD58A0B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8066</id>
        <msg>WEB-ACTIVEX Windows Scripting Host Shell ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-032.mspx</url>
      </rule>
      <rule>
        <bugtraq>8456</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0532</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|9|00|3|00|5|00|D|00|C|00|2|00|2|00|-|00|1|00|C|00|F|00|0|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|D|00|B|00|9|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|5|00|8|00|A|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x009\x003\x005\x00D\x00C\x002\x002\x00-\x001\x00C\x00F\x000\x00-\x001\x001\x00D\x000\x00-\x00A\x00D\x00B\x009\x00-\x000\x000\x00C\x000\x004\x00F\x00D\x005\x008\x00A\x000\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8067</id>
        <msg>WEB-ACTIVEX Windows Scripting Host Shell ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;wscript.shell&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22wscript.shell\x22|\x27wscript.shell\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22wscript.shell\x22|\x27wscript.shell\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8068</id>
        <msg>WEB-ACTIVEX Windows Scripting Host Shell ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>1754</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1061</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0D43FE01-F093-11CF-8940-00A0C9054228&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0D43FE01-F093-11CF-8940-00A0C9054228/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8069</id>
        <msg>WEB-ACTIVEX Microsoft Virtual Machine ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-075.mspx</url>
      </rule>
      <rule>
        <bugtraq>1754</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1061</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|D|00|4|00|3|00|F|00|E|00|0|00|1|00|-|00|F|00|0|00|9|00|3|00|-|00|1|00|1|00|C|00|F|00|-|00|8|00|9|00|4|00|0|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|5|00|4|00|2|00|2|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x00D\x004\x003\x00F\x00E\x000\x001\x00-\x00F\x000\x009\x003\x00-\x001\x001\x00C\x00F\x00-\x008\x009\x004\x000\x00-\x000\x000\x00A\x000\x00C\x009\x000\x005\x004\x002\x002\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8070</id>
        <msg>WEB-ACTIVEX Microsoft Virtual Machine ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-075.mspx</url>
      </rule>
      <rule>
        <bugtraq>16636</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0013</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:C8CB7687-E6D3-11D2-A958-00C04F682E16; dce_opnum:0; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>8253</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP webdav DavrCreateConnection username overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AB9BCEDD-EC7E-47E1-9322-D4A210617116&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*AB9BCEDD-EC7E-47E1-9322-D4A210617116/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8363</id>
        <msg>WEB-ACTIVEX Business Object Factory ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|B|00|9|00|B|00|C|00|E|00|D|00|D|00|-|00|E|00|C|00|7|00|E|00|-|00|4|00|7|00|E|00|1|00|-|00|9|00|3|00|2|00|2|00|-|00|D|00|4|00|A|00|2|00|1|00|0|00|6|00|1|00|7|00|1|00|1|00|6|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x00B\x009\x00B\x00C\x00E\x00D\x00D\x00-\x00E\x00C\x007\x00E\x00-\x004\x007\x00E\x001\x00-\x009\x003\x002\x002\x00-\x00D\x004\x00A\x002\x001\x000\x006\x001\x007\x001\x001\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8364</id>
        <msg>WEB-ACTIVEX Business Object Factory ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;639F725F-1B2D-4831-A9FD-874847682010&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*639F725F-1B2D-4831-A9FD-874847682010/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8365</id>
        <msg>WEB-ACTIVEX DExplore.AppObj.8.0 ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|3|00|9|00|F|00|7|00|2|00|5|00|F|00|-|00|1|00|B|00|2|00|D|00|-|00|4|00|8|00|3|00|1|00|-|00|A|00|9|00|F|00|D|00|-|00|8|00|7|00|4|00|8|00|4|00|7|00|6|00|8|00|2|00|0|00|1|00|0|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x003\x009\x00F\x007\x002\x005\x00F\x00-\x001\x00B\x002\x00D\x00-\x004\x008\x003\x001\x00-\x00A\x009\x00F\x00D\x00-\x008\x007\x004\x008\x004\x007\x006\x008\x002\x000\x001\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8366</id>
        <msg>WEB-ACTIVEX DExplore.AppObj.8.0 ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D0C07D56-7C69-43F1-B4A0-25F5A11FAB19&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D0C07D56-7C69-43F1-B4A0-25F5A11FAB19/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8367</id>
        <msg>WEB-ACTIVEX Microsoft.DbgClr.DTE.8.0 ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|0|00|C|00|0|00|7|00|D|00|5|00|6|00|-|00|7|00|C|00|6|00|9|00|-|00|4|00|3|00|F|00|1|00|-|00|B|00|4|00|A|00|0|00|-|00|2|00|5|00|F|00|5|00|A|00|1|00|1|00|F|00|A|00|B|00|1|00|9|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x000\x00C\x000\x007\x00D\x005\x006\x00-\x007\x00C\x006\x009\x00-\x004\x003\x00F\x001\x00-\x00B\x004\x00A\x000\x00-\x002\x005\x00F\x005\x00A\x001\x001\x00F\x00A\x00B\x001\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8368</id>
        <msg>WEB-ACTIVEX Microsoft.DbgClr.DTE.8.0 ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7F5B7F63-F06F-4331-8A26-339E03C0AE3D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*7F5B7F63-F06F-4331-8A26-339E03C0AE3D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8369</id>
        <msg>WEB-ACTIVEX WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-073.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4704</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|F|00|5|00|B|00|7|00|F|00|6|00|3|00|-|00|F|00|0|00|6|00|F|00|-|00|4|00|3|00|3|00|1|00|-|00|8|00|A|00|2|00|6|00|-|00|3|00|3|00|9|00|E|00|0|00|3|00|C|00|0|00|A|00|E|00|3|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*7\x00F\x005\x00B\x007\x00F\x006\x003\x00-\x00F\x000\x006\x00F\x00-\x004\x003\x003\x001\x00-\x008\x00A\x002\x006\x00-\x003\x003\x009\x00E\x000\x003\x00C\x000\x00A\x00E\x003\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8370</id>
        <msg>WEB-ACTIVEX WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-073.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;06723E09-F4C2-43c8-8358-09FCD1DB0766&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*06723E09-F4C2-43c8-8358-09FCD1DB0766/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8373</id>
        <msg>WEB-ACTIVEX VsmIDE.DTE ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|6|00|7|00|2|00|3|00|E|00|0|00|9|00|-|00|F|00|4|00|C|00|2|00|-|00|4|00|3|00|c|00|8|00|-|00|8|00|3|00|5|00|8|00|-|00|0|00|9|00|F|00|C|00|D|00|1|00|D|00|B|00|0|00|7|00|6|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x006\x007\x002\x003\x00E\x000\x009\x00-\x00F\x004\x00C\x002\x00-\x004\x003\x00c\x008\x00-\x008\x003\x005\x008\x00-\x000\x009\x00F\x00C\x00D\x001\x00D\x00B\x000\x007\x006\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8374</id>
        <msg>WEB-ACTIVEX VsmIDE.DTE ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18C628EE-962A-11D2-8D08-00A0C9441E20&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*18C628EE-962A-11D2-8D08-00A0C9441E20/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8379</id>
        <msg>WEB-ACTIVEX Xml2Dex ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|C|00|6|00|2|00|8|00|E|00|E|00|-|00|9|00|6|00|2|00|A|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|D|00|0|00|8|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|4|00|4|00|1|00|E|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*1\x008\x00C\x006\x002\x008\x00E\x00E\x00-\x009\x006\x002\x00A\x00-\x001\x001\x00D\x002\x00-\x008\x00D\x000\x008\x00-\x000\x000\x00A\x000\x00C\x009\x004\x004\x001\x00E\x002\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8380</id>
        <msg>WEB-ACTIVEX Xml2Dex ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;47F59200-8783-11D2-8343-00A0C945A819&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*47F59200-8783-11D2-8343-00A0C945A819/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8391</id>
        <msg>WEB-ACTIVEX RFXInstMgr Class ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|7|00|F|00|5|00|9|00|2|00|0|00|0|00|-|00|8|00|7|00|8|00|3|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|3|00|4|00|3|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|4|00|5|00|A|00|8|00|1|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x007\x00F\x005\x009\x002\x000\x000\x00-\x008\x007\x008\x003\x00-\x001\x001\x00D\x002\x00-\x008\x003\x004\x003\x00-\x000\x000\x00A\x000\x00C\x009\x004\x005\x00A\x008\x001\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8392</id>
        <msg>WEB-ACTIVEX RFXInstMgr Class ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;61C669C7-EDDD-4277-BF5E-64807CB8DCEF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*61C669C7-EDDD-4277-BF5E-64807CB8DCEF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8393</id>
        <msg>WEB-ACTIVEX WebDetectFrm ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|1|00|C|00|6|00|6|00|9|00|C|00|7|00|-|00|E|00|D|00|D|00|D|00|-|00|4|00|2|00|7|00|7|00|-|00|B|00|F|00|5|00|E|00|-|00|6|00|4|00|8|00|0|00|7|00|C|00|B|00|8|00|D|00|C|00|E|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x001\x00C\x006\x006\x009\x00C\x007\x00-\x00E\x00D\x00D\x00D\x00-\x004\x002\x007\x007\x00-\x00B\x00F\x005\x00E\x00-\x006\x004\x008\x000\x007\x00C\x00B\x008\x00D\x00C\x00E\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8394</id>
        <msg>WEB-ACTIVEX WebDetectFrm ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;63500AE2-0858-11D2-8CE4-00C04F8ECB10&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*63500AE2-0858-11D2-8CE4-00C04F8ECB10/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8395</id>
        <msg>WEB-ACTIVEX DX3DTransform.Microsoft.CrShatter ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|3|00|5|00|0|00|0|00|A|00|E|00|2|00|-|00|0|00|8|00|5|00|8|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|C|00|E|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|8|00|E|00|C|00|B|00|1|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x003\x005\x000\x000\x00A\x00E\x002\x00-\x000\x008\x005\x008\x00-\x001\x001\x00D\x002\x00-\x008\x00C\x00E\x004\x00-\x000\x000\x00C\x000\x004\x00F\x008\x00E\x00C\x00B\x001\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8396</id>
        <msg>WEB-ACTIVEX DX3DTransform.Microsoft.CrShatter ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;742D385A-D5BF-427D-9AF2-88258FB73EAF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*742D385A-D5BF-427D-9AF2-88258FB73EAF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8399</id>
        <msg>WEB-ACTIVEX Microsoft.WebCapture ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|4|00|2|00|D|00|3|00|8|00|5|00|A|00|-|00|D|00|5|00|B|00|F|00|-|00|4|00|2|00|7|00|D|00|-|00|9|00|A|00|F|00|2|00|-|00|8|00|8|00|2|00|5|00|8|00|F|00|B|00|7|00|3|00|E|00|A|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*7\x004\x002\x00D\x003\x008\x005\x00A\x00-\x00D\x005\x00B\x00F\x00-\x004\x002\x007\x00D\x00-\x009\x00A\x00F\x002\x00-\x008\x008\x002\x005\x008\x00F\x00B\x007\x003\x00E\x00A\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8400</id>
        <msg>WEB-ACTIVEX Microsoft.WebCapture ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;88D96A07-F192-11D4-A65F-0040963251E5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*88D96A07-F192-11D4-A65F-0040963251E5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8403</id>
        <msg>WEB-ACTIVEX XML Schema Cache 6.0 ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|8|00|D|00|9|00|6|00|A|00|0|00|7|00|-|00|F|00|1|00|9|00|2|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|6|00|5|00|F|00|-|00|0|00|0|00|4|00|0|00|9|00|6|00|3|00|2|00|5|00|1|00|E|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x008\x00D\x009\x006\x00A\x000\x007\x00-\x00F\x001\x009\x002\x00-\x001\x001\x00D\x004\x00-\x00A\x006\x005\x00F\x00-\x000\x000\x004\x000\x009\x006\x003\x002\x005\x001\x00E\x005\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8404</id>
        <msg>WEB-ACTIVEX XML Schema Cache 6.0 ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>20915</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;88D96A0A-F192-11D4-A65F-0040963251E5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*88D96A0A-F192-11D4-A65F-0040963251E5\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8405</id>
        <msg>WEB-ACTIVEX  ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-071.mspx</url>
      </rule>
      <rule>
        <bugtraq>20915</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|8|00|D|00|9|00|6|00|A|00|0|00|A|00|-|00|F|00|1|00|9|00|2|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|6|00|5|00|F|00|-|00|0|00|0|00|4|00|0|00|9|00|6|00|3|00|2|00|5|00|1|00|E|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8406</id>
        <msg>WEB-ACTIVEX  ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;99EA8527-6A6A-40FE-A67C-82CF763902D0&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*99EA8527-6A6A-40FE-A67C-82CF763902D0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8407</id>
        <msg>WEB-ACTIVEX VisualExec Control ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|9|00|E|00|A|00|8|00|5|00|2|00|7|00|-|00|6|00|A|00|6|00|A|00|-|00|4|00|0|00|F|00|E|00|-|00|A|00|6|00|7|00|C|00|-|00|8|00|2|00|C|00|F|00|7|00|6|00|3|00|9|00|0|00|2|00|D|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x009\x00E\x00A\x008\x005\x002\x007\x00-\x006\x00A\x006\x00A\x00-\x004\x000\x00F\x00E\x00-\x00A\x006\x007\x00C\x00-\x008\x002\x00C\x00F\x007\x006\x003\x009\x000\x002\x00D\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8408</id>
        <msg>WEB-ACTIVEX VisualExec Control ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B005E690-678D-11D1-B758-00A0C90564FE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B005E690-678D-11D1-B758-00A0C90564FE/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8411</id>
        <msg>WEB-ACTIVEX DocFind Command ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|0|00|5|00|E|00|6|00|9|00|0|00|-|00|6|00|7|00|8|00|D|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|7|00|5|00|8|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|5|00|6|00|4|00|F|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x000\x000\x005\x00E\x006\x009\x000\x00-\x006\x007\x008\x00D\x00-\x001\x001\x00D\x001\x00-\x00B\x007\x005\x008\x00-\x000\x000\x00A\x000\x00C\x009\x000\x005\x006\x004\x00F\x00E\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8412</id>
        <msg>WEB-ACTIVEX DocFind Command ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>18946</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3591</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TriEditDocument.TriEditDocument&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22TriEditDocument.TriEditDocument\x22|\x27TriEditDocument.TriEditDocument\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TriEditDocument.TriEditDocument\x22|\x27TriEditDocument.TriEditDocument\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8417</id>
        <msg>WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX function call access</msg>
        <url>osvdb.org/27056</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.RevealTrans.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.RevealTrans.1\x22|\x27DXImageTransform.Microsoft.RevealTrans.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.RevealTrans.1\x22|\x27DXImageTransform.Microsoft.RevealTrans.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8418</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX function call access</msg>
        <url>osvdb.org/27057</url>
      </rule>
      <rule>
        <bugtraq>19030</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3730</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WebViewFolderIcon.WebViewFolderIcon.1&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8419</id>
        <msg>WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX function call</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-057.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.Gradient.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.Gradient.1\x22|\x27DXImageTransform.Microsoft.Gradient.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.Gradient.1\x22|\x27DXImageTransform.Microsoft.Gradient.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8420</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX function call access</msg>
        <url>osvdb.org/27109</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OWC11.DataSourceControl.11&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22OWC11.DataSourceControl.11\x22|\x27OWC11.DataSourceControl.11\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22OWC11.DataSourceControl.11\x22|\x27OWC11.DataSourceControl.11\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8421</id>
        <msg>WEB-ACTIVEX OWC11.DataSourceControl.11 ActiveX function call access</msg>
        <url>osvdb.org/27111</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CEnroll.CEnroll.2&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22CEnroll.CEnroll.2\x22|\x27CEnroll.CEnroll.2\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CEnroll.CEnroll.2\x22|\x27CEnroll.CEnroll.2\x27)\s*\)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8423</id>
        <msg>WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX function call access</msg>
        <url>osvdb.org/27230</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Forms.ListBox.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Forms.ListBox.1\x22|\x27Forms.ListBox.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Forms.ListBox.1\x22|\x27Forms.ListBox.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8424</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX function call access</msg>
        <url>osvdb.org/27372</url>
      </rule>
      <rule>
        <bugtraq>19340</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3638</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.NDFXArtEffects.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DXImageTransform.Microsoft.NDFXArtEffects.1\x22|\x27DXImageTransform.Microsoft.NDFXArtEffects.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DXImageTransform.Microsoft.NDFXArtEffects.1\x22|\x27DXImageTransform.Microsoft.NDFXArtEffects.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8425</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-042.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2006-0001</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;CHNKINK &quot;; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8478</id>
        <msg>WEB-CLIENT Microsoft Publisher file download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E8CCCDDF-CA28-496b-B050-6C07C962476B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*E8CCCDDF-CA28-496b-B050-6C07C962476B/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8717</id>
        <msg>WEB-ACTIVEX VsaIDE.DTE ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|8|00|C|00|C|00|C|00|D|00|D|00|F|00|-|00|C|00|A|00|2|00|8|00|-|00|4|00|9|00|6|00|b|00|-|00|B|00|0|00|5|00|0|00|-|00|6|00|C|00|0|00|7|00|C|00|9|00|6|00|2|00|4|00|7|00|6|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*E\x008\x00C\x00C\x00C\x00D\x00D\x00F\x00-\x00C\x00A\x002\x008\x00-\x004\x009\x006\x00b\x00-\x00B\x000\x005\x000\x00-\x006\x00C\x000\x007\x00C\x009\x006\x002\x004\x007\x006\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8718</id>
        <msg>WEB-ACTIVEX VsaIDE.DTE ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BA018599-1DB3-44f9-83B4-461454C84BF8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*BA018599-1DB3-44f9-83B4-461454C84BF8/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8719</id>
        <msg>WEB-ACTIVEX VisualStudio.DTE.8.0 ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|0|00|1|00|8|00|5|00|9|00|9|00|-|00|1|00|D|00|B|00|3|00|-|00|4|00|4|00|f|00|9|00|-|00|8|00|3|00|B|00|4|00|-|00|4|00|6|00|1|00|4|00|5|00|4|00|C|00|8|00|4|00|B|00|F|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x00A\x000\x001\x008\x005\x009\x009\x00-\x001\x00D\x00B\x003\x00-\x004\x004\x00f\x009\x00-\x008\x003\x00B\x004\x00-\x004\x006\x001\x004\x005\x004\x00C\x008\x004\x00B\x00F\x008\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8720</id>
        <msg>WEB-ACTIVEX VisualStudio.DTE.8.0 ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <bugtraq>1899</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C4D2D8E0-D1DD-11CE-940F-008029004347&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C4D2D8E0-D1DD-11CE-940F-008029004347/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8725</id>
        <msg>WEB-ACTIVEX System Monitor ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS00-085.mspx</url>
      </rule>
      <rule>
        <bugtraq>1899</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-1034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|D|00|2|00|D|00|8|00|E|00|0|00|-|00|D|00|1|00|D|00|D|00|-|00|1|00|1|00|C|00|E|00|-|00|9|00|4|00|0|00|F|00|-|00|0|00|0|00|8|00|0|00|2|00|9|00|0|00|0|00|4|00|3|00|4|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x00D\x002\x00D\x008\x00E\x000\x00-\x00D\x001\x00D\x00D\x00-\x001\x001\x00C\x00E\x00-\x009\x004\x000\x00F\x00-\x000\x000\x008\x000\x002\x009\x000\x000\x004\x003\x004\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8726</id>
        <msg>WEB-ACTIVEX System Monitor ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS00-085.mspx</url>
      </rule>
      <rule>
        <bugtraq>20915</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;88d969c5-f192-11d4-a65f-0040963251e5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*88d969c5-f192-11d4-a65f-0040963251e5\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8727</id>
        <msg>WEB-ACTIVEX XMLHTTP 4.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-071.mspx</url>
      </rule>
      <rule>
        <bugtraq>20915</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|8|00|d|00|9|00|6|00|9|00|c|00|5|00|-|00|f|00|1|00|9|00|2|00|-|00|1|00|1|00|d|00|4|00|-|00|a|00|6|00|5|00|f|00|-|00|0|00|0|00|4|00|0|00|9|00|6|00|3|00|2|00|5|00|1|00|e|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8728</id>
        <msg>WEB-ACTIVEX XMLHTTP 4.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;85A4A99C-8C3D-499E-A386-E0743DFF8FB7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*85A4A99C-8C3D-499E-A386-E0743DFF8FB7/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8735</id>
        <msg>WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|5|00|A|00|4|00|A|00|9|00|9|00|C|00|-|00|8|00|C|00|3|00|D|00|-|00|4|00|9|00|9|00|E|00|-|00|A|00|3|00|8|00|6|00|-|00|E|00|0|00|7|00|4|00|3|00|D|00|F|00|F|00|8|00|F|00|B|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*8\x005\x00A\x004\x00A\x009\x009\x00C\x00-\x008\x00C\x003\x00D\x00-\x004\x009\x009\x00E\x00-\x00A\x003\x008\x006\x00-\x00E\x000\x007\x004\x003\x00D\x00F\x00F\x008\x00F\x00B\x007\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8736</id>
        <msg>WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BOWebAgent.Webagent.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22BOWebAgent.Webagent.1\x22|\x27BOWebAgent.Webagent.1\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(DownloadAndExecute|AddFileEx)\s*\(|.*\3\s*\.\s*(DownloadAndExecute|AddFileEx)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BOWebAgent.Webagent.1\x22|\x27BOWebAgent.Webagent.1\x27)\s*\)(\s*\.\s*(DownloadAndExecute|AddFileEx)\s*\(|.*\7\s*\.\s*(DownloadAndExecute|AddFileEx)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8737</id>
        <msg>WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;25B0F91C-D23D-11D0-9B85-00C04FC2F51D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*25B0F91C-D23D-11D0-9B85-00C04FC2F51D/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8741</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|5|00|B|00|0|00|F|00|9|00|1|00|C|00|-|00|D|00|2|00|3|00|D|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|B|00|8|00|5|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|F|00|5|00|1|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*2\x005\x00B\x000\x00F\x009\x001\x00C\x00-\x00D\x002\x003\x00D\x00-\x001\x001\x00D\x000\x00-\x009\x00B\x008\x005\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00F\x005\x001\x00D\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8742</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAFontStyle.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAFontStyle.1\x22|\x27DirectAnimation.DAFontStyle.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAFontStyle.1\x22|\x27DirectAnimation.DAFontStyle.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8743</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;50B4791F-4731-11D0-8912-00C04FC2A0CA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*50B4791F-4731-11D0-8912-00C04FC2A0CA/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8744</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|0|00|B|00|4|00|7|00|9|00|1|00|F|00|-|00|4|00|7|00|3|00|1|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|9|00|1|00|2|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|A|00|0|00|C|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*5\x000\x00B\x004\x007\x009\x001\x00F\x00-\x004\x007\x003\x001\x00-\x001\x001\x00D\x000\x00-\x008\x009\x001\x002\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00A\x000\x00C\x00A\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8745</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAEvent.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAEvent.1\x22|\x27DirectAnimation.DAEvent.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAEvent.1\x22|\x27DirectAnimation.DAEvent.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8746</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BEC-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BEC-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8747</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|C|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x00C\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8748</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAEndStyle.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAEndStyle.1\x22|\x27DirectAnimation.DAEndStyle.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAEndStyle.1\x22|\x27DirectAnimation.DAEndStyle.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8749</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B1549E58-3894-11D2-BB7F-00A0C999C4C1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B1549E58-3894-11D2-BB7F-00A0C999C4C1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8750</id>
        <msg>WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|1|00|5|00|4|00|9|00|E|00|5|00|8|00|-|00|3|00|8|00|9|00|4|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|B|00|7|00|F|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|9|00|9|00|C|00|4|00|C|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x001\x005\x004\x009\x00E\x005\x008\x00-\x003\x008\x009\x004\x00-\x001\x001\x00D\x002\x00-\x00B\x00B\x007\x00F\x00-\x000\x000\x00A\x000\x00C\x009\x009\x009\x00C\x004\x00C\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8751</id>
        <msg>WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LM.LMBehaviorFactory.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22LM.LMBehaviorFactory.1\x22|\x27LM.LMBehaviorFactory.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22LM.LMBehaviorFactory.1\x22|\x27LM.LMBehaviorFactory.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8752</id>
        <msg>WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BB339A46-7C49-11d2-9BF3-00C04FA34789&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*BB339A46-7C49-11d2-9BF3-00C04FA34789/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8753</id>
        <msg>WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|B|00|3|00|3|00|9|00|A|00|4|00|6|00|-|00|7|00|C|00|4|00|9|00|-|00|1|00|1|00|d|00|2|00|-|00|9|00|B|00|F|00|3|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|A|00|3|00|4|00|7|00|8|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x00B\x003\x003\x009\x00A\x004\x006\x00-\x007\x00C\x004\x009\x00-\x001\x001\x00d\x002\x00-\x009\x00B\x00F\x003\x00-\x000\x000\x00C\x000\x004\x00F\x00A\x003\x004\x007\x008\x009\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8754</id>
        <msg>WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LM.AutoEffectBvr.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22LM.AutoEffectBvr.1\x22|\x27LM.AutoEffectBvr.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22LM.AutoEffectBvr.1\x22|\x27LM.AutoEffectBvr.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8755</id>
        <msg>WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FD179533-D86E-11D0-89D6-00A0C90833E6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*FD179533-D86E-11D0-89D6-00A0C90833E6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8756</id>
        <msg>WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|1|00|7|00|9|00|5|00|3|00|3|00|-|00|D|00|8|00|6|00|E|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|9|00|D|00|6|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|8|00|3|00|3|00|E|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*F\x00D\x001\x007\x009\x005\x003\x003\x00-\x00D\x008\x006\x00E\x00-\x001\x001\x00D\x000\x00-\x008\x009\x00D\x006\x00-\x000\x000\x00A\x000\x00C\x009\x000\x008\x003\x003\x00E\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8757</id>
        <msg>WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.SpriteControl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.SpriteControl\x22|\x27DirectAnimation.SpriteControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.SpriteControl\x22|\x27DirectAnimation.SpriteControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8758</id>
        <msg>WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B0A6BAE2-AAF0-11D0-A152-00A0C908DB96&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B0A6BAE2-AAF0-11D0-A152-00A0C908DB96/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8759</id>
        <msg>WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|0|00|A|00|6|00|B|00|A|00|E|00|2|00|-|00|A|00|A|00|F|00|0|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|1|00|5|00|2|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|8|00|D|00|B|00|9|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x000\x00A\x006\x00B\x00A\x00E\x002\x00-\x00A\x00A\x00F\x000\x00-\x001\x001\x00D\x000\x00-\x00A\x001\x005\x002\x00-\x000\x000\x00A\x000\x00C\x009\x000\x008\x00D\x00B\x009\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8760</id>
        <msg>WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.SequencerControl&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.SequencerControl\x22|\x27DirectAnimation.SequencerControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.SequencerControl\x22|\x27DirectAnimation.SequencerControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8761</id>
        <msg>WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4F241DB1-EE9F-11D0-9824-006097C99E51&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*4F241DB1-EE9F-11D0-9824-006097C99E51/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8762</id>
        <msg>WEB-ACTIVEX DirectAnimation.Sequence ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|F|00|2|00|4|00|1|00|D|00|B|00|1|00|-|00|E|00|E|00|9|00|F|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|8|00|2|00|4|00|-|00|0|00|0|00|6|00|0|00|9|00|7|00|C|00|9|00|9|00|E|00|5|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*4\x00F\x002\x004\x001\x00D\x00B\x001\x00-\x00E\x00E\x009\x00F\x00-\x001\x001\x00D\x000\x00-\x009\x008\x002\x004\x00-\x000\x000\x006\x000\x009\x007\x00C\x009\x009\x00E\x005\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8763</id>
        <msg>WEB-ACTIVEX DirectAnimation.Sequence ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.Sequence&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.Sequence\x22|\x27DirectAnimation.Sequence\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.Sequence\x22|\x27DirectAnimation.Sequence\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8764</id>
        <msg>WEB-ACTIVEX DirectAnimation.Sequence ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;283807B5-2C60-11D0-A31D-00AA00B92C03&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*283807B5-2C60-11D0-A31D-00AA00B92C03/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8765</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|8|00|3|00|8|00|0|00|7|00|B|00|5|00|-|00|2|00|C|00|6|00|0|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|3|00|1|00|D|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|9|00|2|00|C|00|0|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*2\x008\x003\x008\x000\x007\x00B\x005\x00-\x002\x00C\x006\x000\x00-\x001\x001\x00D\x000\x00-\x00A\x003\x001\x00D\x00-\x000\x000\x00A\x00A\x000\x000\x00B\x009\x002\x00C\x000\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8766</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAView.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAView.1\x22|\x27DirectAnimation.DAView.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAView.1\x22|\x27DirectAnimation.DAView.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8767</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BDA-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BDA-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8768</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|A|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x00A\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8769</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAVector3.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAVector3.1\x22|\x27DirectAnimation.DAVector3.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAVector3.1\x22|\x27DirectAnimation.DAVector3.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8770</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BCA-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BCA-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8771</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|A|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x00A\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8772</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAVector2.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAVector2.1\x22|\x27DirectAnimation.DAVector2.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAVector2.1\x22|\x27DirectAnimation.DAVector2.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8773</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF868304-AB0B-11D0-876A-00C04FC29D46&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*AF868304-AB0B-11D0-876A-00C04FC29D46/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8774</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|8|00|6|00|8|00|3|00|0|00|4|00|-|00|A|00|B|00|0|00|B|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|7|00|6|00|A|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|9|00|D|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*A\x00F\x008\x006\x008\x003\x000\x004\x00-\x00A\x00B\x000\x00B\x00-\x001\x001\x00D\x000\x00-\x008\x007\x006\x00A\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x009\x00D\x004\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8775</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAUserData.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAUserData.1\x22|\x27DirectAnimation.DAUserData.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAUserData.1\x22|\x27DirectAnimation.DAUserData.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8776</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BDC-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BDC-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8777</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|C|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x00C\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8778</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DATransform3.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DATransform3.1\x22|\x27DirectAnimation.DATransform3.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DATransform3.1\x22|\x27DirectAnimation.DATransform3.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8779</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BCC-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BCC-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8780</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|C|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x00C\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8781</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DATransform2.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DATransform2.1\x22|\x27DirectAnimation.DATransform2.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DATransform2.1\x22|\x27DirectAnimation.DATransform2.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8782</id>
        <msg>WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BC4-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BC4-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8783</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|4|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x004\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8784</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAString.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAString.1\x22|\x27DirectAnimation.DAString.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAString.1\x22|\x27DirectAnimation.DAString.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8785</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BE4-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BE4-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8786</id>
        <msg>WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|4|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x004\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8787</id>
        <msg>WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DASound.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DASound.1\x22|\x27DirectAnimation.DASound.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DASound.1\x22|\x27DirectAnimation.DASound.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8788</id>
        <msg>WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BD8-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BD8-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8789</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|8|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x008\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8790</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAPoint3.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAPoint3.1\x22|\x27DirectAnimation.DAPoint3.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAPoint3.1\x22|\x27DirectAnimation.DAPoint3.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8791</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BC8-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BC8-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8792</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|8|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x008\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8793</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAPoint2.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAPoint2.1\x22|\x27DirectAnimation.DAPoint2.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAPoint2.1\x22|\x27DirectAnimation.DAPoint2.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8794</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BD0-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BD0-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8795</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|0|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x000\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8796</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAPath2.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAPath2.1\x22|\x27DirectAnimation.DAPath2.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAPath2.1\x22|\x27DirectAnimation.DAPath2.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8797</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BF4-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BF4-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8798</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|F|00|4|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00F\x004\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8799</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAPair.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAPair.1\x22|\x27DirectAnimation.DAPair.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAPair.1\x22|\x27DirectAnimation.DAPair.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8800</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9CDE7341-3C20-11D0-A330-00AA00B92C03&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*9CDE7341-3C20-11D0-A330-00AA00B92C03/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8801</id>
        <msg>WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|C|00|D|00|E|00|7|00|3|00|4|00|1|00|-|00|3|00|C|00|2|00|0|00|-|00|1|00|1|00|D|00|0|00|-|00|A|00|3|00|3|00|0|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|9|00|2|00|C|00|0|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*9\x00C\x00D\x00E\x007\x003\x004\x001\x00-\x003\x00C\x002\x000\x00-\x001\x001\x00D\x000\x00-\x00A\x003\x003\x000\x00-\x000\x000\x00A\x00A\x000\x000\x00B\x009\x002\x00C\x000\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8802</id>
        <msg>WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DANumber.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DANumber.1\x22|\x27DirectAnimation.DANumber.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DANumber.1\x22|\x27DirectAnimation.DANumber.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8803</id>
        <msg>WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BD6-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BD6-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8804</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|6|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x006\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8805</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAMontage.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAMontage.1\x22|\x27DirectAnimation.DAMontage.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAMontage.1\x22|\x27DirectAnimation.DAMontage.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8806</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BE6-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BE6-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8807</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|6|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x006\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8808</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAMicrophone.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAMicrophone.1\x22|\x27DirectAnimation.DAMicrophone.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAMicrophone.1\x22|\x27DirectAnimation.DAMicrophone.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8809</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BD2-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BD2-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8810</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|2|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x002\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8811</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAMatte.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAMatte.1\x22|\x27DirectAnimation.DAMatte.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAMatte.1\x22|\x27DirectAnimation.DAMatte.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8812</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BF2-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BF2-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8813</id>
        <msg>WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|F|00|2|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00F\x002\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8814</id>
        <msg>WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DALineStyle.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DALineStyle.1\x22|\x27DirectAnimation.DALineStyle.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DALineStyle.1\x22|\x27DirectAnimation.DALineStyle.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8815</id>
        <msg>WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BEE-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BEE-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8816</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|E|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x00E\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8817</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAJoinStyle.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAJoinStyle.1\x22|\x27DirectAnimation.DAJoinStyle.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAJoinStyle.1\x22|\x27DirectAnimation.DAJoinStyle.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8818</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BD4-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BD4-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8819</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|4|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x004\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8820</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAImage.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAImage.1\x22|\x27DirectAnimation.DAImage.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAImage.1\x22|\x27DirectAnimation.DAImage.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8821</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BE0-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BE0-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8822</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|0|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x000\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8823</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAGeometry.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAGeometry.1\x22|\x27DirectAnimation.DAGeometry.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAGeometry.1\x22|\x27DirectAnimation.DAGeometry.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8824</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BF0-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BF0-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8825</id>
        <msg>WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|F|00|0|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00F\x000\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8826</id>
        <msg>WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DADashStyle.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DADashStyle.1\x22|\x27DirectAnimation.DADashStyle.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DADashStyle.1\x22|\x27DirectAnimation.DADashStyle.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8827</id>
        <msg>WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BC6-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BC6-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8828</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|6|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x006\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8829</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAColor.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAColor.1\x22|\x27DirectAnimation.DAColor.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAColor.1\x22|\x27DirectAnimation.DAColor.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8830</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BE2-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BE2-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8831</id>
        <msg>WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|E|00|2|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00E\x002\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8832</id>
        <msg>WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DACamera.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DACamera.1\x22|\x27DirectAnimation.DACamera.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DACamera.1\x22|\x27DirectAnimation.DACamera.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8833</id>
        <msg>WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BC1-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BC1-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8834</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|1|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x001\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8835</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DABoolean.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DABoolean.1\x22|\x27DirectAnimation.DABoolean.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DABoolean.1\x22|\x27DirectAnimation.DABoolean.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8836</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BDE-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BDE-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8837</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|D|00|E|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00D\x00E\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8838</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DABbox3.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DABbox3.1\x22|\x27DirectAnimation.DABbox3.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DABbox3.1\x22|\x27DirectAnimation.DABbox3.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8839</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C46C1BCE-3C52-11D0-9200-848C1D000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C46C1BCE-3C52-11D0-9200-848C1D000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8840</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|4|00|6|00|C|00|1|00|B|00|C|00|E|00|-|00|3|00|C|00|5|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|2|00|0|00|0|00|-|00|8|00|4|00|8|00|C|00|1|00|D|00|0|00|0|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x004\x006\x00C\x001\x00B\x00C\x00E\x00-\x003\x00C\x005\x002\x00-\x001\x001\x00D\x000\x00-\x009\x002\x000\x000\x00-\x008\x004\x008\x00C\x001\x00D\x000\x000\x000\x000\x000\x000\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8841</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DABbox2.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DABbox2.1\x22|\x27DirectAnimation.DABbox2.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DABbox2.1\x22|\x27DirectAnimation.DABbox2.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8842</id>
        <msg>WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D17506C3-6B26-11D0-8914-00C04FC2A0CA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D17506C3-6B26-11D0-8914-00C04FC2A0CA/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8843</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|1|00|7|00|5|00|0|00|6|00|C|00|3|00|-|00|6|00|B|00|2|00|6|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|9|00|1|00|4|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|C|00|2|00|A|00|0|00|C|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*D\x001\x007\x005\x000\x006\x00C\x003\x00-\x006\x00B\x002\x006\x00-\x001\x001\x00D\x000\x00-\x008\x009\x001\x004\x00-\x000\x000\x00C\x000\x004\x00F\x00C\x002\x00A\x000\x00C\x00A\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8844</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectAnimation.DAArray.1&quot;; fast_pattern:only; pcre:&quot;/new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation.DAArray.1\x22|\x27DirectAnimation.DAArray.1\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation.DAArray.1\x22|\x27DirectAnimation.DAArray.1\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8845</id>
        <msg>WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D45FD31E-5C6E-11D1-9EC1-00C04FD7081F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31E-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8846</id>
        <msg>WEB-ACTIVEX Microsoft Agent Character Custom Proxy Class ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|5|00|F|00|D|00|3|00|1|00|E|00|-|00|5|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|E|00|C|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|8|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8847</id>
        <msg>WEB-ACTIVEX Microsoft Agent Character Custom Proxy Class ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D45FD31D-5C6E-11D1-9EC1-00C04FD7081F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31D-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8848</id>
        <msg>WEB-ACTIVEX Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|5|00|F|00|D|00|3|00|1|00|D|00|-|00|5|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|E|00|C|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|8|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8849</id>
        <msg>WEB-ACTIVEX Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4BAC124B-78C8-11D1-B9A8-00C04FD97575&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4BAC124B-78C8-11D1-B9A8-00C04FD97575\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8850</id>
        <msg>WEB-ACTIVEX Microsoft Agent Custom Proxy Class ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|B|00|A|00|C|00|1|00|2|00|4|00|B|00|-|00|7|00|8|00|C|00|8|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|9|00|A|00|8|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|9|00|7|00|5|00|7|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8851</id>
        <msg>WEB-ACTIVEX Microsoft Agent Custom Proxy Class ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D45FD31B-5C6E-11D1-9EC1-00C04FD7081F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31B-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Characters.Load)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31B-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Characters.Load))\s*\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8852</id>
        <msg>WEB-ACTIVEX Microsoft Agent v2.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|5|00|F|00|D|00|3|00|1|00|B|00|-|00|5|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|E|00|C|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|8|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8853</id>
        <msg>WEB-ACTIVEX Microsoft Agent v2.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Agent.Control.2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Agent\.Control\.2\x22|\x27Agent\.Control\.2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Characters.Load\s*|.*(?P=v)\s*\.\s*Characters.Load\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Agent\.Control\.2\x22|\x27Agent\.Control\.2\x27)\s*\)(\s*\.\s*Characters.Load\s*|.*(?P=n)\s*\.\s*Characters.Load\s*)\s*\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8854</id>
        <msg>WEB-ACTIVEX Microsoft Agent v2.0 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|5|00|B|00|E|00|8|00|B|00|D|00|2|00|-|00|7|00|D|00|E|00|6|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|1|00|F|00|E|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|1|00|A|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8855</id>
        <msg>WEB-ACTIVEX Microsoft Agent v1.5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1205</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Agent.Control.1&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Agent\.Control\.1\x22|\x27Agent\.Control\.1\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Agent\.Control\.1\x22|\x27Agent\.Control\.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8856</id>
        <msg>WEB-ACTIVEX Microsoft Agent v1.5 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-020.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4691</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:6bffd098-a112-3610-9833-46c3f87e345a; dce_opnum:22; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; content:&quot;|5C 00|&quot;; distance:12; content:!&quot;|00 00|&quot;; within:256; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>9027</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrJoinDomain2 overflow attempt</msg>
        <nessus>11921</nessus>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-070.mspx</url>
      </rule>
      <rule>
        <bugtraq>21108</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5198</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A09AE68F-B14D-43ED-B713-BA413F034904&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A09AE68F-B14D-43ED-B713-BA413F034904\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9129</id>
        <msg>WEB-ACTIVEX WinZip FileView 6.1 ActiveX clsid access</msg>
        <url>www.winzip.com/wz7245.htm</url>
      </rule>
      <rule>
        <bugtraq>21108</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5198</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|0|00|9|00|A|00|E|00|6|00|8|00|F|00|-|00|B|00|1|00|4|00|D|00|-|00|4|00|3|00|E|00|D|00|-|00|B|00|7|00|1|00|3|00|-|00|B|00|A|00|4|00|1|00|3|00|F|00|0|00|3|00|4|00|9|00|0|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x000\x009\x00A\x00E\x006\x008\x00F\x00-\x00B\x001\x004\x00D\x00-\x004\x003\x00E\x00D\x00-\x00B\x007\x001\x003\x00-\x00B\x00A\x004\x001\x003\x00F\x000\x003\x004\x009\x000\x004\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9130</id>
        <msg>WEB-ACTIVEX WinZip FileView 6.1 ActiveX clsid unicode access</msg>
        <url>www.winzip.com/wz7245.htm</url>
      </rule>
      <rule>
        <bugtraq>21108</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5198</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WZFILEVIEW.FileViewCtrl.61&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WZFILEVIEW\.FileViewCtrl\.61(\.\d)?\x22|\x27WZFILEVIEW\.FileViewCtrl\.61(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WZFILEVIEW\.FileViewCtrl\.61(\.\d)?\x22|\x27WZFILEVIEW\.FileViewCtrl\.61(\.\d)?\x27)\s*\)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9131</id>
        <msg>WEB-ACTIVEX WinZip FileView 6.1 ActiveX function call access</msg>
        <url>www.winzip.com/wz7245.htm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D9998BD0-7957-11D2-8FED-00606730D3AA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D9998BD0-7957-11D2-8FED-00606730D3AA\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9427</id>
        <msg>WEB-ACTIVEX Acer LunchApp.APlunch ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|9|00|9|00|9|00|8|00|B|00|D|00|0|00|-|00|7|00|9|00|5|00|7|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|F|00|E|00|D|00|-|00|0|00|0|00|6|00|0|00|6|00|7|00|3|00|0|00|D|00|3|00|A|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9428</id>
        <msg>WEB-ACTIVEX Acer LunchApp.APlunch ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>21034</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|C2 AB CD AB|&quot;; byte_test:4,&lt;,500,0,relative,little; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9433</id>
        <msg>WEB-CLIENT Microsoft Agent buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-068.mspx</url>
      </rule>
      <rule>
        <bugtraq>21155</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CA8A9780-280D-11CF-A24D-444553540000&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CA8A9780-280D-11CF-A24D-444553540000\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CA8A9780-280D-11CF-A24D-444553540000\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(execCommand|LoadFile|src|setLayoutMode|setNamedDest|setPageMode))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9626</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX clsid access</msg>
        <url>www.adobe.com/support/security/advisories/apsa06-02.html</url>
      </rule>
      <rule>
        <bugtraq>21155</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|A|00|8|00|A|00|9|00|7|00|8|00|0|00|-|00|2|00|8|00|0|00|D|00|-|00|1|00|1|00|C|00|F|00|-|00|A|00|2|00|4|00|D|00|-|00|4|00|4|00|4|00|5|00|5|00|3|00|5|00|4|00|0|00|0|00|0|00|0|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00A\x008\x00A\x009\x007\x008\x000\x00-\x002\x008\x000\x00D\x00-\x001\x001\x00C\x00F\x00-\x00A\x002\x004\x00D\x00-\x004\x004\x004\x005\x005\x003\x005\x004\x000\x000\x000\x000\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9627</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX clsid unicode access</msg>
        <url>www.adobe.com/support/security/advisories/apsa06-02.html</url>
      </rule>
      <rule>
        <bugtraq>23246</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6334</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;238F6F83-B8B4-11cf-8771-00A024541EE3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*238F6F83-B8B4-11cf-8771-00A024541EE3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SendChannelData)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*238F6F83-B8B4-11cf-8771-00A024541EE3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SendChannelData))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9629</id>
        <msg>WEB-ACTIVEX Citrix.ICAClient ActiveX clsid access</msg>
        <url>support.citrix.com/article/CTX111827</url>
      </rule>
      <rule>
        <bugtraq>23246</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6334</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|3|00|8|00|F|00|6|00|F|00|8|00|3|00|-|00|B|00|8|00|B|00|4|00|-|00|1|00|1|00|c|00|f|00|-|00|8|00|7|00|7|00|1|00|-|00|0|00|0|00|A|00|0|00|2|00|4|00|5|00|4|00|1|00|E|00|E|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x003\x008\x00F\x006\x00F\x008\x003\x00-\x00B\x008\x00B\x004\x00-\x001\x001\x00c\x00f\x00-\x008\x007\x007\x001\x00-\x000\x000\x00A\x000\x002\x004\x005\x004\x001\x00E\x00E\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9630</id>
        <msg>WEB-ACTIVEX Citrix.ICAClient ActiveX clsid unicode access</msg>
        <url>support.citrix.com/article/CTX111827</url>
      </rule>
      <rule>
        <bugtraq>23246</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6334</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Citrix.ICAClient&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Citrix\.ICAClient(\.\d)?\x22|\x27Citrix\.ICAClient(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SendChannelData\s*|.*(?P=v)\s*\.\s*SendChannelData\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Citrix\.ICAClient(\.\d)?\x22|\x27Citrix\.ICAClient(\.\d)?\x27)\s*\)(\s*\.\s*SendChannelData\s*|.*(?P=n)\s*\.\s*SendChannelData\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9631</id>
        <msg>WEB-ACTIVEX Citrix.ICAClient ActiveX function call access</msg>
        <url>support.citrix.com/article/CTX111827</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-5559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ADODB.Connection.2.7&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22ADODB.Connection.2.7\x22|\x27ADODB.Connection.2.7\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(Execute)\s*\(|.*\3\s*\.\s*(Execute)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ADODB.Connection.2.7\x22|\x27ADODB.Connection.2.7\x27)\s*\)(\s*\.\s*(Execute)\s*\(|.*\7\s*\.\s*(Execute)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9640</id>
        <msg>WEB-ACTIVEX ADODB.Connection ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-009.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0059</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:975201B0-59CA-11D0-A8D5-00A0C90D8051; dce_opnum:4; dce_stub_data; byte_test:4,&gt;,128,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>9769</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msqueue function 4 overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>21607</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6603</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AA218328-0EA8-4D70-8972-E987A9190FF4&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*AA218328-0EA8-4D70-8972-E987A9190FF4\s*}?\4.*\3\.(TextETACalculating)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA218328-0EA8-4D70-8972-E987A9190FF4\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(TextETACalculating)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9793</id>
        <msg>WEB-ACTIVEX YMMAPI.YMailAttach ActiveX clsid access</msg>
        <url>messenger.yahoo.com/security_update.php?id=120806</url>
      </rule>
      <rule>
        <bugtraq>21607</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6603</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|A|00|2|00|1|00|8|00|3|00|2|00|8|00|-|00|0|00|E|00|A|00|8|00|-|00|4|00|D|00|7|00|0|00|-|00|8|00|9|00|7|00|2|00|-|00|E|00|9|00|8|00|7|00|A|00|9|00|1|00|9|00|0|00|F|00|F|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x00A\x002\x001\x008\x003\x002\x008\x00-\x000\x00E\x00A\x008\x00-\x004\x00D\x007\x000\x00-\x008\x009\x007\x002\x00-\x00E\x009\x008\x007\x00A\x009\x001\x009\x000\x00F\x00F\x004\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9794</id>
        <msg>WEB-ACTIVEX YMMAPI.YMailAttach ActiveX clsid unicode access</msg>
        <url>messenger.yahoo.com/security_update.php?id=120806</url>
      </rule>
      <rule>
        <bugtraq>21132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5966</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DA2BD42B-07E8-413A-9FEA-BB3B2E825340&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*DA2BD42B-07E8-413A-9FEA-BB3B2E825340\s*}?\4.*\3\.(Analizar|Reinicializar)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DA2BD42B-07E8-413A-9FEA-BB3B2E825340\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(Analizar|Reinicializar)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9795</id>
        <msg>WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5966</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|A|00|2|00|B|00|D|00|4|00|2|00|B|00|-|00|0|00|7|00|E|00|8|00|-|00|4|00|1|00|3|00|A|00|-|00|9|00|F|00|E|00|A|00|-|00|B|00|B|00|3|00|B|00|2|00|E|00|8|00|2|00|5|00|3|00|4|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00A\x002\x00B\x00D\x004\x002\x00B\x00-\x000\x007\x00E\x008\x00-\x004\x001\x003\x00A\x00-\x009\x00F\x00E\x00A\x00-\x00B\x00B\x003\x00B\x002\x00E\x008\x002\x005\x003\x004\x000\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9796</id>
        <msg>WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ActiveScan.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22ActiveScan.1\x22|\x27ActiveScan.1\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(Analizar|Reinicializar)\s*\(|.*\3\s*\.\s*(Analizar|Reinicializar)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ActiveScan.1\x22|\x27ActiveScan.1\x27)\s*\)(\s*\.\s*(Analizar|Reinicializar)\s*\(|.*\7\s*\.\s*(Analizar|Reinicializar)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9797</id>
        <msg>WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>21132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5966</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DA2BD42B-07E8-413A-9FEA-BB3B2E825340&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*DA2BD42B-07E8-413A-9FEA-BB3B2E825340\s*}?\4.*\3\.(ObtenerTamano)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DA2BD42B-07E8-413A-9FEA-BB3B2E825340\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(ObtenerTamano)\(/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9798</id>
        <msg>WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5966</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|A|00|2|00|B|00|D|00|4|00|2|00|B|00|-|00|0|00|7|00|E|00|8|00|-|00|4|00|1|00|3|00|A|00|-|00|9|00|F|00|E|00|A|00|-|00|B|00|B|00|3|00|B|00|2|00|E|00|8|00|2|00|5|00|3|00|4|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00A\x002\x00B\x00D\x004\x002\x00B\x00-\x000\x007\x00E\x008\x00-\x004\x001\x003\x00A\x00-\x009\x00F\x00E\x00A\x00-\x00B\x00B\x003\x00B\x002\x00E\x008\x002\x005\x003\x004\x000\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9799</id>
        <msg>WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PAVPZ.SOS.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22PAVPZ.SOS.1\x22|\x27PAVPZ.SOS.1\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(ObtenerTamano)\s*\(|.*\3\s*\.\s*(ObtenerTamano)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PAVPZ.SOS.1\x22|\x27PAVPZ.SOS.1\x27)\s*\)(\s*\.\s*(ObtenerTamano)\s*\(|.*\7\s*\.\s*(ObtenerTamano)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9800</id>
        <msg>WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>21221</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6076</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62B93DF0-8B02-11CE-876C-00805F842837; dce_opnum:37; dce_stub_data; byte_test:4,&gt;,4096,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service dcerpc; classtype:attempted-admin;</filter2>
        <id>9806</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc GetGroupStatus overflow attempt</msg>
        <url>www.lssec.com/advisories/LS-20060908.pdf</url>
      </rule>
      <rule>
        <bugtraq>21607</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6603</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YMMAPI.YMailAttach&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22YMMAPI.YMailAttach\x22|\x27YMMAPI.YMailAttach\x27)\s*\x3b.*(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)(\s*\.\s*(TextETACalculating)\s*\(|.*\3\s*\.\s*(TextETACalculating)\s*\()|(\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YMMAPI.YMailAttach\x22|\x27YMMAPI.YMailAttach\x27)\s*\)(\s*\.\s*(TextETACalculating)\s*\(|.*\7\s*\.\s*(TextETACalculating)\s*\()/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9812</id>
        <msg>WEB-ACTIVEX Yahoo Messenger YMailAttach ActiveX function call access</msg>
        <url>messenger.yahoo.com/security_update.php?id=120806</url>
      </rule>
      <rule>
        <bugtraq>20930</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5650</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;54BDE6EC-F42F-4500-AC46-905177444300&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*id\s*=((\x22|\x27)([^\2]*)\2)\s*classid\s*=\s*(\x22|\x27|)clsid\s*\x3a\s*{?\s*54BDE6EC-F42F-4500-AC46-905177444300\s*}?\4.*\3\.(DownloadAgent)\(|&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*54BDE6EC-F42F-4500-AC46-905177444300\s*}?\s*\6\s*id\s*=\s*((\x22|\x27)([^\8]*)\8).*\9\.(DownloadAgent)\(/siO&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9814</id>
        <msg>WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>20930</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5650</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|4|00|B|00|D|00|E|00|6|00|E|00|C|00|-|00|F|00|4|00|2|00|F|00|-|00|4|00|5|00|0|00|0|00|-|00|A|00|C|00|4|00|6|00|-|00|9|00|0|00|5|00|1|00|7|00|7|00|4|00|4|00|4|00|3|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x004\x00B\x00D\x00E\x006\x00E\x00C\x00-\x00F\x004\x002\x00F\x00-\x004\x005\x000\x000\x00-\x00A\x00C\x004\x006\x00-\x009\x000\x005\x001\x007\x007\x004\x004\x004\x003\x000\x000\x00(}\x00)?\5/siO&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9815</id>
        <msg>WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>20930</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5650</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ICQPhone.SipxPhoneManager&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ICQPhone.SipxPhoneManager(\.\d)?\x22|\x27ICQPhone.SipxPhoneManager(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DownloadAgent)\s*\(|.*(?P=v)\s*\.\s*(DownloadAgent)\s*\()|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ICQPhone.SipxPhoneManager(\.\d)?\x22|\x27ICQPhone.SipxPhoneManager(\.\d)?\x27)\s*\)(\s*\.\s*(DownloadAgent)\s*\(|.*(?P=n)\s*\.\s*(DownloadAgent)\s*\()/siO&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9816</id>
        <msg>WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;127698E4-E730-4E5C-A2B1-21490A70C8A1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*127698E4-E730-4E5C-A2B1-21490A70C8A1\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9817</id>
        <msg>WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX clsid access</msg>
        <url>osvdb.org/27230</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|2|00|7|00|6|00|9|00|8|00|E|00|4|00|-|00|E|00|7|00|3|00|0|00|-|00|4|00|E|00|5|00|C|00|-|00|A|00|2|00|B|00|1|00|-|00|2|00|1|00|4|00|9|00|0|00|A|00|7|00|0|00|C|00|8|00|A|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x002\x007\x006\x009\x008\x00E\x004\x00-\x00E\x007\x003\x000\x00-\x004\x00E\x005\x00C\x00-\x00A\x002\x00B\x001\x00-\x002\x001\x004\x009\x000\x00A\x007\x000\x00C\x008\x00A\x001\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9818</id>
        <msg>WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX clsid unicode access</msg>
        <url>osvdb.org/27230</url>
      </rule>
      <rule>
        <bugtraq>19069</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3729</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OWC11.DataSourceControl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OWC11\.DataSourceControl(\.\d+)?\x22|\x27OWC11\.DataSourceControl(\.\d+)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OWC11\.DataSourceControl(\.\d+)?\x22|\x27OWC11\.DataSourceControl(\.\d+)?\x27)\s*\)/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>9820</id>
        <msg>WEB-ACTIVEX OWC11.DataSourceControl.11 ActiveX function call access</msg>
        <url>osvdb.org/27111</url>
      </rule>
      <rule>
        <bugtraq>18946</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3591</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;438DA5E0-F171-11D0-984E-0000F80270F8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*438DA5E0-F171-11D0-984E-0000F80270F8\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9821</id>
        <msg>WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX clsid access</msg>
        <url>osvdb.org/27056</url>
      </rule>
      <rule>
        <bugtraq>18946</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3591</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|3|00|8|00|D|00|A|00|5|00|E|00|0|00|-|00|F|00|1|00|7|00|1|00|-|00|1|00|1|00|D|00|0|00|-|00|9|00|8|00|4|00|E|00|-|00|0|00|0|00|0|00|0|00|F|00|8|00|0|00|2|00|7|00|0|00|F|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x003\x008\x00D\x00A\x005\x00E\x000\x00-\x00F\x001\x007\x001\x00-\x001\x001\x00D\x000\x00-\x009\x008\x004\x00E\x00-\x000\x000\x000\x000\x00F\x008\x000\x002\x007\x000\x00F\x008\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9822</id>
        <msg>WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX clsid unicode access</msg>
        <url>osvdb.org/27056</url>
      </rule>
      <rule>
        <bugtraq>21831</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6838</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BADA82CB-BF48-4D76-9611-78E2C6F49F03&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BADA82CB-BF48-4D76-9611-78E2C6F49F03\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9824</id>
        <msg>WEB-ACTIVEX Rediff Bol Downloader ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21831</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6838</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|D|00|A|00|8|00|2|00|C|00|B|00|-|00|B|00|F|00|4|00|8|00|-|00|4|00|D|00|7|00|6|00|-|00|9|00|6|00|1|00|1|00|-|00|7|00|8|00|E|00|2|00|C|00|6|00|F|00|4|00|9|00|F|00|0|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00A\x00D\x00A\x008\x002\x00C\x00B\x00-\x00B\x00F\x004\x008\x00-\x004\x00D\x007\x006\x00-\x009\x006\x001\x001\x00-\x007\x008\x00E\x002\x00C\x006\x00F\x004\x009\x00F\x000\x003\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9825</id>
        <msg>WEB-ACTIVEX Rediff Bol Downloader ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21831</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6838</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BOLDOWNLOADER.BolDownloaderCtrl.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22BOLDOWNLOADER.BolDownloaderCtrl.1\x22|\x27BOLDOWNLOADER.BolDownloaderCtrl.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BOLDOWNLOADER.BolDownloaderCtrl.1\x22|\x27BOLDOWNLOADER.BolDownloaderCtrl.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9826</id>
        <msg>WEB-ACTIVEX Rediff Bol Downloader ActiveX function call access</msg>
      </rule>
    </attacks>
    <groupid>110</groupid>
    <groupname>OS / Windows</groupname>
    <warnings>
      <rule>
        <bugtraq>22010</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-0168</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62B93DF0-8B02-11CE-876C-00805F842837; dce_opnum:191; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>10024</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ClientDBMiniAgentClose attempt</msg>
        <url>www.lssec.com/advisories/LS-20061002.pdf</url>
      </rule>
      <rule>
        <bugtraq>20365</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5143</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:45; dce_stub_data; byte_test:4,&gt;,1,0,relative,dce; content:&quot;|05 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>10030</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath_Function_45 overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:47; dce_stub_data; byte_test:4,&gt;,624,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>10036</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor ASRemotePFC overflow attempt</msg>
        <url>www.kb.cert.org/vuls/id/180336</url>
      </rule>
      <rule>
        <bugtraq>22005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62B93DF0-8B02-11CE-876C-00805F842837; dce_opnum:207; dce_stub_data; byte_test:4,&gt;,1024,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>10117</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc GetGCBHandleFromGroupName overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22639</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|04 00 03 00|&quot;; within:4; byte_test:4,&gt;,600,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>10202</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetRealTimeScanConfigInfo attempt</msg>
        <url>esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</url>
      </rule>
      <rule>
        <bugtraq>22639</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|17 00 0A 00|&quot;; within:4; byte_test:4,&gt;,600,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>10208</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect COMN_NetTestConnection attempt</msg>
        <url>esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:367abb81-9844-35f1-ad32-98f038001003; dce_opnum:36; dce_stub_data; byte_test:4,=,1,24,relative,dce; content:&quot;|00 00 00 00|&quot;; within:4; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>10285</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP svcctl ChangeServiceConfig2A attempt</msg>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;01010e00-5e80-11d8-9e86-0007e96c65ae&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*01010e00-5e80-11d8-9e86-0007e96c65ae\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(EnableExtension)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*01010e00-5e80-11d8-9e86-0007e96c65ae\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(EnableExtension))\s*\(/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>10393</id>
        <msg>WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX clsid access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|1|00|0|00|1|00|0|00|e|00|0|00|0|00|-|00|5|00|e|00|8|00|0|00|-|00|1|00|1|00|d|00|8|00|-|00|9|00|e|00|8|00|6|00|-|00|0|00|0|00|0|00|7|00|e|00|9|00|6|00|c|00|6|00|5|00|a|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x001\x000\x001\x000\x00e\x000\x000\x00-\x005\x00e\x008\x000\x00-\x001\x001\x00d\x008\x00-\x009\x00e\x008\x006\x00-\x000\x000\x000\x007\x00e\x009\x006\x00c\x006\x005\x00a\x00e\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>10394</id>
        <msg>WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX clsid unicode access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SPRT.SmartIssue&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SPRT\.SmartIssue(\.\d)?\x22|\x27SPRT\.SmartIssue(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*EnableExtension\s*|.*(?P=v)\s*\.\s*EnableExtension\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SPRT\.SmartIssue(\.\d)?\x22|\x27SPRT\.SmartIssue(\.\d)?\x27)\s*\)(\s*\.\s*EnableExtension\s*|.*(?P=n)\s*\.\s*EnableExtension\s*)\s*\(/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>10395</id>
        <msg>WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX function call access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <bugtraq>22551</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-0915</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot; |00 00 01|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10408</id>
        <msg>RPC portmap HP-UX Single Logical Screen SLSD tcp request</msg>
      </rule>
      <rule>
        <bugtraq>22551</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-0915</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot; |00 00 01|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10409</id>
        <msg>RPC portmap HP-UX Single Logical Screen SLSD udp request</msg>
      </rule>
      <rule>
        <bugtraq>22551</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-0915</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 5C E0|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10410</id>
        <msg>RPC portmap HP-UX Single Logical Screen SLSD tcp request</msg>
      </rule>
      <rule>
        <bugtraq>22551</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-0915</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 5C E0|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10411</id>
        <msg>RPC portmap HP-UX Single Logical Screen SLSD udp request</msg>
      </rule>
      <rule>
        <bugtraq>22994</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1447</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62B93DF0-8B02-11CE-876C-00805F842837; dce_opnum:15,16,17; content:&quot;|05 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>10486</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 15,16,17 attempt</msg>
        <url>www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0605</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:b9e79e60-3d52-11ce-aaa1-00006901293f; dce_opnum:3; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>11073</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rpcss _RemoteGetClassObject attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0605</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:b9e79e60-3d52-11ce-aaa1-00006901293f; dce_opnum:3; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>11074</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP rpcss _RemoteGetClassObject attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>16838</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2006-0900</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A5|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>11288</id>
        <msg>RPC portmap mountd tcp request</msg>
      </rule>
      <rule>
        <bugtraq>16838</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2006-0900</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; pcre:&quot;/^[\x00\x80]\x00\x00\x00/s&quot;; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>11289</id>
        <msg>RPC portmap mountd tcp zero-length payload denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345778-1234-abcd-ef00-0123456789ab; dce_opnum:19; dce_stub_data; isdataat:32,relative; pcre:&quot;/^.{20}(.{4}).{4}(?!\1)/Rs&quot;; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>11442</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP lsarpc LsarAddPrivilegesToAccount overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:12345778-1234-abcd-ef00-0123456789ab; dce_opnum:19; dce_stub_data; isdataat:32,relative; pcre:&quot;/^.{20}(.{4}).{4}(?!\1)/Rs&quot;; content:&quot;|04 00|&quot;; metadata:service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>11443</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP lsarpc LsarAddPrivilegesToAccount overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24188</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXImageTransform.Microsoft.Chroma&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DXImageTransform\.Microsoft\.Chroma\x22|\x27DXImageTransform\.Microsoft\.Chroma\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DXImageTransform\.Microsoft\.Chroma\x22|\x27DXImageTransform\.Microsoft\.Chroma\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>11620</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX function call access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <bugtraq>24188</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|X|00|I|00|m|00|a|00|g|00|e|00|T|00|r|00|a|00|n|00|s|00|f|00|o|00|r|00|m|00|.|00|M|00|i|00|c|00|r|00|o|00|s|00|o|00|f|00|t|00|.|00|C|00|h|00|r|00|o|00|m|00|a|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)D\x00X\x00I\x00m\x00a\x00g\x00e\x00T\x00r\x00a\x00n\x00s\x00f\x00o\x00r\x00m\x00.\x00M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00C\x00h\x00r\x00o\x00m\x00a\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00X\x00I\x00m\x00a\x00g\x00e\x00T\x00r\x00a\x00n\x00s\x00f\x00o\x00r\x00m\x00.\x00M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00.\x00C\x00h\x00r\x00o\x00m\x00a\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11621</id>
        <msg>WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX function call unicode access</msg>
        <url>www.securityfocus.com/archive/1/443907</url>
      </rule>
      <rule>
        <bugtraq>24094</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140050-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140050-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(DriverName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140050-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(DriverName))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11624</id>
        <msg>WEB-ACTIVEX LeadTools ISIS ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html</url>
      </rule>
      <rule>
        <bugtraq>24094</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|0|00|5|00|0|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11625</id>
        <msg>WEB-ACTIVEX LeadTools ISIS ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html</url>
      </rule>
      <rule>
        <bugtraq>24094</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADIsis.LEADIsis&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADIsis\.LEADIsis\x22|\x27LEADIsis\.LEADIsis\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DriverName\s*|.*(?P=v)\s*\.\s*DriverName\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADIsis\.LEADIsis\x22|\x27LEADIsis\.LEADIsis\x27)\s*\)(\s*\.\s*DriverName\s*|.*(?P=n)\s*\.\s*DriverName)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11626</id>
        <msg>WEB-ACTIVEX LeadTools ISIS ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html</url>
      </rule>
      <rule>
        <bugtraq>24094</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|I|00|s|00|i|00|s|00|.|00|L|00|E|00|A|00|D|00|I|00|s|00|i|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)L\x00E\x00A\x00D\x00I\x00s\x00i\x00s\x00.\x00L\x00E\x00A\x00D\x00I\x00s\x00i\x00s\x00(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)L\x00E\x00A\x00D\x00I\x00s\x00i\x00s\x00.\x00L\x00E\x00A\x00D\x00I\x00s\x00i\x00s\x00(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11627</id>
        <msg>WEB-ACTIVEX LeadTools ISIS ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html</url>
      </rule>
      <rule>
        <bugtraq>24040</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterVariant.LEADRasterVariant&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterVariant\.LEADRasterVariant\x22|\x27LEADRasterVariant\.LEADRasterVariant\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*BitmapDataPath\s*|.*(?P=v)\s*\.\s*BitmapDataPath\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterVariant\.LEADRasterVariant\x22|\x27LEADRasterVariant\.LEADRasterVariant\x27)\s*\)(\s*\.\s*BitmapDataPath\s*|.*(?P=n)\s*\.\s*BitmapDataPath)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11628</id>
        <msg>WEB-ACTIVEX LeadTools JPEG 2000 COM Object ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-18-leadtools-jpeg-2000-com.html</url>
      </rule>
      <rule>
        <bugtraq>24040</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|V|00|a|00|r|00|i|00|a|00|n|00|t|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|V|00|a|00|r|00|i|00|a|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11629</id>
        <msg>WEB-ACTIVEX LeadTools JPEG 2000 COM Object ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-18-leadtools-jpeg-2000-com.html</url>
      </rule>
      <rule>
        <bugtraq>24133</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140B79-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B79-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(Directory)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B79-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\s*\.\s*(Directory))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11630</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-24-leadtools-raster-dialog-file.html</url>
      </rule>
      <rule>
        <bugtraq>24133</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|B|00|7|00|9|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q13&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11631</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-24-leadtools-raster-dialog-file.html</url>
      </rule>
      <rule>
        <bugtraq>24133</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterDlgFile.LEADRasterDlgFile&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterDlgFile\.LEADRasterDlgFile\x22|\x27LEADRasterDlgFile\.LEADRasterDlgFile\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Directory\s*|.*(?P=v)\s*\.\s*Directory\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterDlgFile\.LEADRasterDlgFile\x22|\x27LEADRasterDlgFile\.LEADRasterDlgFile\x27)\s*\)(\s*\.\s*Directory\s*|.*(?P=n)\s*\.\s*Directory)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11632</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-24-leadtools-raster-dialog-file.html</url>
      </rule>
      <rule>
        <bugtraq>24133</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|l|00|g|00|F|00|i|00|l|00|e|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|l|00|g|00|F|00|i|00|l|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00l\x00g\x00F\x00i\x00l\x00e\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00l\x00g\x00F\x00i\x00l\x00e\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00l\x00g\x00F\x00i\x00l\x00e\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00l\x00g\x00F\x00i\x00l\x00e\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11633</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-24-leadtools-raster-dialog-file.html</url>
      </rule>
      <rule>
        <bugtraq>24153</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140BB5-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140BB5-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(DestinationPath)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140BB5-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\s*\.\s*(DestinationPath))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11634</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-25-leadtools-raster-dialog-filed.html</url>
      </rule>
      <rule>
        <bugtraq>24153</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|B|00|B|00|5|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q18&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11635</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-25-leadtools-raster-dialog-filed.html</url>
      </rule>
      <rule>
        <bugtraq>24153</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterDocument.LEADRasterDocument&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterDocument\.LEADRasterDocument\x22|\x27LEADRasterDocument\.LEADRasterDocument\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DestinationPath\s*|.*(?P=v)\s*\.\s*DestinationPath\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterDocument\.LEADRasterDocument\x22|\x27LEADRasterDocument\.LEADRasterDocument\x27)\s*\)(\s*\.\s*DestinationPath\s*|.*(?P=n)\s*\.\s*DestinationPath)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11636</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-25-leadtools-raster-dialog-filed.html</url>
      </rule>
      <rule>
        <bugtraq>24153</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|o|00|c|00|u|00|m|00|e|00|n|00|t|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|o|00|c|00|u|00|m|00|e|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q19&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00(?P=q19)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00(?P=q20)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11637</id>
        <msg>WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-25-leadtools-raster-dialog-filed.html</url>
      </rule>
      <rule>
        <bugtraq>24179</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140B30-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q21&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B30-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q21)(\s|&gt;).*(?P=id1)\s*\.\s*(DictionaryFileName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q22&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B30-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q22)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\s*\.\s*(DictionaryFileName))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11638</id>
        <msg>WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-26-leadtools-raster-ocr-document.html</url>
      </rule>
      <rule>
        <bugtraq>24179</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|B|00|3|00|0|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q23&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q23)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11639</id>
        <msg>WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-26-leadtools-raster-ocr-document.html</url>
      </rule>
      <rule>
        <bugtraq>24179</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterDocument.LEADRasterDocument&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterDocument\.LEADRasterDocument\x22|\x27LEADRasterDocument\.LEADRasterDocument\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DictionaryFileName\s*|.*(?P=v)\s*\.\s*DictionaryFileName\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterDocument\.LEADRasterDocument\x22|\x27LEADRasterDocument\.LEADRasterDocument\x27)\s*\)(\s*\.\s*DictionaryFileName\s*|.*(?P=n)\s*\.\s*DictionaryFileName)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11640</id>
        <msg>WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-26-leadtools-raster-ocr-document.html</url>
      </rule>
      <rule>
        <bugtraq>24179</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|o|00|c|00|u|00|m|00|e|00|n|00|t|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|D|00|o|00|c|00|u|00|m|00|e|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q24&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00(?P=q24)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q25&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00D\x00o\x00c\x00u\x00m\x00e\x00n\x00t\x00(?P=q25)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11641</id>
        <msg>WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-26-leadtools-raster-ocr-document.html</url>
      </rule>
      <rule>
        <bugtraq>24193</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140797-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q26&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140797-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q26)(\s|&gt;).*(?P=id1)\s*\.\s*(DriverName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q27&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140797-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q27)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\s*\.\s*(DriverName))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11642</id>
        <msg>WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html</url>
      </rule>
      <rule>
        <bugtraq>24193</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|7|00|9|00|7|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q28&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q28)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11643</id>
        <msg>WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html</url>
      </rule>
      <rule>
        <bugtraq>24193</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterISIS.LeadRasterISIS&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterISIS\.LeadRasterISIS\x22|\x27LEADRasterISIS\.LeadRasterISIS\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DriverName\s*|.*(?P=v)\s*\.\s*DriverName\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterISIS\.LeadRasterISIS\x22|\x27LEADRasterISIS\.LeadRasterISIS\x27)\s*\)(\s*\.\s*DriverName\s*|.*(?P=n)\s*\.\s*DriverName)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11644</id>
        <msg>WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html</url>
      </rule>
      <rule>
        <bugtraq>24193</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|I|00|S|00|I|00|S|00|.|00|L|00|e|00|a|00|d|00|R|00|a|00|s|00|t|00|e|00|r|00|I|00|S|00|I|00|S|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q29&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00I\x00S\x00I\x00S\x00.\x00L\x00e\x00a\x00d\x00R\x00a\x00s\x00t\x00e\x00r\x00I\x00S\x00I\x00S\x00(?P=q29)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q30&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00I\x00S\x00I\x00S\x00.\x00L\x00e\x00a\x00d\x00R\x00a\x00s\x00t\x00e\x00r\x00I\x00S\x00I\x00S\x00(?P=q30)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11645</id>
        <msg>WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html</url>
      </rule>
      <rule>
        <bugtraq>24057</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140780-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q31&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140780-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q31)(\s|&gt;).*(?P=id1)\s*\.\s*(BrowseDir)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q32&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140780-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q32)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\.(BrowseDir))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11646</id>
        <msg>WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-20-leadtools-raster-thumbnail.html</url>
      </rule>
      <rule>
        <bugtraq>24057</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|7|00|8|00|0|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q33&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q33)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11647</id>
        <msg>WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-20-leadtools-raster-thumbnail.html</url>
      </rule>
      <rule>
        <bugtraq>24057</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterThumbnail.LEADRasterThumbnail&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterThumbnail\.LEADRasterThumbnail\x22|\x27LEADRasterThumbnail\.LEADRasterThumbnail\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*BrowseDir\s*|.*(?P=v)\s*\.\s*BrowseDir\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterThumbnail\.LEADRasterThumbnail\x22|\x27LEADRasterThumbnail\.LEADRasterThumbnail\x27)\s*\)(\s*\.\s*BrowseDir\s*|.*(?P=n)\s*\.\s*BrowseDir\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>11648</id>
        <msg>WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-20-leadtools-raster-thumbnail.html</url>
      </rule>
      <rule>
        <bugtraq>24057</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|T|00|h|00|u|00|m|00|b|00|n|00|a|00|i|00|l|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|T|00|h|00|u|00|m|00|b|00|n|00|a|00|i|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q34&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00T\x00h\x00u\x00m\x00b\x00n\x00a\x00i\x00l\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00T\x00h\x00u\x00m\x00b\x00n\x00a\x00i\x00l\x00(?P=q34)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q35&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00T\x00h\x00u\x00m\x00b\x00n\x00a\x00i\x00l\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00T\x00h\x00u\x00m\x00b\x00n\x00a\x00i\x00l\x00(?P=q35)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11649</id>
        <msg>WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-20-leadtools-raster-thumbnail.html</url>
      </rule>
      <rule>
        <bugtraq>24075</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140B9B-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m15&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m15)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q36&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B9B-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q36)(\s|&gt;).*(?P=id1)\s*\.\s*(WriteDataToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q37&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140B9B-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q37)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m16&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m16)(\s|&gt;).*(?P=id2)\.(WriteDataToFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11650</id>
        <msg>WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-21-leadtools-raster-variant.html</url>
      </rule>
      <rule>
        <bugtraq>24075</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|B|00|9|00|B|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q38&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q38)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11651</id>
        <msg>WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-21-leadtools-raster-variant.html</url>
      </rule>
      <rule>
        <bugtraq>24075</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADRasterVariant.LEADRasterVariant&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADRasterVariant\.LEADRasterVariant\x22|\x27LEADRasterVariant\.LEADRasterVariant\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*WriteDataToFile\s*|.*(?P=v)\s*\.\s*WriteDataToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADRasterVariant\.LEADRasterVariant\x22|\x27LEADRasterVariant\.LEADRasterVariant\x27)\s*\)(\s*\.\s*WriteDataToFile\s*|.*(?P=n)\s*\.\s*WriteDataToFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>11652</id>
        <msg>WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-21-leadtools-raster-variant.html</url>
      </rule>
      <rule>
        <bugtraq>24075</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|V|00|a|00|r|00|i|00|a|00|n|00|t|00|.|00|L|00|E|00|A|00|D|00|R|00|a|00|s|00|t|00|e|00|r|00|V|00|a|00|r|00|i|00|a|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q39&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00(?P=q39)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q40&gt;\x22|\x27|)L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00.\x00L\x00E\x00A\x00D\x00R\x00a\x00s\x00t\x00e\x00r\x00V\x00a\x00r\x00i\x00a\x00n\x00t\x00(?P=q40)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11653</id>
        <msg>WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-21-leadtools-raster-variant.html</url>
      </rule>
      <rule>
        <bugtraq>24053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00140200-B1BA-11CE-ABC6-F5B2E79D9E3F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m17&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m17)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q41&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140200-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q41)(\s|&gt;).*(?P=id1)\s*\.\s*(BrowseDir)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q42&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*00140200-B1BA-11CE-ABC6-F5B2E79D9E3F\s*}?\s*(?P=q42)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m18&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m18)(\s|&gt;).*(?P=id2)\.(BrowseDir))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11654</id>
        <msg>WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-19-leadtools-thumbnail-browser.html</url>
      </rule>
      <rule>
        <bugtraq>24053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|1|00|4|00|0|00|2|00|0|00|0|00|-|00|B|00|1|00|B|00|A|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|C|00|6|00|-|00|F|00|5|00|B|00|2|00|E|00|7|00|9|00|D|00|9|00|E|00|3|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q43&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q43)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11655</id>
        <msg>WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-19-leadtools-thumbnail-browser.html</url>
      </rule>
      <rule>
        <bugtraq>24053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LEADThumb.LEADThumb&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LEADThumb\.LEADThumb\x22|\x27LEADThumb\.LEADThumb\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*BrowseDir\s*|.*(?P=v)\s*\.\s*BrowseDir\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LEADThumb\.LEADThumb\x22|\x27LEADThumb\.LEADThumb\x27)\s*\)(\s*\.\s*BrowseDir\s*|.*(?P=n)\s*\.\s*BrowseDir\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>11656</id>
        <msg>WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-19-leadtools-thumbnail-browser.html</url>
      </rule>
      <rule>
        <bugtraq>24053</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|E|00|A|00|D|00|T|00|h|00|u|00|m|00|b|00|.|00|L|00|E|00|A|00|D|00|T|00|h|00|u|00|m|00|b|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q44&gt;\x22|\x27|)L\x00E\x00A\x00D\x00T\x00h\x00u\x00m\x00b\x00.\x00L\x00E\x00A\x00D\x00T\x00h\x00u\x00m\x00b\x00(?P=q44)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q45&gt;\x22|\x27|)L\x00E\x00A\x00D\x00T\x00h\x00u\x00m\x00b\x00.\x00L\x00E\x00A\x00D\x00T\x00h\x00u\x00m\x00b\x00(?P=q45)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11657</id>
        <msg>WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-19-leadtools-thumbnail-browser.html</url>
      </rule>
      <rule>
        <bugtraq>24099</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;42BA826E-F8D8-4D8D-8C05-14ABCE00D4DD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42BA826E-F8D8-4D8D-8C05-14ABCE00D4DD\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(QuickZip)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42BA826E-F8D8-4D8D-8C05-14ABCE00D4DD\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(QuickZip))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11658</id>
        <msg>WEB-ACTIVEX Dart ZipLite Compression ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-bonus-dart-ziplite-compression.html</url>
      </rule>
      <rule>
        <bugtraq>24099</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|B|00|A|00|8|00|2|00|6|00|E|00|-|00|F|00|8|00|D|00|8|00|-|00|4|00|D|00|8|00|D|00|-|00|8|00|C|00|0|00|5|00|-|00|1|00|4|00|A|00|B|00|C|00|E|00|0|00|0|00|D|00|4|00|D|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11659</id>
        <msg>WEB-ACTIVEX Dart ZipLite Compression ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-22-bonus-dart-ziplite-compression.html</url>
      </rule>
      <rule>
        <bugtraq>24883</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3703</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;59DBDDA6-9A80-42A4-B824-9BC50CC172F5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*59DBDDA6-9A80-42A4-B824-9BC50CC172F5\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(Fill|DebugMsgLog|DownloadFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*59DBDDA6-9A80-42A4-B824-9BC50CC172F5\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(Fill|DebugMsgLog|DownloadFile))\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>11673</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24883</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3703</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|9|00|D|00|B|00|D|00|D|00|A|00|6|00|-|00|9|00|A|00|8|00|0|00|-|00|4|00|2|00|A|00|4|00|-|00|B|00|8|00|2|00|4|00|-|00|9|00|B|00|C|00|5|00|0|00|C|00|C|00|1|00|7|00|2|00|F|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11674</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24883</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3703</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SafeAndSoundATL.NixonConfigMgrEx&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SafeAndSoundATL\.NixonConfigMgrEx\x22|\x27SafeAndSoundATL\.NixonConfigMgrEx\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Fill|DebugMsgLog|DownloadFile)\s*|.*(?P=v)\s*\.\s*(Fill|DebugMsgLog|DownloadFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SafeAndSoundATL\.NixonConfigMgrEx\x22|\x27SafeAndSoundATL\.NixonConfigMgrEx\x27)\s*\)(\s*\.\s*(Fill|DebugMsgLog|DownloadFile)\s*|.*(?P=n)\s*\.\s*(Fill|DebugMsgLog|DownloadFile)\s*)\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>11675</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24883</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3703</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|a|00|f|00|e|00|A|00|n|00|d|00|S|00|o|00|u|00|n|00|d|00|A|00|T|00|L|00|.|00|N|00|i|00|x|00|o|00|n|00|C|00|o|00|n|00|f|00|i|00|g|00|M|00|g|00|r|00|E|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)S\x00a\x00f\x00e\x00A\x00n\x00d\x00S\x00o\x00u\x00n\x00d\x00A\x00T\x00L\x00.\x00N\x00i\x00x\x00o\x00n\x00C\x00o\x00n\x00f\x00i\x00g\x00M\x00g\x00r\x00E\x00x\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)S\x00a\x00f\x00e\x00A\x00n\x00d\x00S\x00o\x00u\x00n\x00d\x00A\x00T\x00L\x00.\x00N\x00i\x00x\x00o\x00n\x00C\x00o\x00n\x00f\x00i\x00g\x00M\x00g\x00r\x00E\x00x\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; classtype:attempted-user;</filter2>
        <id>11676</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AA0FB75C-C50E-47B6-B7E0-3B9C3FAA8AC4&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA0FB75C-C50E-47B6-B7E0-3B9C3FAA8AC4\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(URL)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AA0FB75C-C50E-47B6-B7E0-3B9C3FAA8AC4\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(URL))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11677</id>
        <msg>WEB-ACTIVEX Provideo Camimage Class ISSCamControl ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|A|00|0|00|F|00|B|00|7|00|5|00|C|00|-|00|C|00|5|00|0|00|E|00|-|00|4|00|7|00|B|00|6|00|-|00|B|00|7|00|E|00|0|00|-|00|3|00|B|00|9|00|C|00|3|00|F|00|A|00|A|00|8|00|A|00|C|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11678</id>
        <msg>WEB-ACTIVEX Provideo Camimage Class ISSCamControl ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>11922</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0567</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>flow:to_server,established; byte_test:1,&amp;,64,6; byte_test:1,&amp;,32,6; byte_test:1,&amp;,16,6; byte_test:1,&amp;,8,6; content:!&quot;|00 00 00 02|&quot;; depth:4; offset:12; content:&quot;|00 00 00 06|&quot;; within:4; distance:16; pcre:&quot;/^.{20}([\x01-\xff]|0x00[\x01-\xff]|\x00{2}[\x02-\xff]|\x00{2}\x01[\x15-\xff])/s&quot;; classtype:misc-attack;</filter2>
        <id>11684</id>
        <msg>EXPLOIT WINS overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS04-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>11372</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|01 00 00 00|&quot;; depth:4; offset:36; content:!&quot;|03 00|&quot;; depth:2; offset:44; byte_jump:2,50, from_beginning; content:!&quot;|00|&quot;; within:34; distance:58; classtype:attempted-admin;</filter2>
        <id>11816</id>
        <msg>NETBIOS Session Service NetDDE attack</msg>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3148</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9D39223E-AE8E-11D4-8FD3-00D0B7730277&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9D39223E-AE8E-11D4-8FD3-00D0B7730277\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(server)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9D39223E-AE8E-11D4-8FD3-00D0B7730277\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(server))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>11818</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX clsid access</msg>
        <url>www.frsirt.com/english/advisories/2007/2094</url>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3148</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|D|00|3|00|9|00|2|00|2|00|3|00|E|00|-|00|A|00|E|00|8|00|E|00|-|00|1|00|1|00|D|00|4|00|-|00|8|00|F|00|D|00|3|00|-|00|0|00|0|00|D|00|0|00|B|00|7|00|7|00|3|00|0|00|2|00|7|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11819</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX clsid unicode access</msg>
        <url>www.frsirt.com/english/advisories/2007/2094</url>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3148</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YWcVwr.WcViewer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YWcVwr\.WcViewer\x22|\x27YWcVwr\.WcViewer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*server\s*|.*(?P=v)\s*\.\s*server\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YWcVwr\.WcViewer\x22|\x27YWcVwr\.WcViewer\x27)\s*\)(\s*\.\s*server\s*|.*(?P=n)\s*\.\s*server)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>11820</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX function call access</msg>
        <url>www.frsirt.com/english/advisories/2007/2094</url>
      </rule>
      <rule>
        <bugtraq>24341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3148</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|W|00|c|00|V|00|w|00|r|00|.|00|W|00|c|00|V|00|i|00|e|00|w|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Y\x00W\x00c\x00V\x00w\x00r\x00.\x00W\x00c\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Y\x00W\x00c\x00V\x00w\x00r\x00.\x00W\x00c\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11821</id>
        <msg>WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX function call unicode access</msg>
        <url>www.frsirt.com/english/advisories/2007/2094</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EEE78591-FE22-11D0-8BEF-0060081841DE&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EEE78591-FE22-11D0-8BEF-0060081841DE\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Find)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EEE78591-FE22-11D0-8BEF-0060081841DE\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Find))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>11826</id>
        <msg>WEB-ACTIVEX Microsoft Voice Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|E|00|E|00|7|00|8|00|5|00|9|00|1|00|-|00|F|00|E|00|2|00|2|00|-|00|1|00|1|00|D|00|0|00|-|00|8|00|B|00|E|00|F|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|1|00|8|00|4|00|1|00|D|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>11827</id>
        <msg>WEB-ACTIVEX Microsoft Voice Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectSS.DirectSS&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DirectSS\.DirectSS\x22|\x27DirectSS\.DirectSS\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Find\s*|.*(?P=v)\s*\.\s*Find\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DirectSS\.DirectSS\x22|\x27DirectSS\.DirectSS\x27)\s*\)(\s*\.\s*Find\s*|.*(?P=n)\s*\.\s*Find\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>11828</id>
        <msg>WEB-ACTIVEX Microsoft Voice Control ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|i|00|r|00|e|00|c|00|t|00|S|00|S|00|.|00|D|00|i|00|r|00|e|00|c|00|t|00|S|00|S|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00S\x00S\x00.\x00D\x00i\x00r\x00e\x00c\x00t\x00S\x00S\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00S\x00S\x00.\x00D\x00i\x00r\x00e\x00c\x00t\x00S\x00S\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>11829</id>
        <msg>WEB-ACTIVEX Microsoft Voice Control ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4E3D9D1F-0C63-11D1-8BFB-0060081841DE&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4E3D9D1F-0C63-11D1-8BFB-0060081841DE\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(Find)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4E3D9D1F-0C63-11D1-8BFB-0060081841DE\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(Find))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>11830</id>
        <msg>WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|E|00|3|00|D|00|9|00|D|00|1|00|F|00|-|00|0|00|C|00|6|00|3|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|B|00|F|00|B|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|1|00|8|00|4|00|1|00|D|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>11831</id>
        <msg>WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DirectSR.DirectSR&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DirectSR\.DirectSR\x22|\x27DirectSR\.DirectSR\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Find\s*|.*(?P=v)\s*\.\s*Find\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DirectSR\.DirectSR\x22|\x27DirectSR\.DirectSR\x27)\s*\)(\s*\.\s*Find\s*|.*(?P=n)\s*\.\s*Find\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>11832</id>
        <msg>WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2222</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|i|00|r|00|e|00|c|00|t|00|S|00|R|00|.|00|D|00|i|00|r|00|e|00|c|00|t|00|S|00|R|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00S\x00R\x00.\x00D\x00i\x00r\x00e\x00c\x00t\x00S\x00R\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)D\x00i\x00r\x00e\x00c\x00t\x00S\x00R\x00.\x00D\x00i\x00r\x00e\x00c\x00t\x00S\x00R\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>11833</id>
        <msg>WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <bugtraq>24440</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D8541765-F6D2-4EE1-AEAA-4016BE1D9859&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D8541765-F6D2-4EE1-AEAA-4016BE1D9859\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveImage)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D8541765-F6D2-4EE1-AEAA-4016BE1D9859\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveImage))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11839</id>
        <msg>WEB-ACTIVEX TEC-IT TBarCode ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24440</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|8|00|5|00|4|00|1|00|7|00|6|00|5|00|-|00|F|00|6|00|D|00|2|00|-|00|4|00|E|00|E|00|1|00|-|00|A|00|E|00|A|00|A|00|-|00|4|00|0|00|1|00|6|00|B|00|E|00|1|00|D|00|9|00|8|00|5|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11840</id>
        <msg>WEB-ACTIVEX TEC-IT TBarCode ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24440</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TBarCode7.TBarCode7&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TBarCode7\.TBarCode7\x22|\x27TBarCode7\.TBarCode7\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveImage\s*|.*(?P=v)\s*\.\s*SaveImage\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TBarCode7\.TBarCode7\x22|\x27TBarCode7\.TBarCode7\x27)\s*\)(\s*\.\s*SaveImage\s*|.*(?P=n)\s*\.\s*SaveImage\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>11841</id>
        <msg>WEB-ACTIVEX TEC-IT TBarCode ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24440</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|B|00|a|00|r|00|C|00|o|00|d|00|e|00|7|00|.|00|T|00|B|00|a|00|r|00|C|00|o|00|d|00|e|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)T\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x007\x00.\x00T\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x007\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)T\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x007\x00.\x00T\x00B\x00a\x00r\x00C\x00o\x00d\x00e\x007\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11842</id>
        <msg>WEB-ACTIVEX TEC-IT TBarCode ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>14514</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1984</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:5; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,28,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>11843</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss AddPrinter overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>24400</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|A|00|6|00|4|00|6|00|6|00|7|00|2|00|-|00|9|00|C|00|3|00|A|00|-|00|4|00|C|00|2|00|8|00|-|00|9|00|A|00|7|00|A|00|-|00|1|00|F|00|B|00|0|00|F|00|6|00|3|00|F|00|2|00|8|00|B|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11939</id>
        <msg>WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24400</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;idaiehlp.IDAIEHelper&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22idaiehlp\.IDAIEHelper\x22|\x27idaiehlp\.IDAIEHelper\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22idaiehlp\.IDAIEHelper\x22|\x27idaiehlp\.IDAIEHelper\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>11940</id>
        <msg>WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24400</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;i|00|d|00|a|00|i|00|e|00|h|00|l|00|p|00|.|00|I|00|D|00|A|00|I|00|E|00|H|00|e|00|l|00|p|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)i\x00d\x00a\x00i\x00e\x00h\x00l\x00p\x00.\x00I\x00D\x00A\x00I\x00E\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)i\x00d\x00a\x00i\x00e\x00h\x00l\x00p\x00.\x00I\x00D\x00A\x00I\x00E\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11941</id>
        <msg>WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24400</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2A646672-9C3A-4C28-9A7A-1FB0F63F28B6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2A646672-9C3A-4C28-9A7A-1FB0F63F28B6\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>11942</id>
        <msg>WEB-ACTIVEX Westbyte internet download accelerator ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C6A96E83-F5AF-4BD4-9BDD-7B18444F814F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C6A96E83-F5AF-4BD4-9BDD-7B18444F814F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DialNumber)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C6A96E83-F5AF-4BD4-9BDD-7B18444F814F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DialNumber))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11943</id>
        <msg>WEB-ACTIVEX HP ModemUtil ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|6|00|A|00|9|00|6|00|E|00|8|00|3|00|-|00|F|00|5|00|A|00|F|00|-|00|4|00|B|00|D|00|4|00|-|00|9|00|B|00|D|00|D|00|-|00|7|00|B|00|1|00|8|00|4|00|4|00|4|00|F|00|8|00|1|00|4|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11944</id>
        <msg>WEB-ACTIVEX HP ModemUtil ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11945</id>
        <msg>NETBIOS SMB Trans2 OPEN2 maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11372</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0206</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>content:&quot;|10|&quot;; depth:1; content:&quot;|01 00 00 00|&quot;; depth:4; offset:114; content:!&quot;|03 00|&quot;; depth:2; offset:122; byte_jump:2,128,from_beginning; content:!&quot;|00|&quot;; within:34; distance:136; classtype:attempted-admin;</filter2>
        <id>11946</id>
        <msg>NETBIOS Datagram Service NetDDE attack</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;@|11 00 00 00 00 00 00 1C 00 00 00 10 00 03 00 00 00 01 00 02 00|&quot;; depth:22;  classtype:trojan-activity;</filter2>
        <id>11951</id>
        <msg>BACKDOOR winshadow runtime detection - init connection request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060036</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 3262 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|03 00 00 00 01 00 02 00 00 00 00 00|&quot;; depth:12; offset:5;  classtype:trojan-activity;</filter2>
        <id>11952</id>
        <msg>BACKDOOR winshadow runtime detection - udp response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060036</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11955</id>
        <msg>NETBIOS SMB-DS Trans2 OPEN2 maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11956</id>
        <msg>NETBIOS SMB-DS Trans2 OPEN2 unicode maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11957</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB2&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11958</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11959</id>
        <msg>NETBIOS SMB Trans2 OPEN2 andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11960</id>
        <msg>NETBIOS SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11961</id>
        <msg>NETBIOS SMB-DS Trans2 OPEN2 andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11962</id>
        <msg>NETBIOS SMB-DS Trans2 OPEN2 unicode andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11963</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0201</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;2&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00|&quot;; within:2; distance:29; byte_test:2,&gt;,1024,-12,relative,little; classtype:protocol-command-decode;</filter2>
        <id>11964</id>
        <msg>NETBIOS-DG SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24656</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A77849B6-6125-4466-88DC-4855C014A0C4&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A77849B6-6125-4466-88DC-4855C014A0C4\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(CreateFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A77849B6-6125-4466-88DC-4855C014A0C4\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(CreateFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12015</id>
        <msg>WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX clsid access</msg>
        <url>nctsoft.com/products/NCTAudioStudio2/</url>
      </rule>
      <rule>
        <bugtraq>24656</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|7|00|7|00|8|00|4|00|9|00|B|00|6|00|-|00|6|00|1|00|2|00|5|00|-|00|4|00|4|00|6|00|6|00|-|00|8|00|8|00|D|00|C|00|-|00|4|00|8|00|5|00|5|00|C|00|0|00|1|00|4|00|A|00|0|00|C|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12016</id>
        <msg>WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX clsid unicode access</msg>
        <url>nctsoft.com/products/NCTAudioStudio2/</url>
      </rule>
      <rule>
        <bugtraq>24656</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCTWavChunksEditor2.WavChunksEditor2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCTWavChunksEditor2\.WavChunksEditor2\x22|\x27NCTWavChunksEditor2\.WavChunksEditor2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*CreateFile\s*|.*(?P=v)\s*\.\s*CreateFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCTWavChunksEditor2\.WavChunksEditor2\x22|\x27NCTWavChunksEditor2\.WavChunksEditor2\x27)\s*\)(\s*\.\s*CreateFile\s*|.*(?P=n)\s*\.\s*CreateFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12017</id>
        <msg>WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX function call access</msg>
        <url>nctsoft.com/products/NCTAudioStudio2/</url>
      </rule>
      <rule>
        <bugtraq>24656</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|T|00|W|00|a|00|v|00|C|00|h|00|u|00|n|00|k|00|s|00|E|00|d|00|i|00|t|00|o|00|r|00|2|00|.|00|W|00|a|00|v|00|C|00|h|00|u|00|n|00|k|00|s|00|E|00|d|00|i|00|t|00|o|00|r|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00C\x00T\x00W\x00a\x00v\x00C\x00h\x00u\x00n\x00k\x00s\x00E\x00d\x00i\x00t\x00o\x00r\x002\x00.\x00W\x00a\x00v\x00C\x00h\x00u\x00n\x00k\x00s\x00E\x00d\x00i\x00t\x00o\x00r\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00C\x00T\x00W\x00a\x00v\x00C\x00h\x00u\x00n\x00k\x00s\x00E\x00d\x00i\x00t\x00o\x00r\x002\x00.\x00W\x00a\x00v\x00C\x00h\x00u\x00n\x00k\x00s\x00E\x00d\x00i\x00t\x00o\x00r\x002\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12018</id>
        <msg>WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX function call unicode access</msg>
        <url>nctsoft.com/products/NCTAudioStudio2/</url>
      </rule>
      <rule>
        <bugtraq>24613</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6ED74AE3-8066-4385-AABA-243E033F75A3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6ED74AE3-8066-4385-AABA-243E033F75A3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(CreateFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6ED74AE3-8066-4385-AABA-243E033F75A3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(CreateFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12019</id>
        <msg>WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX clsid access</msg>
        <url>nctsoft.com/products/NCTAudioEditor2/</url>
      </rule>
      <rule>
        <bugtraq>24613</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|D|00|7|00|4|00|A|00|E|00|3|00|-|00|8|00|0|00|6|00|6|00|-|00|4|00|3|00|8|00|5|00|-|00|A|00|A|00|B|00|A|00|-|00|2|00|4|00|3|00|E|00|0|00|3|00|3|00|F|00|7|00|5|00|A|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12020</id>
        <msg>WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX clsid unicode access</msg>
        <url>nctsoft.com/products/NCTAudioEditor2/</url>
      </rule>
      <rule>
        <bugtraq>24613</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCTWMAFile2.WMAFile2&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCTWMAFile2\.WMAFile2\x22|\x27NCTWMAFile2\.WMAFile2\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*CreateFile\s*|.*(?P=v)\s*\.\s*CreateFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCTWMAFile2\.WMAFile2\x22|\x27NCTWMAFile2\.WMAFile2\x27)\s*\)(\s*\.\s*CreateFile\s*|.*(?P=n)\s*\.\s*CreateFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12021</id>
        <msg>WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX function call access</msg>
        <url>nctsoft.com/products/NCTAudioEditor2/</url>
      </rule>
      <rule>
        <bugtraq>24613</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|T|00|W|00|M|00|A|00|F|00|i|00|l|00|e|00|2|00|.|00|W|00|M|00|A|00|F|00|i|00|l|00|e|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00C\x00T\x00W\x00M\x00A\x00F\x00i\x00l\x00e\x002\x00.\x00W\x00M\x00A\x00F\x00i\x00l\x00e\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00C\x00T\x00W\x00M\x00A\x00F\x00i\x00l\x00e\x002\x00.\x00W\x00M\x00A\x00F\x00i\x00l\x00e\x002\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12022</id>
        <msg>WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX function call unicode access</msg>
        <url>nctsoft.com/products/NCTAudioEditor2/</url>
      </rule>
      <rule>
        <bugtraq>24678</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3487</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9C0A0321-B328-466C-8ECA-B9A5522466D3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9C0A0321-B328-466C-8ECA-B9A5522466D3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(saveXMLAsFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9C0A0321-B328-466C-8ECA-B9A5522466D3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(saveXMLAsFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12029</id>
        <msg>WEB-ACTIVEX HP Digital Imaging hpqxml.dll ActiveX clsid access</msg>
        <url>www.securityfocus.com/archive/1/472384</url>
      </rule>
      <rule>
        <bugtraq>24678</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3487</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|C|00|0|00|A|00|0|00|3|00|2|00|1|00|-|00|B|00|3|00|2|00|8|00|-|00|4|00|6|00|6|00|C|00|-|00|8|00|E|00|C|00|A|00|-|00|B|00|9|00|A|00|5|00|5|00|2|00|2|00|4|00|6|00|6|00|D|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12030</id>
        <msg>WEB-ACTIVEX HP Digital Imaging hpqxml.dll ActiveX clsid unicode access</msg>
        <url>www.securityfocus.com/archive/1/472384</url>
      </rule>
      <rule>
        <bugtraq>9633</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A| Negotiate &quot;; nocase; http_header; pcre:&quot;/^Authorization\x3a\s*Negotiate\s*((YE4G.{40}LgMc)|(YIIQ.{40}QUFB))/smiH&quot;; classtype:attempted-admin;</filter2>
        <id>12058</id>
        <msg>SPECIFIC-THREATS Microsoft SPNEGO ASN.1 library heap corruption overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>24730</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3554</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;156BF4B7-AE3A-4365-BD88-95A75AF8F09D&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*156BF4B7-AE3A-4365-BD88-95A75AF8F09D\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(queryHub)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*156BF4B7-AE3A-4365-BD88-95A75AF8F09D\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(queryHub))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>12062</id>
        <msg>WEB-ACTIVEX HP Instant Support ActiveX clsid access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01077597</url>
      </rule>
      <rule>
        <bugtraq>24730</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3554</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|5|00|6|00|B|00|F|00|4|00|B|00|7|00|-|00|A|00|E|00|3|00|A|00|-|00|4|00|3|00|6|00|5|00|-|00|B|00|D|00|8|00|8|00|-|00|9|00|5|00|A|00|7|00|5|00|A|00|F|00|8|00|F|00|0|00|9|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12063</id>
        <msg>WEB-ACTIVEX HP Instant Support ActiveX clsid unicode access</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01077597</url>
      </rule>
      <rule>
        <bugtraq>24959</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5407153D-022F-4CD2-8BFF-465569BC5DB8&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5407153D-022F-4CD2-8BFF-465569BC5DB8\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Save|SaveLayoutChanges|SaveMenuUsageData)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5407153D-022F-4CD2-8BFF-465569BC5DB8\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Save|SaveLayoutChanges|SaveMenuUsageData))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12083</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24959</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|4|00|0|00|7|00|1|00|5|00|3|00|D|00|-|00|0|00|2|00|2|00|F|00|-|00|4|00|C|00|D|00|2|00|-|00|8|00|B|00|F|00|F|00|-|00|4|00|6|00|5|00|5|00|6|00|9|00|B|00|C|00|5|00|D|00|B|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12084</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24959</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ActiveBar3Library.ActiveBar3&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ActiveBar3Library\.ActiveBar3\x22|\x27ActiveBar3Library\.ActiveBar3\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Save|SaveLayoutChanges|SaveMenuUsageData)\s*|.*(?P=v)\s*\.\s*(Save|SaveLayoutChanges|SaveMenuUsageData)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ActiveBar3Library\.ActiveBar3\x22|\x27ActiveBar3Library\.ActiveBar3\x27)\s*\)(\s*\.\s*(Save|SaveLayoutChanges|SaveMenuUsageData)\s*|.*(?P=n)\s*\.\s*(Save|SaveLayoutChanges|SaveMenuUsageData)\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12085</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24959</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|c|00|t|00|i|00|v|00|e|00|B|00|a|00|r|00|3|00|L|00|i|00|b|00|r|00|a|00|r|00|y|00|.|00|A|00|c|00|t|00|i|00|v|00|e|00|B|00|a|00|r|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00c\x00t\x00i\x00v\x00e\x00B\x00a\x00r\x003\x00L\x00i\x00b\x00r\x00a\x00r\x00y\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00B\x00a\x00r\x003\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00c\x00t\x00i\x00v\x00e\x00B\x00a\x00r\x003\x00L\x00i\x00b\x00r\x00a\x00r\x00y\x00.\x00A\x00c\x00t\x00i\x00v\x00e\x00B\x00a\x00r\x003\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12086</id>
        <msg>WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6707</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3E1DD897-F300-486C-BEAF-711183773554&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3E1DD897-F300-486C-BEAF-711183773554\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(TraceTarget)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3E1DD897-F300-486C-BEAF-711183773554\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(TraceTarget))\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>12087</id>
        <msg>WEB-ACTIVEX McAfee NeoTrace ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6707</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|E|00|1|00|D|00|D|00|8|00|9|00|7|00|-|00|F|00|3|00|0|00|0|00|-|00|4|00|8|00|6|00|C|00|-|00|B|00|E|00|A|00|F|00|-|00|7|00|1|00|1|00|1|00|8|00|3|00|7|00|7|00|3|00|5|00|5|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12088</id>
        <msg>WEB-ACTIVEX McAfee NeoTrace ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6707</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NeoTraceExplorer.NeoTraceLoader&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NeoTraceExplorer\.NeoTraceLoader\x22|\x27NeoTraceExplorer\.NeoTraceLoader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*TraceTarget\s*|.*(?P=v)\s*\.\s*TraceTarget\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NeoTraceExplorer\.NeoTraceLoader\x22|\x27NeoTraceExplorer\.NeoTraceLoader\x27)\s*\)(\s*\.\s*TraceTarget\s*|.*(?P=n)\s*\.\s*TraceTarget\s*)\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>12089</id>
        <msg>WEB-ACTIVEX McAfee NeoTrace ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>21697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6707</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|e|00|o|00|T|00|r|00|a|00|c|00|e|00|E|00|x|00|p|00|l|00|o|00|r|00|e|00|r|00|.|00|N|00|e|00|o|00|T|00|r|00|a|00|c|00|e|00|L|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00e\x00o\x00T\x00r\x00a\x00c\x00e\x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00.\x00N\x00e\x00o\x00T\x00r\x00a\x00c\x00e\x00L\x00o\x00a\x00d\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00e\x00o\x00T\x00r\x00a\x00c\x00e\x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00.\x00N\x00e\x00o\x00T\x00r\x00a\x00c\x00e\x00L\x00o\x00a\x00d\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; classtype:attempted-user;</filter2>
        <id>12090</id>
        <msg>WEB-ACTIVEX McAfee NeoTrace ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C22BB435-9B7F-4B1F-ACBD-CD36D34D6DFF&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C22BB435-9B7F-4B1F-ACBD-CD36D34D6DFF\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C22BB435-9B7F-4B1F-ACBD-CD36D34D6DFF\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12091</id>
        <msg>WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>24882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|2|00|2|00|B|00|B|00|4|00|3|00|5|00|-|00|9|00|B|00|7|00|F|00|-|00|4|00|B|00|1|00|F|00|-|00|A|00|C|00|B|00|D|00|-|00|C|00|D|00|3|00|6|00|D|00|3|00|4|00|D|00|6|00|D|00|F|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12092</id>
        <msg>WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;pgpbbox.ElPGPJpegImageX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22pgpbbox\.ElPGPJpegImageX\x22|\x27pgpbbox\.ElPGPJpegImageX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=v)\s*\.\s*SaveToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22pgpbbox\.ElPGPJpegImageX\x22|\x27pgpbbox\.ElPGPJpegImageX\x27)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=n)\s*\.\s*SaveToFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12093</id>
        <msg>WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>24882</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;p|00|g|00|p|00|b|00|b|00|o|00|x|00|.|00|E|00|l|00|P|00|G|00|P|00|J|00|p|00|e|00|g|00|I|00|m|00|a|00|g|00|e|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)p\x00g\x00p\x00b\x00b\x00o\x00x\x00.\x00E\x00l\x00P\x00G\x00P\x00J\x00p\x00e\x00g\x00I\x00m\x00a\x00g\x00e\x00X\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)p\x00g\x00p\x00b\x00b\x00o\x00x\x00.\x00E\x00l\x00P\x00G\x00P\x00J\x00p\x00e\x00g\x00I\x00m\x00a\x00g\x00e\x00X\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12094</id>
        <msg>WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>24947</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3825</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:3d742890-397c-11cf-9bf1-00805f88cb72; dce_opnum:16,23; dce_stub_data; byte_test:4,&gt;,200,12,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>12100</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP ca-alert function 16,23 overflow attempt</msg>
        <url>supportconnectw.ca.com/public/antivirus/infodocs/caantivirus-secnotice.asp</url>
      </rule>
      <rule>
        <bugtraq>25025</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3984</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6754F588-E262-42D2-A6BC-3BB400ACFEED&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6754F588-E262-42D2-A6BC-3BB400ACFEED\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Scan)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6754F588-E262-42D2-A6BC-3BB400ACFEED\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Scan))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12116</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25025</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3984</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|7|00|5|00|4|00|F|00|5|00|8|00|8|00|-|00|E|00|2|00|6|00|2|00|-|00|4|00|2|00|D|00|2|00|-|00|A|00|6|00|B|00|C|00|-|00|3|00|B|00|B|00|4|00|0|00|0|00|A|00|C|00|F|00|E|00|E|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12117</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25025</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3984</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SafeAndSoundATL.NixonMyPrograms&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SafeAndSoundATL\.NixonMyPrograms\x22|\x27SafeAndSoundATL\.NixonMyPrograms\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Scan\s*|.*(?P=v)\s*\.\s*Scan\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SafeAndSoundATL\.NixonMyPrograms\x22|\x27SafeAndSoundATL\.NixonMyPrograms\x27)\s*\)(\s*\.\s*Scan\s*|.*(?P=n)\s*\.\s*Scan\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12118</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25025</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3984</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|a|00|f|00|e|00|A|00|n|00|d|00|S|00|o|00|u|00|n|00|d|00|A|00|T|00|L|00|.|00|N|00|i|00|x|00|o|00|n|00|M|00|y|00|P|00|r|00|o|00|g|00|r|00|a|00|m|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00a\x00f\x00e\x00A\x00n\x00d\x00S\x00o\x00u\x00n\x00d\x00A\x00T\x00L\x00.\x00N\x00i\x00x\x00o\x00n\x00M\x00y\x00P\x00r\x00o\x00g\x00r\x00a\x00m\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00a\x00f\x00e\x00A\x00n\x00d\x00S\x00o\x00u\x00n\x00d\x00A\x00T\x00L\x00.\x00N\x00i\x00x\x00o\x00n\x00M\x00y\x00P\x00r\x00o\x00g\x00r\x00a\x00m\x00s\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12119</id>
        <msg>WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AccessRemotePC_RPCdetection; content:&quot;|99 F3 00 00 00 00 00 00 FF FF FF FF|&quot;; depth:12; classtype:trojan-activity;</filter2>
        <id>12145</id>
        <msg>BACKDOOR access remote pc runtime detection - rpc setup</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Access%20Remote%20PC&amp;threatid=29373</url>
      </rule>
      <rule>
        <bugtraq>25050</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3302</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;41266C21-18D8-414B-88C0-8DCA6C25CEA0&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*41266C21-18D8-414B-88C0-8DCA6C25CEA0\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*41266C21-18D8-414B-88C0-8DCA6C25CEA0\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12168</id>
        <msg>WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX clsid access</msg>
        <url>supportconnectw.ca.com/public/etrust/etrust_intrusion/infodocs/eid-callervilnsecnot.asp</url>
      </rule>
      <rule>
        <bugtraq>25050</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3302</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|1|00|2|00|6|00|6|00|C|00|2|00|1|00|-|00|1|00|8|00|D|00|8|00|-|00|4|00|1|00|4|00|B|00|-|00|8|00|8|00|C|00|0|00|-|00|8|00|D|00|C|00|A|00|6|00|C|00|2|00|5|00|C|00|E|00|A|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12169</id>
        <msg>WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX clsid unicode access</msg>
        <url>supportconnectw.ca.com/public/etrust/etrust_intrusion/infodocs/eid-callervilnsecnot.asp</url>
      </rule>
      <rule>
        <bugtraq>24653</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-2798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 00 08|@&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12185</id>
        <msg>RPC portmap 2112 tcp request</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-005.txt</url>
      </rule>
      <rule>
        <bugtraq>24653</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-2798</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 00 08|@&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12186</id>
        <msg>RPC portmap 2112 udp request</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-005.txt</url>
      </rule>
      <rule>
        <bugtraq>25063</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4067</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E8F92847-7C21-452B-91A5-49D93AA18F30&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E8F92847-7C21-452B-91A5-49D93AA18F30\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GetToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E8F92847-7C21-452B-91A5-49D93AA18F30\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GetToFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12189</id>
        <msg>WEB-ACTIVEX Clever Internet Suite ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25063</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4067</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|8|00|F|00|9|00|2|00|8|00|4|00|7|00|-|00|7|00|C|00|2|00|1|00|-|00|4|00|5|00|2|00|B|00|-|00|9|00|1|00|A|00|5|00|-|00|4|00|9|00|D|00|9|00|3|00|A|00|A|00|1|00|8|00|F|00|3|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12190</id>
        <msg>WEB-ACTIVEX Clever Internet Suite ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25063</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4067</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;clInetSuiteX6.clWebDav&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22clInetSuiteX6\.clWebDav\x22|\x27clInetSuiteX6\.clWebDav\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GetToFile\s*|.*(?P=v)\s*\.\s*GetToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22clInetSuiteX6\.clWebDav\x22|\x27clInetSuiteX6\.clWebDav\x27)\s*\)(\s*\.\s*GetToFile\s*|.*(?P=n)\s*\.\s*GetToFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12191</id>
        <msg>WEB-ACTIVEX Clever Internet Suite ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25063</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4067</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;c|00|l|00|I|00|n|00|e|00|t|00|S|00|u|00|i|00|t|00|e|00|X|00|6|00|.|00|c|00|l|00|W|00|e|00|b|00|D|00|a|00|v|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)c\x00l\x00I\x00n\x00e\x00t\x00S\x00u\x00i\x00t\x00e\x00X\x006\x00.\x00c\x00l\x00W\x00e\x00b\x00D\x00a\x00v\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)c\x00l\x00I\x00n\x00e\x00t\x00S\x00u\x00i\x00t\x00e\x00X\x006\x00.\x00c\x00l\x00W\x00e\x00b\x00D\x00a\x00v\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12192</id>
        <msg>WEB-ACTIVEX Clever Internet Suite ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25086</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7EC7B6C5-25BD-4586-A641-D2ACBB6629DD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7EC7B6C5-25BD-4586-A641-D2ACBB6629DD\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GetComponentVersion)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7EC7B6C5-25BD-4586-A641-D2ACBB6629DD\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GetComponentVersion))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12193</id>
        <msg>WEB-ACTIVEX Yahoo Widgets Engine ActiveX clsid access</msg>
        <url>help.yahoo.com/l/us/yahoo/widgets/security/security-08.html</url>
      </rule>
      <rule>
        <bugtraq>25086</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|E|00|C|00|7|00|B|00|6|00|C|00|5|00|-|00|2|00|5|00|B|00|D|00|-|00|4|00|5|00|8|00|6|00|-|00|A|00|6|00|4|00|1|00|-|00|D|00|2|00|A|00|C|00|B|00|B|00|6|00|6|00|2|00|9|00|D|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12194</id>
        <msg>WEB-ACTIVEX Yahoo Widgets Engine ActiveX clsid unicode access</msg>
        <url>help.yahoo.com/l/us/yahoo/widgets/security/security-08.html</url>
      </rule>
      <rule>
        <bugtraq>25086</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YDPCTL.YDPControl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YDPCTL\.YDPControl\x22|\x27YDPCTL\.YDPControl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GetComponentVersion\s*|.*(?P=v)\s*\.\s*GetComponentVersion\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YDPCTL\.YDPControl\x22|\x27YDPCTL\.YDPControl\x27)\s*\)(\s*\.\s*GetComponentVersion\s*|.*(?P=n)\s*\.\s*GetComponentVersion\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12195</id>
        <msg>WEB-ACTIVEX Yahoo Widgets Engine ActiveX function call access</msg>
        <url>help.yahoo.com/l/us/yahoo/widgets/security/security-08.html</url>
      </rule>
      <rule>
        <bugtraq>25086</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|D|00|P|00|C|00|T|00|L|00|.|00|Y|00|D|00|P|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)Y\x00D\x00P\x00C\x00T\x00L\x00.\x00Y\x00D\x00P\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)Y\x00D\x00P\x00C\x00T\x00L\x00.\x00Y\x00D\x00P\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12196</id>
        <msg>WEB-ACTIVEX Yahoo Widgets Engine ActiveX function call unicode access</msg>
        <url>help.yahoo.com/l/us/yahoo/widgets/security/security-08.html</url>
      </rule>
      <rule>
        <bugtraq>25110</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4059</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AF13B07E-28A1-4CAC-9C9A-EC582E354A24&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AF13B07E-28A1-4CAC-9C9A-EC582E354A24\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetLogFileName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AF13B07E-28A1-4CAC-9C9A-EC582E354A24\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetLogFileName))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12200</id>
        <msg>WEB-ACTIVEX VMWare IntraProcessLogging ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25110</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4059</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|F|00|1|00|3|00|B|00|0|00|7|00|E|00|-|00|2|00|8|00|A|00|1|00|-|00|4|00|C|00|A|00|C|00|-|00|9|00|C|00|9|00|A|00|-|00|E|00|C|00|5|00|8|00|2|00|E|00|3|00|5|00|4|00|A|00|2|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12201</id>
        <msg>WEB-ACTIVEX VMWare IntraProcessLogging ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4058</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7B9C5422-39AA-4C21-BEEF-645E42EB4529&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7B9C5422-39AA-4C21-BEEF-645E42EB4529\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(StartProcess)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7B9C5422-39AA-4C21-BEEF-645E42EB4529\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(StartProcess))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12203</id>
        <msg>WEB-ACTIVEX VMWare Vielib.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4058</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|B|00|9|00|C|00|5|00|4|00|2|00|2|00|-|00|3|00|9|00|A|00|A|00|-|00|4|00|C|00|2|00|1|00|-|00|B|00|E|00|E|00|F|00|-|00|6|00|4|00|5|00|E|00|4|00|2|00|E|00|B|00|4|00|5|00|2|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12204</id>
        <msg>WEB-ACTIVEX VMWare Vielib.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4058</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VieLib2.Vie2Process&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*StartProcess\s*|.*(?P=v)\s*\.\s*StartProcess\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VieLib2\.Vie2Process\x22|\x27VieLib2\.Vie2Process\x27)\s*\)(\s*\.\s*StartProcess\s*|.*(?P=n)\s*\.\s*StartProcess\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12205</id>
        <msg>WEB-ACTIVEX VMWare Vielib.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4058</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|i|00|e|00|L|00|i|00|b|00|2|00|.|00|V|00|i|00|e|00|2|00|P|00|r|00|o|00|c|00|e|00|s|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00i\x00e\x00L\x00i\x00b\x002\x00.\x00V\x00i\x00e\x002\x00P\x00r\x00o\x00c\x00e\x00s\x00s\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12206</id>
        <msg>WEB-ACTIVEX VMWare Vielib.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25050</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3302</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Caller.CallCode&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Caller\.CallCode\x22|\x27Caller\.CallCode\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0)\s*|.*(?P=v)\s*\.\s*(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Caller\.CallCode\x22|\x27Caller\.CallCode\x27)\s*\)(\s*\.\s*(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0)\s*|.*(?P=n)\s*\.\s*(CallDLLLong_S|CallDLLLong_S_DW_S|CallDLLLong_S_S|CallDLLLong0|CallDLLVoid_S|CallDLLVoid_S_S|CallDLLVoid0)\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12207</id>
        <msg>WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX function call access</msg>
        <url>supportconnectw.ca.com/public/etrust/etrust_intrusion/infodocs/eid-callervilnsecnot.asp</url>
      </rule>
      <rule>
        <bugtraq>25050</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3302</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|a|00|l|00|l|00|e|00|r|00|.|00|C|00|a|00|l|00|l|00|C|00|o|00|d|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00a\x00l\x00l\x00e\x00r\x00.\x00C\x00a\x00l\x00l\x00C\x00o\x00d\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00a\x00l\x00l\x00e\x00r\x00.\x00C\x00a\x00l\x00l\x00C\x00o\x00d\x00e\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12208</id>
        <msg>WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX function call unicode access</msg>
        <url>supportconnectw.ca.com/public/etrust/etrust_intrusion/infodocs/eid-callervilnsecnot.asp</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0A398EE6-277C-480D-BD4F-3288EA3AB8E2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0A398EE6-277C-480D-BD4F-3288EA3AB8E2\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AnomalyList)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0A398EE6-277C-480D-BD4F-3288EA3AB8E2\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(AnomalyList))\s*=/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12246</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX clsid access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|A|00|3|00|9|00|8|00|E|00|E|00|6|00|-|00|2|00|7|00|7|00|C|00|-|00|4|00|8|00|0|00|D|00|-|00|B|00|D|00|4|00|F|00|-|00|3|00|2|00|8|00|8|00|E|00|A|00|3|00|A|00|B|00|8|00|E|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12247</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX clsid unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NavComUI.AxSysListView32&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NavComUI\.AxSysListView32\x22|\x27NavComUI\.AxSysListView32\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AnomalyList\s*|.*(?P=v)\s*\.\s*AnomalyList\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NavComUI\.AxSysListView32\x22|\x27NavComUI\.AxSysListView32\x27)\s*\)(\s*\.\s*AnomalyList\s*|.*(?P=n)\s*\.\s*AnomalyList)\s*=/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12248</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX function call access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|a|00|v|00|C|00|o|00|m|00|U|00|I|00|.|00|A|00|x|00|S|00|y|00|s|00|L|00|i|00|s|00|t|00|V|00|i|00|e|00|w|00|3|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00a\x00v\x00C\x00o\x00m\x00U\x00I\x00.\x00A\x00x\x00S\x00y\x00s\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x003\x002\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00a\x00v\x00C\x00o\x00m\x00U\x00I\x00.\x00A\x00x\x00S\x00y\x00s\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x003\x002\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12249</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX function call unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FAF02D9B-963D-43D8-91A6-E71383503FDA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FAF02D9B-963D-43D8-91A6-E71383503FDA\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(Anomaly)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FAF02D9B-963D-43D8-91A6-E71383503FDA\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(Anomaly))\s*=/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12250</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX clsid access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|A|00|F|00|0|00|2|00|D|00|9|00|B|00|-|00|9|00|6|00|3|00|D|00|-|00|4|00|3|00|D|00|8|00|-|00|9|00|1|00|A|00|6|00|-|00|E|00|7|00|1|00|3|00|8|00|3|00|5|00|0|00|3|00|F|00|D|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12251</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX clsid unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NavComUI.AxSysListView32OAA&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NavComUI\.AxSysListView32OAA\x22|\x27NavComUI\.AxSysListView32OAA\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Anomaly\s*|.*(?P=v)\s*\.\s*Anomaly\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NavComUI\.AxSysListView32OAA\x22|\x27NavComUI\.AxSysListView32OAA\x27)\s*\)(\s*\.\s*Anomaly\s*|.*(?P=n)\s*\.\s*Anomaly)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>12252</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX function call access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>24983</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|a|00|v|00|C|00|o|00|m|00|U|00|I|00|.|00|A|00|x|00|S|00|y|00|s|00|L|00|i|00|s|00|t|00|V|00|i|00|e|00|w|00|3|00|2|00|O|00|A|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)N\x00a\x00v\x00C\x00o\x00m\x00U\x00I\x00.\x00A\x00x\x00S\x00y\x00s\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x003\x002\x00O\x00A\x00A\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)N\x00a\x00v\x00C\x00o\x00m\x00U\x00I\x00.\x00A\x00x\x00S\x00y\x00s\x00L\x00i\x00s\x00t\x00V\x00i\x00e\x00w\x003\x002\x00O\x00A\x00A\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12253</id>
        <msg>WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX function call unicode access</msg>
        <url>www.symantec.com/avcenter/security/Content/2007.08.09.html</url>
      </rule>
      <rule>
        <bugtraq>25279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4336</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;201EA564-A6F6-11D1-811D-00C04FB6BD36&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*201EA564-A6F6-11D1-811D-00C04FB6BD36\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SourceUrl)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*201EA564-A6F6-11D1-811D-00C04FB6BD36\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(SourceUrl))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>12257</id>
        <msg>WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4336</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|0|00|1|00|E|00|A|00|5|00|6|00|4|00|-|00|A|00|6|00|F|00|6|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|1|00|1|00|D|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|B|00|6|00|B|00|D|00|3|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12258</id>
        <msg>WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4336</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DXSurface.LivePicture.FlashPix&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DXSurface\.LivePicture\.FlashPix\x22|\x27DXSurface\.LivePicture\.FlashPix\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SourceUrl\s*|.*(?P=v)\s*\.\s*SourceUrl\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DXSurface\.LivePicture\.FlashPix\x22|\x27DXSurface\.LivePicture\.FlashPix\x27)\s*\)(\s*\.\s*SourceUrl\s*|.*(?P=n)\s*\.\s*SourceUrl)\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>12259</id>
        <msg>WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25279</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4336</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|X|00|S|00|u|00|r|00|f|00|a|00|c|00|e|00|.|00|L|00|i|00|v|00|e|00|P|00|i|00|c|00|t|00|u|00|r|00|e|00|.|00|F|00|l|00|a|00|s|00|h|00|P|00|i|00|x|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00X\x00S\x00u\x00r\x00f\x00a\x00c\x00e\x00.\x00L\x00i\x00v\x00e\x00P\x00i\x00c\x00t\x00u\x00r\x00e\x00.\x00F\x00l\x00a\x00s\x00h\x00P\x00i\x00x\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00X\x00S\x00u\x00r\x00f\x00a\x00c\x00e\x00.\x00L\x00i\x00v\x00e\x00P\x00i\x00c\x00t\x00u\x00r\x00e\x00.\x00F\x00l\x00a\x00s\x00h\x00P\x00i\x00x\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12260</id>
        <msg>WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0943</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Content-Type|3A| text/css&quot;; fast_pattern; nocase; http_header; pcre:!&quot;/^Content-encoding\x3A\s*(gzip|compress)/Him&quot;; pcre:&quot;/\x7D\s*\/[^\/\x2A]/H&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12277</id>
        <msg>EXPLOIT Microsoft IE CSS memory corruption exploit</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>25383</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4489</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BD80D375-5439-4D80-B128-DDA5FDC3AE6C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BD80D375-5439-4D80-B128-DDA5FDC3AE6C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ReInit)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BD80D375-5439-4D80-B128-DDA5FDC3AE6C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ReInit))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12301</id>
        <msg>WEB-ACTIVEX eCentrex VOIP Client Module ActiveX clsid access</msg>
        <url>www.e800phone.com</url>
      </rule>
      <rule>
        <bugtraq>25383</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4489</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|D|00|8|00|0|00|D|00|3|00|7|00|5|00|-|00|5|00|4|00|3|00|9|00|-|00|4|00|D|00|8|00|0|00|-|00|B|00|1|00|2|00|8|00|-|00|D|00|D|00|A|00|5|00|F|00|D|00|C|00|3|00|A|00|E|00|6|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12302</id>
        <msg>WEB-ACTIVEX eCentrex VOIP Client Module ActiveX clsid unicode access</msg>
        <url>www.e800phone.com</url>
      </rule>
      <rule>
        <bugtraq>25473</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4467</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9b935470-ad4a-11d5-b63e-00c04faedb18&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*9b935470-ad4a-11d5-b63e-00c04faedb18\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12380</id>
        <msg>WEB-ACTIVEX Oracle JInitiator ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25473</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4467</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|b|00|9|00|3|00|5|00|4|00|7|00|0|00|-|00|a|00|d|00|4|00|a|00|-|00|1|00|1|00|d|00|5|00|-|00|b|00|6|00|3|00|e|00|-|00|0|00|0|00|c|00|0|00|4|00|f|00|a|00|e|00|d|00|b|00|1|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12381</id>
        <msg>WEB-ACTIVEX Oracle JInitiator ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;68AC0D5F-0424-11D5-822F-00C04F6BA8D9&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*68AC0D5F-0424-11D5-822F-00C04F6BA8D9\s*}?\s*(?P=q3)(\s|&gt;).*(?P=id1)\s*\.\s*(SubmitToExpress)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*68AC0D5F-0424-11D5-822F-00C04F6BA8D9\s*}?\s*(?P=q4)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SubmitToExpress))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12382</id>
        <msg>WEB-ACTIVEX EasyMail Objects ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|8|00|A|00|C|00|0|00|D|00|5|00|F|00|-|00|0|00|4|00|2|00|4|00|-|00|1|00|1|00|D|00|5|00|-|00|8|00|2|00|2|00|F|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|6|00|B|00|A|00|8|00|D|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q5&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12383</id>
        <msg>WEB-ACTIVEX EasyMail Objects ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25494</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4515</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D5184A39-CBDF-4A4F-AC1A-7A45A852C883&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D5184A39-CBDF-4A4F-AC1A-7A45A852C883\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(fvCom|info)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D5184A39-CBDF-4A4F-AC1A-7A45A852C883\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(fvCom|info))\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>12384</id>
        <msg>WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX clsid access</msg>
        <url>messenger.yahoo.com/security_update.php?id=082907</url>
      </rule>
      <rule>
        <bugtraq>25494</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4515</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|5|00|1|00|8|00|4|00|A|00|3|00|9|00|-|00|C|00|B|00|D|00|F|00|-|00|4|00|A|00|4|00|F|00|-|00|A|00|C|00|1|00|A|00|-|00|7|00|A|00|4|00|5|00|A|00|8|00|5|00|2|00|C|00|8|00|8|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12385</id>
        <msg>WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX clsid unicode access</msg>
        <url>messenger.yahoo.com/security_update.php?id=082907</url>
      </rule>
      <rule>
        <bugtraq>25494</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4515</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;YVerInfo.GetInfo&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22YVerInfo\.GetInfo\x22|\x27YVerInfo\.GetInfo\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(fvCom|info)\s*|.*(?P=v)\s*\.\s*(fvCom|info)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22YVerInfo\.GetInfo\x22|\x27YVerInfo\.GetInfo\x27)\s*\)(\s*\.\s*(fvCom|info)\s*|.*(?P=n)\s*\.\s*(fvCom|info)\s*)\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>12386</id>
        <msg>WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX function call access</msg>
        <url>messenger.yahoo.com/security_update.php?id=082907</url>
      </rule>
      <rule>
        <bugtraq>25494</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4515</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Y|00|V|00|e|00|r|00|I|00|n|00|f|00|o|00|.|00|G|00|e|00|t|00|I|00|n|00|f|00|o|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)Y\x00V\x00e\x00r\x00I\x00n\x00f\x00o\x00.\x00G\x00e\x00t\x00I\x00n\x00f\x00o\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)Y\x00V\x00e\x00r\x00I\x00n\x00f\x00o\x00.\x00G\x00e\x00t\x00I\x00n\x00f\x00o\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; classtype:attempted-user;</filter2>
        <id>12387</id>
        <msg>WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX function call unicode access</msg>
        <url>messenger.yahoo.com/security_update.php?id=082907</url>
      </rule>
      <rule>
        <bugtraq>25502</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5EC7C511-CD0F-42E6-830C-1BD9882F3458&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5EC7C511-CD0F-42E6-830C-1BD9882F3458\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Logo)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5EC7C511-CD0F-42E6-830C-1BD9882F3458\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Logo))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>12388</id>
        <msg>WEB-ACTIVEX PPStream PowerPlayer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25502</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4748</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|E|00|C|00|7|00|C|00|5|00|1|00|1|00|-|00|C|00|D|00|0|00|F|00|-|00|4|00|2|00|E|00|6|00|-|00|8|00|3|00|0|00|C|00|-|00|1|00|B|00|D|00|9|00|8|00|8|00|2|00|F|00|3|00|4|00|5|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12389</id>
        <msg>WEB-ACTIVEX PPStream PowerPlayer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25584</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8EC18CE2-D7B4-11D2-88C8-006008A717FD&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8EC18CE2-D7B4-11D2-88C8-006008A717FD\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12413</id>
        <msg>WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25584</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|E|00|C|00|1|00|8|00|C|00|E|00|2|00|-|00|D|00|7|00|B|00|4|00|-|00|1|00|1|00|D|00|2|00|-|00|8|00|8|00|C|00|8|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|A|00|7|00|1|00|7|00|F|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12414</id>
        <msg>WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25584</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NCSViewManager.NCSView&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NCSViewManager\.NCSView\x22|\x27NCSViewManager\.NCSView\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NCSViewManager\.NCSView\x22|\x27NCSViewManager\.NCSView\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>12415</id>
        <msg>WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25584</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|C|00|S|00|V|00|i|00|e|00|w|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|.|00|N|00|C|00|S|00|V|00|i|00|e|00|w|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)N\x00C\x00S\x00V\x00i\x00e\x00w\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00.\x00N\x00C\x00S\x00V\x00i\x00e\x00w\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00C\x00S\x00V\x00i\x00e\x00w\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00.\x00N\x00C\x00S\x00V\x00i\x00e\x00w\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12416</id>
        <msg>WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25586</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7D1425D4-E2FC-4A52-BDA9-B9DCAC5EF574&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7D1425D4-E2FC-4A52-BDA9-B9DCAC5EF574\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetClientInfo)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7D1425D4-E2FC-4A52-BDA9-B9DCAC5EF574\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetClientInfo))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12428</id>
        <msg>WEB-ACTIVEX GlobalLink glitemflat.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25586</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|D|00|1|00|4|00|2|00|5|00|D|00|4|00|-|00|E|00|2|00|F|00|C|00|-|00|4|00|A|00|5|00|2|00|-|00|B|00|D|00|A|00|9|00|-|00|B|00|9|00|D|00|C|00|A|00|C|00|5|00|E|00|F|00|5|00|7|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12429</id>
        <msg>WEB-ACTIVEX GlobalLink glitemflat.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25601</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1612</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB\s*}?\s*(?P=q4)(\s|&gt;).*(?P=id1)\s*\.\s*(advancedOpen|backImage|isDVDPath|rawParse|titleImage|URL|OnBeforeVideoDownload)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB\s*}?\s*(?P=q5)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(advancedOpen|backImage|isDVDPath|rawParse|titleImage|URL|OnBeforeVideoDownload))\s*\(/siO&quot;; classtype:attempted-user;</filter2>
        <id>12434</id>
        <msg>WEB-ACTIVEX BaoFeng Storm MPS.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25601</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1612</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|B|00|E|00|5|00|2|00|E|00|1|00|D|00|-|00|E|00|5|00|8|00|6|00|-|00|4|00|7|00|4|00|F|00|-|00|A|00|6|00|E|00|2|00|-|00|1|00|A|00|8|00|5|00|A|00|9|00|B|00|4|00|D|00|9|00|F|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; classtype:attempted-user;</filter2>
        <id>12435</id>
        <msg>WEB-ACTIVEX BaoFeng Storm MPS.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25609</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;09C282FE-7DE7-4697-9BE2-1C4F4DA825B3&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*09C282FE-7DE7-4697-9BE2-1C4F4DA825B3\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AcquireContext)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*09C282FE-7DE7-4697-9BE2-1C4F4DA825B3\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AcquireContext))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12438</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX clsid access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25609</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|9|00|C|00|2|00|8|00|2|00|F|00|E|00|-|00|7|00|D|00|E|00|7|00|-|00|4|00|6|00|9|00|7|00|-|00|9|00|B|00|E|00|2|00|-|00|1|00|C|00|4|00|F|00|4|00|D|00|A|00|8|00|2|00|5|00|B|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12439</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX clsid unicode access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25609</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CryptoX.CryptoObj&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22CryptoX\.CryptoObj\x22|\x27CryptoX\.CryptoObj\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AcquireContext\s*|.*(?P=v)\s*\.\s*AcquireContext\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22CryptoX\.CryptoObj\x22|\x27CryptoX\.CryptoObj\x27)\s*\)(\s*\.\s*AcquireContext\s*|.*(?P=n)\s*\.\s*AcquireContext\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12440</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX function call access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25609</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|r|00|y|00|p|00|t|00|o|00|X|00|.|00|C|00|r|00|y|00|p|00|t|00|o|00|O|00|b|00|j|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)C\x00r\x00y\x00p\x00t\x00o\x00X\x00.\x00C\x00r\x00y\x00p\x00t\x00o\x00O\x00b\x00j\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)C\x00r\x00y\x00p\x00t\x00o\x00X\x00.\x00C\x00r\x00y\x00p\x00t\x00o\x00O\x00b\x00j\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12441</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX function call unicode access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25611</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FD22F3AE-1450-4BDC-ADBE-6AF210A78C2C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FD22F3AE-1450-4BDC-ADBE-6AF210A78C2C\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FD22F3AE-1450-4BDC-ADBE-6AF210A78C2C\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12442</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll 2 ActiveX clsid access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25611</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|2|00|2|00|F|00|3|00|A|00|E|00|-|00|1|00|4|00|5|00|0|00|-|00|4|00|B|00|D|00|C|00|-|00|A|00|D|00|B|00|E|00|-|00|6|00|A|00|F|00|2|00|1|00|0|00|A|00|7|00|8|00|C|00|2|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12443</id>
        <msg>WEB-ACTIVEX Ultra Crypto Component CryptoX.dll 2 ActiveX clsid unicode access</msg>
        <url>www.ultrashareware.com/Ultra-Crypto-Component.htm</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D45FD31B-5C6E-11D1-9EC1-00C04FD7081F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31B-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Characters.Load)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD31B-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Characters.Load))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12448</id>
        <msg>WEB-ACTIVEX Microsoft Agent Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|5|00|F|00|D|00|3|00|1|00|B|00|-|00|5|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|E|00|C|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|8|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12449</id>
        <msg>WEB-ACTIVEX Microsoft Agent Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Agent.Control&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Agent\.Control\x22|\x27Agent\.Control\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Characters.Load\s*|.*(?P=v)\s*\.\s*Characters.Load\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Agent\.Control\x22|\x27Agent\.Control\x27)\s*\)(\s*\.\s*Characters.Load\s*|.*(?P=n)\s*\.\s*Characters.Load\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12450</id>
        <msg>WEB-ACTIVEX Microsoft Agent Control ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|g|00|e|00|n|00|t|00|.|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00g\x00e\x00n\x00t\x00.\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00g\x00e\x00n\x00t\x00.\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12451</id>
        <msg>WEB-ACTIVEX Microsoft Agent Control ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D45FD300-5C6E-11D1-9EC1-00C04FD7081F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD300-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(Characters.Load)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D45FD300-5C6E-11D1-9EC1-00C04FD7081F\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(Characters.Load))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12452</id>
        <msg>WEB-ACTIVEX MS Agent File Provider ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>25566</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|4|00|5|00|F|00|D|00|3|00|0|00|0|00|-|00|5|00|C|00|6|00|E|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|E|00|C|00|1|00|-|00|0|00|0|00|C|00|0|00|4|00|F|00|D|00|7|00|0|00|8|00|1|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12453</id>
        <msg>WEB-ACTIVEX MS Agent File Provider ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>8615</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0722</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; classtype:rpc-portmap-decode;</filter2>
        <id>12458</id>
        <msg>RPC portmap Solaris sadmin port query tcp request</msg>
      </rule>
      <rule>
        <bugtraq>25638</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4891</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0DDF3C0B-E692-11D1-AB06-00AA00BDD685&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0DDF3C0B-E692-11D1-AB06-00AA00BDD685\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(StartProcess)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0DDF3C0B-E692-11D1-AB06-00AA00BDD685\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(StartProcess))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12459</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25638</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4891</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|D|00|D|00|F|00|3|00|C|00|0|00|B|00|-|00|E|00|6|00|9|00|2|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|B|00|0|00|6|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|D|00|D|00|6|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12460</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25635</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4890</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7EEA39E3-41D1-11D2-AB3B-00AA00BDD685&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q4&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7EEA39E3-41D1-11D2-AB3B-00AA00BDD685\s*}?\s*(?P=q4)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12461</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 VBTOVSI.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25635</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4890</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|E|00|E|00|A|00|3|00|9|00|E|00|3|00|-|00|4|00|1|00|D|00|1|00|-|00|1|00|1|00|D|00|2|00|-|00|A|00|B|00|3|00|B|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|D|00|D|00|6|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q5&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q5)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12462</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 VBTOVSI.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25723</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4983</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8D1636FD-CA49-4B4E-90E4-0A20E03A15E8&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8D1636FD-CA49-4B4E-90E4-0A20E03A15E8\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12468</id>
        <msg>WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25723</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4983</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|D|00|1|00|6|00|3|00|6|00|F|00|D|00|-|00|C|00|A|00|4|00|9|00|-|00|4|00|B|00|4|00|E|00|-|00|9|00|0|00|E|00|4|00|-|00|0|00|A|00|2|00|0|00|E|00|0|00|3|00|A|00|1|00|5|00|E|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12469</id>
        <msg>WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25723</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4983</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;JetAudio.Interface&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22JetAudio\.Interface\x22|\x27JetAudio\.Interface\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22JetAudio\.Interface\x22|\x27JetAudio\.Interface\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>12470</id>
        <msg>WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25723</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4983</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;J|00|e|00|t|00|A|00|u|00|d|00|i|00|o|00|.|00|I|00|n|00|t|00|e|00|r|00|f|00|a|00|c|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)J\x00e\x00t\x00A\x00u\x00d\x00i\x00o\x00.\x00I\x00n\x00t\x00e\x00r\x00f\x00a\x00c\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)J\x00e\x00t\x00A\x00u\x00d\x00i\x00o\x00.\x00I\x00n\x00t\x00e\x00r\x00f\x00a\x00c\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12471</id>
        <msg>WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25727</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;24F3EAD6-8B87-4C1A-97DA-71C126BDA08F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24F3EAD6-8B87-4C1A-97DA-71C126BDA08F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GetFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*24F3EAD6-8B87-4C1A-97DA-71C126BDA08F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GetFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12476</id>
        <msg>WEB-ACTIVEX Yahoo Messenger CYFT ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25727</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|4|00|F|00|3|00|E|00|A|00|D|00|6|00|-|00|8|00|B|00|8|00|7|00|-|00|4|00|C|00|1|00|A|00|-|00|9|00|7|00|D|00|A|00|-|00|7|00|1|00|C|00|1|00|2|00|6|00|B|00|D|00|A|00|0|00|8|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12477</id>
        <msg>WEB-ACTIVEX Yahoo Messenger CYFT ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25727</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ft60.YFT&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ft60\.YFT\x22|\x27ft60\.YFT\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*GetFile\s*|.*(?P=v)\s*\.\s*GetFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ft60\.YFT\x22|\x27ft60\.YFT\x27)\s*\)(\s*\.\s*GetFile\s*|.*(?P=n)\s*\.\s*GetFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12478</id>
        <msg>WEB-ACTIVEX Yahoo Messenger CYFT ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25727</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;f|00|t|00|6|00|0|00|.|00|Y|00|F|00|T|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)f\x00t\x006\x000\x00.\x00Y\x00F\x00T\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)f\x00t\x006\x000\x00.\x00Y\x00F\x00T\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12479</id>
        <msg>WEB-ACTIVEX Yahoo Messenger CYFT ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EEDD6FF9-13DE-496B-9A1C-D78B3215E266&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EEDD6FF9-13DE-496B-9A1C-D78B3215E266\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DownURL2)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*EEDD6FF9-13DE-496B-9A1C-D78B3215E266\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DownURL2))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12598</id>
        <msg>WEB-ACTIVEX Xunlei Web Thunder ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|E|00|D|00|D|00|6|00|F|00|F|00|9|00|-|00|1|00|3|00|D|00|E|00|-|00|4|00|9|00|6|00|B|00|-|00|9|00|A|00|1|00|C|00|-|00|D|00|7|00|8|00|B|00|3|00|2|00|1|00|5|00|E|00|2|00|6|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12599</id>
        <msg>WEB-ACTIVEX Xunlei Web Thunder ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25789</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3C34EAC7-9904-4415-BBE4-82AA8C0C0BE8&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3C34EAC7-9904-4415-BBE4-82AA8C0C0BE8\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddString)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3C34EAC7-9904-4415-BBE4-82AA8C0C0BE8\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddString))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12600</id>
        <msg>WEB-ACTIVEX ebCrypt IncrementalHash ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25789</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|C|00|3|00|4|00|E|00|A|00|C|00|7|00|-|00|9|00|9|00|0|00|4|00|-|00|4|00|4|00|1|00|5|00|-|00|B|00|B|00|E|00|4|00|-|00|8|00|2|00|A|00|A|00|8|00|C|00|0|00|C|00|0|00|B|00|E|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12601</id>
        <msg>WEB-ACTIVEX ebCrypt IncrementalHash ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25789</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EbCrypt.eb_c_IncrementalHash&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EbCrypt\.eb_c_IncrementalHash\x22|\x27EbCrypt\.eb_c_IncrementalHash\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddString\s*|.*(?P=v)\s*\.\s*AddString\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EbCrypt\.eb_c_IncrementalHash\x22|\x27EbCrypt\.eb_c_IncrementalHash\x27)\s*\)(\s*\.\s*AddString\s*|.*(?P=n)\s*\.\s*AddString\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12602</id>
        <msg>WEB-ACTIVEX ebCrypt IncrementalHash ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25789</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|b|00|C|00|r|00|y|00|p|00|t|00|.|00|e|00|b|00|_|00|c|00|_|00|I|00|n|00|c|00|r|00|e|00|m|00|e|00|n|00|t|00|a|00|l|00|H|00|a|00|s|00|h|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00b\x00C\x00r\x00y\x00p\x00t\x00.\x00e\x00b\x00_\x00c\x00_\x00I\x00n\x00c\x00r\x00e\x00m\x00e\x00n\x00t\x00a\x00l\x00H\x00a\x00s\x00h\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00b\x00C\x00r\x00y\x00p\x00t\x00.\x00e\x00b\x00_\x00c\x00_\x00I\x00n\x00c\x00r\x00e\x00m\x00e\x00n\x00t\x00a\x00l\x00H\x00a\x00s\x00h\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12603</id>
        <msg>WEB-ACTIVEX ebCrypt IncrementalHash ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25787</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B1E7505E-BBFD-42BF-98C9-602205A1504C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B1E7505E-BBFD-42BF-98C9-602205A1504C\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B1E7505E-BBFD-42BF-98C9-602205A1504C\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(SaveToFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12604</id>
        <msg>WEB-ACTIVEX ebCrypt PRNGenerator ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25787</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|1|00|E|00|7|00|5|00|0|00|5|00|E|00|-|00|B|00|B|00|F|00|D|00|-|00|4|00|2|00|B|00|F|00|-|00|9|00|8|00|C|00|9|00|-|00|6|00|0|00|2|00|2|00|0|00|5|00|A|00|1|00|5|00|0|00|4|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12605</id>
        <msg>WEB-ACTIVEX ebCrypt PRNGenerator ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25787</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EbCrypt.eb_c_PRNGenerator&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EbCrypt\.eb_c_PRNGenerator\x22|\x27EbCrypt\.eb_c_PRNGenerator\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=v)\s*\.\s*SaveToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EbCrypt\.eb_c_PRNGenerator\x22|\x27EbCrypt\.eb_c_PRNGenerator\x27)\s*\)(\s*\.\s*SaveToFile\s*|.*(?P=n)\s*\.\s*SaveToFile\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12606</id>
        <msg>WEB-ACTIVEX ebCrypt PRNGenerator ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25787</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|b|00|C|00|r|00|y|00|p|00|t|00|.|00|e|00|b|00|_|00|c|00|_|00|P|00|R|00|N|00|G|00|e|00|n|00|e|00|r|00|a|00|t|00|o|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)E\x00b\x00C\x00r\x00y\x00p\x00t\x00.\x00e\x00b\x00_\x00c\x00_\x00P\x00R\x00N\x00G\x00e\x00n\x00e\x00r\x00a\x00t\x00o\x00r\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)E\x00b\x00C\x00r\x00y\x00p\x00t\x00.\x00e\x00b\x00_\x00c\x00_\x00P\x00R\x00N\x00G\x00e\x00n\x00e\x00r\x00a\x00t\x00o\x00r\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12607</id>
        <msg>WEB-ACTIVEX ebCrypt PRNGenerator ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>4639</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0573</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A8|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12608</id>
        <msg>RPC portmap walld udp request</msg>
      </rule>
      <rule>
        <bugtraq>4639</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0573</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A8|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;%&quot;; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>12609</id>
        <msg>RPC portmap walld udp format string attack attempt</msg>
      </rule>
      <rule>
        <bugtraq>25638</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4891</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PDWizard.PublicTools&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PDWizard\.PublicTools\x22|\x27PDWizard\.PublicTools\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*StartProcess\s*|.*(?P=v)\s*\.\s*StartProcess\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PDWizard\.PublicTools\x22|\x27PDWizard\.PublicTools\x27)\s*\)(\s*\.\s*StartProcess\s*|.*(?P=n)\s*\.\s*StartProcess\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12616</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25638</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4891</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|D|00|W|00|i|00|z|00|a|00|r|00|d|00|.|00|P|00|u|00|b|00|l|00|i|00|c|00|T|00|o|00|o|00|l|00|s|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00P\x00u\x00b\x00l\x00i\x00c\x00T\x00o\x00o\x00l\x00s\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00P\x00u\x00b\x00l\x00i\x00c\x00T\x00o\x00o\x00l\x00s\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12617</id>
        <msg>WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 F7|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1262</id>
        <msg>RPC portmap admind request TCP</msg>
      </rule>
      <rule>
        <bugtraq>8615</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0722</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; classtype:rpc-portmap-decode;</filter2>
        <id>12626</id>
        <msg>RPC portmap Solaris sadmin port query udp request</msg>
      </rule>
      <rule>
        <bugtraq>8615</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0722</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 87 88|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; classtype:rpc-portmap-decode;</filter2>
        <id>12627</id>
        <msg>RPC portmap Solaris sadmin port query tcp portmapper sadmin port query attempt</msg>
      </rule>
      <rule>
        <bugtraq>8615</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0722</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 87 88|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; classtype:rpc-portmap-decode;</filter2>
        <id>12628</id>
        <msg>RPC portmap Solaris sadmin port query udp portmapper sadmin port query attempt</msg>
      </rule>
      <rule>
        <bugtraq>614</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0704</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 03|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1263</id>
        <msg>RPC portmap amountd request TCP</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|0D 0A FF D8|&quot;; content:&quot;|FF DB|&quot;; distance:0; byte_test:2, =, 0, 2, relative; classtype:attempted-user;</filter2>
        <id>12631</id>
        <msg>EXPLOIT Microsoft Kodak Imaging small offset malformed jpeg tables</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-055.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|0D 0A FF D8|&quot;; content:&quot;|FF DB|&quot;; distance:0; byte_test:2, &gt;, 32767, 2, relative; classtype:attempted-user;</filter2>
        <id>12632</id>
        <msg>EXPLOIT Microsoft Kodak Imaging large offset malformed jpeg tables</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-055.mspx</url>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2007-2228</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:established,to_server; content:&quot;NTLMSSP|00 03 00 00 00|&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:16; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|05 00 00 03 10 00 00 00|&quot;; within:500; pcre:&quot;/\x05\x00\x00\x03\x10\x00\x00\x00.{16}\x0a[\x03\x04]/&quot;; classtype:denial-of-service;</filter2>
        <id>12635</id>
        <msg>DOS RPC NTLMSSP malformed credentials</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-058.mspx</url>
      </rule>
      <rule>
        <bugtraq>26004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12637</id>
        <msg>WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|E|00|B|00|0|00|E|00|7|00|4|00|A|00|-|00|2|00|A|00|7|00|6|00|-|00|4|00|A|00|B|00|3|00|-|00|A|00|7|00|F|00|B|00|-|00|9|00|B|00|D|00|8|00|C|00|2|00|9|00|F|00|7|00|F|00|7|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12638</id>
        <msg>WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;kavwebscan.CKAVWebScan&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22kavwebscan\.CKAVWebScan\x22|\x27kavwebscan\.CKAVWebScan\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22kavwebscan\.CKAVWebScan\x22|\x27kavwebscan\.CKAVWebScan\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>12639</id>
        <msg>WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0647</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 BA|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1264</id>
        <msg>RPC portmap bootparam request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;k|00|a|00|v|00|w|00|e|00|b|00|s|00|c|00|a|00|n|00|.|00|C|00|K|00|A|00|V|00|W|00|e|00|b|00|S|00|c|00|a|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)k\x00a\x00v\x00w\x00e\x00b\x00s\x00c\x00a\x00n\x00.\x00C\x00K\x00A\x00V\x00W\x00e\x00b\x00S\x00c\x00a\x00n\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)k\x00a\x00v\x00w\x00e\x00b\x00s\x00c\x00a\x00n\x00.\x00C\x00K\x00A\x00V\x00W\x00e\x00b\x00S\x00c\x00a\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12640</id>
        <msg>WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2007-2228</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:established,to_server; content:&quot;NTLMSSP|00 03 00 00 00|&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:16; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|05 00 00 03 10 00 00 00|&quot;; within:500; pcre:&quot;/\x05\x00\x00\x03\x10\x00\x00\x00.{16}\x0a[\x03\x04]/&quot;; classtype:denial-of-service;</filter2>
        <id>12642</id>
        <msg>DOS RPC NTLMSSP malformed credentials</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-058.mspx</url>
      </rule>
      <rule>
        <bugtraq>26058</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5446</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;30C0FDCB-53BE-4DB3-869D-32BF2DAD0DEC&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*30C0FDCB-53BE-4DB3-869D-32BF2DAD0DEC\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*SaveSenderToXML|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*30C0FDCB-53BE-4DB3-869D-32BF2DAD0DEC\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.SaveSenderToXML)\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12644</id>
        <msg>WEB-ACTIVEX PBEmail7 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26058</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5446</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|0|00|C|00|0|00|F|00|D|00|C|00|B|00|-|00|5|00|3|00|B|00|E|00|-|00|4|00|D|00|B|00|3|00|-|00|8|00|6|00|9|00|D|00|-|00|3|00|2|00|B|00|F|00|2|00|D|00|A|00|D|00|0|00|D|00|E|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12645</id>
        <msg>WEB-ACTIVEX PBEmail7 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26058</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5446</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PBEmail7.EmailSender&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PBEmail7\.EmailSender\x22|\x27PBEmail7\.EmailSender\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SaveSenderToXML\s*|.*(?P=v)\s*\.\s*SaveSenderToXML\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PBEmail7\.EmailSender\x22|\x27PBEmail7\.EmailSender\x27)\s*\)(\s*\.\s*SaveSenderToXML\s*|.*(?P=n)\s*\.\s*SaveSenderToXML\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12646</id>
        <msg>WEB-ACTIVEX PBEmail7 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26058</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5446</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|B|00|E|00|m|00|a|00|i|00|l|00|7|00|.|00|E|00|m|00|a|00|i|00|l|00|S|00|e|00|n|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00B\x00E\x00m\x00a\x00i\x00l\x007\x00.\x00E\x00m\x00a\x00i\x00l\x00S\x00e\x00n\x00d\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)P\x00B\x00E\x00m\x00a\x00i\x00l\x007\x00.\x00E\x00m\x00a\x00i\x00l\x00S\x00e\x00n\x00d\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12647</id>
        <msg>WEB-ACTIVEX PBEmail7 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26064</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7600707B-9F47-416D-8AB5-6FD96EA37968&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7600707B-9F47-416D-8AB5-6FD96EA37968\s*}?\s*(?P=q6)(\s|&gt;)/si&quot;; classtype:attempted-user;</filter2>
        <id>12648</id>
        <msg>WEB-ACTIVEX DB Software Laboratory VImpX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26064</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|6|00|0|00|0|00|7|00|0|00|7|00|B|00|-|00|9|00|F|00|4|00|7|00|-|00|4|00|1|00|6|00|D|00|-|00|8|00|A|00|B|00|5|00|-|00|6|00|F|00|D|00|9|00|6|00|E|00|A|00|3|00|7|00|9|00|6|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q7&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12649</id>
        <msg>WEB-ACTIVEX DB Software Laboratory VImpX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 E4|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1265</id>
        <msg>RPC portmap cmsd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26064</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VImpX.VImpAX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VImpX\.VImpAX\x22|\x27VImpX\.VImpAX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VImpX\.VImpAX\x22|\x27VImpX\.VImpAX\x27)\s*\)/smi&quot;; classtype:attempted-user;</filter2>
        <id>12650</id>
        <msg>WEB-ACTIVEX DB Software Laboratory VImpX ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26064</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|I|00|m|00|p|00|X|00|.|00|V|00|I|00|m|00|p|00|A|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)V\x00I\x00m\x00p\x00X\x00.\x00V\x00I\x00m\x00p\x00A\x00X\x00(?P=q8)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)V\x00I\x00m\x00p\x00X\x00.\x00V\x00I\x00m\x00p\x00A\x00X\x00(?P=q9)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12651</id>
        <msg>WEB-ACTIVEX DB Software Laboratory VImpX ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 CC|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1267</id>
        <msg>RPC portmap nisd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>4816</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0910</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 02|I|F1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1268</id>
        <msg>RPC portmap pcnfsd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26244</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5722</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AE93C5DF-A990-11D1-AEBD-5254ABDD2B69&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AE93C5DF-A990-11D1-AEBD-5254ABDD2B69\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ConnectAndEnterRoom)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*AE93C5DF-A990-11D1-AEBD-5254ABDD2B69\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ConnectAndEnterRoom))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12689</id>
        <msg>WEB-ACTIVEX GlobalLink ConnectAndEnterRoom ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1269</id>
        <msg>RPC portmap rexd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26244</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5722</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|E|00|9|00|3|00|C|00|5|00|D|00|F|00|-|00|A|00|9|00|9|00|0|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|E|00|B|00|D|00|-|00|5|00|2|00|5|00|4|00|A|00|B|00|D|00|D|00|2|00|B|00|6|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12690</id>
        <msg>WEB-ACTIVEX GlobalLink ConnectAndEnterRoom ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1270</id>
        <msg>RPC portmap rstatd request TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0626</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A2|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1271</id>
        <msg>RPC portmap rusers request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26430</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E06E2E99-0AA1-11D4-ABA6-0060082AA75C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E06E2E99-0AA1-11D4-ABA6-0060082AA75C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(InitParam|SetParam)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E06E2E99-0AA1-11D4-ABA6-0060082AA75C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(InitParam|SetParam))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12714</id>
        <msg>WEB-ACTIVEX WebEx GPCContainer ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26430</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|0|00|6|00|E|00|2|00|E|00|9|00|9|00|-|00|0|00|A|00|A|00|1|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|B|00|A|00|6|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|2|00|A|00|A|00|7|00|5|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12715</id>
        <msg>WEB-ACTIVEX WebEx GPCContainer ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26430</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;GpcContainer.GpcContainer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22GpcContainer\.GpcContainer\x22|\x27GpcContainer\.GpcContainer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(InitParam|SetParam)\s*|.*(?P=v)\s*\.\s*(InitParam|SetParam)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22GpcContainer\.GpcContainer\x22|\x27GpcContainer\.GpcContainer\x27)\s*\)(\s*\.\s*(InitParam|SetParam)\s*|.*(?P=n)\s*\.\s*(InitParam|SetParam)\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12716</id>
        <msg>WEB-ACTIVEX WebEx GPCContainer ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26430</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;G|00|p|00|c|00|C|00|o|00|n|00|t|00|a|00|i|00|n|00|e|00|r|00|.|00|G|00|p|00|c|00|C|00|o|00|n|00|t|00|a|00|i|00|n|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)G\x00p\x00c\x00C\x00o\x00n\x00t\x00a\x00i\x00n\x00e\x00r\x00.\x00G\x00p\x00c\x00C\x00o\x00n\x00t\x00a\x00i\x00n\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)G\x00p\x00c\x00C\x00o\x00n\x00t\x00a\x00i\x00n\x00e\x00r\x00.\x00G\x00p\x00c\x00C\x00o\x00n\x00t\x00a\x00i\x00n\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12717</id>
        <msg>WEB-ACTIVEX WebEx GPCContainer ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1272</id>
        <msg>RPC portmap sadmind request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B49C4597-8721-4789-9250-315DFBD9F525&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B49C4597-8721-4789-9250-315DFBD9F525\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SetMetadata)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*B49C4597-8721-4789-9250-315DFBD9F525\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(SetMetadata))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12729</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>205</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0209</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 AF|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1273</id>
        <msg>RPC portmap selection_svc request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|4|00|9|00|C|00|4|00|5|00|9|00|7|00|-|00|8|00|7|00|2|00|1|00|-|00|4|00|7|00|8|00|9|00|-|00|9|00|2|00|5|00|0|00|-|00|3|00|1|00|5|00|D|00|F|00|B|00|D|00|9|00|F|00|5|00|2|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12730</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>35028</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;WinAmpX.IWinAmpActiveX&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22WinAmpX\.IWinAmpActiveX\x22|\x27WinAmpX\.IWinAmpActiveX\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(SetMetadata|ConvertFile)\s*|.*(?P=v)\s*\.\s*(SetMetadata|ConvertFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22WinAmpX\.IWinAmpActiveX\x22|\x27WinAmpX\.IWinAmpActiveX\x27)\s*\)(\s*\.\s*(SetMetadata|ConvertFile)\s*|.*(?P=n)\s*\.\s*(SetMetadata|ConvertFile)\s*)\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12731</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;W|00|i|00|n|00|A|00|m|00|p|00|X|00|.|00|I|00|W|00|i|00|n|00|A|00|m|00|p|00|A|00|c|00|t|00|i|00|v|00|e|00|X|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)W\x00i\x00n\x00A\x00m\x00p\x00X\x00.\x00I\x00W\x00i\x00n\x00A\x00m\x00p\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)W\x00i\x00n\x00A\x00m\x00p\x00X\x00.\x00I\x00W\x00i\x00n\x00A\x00m\x00p\x00A\x00c\x00t\x00i\x00v\x00e\x00X\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12732</id>
        <msg>WEB-ACTIVEX AOL Radio AmpX ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C0A63B86-4B21-11d3-BD95-D426EF2C7949&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C0A63B86-4B21-11d3-BD95-D426EF2C7949\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Text|EditSelText|EditText|CellFontName)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*C0A63B86-4B21-11d3-BD95-D426EF2C7949\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Text|EditSelText|EditText|CellFontName))\s*=/si&quot;; classtype:attempted-user;</filter2>
        <id>12733</id>
        <msg>WEB-ACTIVEX ComponentOne FlexGrid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|0|00|A|00|6|00|3|00|B|00|8|00|6|00|-|00|4|00|B|00|2|00|1|00|-|00|1|00|1|00|d|00|3|00|-|00|B|00|D|00|9|00|5|00|-|00|D|00|4|00|2|00|6|00|E|00|F|00|2|00|C|00|7|00|9|00|4|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12734</id>
        <msg>WEB-ACTIVEX ComponentOne FlexGrid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VSFlexGrid.VSFlexGridL&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22VSFlexGrid\.VSFlexGridL\x22|\x27VSFlexGrid\.VSFlexGridL\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Text|EditSelText|EditText|CellFontName)\s*|.*(?P=v)\s*\.\s*(Text|EditSelText|EditText|CellFontName)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22VSFlexGrid\.VSFlexGridL\x22|\x27VSFlexGrid\.VSFlexGridL\x27)\s*\)(\s*\.\s*(Text|EditSelText|EditText|CellFontName)\s*|.*(?P=n)\s*\.\s*(Text|EditSelText|EditText|CellFontName))\s*=/smi&quot;; classtype:attempted-user;</filter2>
        <id>12735</id>
        <msg>WEB-ACTIVEX ComponentOne FlexGrid ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;V|00|S|00|F|00|l|00|e|00|x|00|G|00|r|00|i|00|d|00|.|00|V|00|S|00|F|00|l|00|e|00|x|00|G|00|r|00|i|00|d|00|L|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00.\x00V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00L\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00.\x00V\x00S\x00F\x00l\x00e\x00x\x00G\x00r\x00i\x00d\x00L\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12736</id>
        <msg>WEB-ACTIVEX ComponentOne FlexGrid ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6144</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F3E70CEA-956E-49CC-B444-73AFE593AD7F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F3E70CEA-956E-49CC-B444-73AFE593AD7F\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(FlvPlayerUrl)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F3E70CEA-956E-49CC-B444-73AFE593AD7F\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(FlvPlayerUrl))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12737</id>
        <msg>WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6144</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|3|00|E|00|7|00|0|00|C|00|E|00|A|00|-|00|9|00|5|00|6|00|E|00|-|00|4|00|9|00|C|00|C|00|-|00|B|00|4|00|4|00|4|00|-|00|7|00|3|00|A|00|F|00|E|00|5|00|9|00|3|00|A|00|D|00|7|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12738</id>
        <msg>WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6144</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PPlayer.XPPlayer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PPlayer\.XPPlayer\x22|\x27PPlayer\.XPPlayer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*FlvPlayerUrl\s*|.*(?P=v)\s*\.\s*FlvPlayerUrl\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PPlayer\.XPPlayer\x22|\x27PPlayer\.XPPlayer\x27)\s*\)(\s*\.\s*FlvPlayerUrl\s*|.*(?P=n)\s*\.\s*FlvPlayerUrl\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12739</id>
        <msg>WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>3382</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 F3|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1274</id>
        <msg>RPC portmap ttdbserv request TCP</msg>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
      <rule>
        <bugtraq>26536</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6144</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|P|00|l|00|a|00|y|00|e|00|r|00|.|00|X|00|P|00|P|00|l|00|a|00|y|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00P\x00l\x00a\x00y\x00e\x00r\x00.\x00X\x00P\x00P\x00l\x00a\x00y\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)P\x00P\x00l\x00a\x00y\x00e\x00r\x00.\x00X\x00P\x00P\x00l\x00a\x00y\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12740</id>
        <msg>WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26210</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5775</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5D86DDB5-BDF9-441B-9E9E-D4730F4EE499&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5D86DDB5-BDF9-441B-9E9E-D4730F4EE499\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(InitX)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5D86DDB5-BDF9-441B-9E9E-D4730F4EE499\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(InitX))\s*\(/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12747</id>
        <msg>WEB-ACTIVEX BitDefender Online Scanner ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26210</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5775</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|D|00|8|00|6|00|D|00|D|00|B|00|5|00|-|00|B|00|D|00|F|00|9|00|-|00|4|00|4|00|1|00|B|00|-|00|9|00|E|00|9|00|E|00|-|00|D|00|4|00|7|00|3|00|0|00|F|00|4|00|E|00|E|00|4|00|9|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*5\x00D\x008\x006\x00D\x00D\x00B\x005\x00-\x00B\x00D\x00F\x009\x00-\x004\x004\x001\x00B\x00-\x009\x00E\x009\x00E\x00-\x00D\x004\x007\x003\x000\x00F\x004\x00E\x00E\x004\x009\x009\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12748</id>
        <msg>WEB-ACTIVEX BitDefender Online Scanner ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26210</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5775</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BDSCANONLINE.BDSCANONLINECtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22BDSCANONLINE\.BDSCANONLINECtrl(\.\d)?\x22|\x27BDSCANONLINE\.BDSCANONLINECtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*InitX\s*|.*(?P=v)\s*\.\s*InitX\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22BDSCANONLINE\.BDSCANONLINECtrl(\.\d)?\x22|\x27BDSCANONLINE\.BDSCANONLINECtrl(\.\d)?\x27)\s*\)(\s*\.\s*InitX\s*|.*(?P=n)\s*\.\s*InitX\s*)\s*\(/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12749</id>
        <msg>WEB-ACTIVEX BitDefender Online Scanner ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A9|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1275</id>
        <msg>RPC portmap yppasswd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>26210</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5775</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|D|00|S|00|C|00|A|00|N|00|O|00|N|00|L|00|I|00|N|00|E|00|.|00|B|00|D|00|S|00|C|00|A|00|N|00|O|00|N|00|L|00|I|00|N|00|E|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)B\x00D\x00S\x00C\x00A\x00N\x00O\x00N\x00L\x00I\x00N\x00E\x00.\x00B\x00D\x00S\x00C\x00A\x00N\x00O\x00N\x00L\x00I\x00N\x00E\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)B\x00D\x00S\x00C\x00A\x00N\x00O\x00N\x00L\x00I\x00N\x00E\x00.\x00B\x00D\x00S\x00C\x00A\x00N\x00O\x00N\x00L\x00I\x00N\x00E\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12750</id>
        <msg>WEB-ACTIVEX BitDefender Online Scanner ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>6016</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-1232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A4|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1276</id>
        <msg>RPC portmap ypserv request TCP</msg>
      </rule>
      <rule>
        <bugtraq>28383</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0208</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 BC|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1277</id>
        <msg>RPC portmap ypupdated request UDP</msg>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6E5E167B-1566-4316-B27F-0DDAB3484CF7&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E5E167B-1566-4316-B27F-0DDAB3484CF7\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GotoFolder|CanGotoFolder)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E5E167B-1566-4316-B27F-0DDAB3484CF7\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GotoFolder|CanGotoFolder))\s*\(/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12780</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|5|00|E|00|1|00|6|00|7|00|B|00|-|00|1|00|5|00|6|00|6|00|-|00|4|00|3|00|1|00|6|00|-|00|B|00|2|00|7|00|F|00|-|00|0|00|D|00|D|00|A|00|B|00|3|00|4|00|8|00|4|00|C|00|F|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00E\x005\x00E\x001\x006\x007\x00B\x00-\x001\x005\x006\x006\x00-\x004\x003\x001\x006\x00-\x00B\x002\x007\x00F\x00-\x000\x00D\x00D\x00A\x00B\x003\x004\x008\x004\x00C\x00F\x007\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12781</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Aurigma.ImageUploader&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(GotoFolder|CanGotoFolder)\s*|.*(?P=v)\s*\.\s*(GotoFolder|CanGotoFolder)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\)(\s*\.\s*(GotoFolder|CanGotoFolder)\s*|.*(?P=n)\s*\.\s*(GotoFolder|CanGotoFolder)\s*)\s*\(/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12782</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|u|00|r|00|i|00|g|00|m|00|a|00|.|00|I|00|m|00|a|00|g|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12783</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1280</id>
        <msg>RPC portmap listing UDP 111</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 32771</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1281</id>
        <msg>RPC portmap listing UDP 32771</msg>
      </rule>
      <rule>
        <bugtraq>9633</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A| Negotiate &quot;; nocase; http_header; pcre:&quot;/^Authorization\x3a\s*Negotiate\s*((YE4G.{40}LgMc)|(YIIQ.{40}QUFB))/smiH&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>12905</id>
        <msg>SPECIFIC-THREATS Microsoft SPNEGO ASN.1 library heap corruption overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>26015</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5327</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [6503,6504]</filter1>
        <filter2>flow:established,to_server; dce_iface:506B1890-14C8-11D1-BBC3-00805FA6962E; dce_opnum:269; dce_stub_data; pcre:&quot;/^.{268}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; byte_test:4,&gt;,190,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>12940</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 CA call 269 overflow attempt</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;R|00|I|00|C|00|H|00|E|00|D|00|2|00|0|00|.|00|D|00|L|00|L&quot;; nocase; classtype:bad-unknown;</filter2>
        <id>1295</id>
        <msg>NETBIOS nimda RICHED20.DLL</msg>
        <url>www.f-secure.com/v-descs/nimda.shtml</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>flow:established,to_server; dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:6; dce_stub_data; byte_test:4,=,1,0,relative,dce; byte_test:4,&gt;,142,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>12977</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP mqqm QMCreateObjectInternal overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-065.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3039</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:6; dce_stub_data; byte_test:4,=,1,0,relative,dce; byte_test:4,&gt;,142,4,relative,dce; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>12978</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP mqqm QMCreateObjectInternal overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-065.mspx</url>
      </rule>
      <rule>
        <bugtraq>24196</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:40; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,=,4294967295,40,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>12984</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP srvsvc NetSetFileSecurity integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24196</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:40; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,=,4294967295,40,relative,dce; content:&quot;|04 00|&quot;; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>12985</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP srvsvc NetSetFileSecurity integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>flow:established,to_server; dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:12; dce_stub_data; byte_test:4,&gt;,142,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>13210</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP mqqm QMObjectPathToObjectFormat overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-065.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3039</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:12; dce_stub_data; byte_test:4,&gt;,142,0,relative,dce; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>13211</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP mqqm QMObjectPathToObjectFormat overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-065.mspx</url>
      </rule>
      <rule>
        <bugtraq>26967</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0C378864-D5C4-4D9C-854C-432E3BEC9CCB&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0C378864-D5C4-4D9C-854C-432E3BEC9CCB\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ReadValue)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0C378864-D5C4-4D9C-854C-432E3BEC9CCB\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ReadValue))\s*\(/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13228</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>26967</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|C|00|3|00|7|00|8|00|8|00|6|00|4|00|-|00|D|00|5|00|C|00|4|00|-|00|4|00|D|00|9|00|C|00|-|00|8|00|5|00|4|00|C|00|-|00|4|00|3|00|2|00|E|00|3|00|B|00|E|00|C|00|9|00|C|00|C|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00C\x003\x007\x008\x008\x006\x004\x00-\x00D\x005\x00C\x004\x00-\x004\x00D\x009\x00C\x00-\x008\x005\x004\x00C\x00-\x004\x003\x002\x00E\x003\x00B\x00E\x00C\x009\x00C\x00C\x00B\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13229</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>26967</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CDAF9CEC-F3EC-4B22-ABA3-9726713560F8&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q24&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CDAF9CEC-F3EC-4B22-ABA3-9726713560F8\s*}?\s*(?P=q24)(\s|&gt;).*(?P=id1)\s*\.\s*(ReadTextFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CDAF9CEC-F3EC-4B22-ABA3-9726713560F8\s*}?\s*(?P=q25)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(ReadTextFile))\s*\(/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13230</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>26967</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|D|00|A|00|F|00|9|00|C|00|E|00|C|00|-|00|F|00|3|00|E|00|C|00|-|00|4|00|B|00|2|00|2|00|-|00|A|00|B|00|A|00|3|00|-|00|9|00|7|00|2|00|6|00|7|00|1|00|3|00|5|00|6|00|0|00|F|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q26&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00D\x00A\x00F\x009\x00C\x00E\x00C\x00-\x00F\x003\x00E\x00C\x00-\x004\x00B\x002\x002\x00-\x00A\x00B\x00A\x003\x00-\x009\x007\x002\x006\x007\x001\x003\x005\x006\x000\x00F\x008\x00(}\x00)?(?P=q26)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13231</id>
        <msg>WEB-ACTIVEX HP eSupportDiagnostics 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>36550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3693</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E87F6C8E-16C0-11D3-BEF7-009027438003&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E87F6C8E-16C0-11D3-BEF7-009027438003\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddFolder|AddFile|MakeHttpRequest)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E87F6C8E-16C0-11D3-BEF7-009027438003\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddFolder|AddFile|MakeHttpRequest))\s*\(/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13232</id>
        <msg>WEB-ACTIVEX Persits Software XUpload ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>36550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3693</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|8|00|7|00|F|00|6|00|C|00|8|00|E|00|-|00|1|00|6|00|C|00|0|00|-|00|1|00|1|00|D|00|3|00|-|00|B|00|E|00|F|00|7|00|-|00|0|00|0|00|9|00|0|00|2|00|7|00|4|00|3|00|8|00|0|00|0|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x008\x007\x00F\x006\x00C\x008\x00E\x00-\x001\x006\x00C\x000\x00-\x001\x001\x00D\x003\x00-\x00B\x00E\x00F\x007\x00-\x000\x000\x009\x000\x002\x007\x004\x003\x008\x000\x000\x003\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13233</id>
        <msg>WEB-ACTIVEX Persits Software XUpload ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3693</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Persits.XUpload&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Persits\.XUpload(\.\d)?\x22|\x27Persits\.XUpload(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(AddFolder|AddFile|MakeHttpRequest)\s*|.*(?P=v)\s*\.\s*(AddFolder|AddFile|MakeHttpRequest)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Persits\.XUpload(\.\d)?\x22|\x27Persits\.XUpload(\.\d)?\x27)\s*\)(\s*\.\s*(AddFolder|AddFile|MakeHttpRequest)\s*|.*(?P=n)\s*\.\s*(AddFolder|AddFile|MakeHttpRequest)\s*)\s*\(/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13234</id>
        <msg>WEB-ACTIVEX Persits Software XUpload ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>36550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3693</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|e|00|r|00|s|00|i|00|t|00|s|00|.|00|X|00|U|00|p|00|l|00|o|00|a|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00e\x00r\x00s\x00i\x00t\x00s\x00.\x00X\x00U\x00p\x00l\x00o\x00a\x00d\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)P\x00e\x00r\x00s\x00i\x00t\x00s\x00.\x00X\x00U\x00p\x00l\x00o\x00a\x00d\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13235</id>
        <msg>WEB-ACTIVEX Persits Software XUpload ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6E5E167B-1566-4316-B27F-0DDAB3484CF7&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E5E167B-1566-4316-B27F-0DDAB3484CF7\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(ExtractIptc|ExtractExif)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E5E167B-1566-4316-B27F-0DDAB3484CF7\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(ExtractIptc|ExtractExif))\s*=/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13434</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|5|00|E|00|1|00|6|00|7|00|B|00|-|00|1|00|5|00|6|00|6|00|-|00|4|00|3|00|1|00|6|00|-|00|B|00|2|00|7|00|F|00|-|00|0|00|D|00|D|00|A|00|B|00|3|00|4|00|8|00|4|00|C|00|F|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00E\x005\x00E\x001\x006\x007\x00B\x00-\x001\x005\x006\x006\x00-\x004\x003\x001\x006\x00-\x00B\x002\x007\x00F\x00-\x000\x00D\x00D\x00A\x00B\x003\x004\x008\x004\x00C\x00F\x007\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13435</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Aurigma.ImageUploader&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(ExtractIptc|ExtractExif)\s*|.*(?P=v)\s*\.\s*(ExtractIptc|ExtractExif)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\)(\s*\.\s*(ExtractIptc|ExtractExif)\s*|.*(?P=n)\s*\.\s*(ExtractIptc|ExtractExif))\s*=/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13436</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|u|00|r|00|i|00|g|00|m|00|a|00|.|00|I|00|m|00|a|00|g|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13437</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BA162249-F2C5-4851-8ADC-FC58CB424243&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q11&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA162249-F2C5-4851-8ADC-FC58CB424243\s*}?\s*(?P=q11)(\s|&gt;).*(?P=id1)\s*\.\s*(GotoFolder|CanGotoFolder)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA162249-F2C5-4851-8ADC-FC58CB424243\s*}?\s*(?P=q12)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(GotoFolder|CanGotoFolder))\s*\(/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13438</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|1|00|6|00|2|00|2|00|4|00|9|00|-|00|F|00|2|00|C|00|5|00|-|00|4|00|8|00|5|00|1|00|-|00|8|00|A|00|D|00|C|00|-|00|F|00|C|00|5|00|8|00|C|00|B|00|4|00|2|00|4|00|2|00|4|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q13&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00A\x001\x006\x002\x002\x004\x009\x00-\x00F\x002\x00C\x005\x00-\x004\x008\x005\x001\x00-\x008\x00A\x00D\x00C\x00-\x00F\x00C\x005\x008\x00C\x00B\x004\x002\x004\x002\x004\x003\x00(}\x00)?(?P=q13)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13439</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Aurigma.ImageUploader&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(GotoFolder|CanGotoFolder)\s*|.*(?P=v)\s*\.\s*(GotoFolder|CanGotoFolder)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\)(\s*\.\s*(GotoFolder|CanGotoFolder)\s*|.*(?P=n)\s*\.\s*(GotoFolder|CanGotoFolder)\s*)\s*\(/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13440</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|u|00|r|00|i|00|g|00|m|00|a|00|.|00|I|00|m|00|a|00|g|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q14&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q14)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q15)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13441</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BA162249-F2C5-4851-8ADC-FC58CB424243&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA162249-F2C5-4851-8ADC-FC58CB424243\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(ExtractIptc|ExtractExif)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*BA162249-F2C5-4851-8ADC-FC58CB424243\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\s*\.\s*(ExtractIptc|ExtractExif))\s*=/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13442</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|A|00|1|00|6|00|2|00|2|00|4|00|9|00|-|00|F|00|2|00|C|00|5|00|-|00|4|00|8|00|5|00|1|00|-|00|8|00|A|00|D|00|C|00|-|00|F|00|C|00|5|00|8|00|C|00|B|00|4|00|2|00|4|00|2|00|4|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q18&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*B\x00A\x001\x006\x002\x002\x004\x009\x00-\x00F\x002\x00C\x005\x00-\x004\x008\x005\x001\x00-\x008\x00A\x00D\x00C\x00-\x00F\x00C\x005\x008\x00C\x00B\x004\x002\x004\x002\x004\x003\x00(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13443</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Aurigma.ImageUploader&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(ExtractIptc|ExtractExif)\s*|.*(?P=v)\s*\.\s*(ExtractIptc|ExtractExif)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Aurigma\.ImageUploader\x22|\x27Aurigma\.ImageUploader\x27)\s*\)(\s*\.\s*(ExtractIptc|ExtractExif)\s*|.*(?P=n)\s*\.\s*(ExtractIptc|ExtractExif))\s*=/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13444</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>27577</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|u|00|r|00|i|00|g|00|m|00|a|00|.|00|I|00|m|00|a|00|g|00|e|00|U|00|p|00|l|00|o|00|a|00|d|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q19&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q19)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)A\x00u\x00r\x00i\x00g\x00m\x00a\x00.\x00I\x00m\x00a\x00g\x00e\x00U\x00p\x00l\x00o\x00a\x00d\x00e\x00r\x00(?P=q20)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13445</id>
        <msg>WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/advisory/953839.mspx</url>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13451;</filter2>
        <id>13451</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro foxtlib ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>25977</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5322</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13452;</filter2>
        <id>13452</id>
        <msg>WEB-ACTIVEX Microsoft Visual FoxPro foxtlib ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0078</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13454;</filter2>
        <id>13454</id>
        <msg>WEB-CLIENT Microsoft DXLUTBuilder ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0078</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13456;</filter2>
        <id>13456</id>
        <msg>WEB-CLIENT Microsoft DXLUTBuilder ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0065</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13458;</filter2>
        <id>13458</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0065</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13460;</filter2>
        <id>13460</id>
        <msg>WEB-ACTIVEX Microsoft Forms 2.0 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0108</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CHNKWKS&quot;; content:&quot;|18 00|TEXT&quot;; distance:0; isdataat:4,relative; content:!&quot;|01 00|&quot;; within:2; distance:2; classtype:attempted-user;</filter2>
        <id>13472</id>
        <msg>EXPLOIT Microsoft Works invalid chunk size</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-011.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-0088</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13475;</filter2>
        <id>13475</id>
        <msg>DOS Microsoft Active Directory LDAP denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-003.mspx</url>
      </rule>
      <rule>
        <bugtraq>21401</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-6296</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;&amp;|00|&quot;; within:2; distance:29; byte_jump:2,-6,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:&quot;|05|&quot;; within:1; byte_test:1,&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; content:&quot;|1A 00|&quot;; within:2; distance:19; pcre:&quot;/^.{20}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,little,multiplier 2,relative,align; byte_test:4,&gt;,65536,0,little,relative; content:&quot;b|00|l|00|a|00|h|00|_|00|b|00|l|00|a|00|h|00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>13594</id>
        <msg>SPECIFIC-THREATS Microsoft Windows print spooler little endian DoS attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13669;</filter2>
        <id>13669</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13671;</filter2>
        <id>13671</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13673;</filter2>
        <id>13673</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13675;</filter2>
        <id>13675</id>
        <msg>WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13828, service http;</filter2>
        <id>13828</id>
        <msg>WEB-ACTIVEX sapi.dll ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13829;</filter2>
        <id>13829</id>
        <msg>WEB-ACTIVEX sapi.dll ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13830, service http;</filter2>
        <id>13830</id>
        <msg>WEB-ACTIVEX sapi.dll alternate killbit ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13831;</filter2>
        <id>13831</id>
        <msg>WEB-ACTIVEX sapi.dll alternate killbit ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13832, service http;</filter2>
        <id>13832</id>
        <msg>WEB-ACTIVEX backweb ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13833;</filter2>
        <id>13833</id>
        <msg>WEB-ACTIVEX backweb ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-1445</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13835;</filter2>
        <id>13835</id>
        <msg>DOS Microsoft Active Directory LDAP cookie denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-035.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0082</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13966;</filter2>
        <id>13966</id>
        <msg>WEB-ACTIVEX Microsoft Message System ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0082</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13968;</filter2>
        <id>13968</id>
        <msg>WEB-ACTIVEX Microsoft Message System ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-050.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1457</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13976;</filter2>
        <id>13976</id>
        <msg>WEB-CLIENT Microsoft Windows Event System ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-049.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1457</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13978;</filter2>
        <id>13978</id>
        <msg>WEB-CLIENT Microsoft Windows Event System ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-049.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3F1D494B-0CEF-4468-96C9-386E2E4DEC90&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3F1D494B-0CEF-4468-96C9-386E2E4DEC90\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Download)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3F1D494B-0CEF-4468-96C9-386E2E4DEC90\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(Download))\s*\(/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14033</id>
        <msg>WEB-ACTIVEX Orbit Downloader ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|F|00|1|00|D|00|4|00|9|00|4|00|B|00|-|00|0|00|C|00|E|00|F|00|-|00|4|00|4|00|6|00|8|00|-|00|9|00|6|00|C|00|9|00|-|00|3|00|8|00|6|00|E|00|2|00|E|00|4|00|D|00|E|00|C|00|9|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00F\x001\x00D\x004\x009\x004\x00B\x00-\x000\x00C\x00E\x00F\x00-\x004\x004\x006\x008\x00-\x009\x006\x00C\x009\x00-\x003\x008\x006\x00E\x002\x00E\x004\x00D\x00E\x00C\x009\x000\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14034</id>
        <msg>WEB-ACTIVEX Orbit Downloader ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Orbitmxt.Orbit&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Orbitmxt\.Orbit\x22|\x27Orbitmxt\.Orbit\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Download\s*|.*(?P=v)\s*\.\s*Download\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Orbitmxt\.Orbit\x22|\x27Orbitmxt\.Orbit\x27)\s*\)(\s*\.\s*Download\s*|.*(?P=n)\s*\.\s*Download\s*)\s*\(/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14035</id>
        <msg>WEB-ACTIVEX Orbit Downloader ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1602</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|r|00|b|00|i|00|t|00|m|00|x|00|t|00|.|00|O|00|r|00|b|00|i|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)O\x00r\x00b\x00i\x00t\x00m\x00x\x00t\x00.\x00O\x00r\x00b\x00i\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)O\x00r\x00b\x00i\x00t\x00m\x00x\x00t\x00.\x00O\x00r\x00b\x00i\x00t\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14036</id>
        <msg>WEB-ACTIVEX Orbit Downloader ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29736</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;36723f97-7aa0-11d4-8919-ff2d71d0d32c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*36723f97-7aa0-11d4-8919-ff2d71d0d32c\s*}?\s*(?P=q1)[^&gt;]*&gt;.*&lt;param\s*[^&gt;]*\s*name\s*=\s*target-frame[^&gt;]*\s*value\s*=\s*(\x22[^&gt;\s\x22]{128}|\x27[^&gt;\s\x27]{128}|[^&gt;\s]{128})/Osmi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14038</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX target-frame parameter overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;WinSecureDisc&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*WinSecureDisc/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>14066</id>
        <msg>SPYWARE-PUT Adware winsecuredisc runtime detection</msg>
        <url>www.spywareremove.com/removeWinSecureDisc.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mxlivemedia/multi/73.exe&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Installer&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Installer/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14078</id>
        <msg>SPYWARE-PUT Adware winspywareprotect runtime detection - download malicous code</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&amp;tabid=1</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/123kah.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;a1.mxlivemedia.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*a1\x2Emxlivemedia\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14079</id>
        <msg>SPYWARE-PUT Adware winspywareprotect runtime detection - connection to malicious sites</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&amp;tabid=1</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/confuci.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;xiphoman.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*xiphoman\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14080</id>
        <msg>SPYWARE-PUT Adware winspywareprotect runtime detection - connection to malicious server</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&amp;tabid=1</url>
      </rule>
      <rule>
        <bugtraq>30826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1682</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|7|00|B|00|6|00|2|00|F|00|4|00|E|00|-|00|8|00|2|00|F|00|4|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|D|00|4|00|1|00|-|00|0|00|0|00|1|00|0|00|5|00|A|00|0|00|A|00|7|00|E|00|8|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x007\x00B\x006\x002\x00F\x004\x00E\x00-\x008\x002\x00F\x004\x00-\x001\x001\x00D\x002\x00-\x00B\x00D\x004\x001\x00-\x000\x000\x001\x000\x005\x00A\x000\x00A\x007\x00E\x008\x009\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14232</id>
        <msg>WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX clsid unicode access</msg>
        <url>support.softartisans.com/Support-114.aspx</url>
      </rule>
      <rule>
        <bugtraq>3099</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2001-0540</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3389</filter1>
        <filter2>flow:to_server,established; content:&quot;|03 00 00 0B 06 E0 00 00 00 00 00|&quot;; depth:11; classtype:protocol-command-decode;</filter2>
        <id>1447</id>
        <msg>MISC MS Terminal server request RDP</msg>
        <nessus>10940</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS01-040.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15085;</filter2>
        <id>15085</id>
        <msg>WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15087;</filter2>
        <id>15087</id>
        <msg>WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15109, service http;</filter2>
        <id>15109</id>
        <msg>WEB-ACTIVEX Shell.Explorer 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15110;</filter2>
        <id>15110</id>
        <msg>WEB-ACTIVEX Shell.Explorer 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>11466</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15111;</filter2>
        <id>15111</id>
        <msg>WEB-ACTIVEX Shell.Explorer 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>11466</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15112, service http;</filter2>
        <id>15112</id>
        <msg>WEB-ACTIVEX Shell.Explorer 2 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>11466</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15113;</filter2>
        <id>15113</id>
        <msg>WEB-ACTIVEX Shell.Explorer 2 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>11466</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15122, service http;</filter2>
        <id>15122</id>
        <msg>WEB-ACTIVEX Shell.Explorer 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:15; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; content:&quot;|00 00 00 00|&quot;; within:4; distance:8; content:&quot;|04 00|&quot;; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15448</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrShareEnum null policy handle attempt</msg>
      </rule>
      <rule>
        <bugtraq>24196</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345778-1234-abcd-ef00-0123456789ab; dce_opnum:15; dce_stub_data; byte_test:4,&gt;,255,36,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15507</id>
        <msg>SPECIFIC-THREATS DCERPC NCACN-IP-TCP lsarpc LsarLookupSids translated_names overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24196</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [138,1024:]</filter1>
        <filter2>dce_iface:12345778-1234-abcd-ef00-0123456789ab; dce_opnum:15; dce_stub_data; byte_test:4,&gt;,255,36,relative,dce; content:&quot;|04 00|&quot;; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15508</id>
        <msg>SPECIFIC-THREATS DCERPC NCADG-IP-UDP lsarpc LsarLookupSids translated_names overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1929</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15862;</filter2>
        <id>15862</id>
        <msg>WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX clsid unicode access </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1929</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15864;</filter2>
        <id>15864</id>
        <msg>WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX function call unicode access </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-044.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-0639</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,283,16,relative,dce; content:&quot;N|00|e|00|t|00|W|00|a|00|r|00|e|00| |00|R|00|e|00|m|00|o|00|t|00|e|00| |00|P|00|r|00|i|00|n|00|t|00|e|00|r|00|s|00|&quot;; within:46; distance:20; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15881</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters Name Field attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:65; dce_stub_data; pcre:&quot;/^.{32}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,26,48,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15911</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss RouteRefreshPrinterChangeNotification attempt</msg>
      </rule>
      <rule>
        <bugtraq>22564</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|P|00|R|00|T|00|.|00|S|00|m|00|a|00|r|00|t|00|I|00|s|00|s|00|u|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00P\x00R\x00T\x00.\x00S\x00m\x00a\x00r\x00t\x00I\x00s\x00s\x00u\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00P\x00R\x00T\x00.\x00S\x00m\x00a\x00r\x00t\x00I\x00s\x00s\x00u\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16012</id>
        <msg>WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX function call unicode access</msg>
        <url>securityresponse.symantec.com/avcenter/security/Content/2007.02.22.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4688</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:e67ab081-9844-3521-9d32-834f038001c0; dce_opnum:9; dce_stub_data; content:&quot;|5C 00 5C 00|&quot;; pcre:&quot;/^(B\x00B\x00B\x00|\x41\x41\x41\x41)/R&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16016</id>
        <msg>SPECIFIC-THREATS Microsoft client for netware overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-066.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;SMB&quot;; nocase; content:&quot;|9C E0 0A 00 09 00 00 00 0A 00 0B 00 0D 00 03 00 14 00 15 00 10 00 17 00 16 00 00 00|P|00 00 00|&quot;; distance:0; metadata:policy balanced-ips drop, policy connectivity-ips drop; classtype:attempted-user;</filter2>
        <id>16034</id>
        <msg>SPECIFIC-THREATS Samba spools RPC smb_io_notify_option_type_data request handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26455</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5398</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 137</filter1>
        <filter2>flow:to_server,established; content:&quot; FGFEFEFGENCNFHEJEODCELFDFCFGCABM|00 00| |00 01|&quot;;  metadata:service netbios-ns; classtype:attempted-user;</filter2>
        <id>16058</id>
        <msg>SPECIFIC-THREATS Samba WINS Server Name Registration handling stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-3942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|11 00 5C|MAILSLOT|5C|LANMANA&quot;; classtype:attempted-dos;</filter2>
        <id>16066</id>
        <msg>EXPLOIT Microsoft Windows Server driver crafted SMB data denial of service </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>29283</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 06 09 82|&quot;; depth:4; offset:16; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;SString&quot;; byte_test:4,&gt;,4096,1,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16081</id>
        <msg>RPC portmap 395650 tcp XDR SString buffer overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <bugtraq>29283</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 06 09 82|&quot;; depth:4; offset:12; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;SString&quot;; byte_test:4,&gt;,4096,1,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16082</id>
        <msg>RPC portmap 395650 udp XDR SString buffer overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 06 09 82|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16083</id>
        <msg>RPC portmap 395650 tcp request</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 06 09 82|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16084</id>
        <msg>RPC portmap 395650 udp request</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 06 09 82|&quot;; depth:4; offset:16; content:&quot;|00 00 00|y&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,28,relative,align; byte_jump:4,32,relative,align; byte_test:4,&gt;,1988,240,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16085</id>
        <msg>RPC portmap 395650 tcp xml buffer overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-2242</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 06 09 82|&quot;; depth:4; offset:12; content:&quot;|00 00 00|y&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,28,relative,align; byte_jump:4,32,relative,align; byte_test:4,&gt;,1988,240,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16086</id>
        <msg>RPC portmap 395650 udp xml buffer overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=176798</url>
      </rule>
      <rule>
        <bugtraq>34414</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0077</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16221, service http;</filter2>
        <id>16221</id>
        <msg>EXPLOIT Microsoft ISA and Forefront Threat Management Web Proxy TCP Listener denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-016.mspx</url>
      </rule>
      <rule>
        <bugtraq>31545</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-4609</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16294, service http;</filter2>
        <id>16294</id>
        <msg>EXPLOIT Microsoft Windows TCP stack zero window size exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-048.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2987</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16386, service http;</filter2>
        <id>16386</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2987</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16387;</filter2>
        <id>16387</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2987</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16388;</filter2>
        <id>16388</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2987</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16389;</filter2>
        <id>16389</id>
        <msg>WEB-ACTIVEX AcroPDF.PDF ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16397, service netbios-ssn;</filter2>
        <id>16397</id>
        <msg>NETBIOS SMB andx invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16398, service netbios-ssn;</filter2>
        <id>16398</id>
        <msg>NETBIOS SMB invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16399, service netbios-ssn;</filter2>
        <id>16399</id>
        <msg>NETBIOS SMB unicode andx invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16400, service netbios-ssn;</filter2>
        <id>16400</id>
        <msg>NETBIOS SMB unicode invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16401, service netbios-dgm;</filter2>
        <id>16401</id>
        <msg>NETBIOS-DG SMB andx invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16402, service netbios-dgm;</filter2>
        <id>16402</id>
        <msg>NETBIOS-DG SMB invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16403, service netbios-dgm;</filter2>
        <id>16403</id>
        <msg>NETBIOS-DG SMB unicode andx invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2010-0022</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|16404, service netbios-dgm;</filter2>
        <id>16404</id>
        <msg>NETBIOS-DG SMB unicode invalid server name share access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|16413;</filter2>
        <id>16413</id>
        <msg>WEB-CLIENT Microsoft PowerPoint invalid TextCharsAtom remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16420;</filter2>
        <id>16420</id>
        <msg>WEB-ACTIVEX Microsoft Data Analyzer 3.5 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-008.mspx</url>
      </rule>
      <rule>
        <bugtraq>31751</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-4556</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16446</id>
        <msg>RPC portmap Solaris sadmin tcp request</msg>
      </rule>
      <rule>
        <bugtraq>31751</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-4556</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16447</id>
        <msg>RPC portmap Solaris sadmin udp request</msg>
      </rule>
      <rule>
        <bugtraq>31751</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-4556</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 87 88|&quot;; depth:4; offset:16; byte_jump:4,8,relative,align; byte_jump:4,4,relative,align; content:&quot;ADM_METHOD&quot;; content:&quot;|00 00 00 09|&quot;; within:8; byte_test:4,&gt;,999,0,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16448</id>
        <msg>RPC portmap Solaris sadmin tcp adm_build_path overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31751</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2008-4556</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 01 87 88|&quot;; depth:4; offset:12; byte_jump:4,8,relative,align; byte_jump:4,4,relative,align; content:&quot;ADM_METHOD&quot;; content:&quot;|00 00 00 09|&quot;; within:8; byte_test:4,&gt;,999,0,relative; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>16449</id>
        <msg>RPC portmap Solaris sadmin udp adm_build_path overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2010-0812</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|16533;</filter2>
        <id>16533</id>
        <msg>BAD-TRAFFIC Microsoft Windows ISATAP-addressed IPv6 traffic spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-029.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0477</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16540, service netbios-ssn;</filter2>
        <id>16540</id>
        <msg>NETBIOS SMB2 client NetBufferList NULL entry remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>36550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3693</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E87F6C8E-16C0-11D3-BEF7-009027438003&quot;; fast_pattern:only; nocase; pcre:&quot;/|2E|(AddFolder|AddFile|MakeHttpRequest)/i&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16581</id>
        <msg>SPECIFIC-THREATS Persits Software XUpload ActiveX clsid unsafe function access attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;strMode=setup&amp;strID=pcvaccine&amp;strPC=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16926</id>
        <msg>BLACKLIST URI request for known malicious URI - strMode=setup&amp;strID=pcvaccine&amp;strPC=</msg>
        <url>labs.snort.org/docs/16926.html</url>
      </rule>
      <rule>
        <bugtraq>35558</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;String.fromCharCode|28|parseInt&quot;; content:&quot;String.fromCharCode|28|&quot;; distance:0; content:&quot;.charCodeAt|28|&quot;; distance:0; content:&quot;.replace&quot;; distance:0; content:&quot;|3C 2F|script|3E 20 0A 3C 2F|body|3E 20 0A 3C 2F|html|3E|&quot;; distance:0; classtype:attempted-user;</filter2>
        <id>17111</id>
        <msg>SPECIFIC-THREATS Microsoft Video ActiveX Control stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0715</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>content:&quot;|5C 00 43 00 24 00 5C 00 31 00 32 00 33 00 34 00|&quot;; metadata:service netbios-ssn; classtype:attempted-user;</filter2>
        <id>17112</id>
        <msg>SPECIFIC-THREATS DCERPC rpcss2 _RemoteGetClassObject attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-2561</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|17133;</filter2>
        <id>17133</id>
        <msg>WEB-CLIENT MSXML2 ActiveX malformed HTTP response</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>38472</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2754</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0 00|&quot;; depth:5; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:7; byte_test:1,&amp;,0x80,8,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>17205</id>
        <msg>RPC Multiple vendors librpc.dll stack buffer overflow attempt - udp</msg>
      </rule>
      <rule>
        <bugtraq>38472</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2754</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [111,36890]</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0 00|&quot;; depth:5; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:7; byte_test:1,&amp;,0x80,8,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>17206</id>
        <msg>RPC Multiple vendors librpc.dll stack buffer overflow attempt - tcp</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.tiff; content:&quot;|02 01 03 00|&quot;; byte_test:4,&gt;,6,0,relative,little; metadata:service http; classtype:attempted-user;</filter2>
        <id>17231</id>
        <msg>WEB-CLIENT Microsoft Kodak Imaging small offset malformed tiff - little-endian</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-055.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.tiff; content:&quot;|01 02 00 03|&quot;; byte_test:4,&gt;,6,0,relative,big; metadata:service http; classtype:attempted-user;</filter2>
        <id>17232</id>
        <msg>WEB-CLIENT Microsoft Kodak Imaging large offset malformed tiff - big-endian</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-055.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2729</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17252;</filter2>
        <id>17252</id>
        <msg>NETBIOS Microsoft Windows Print Spooler arbitrary file write attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-061.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2729</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17253;</filter2>
        <id>17253</id>
        <msg>NETBIOS Microsoft Windows Print Spooler arbitrary file write attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-061.mspx</url>
      </rule>
      <rule>
        <bugtraq>205</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0181</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A8|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1732</id>
        <msg>RPC portmap rwalld request UDP</msg>
      </rule>
      <rule>
        <bugtraq>205</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0181</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A8|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1733</id>
        <msg>RPC portmap rwalld request TCP</msg>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:10; dce_stub_data; content:&quot;|5C 00 5C 00|&quot;; distance:16; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>17435</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:10; dce_stub_data; content:&quot;|5C 5C|&quot;; distance:16; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>17437</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>15058</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1979</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3372</filter1>
        <filter2>flow:to_server,established; content:&quot;PUSH|20|test|0A|&quot;; depth:10; classtype:attempted-dos;</filter2>
        <id>17439</id>
        <msg>EXPLOIT Microsoft Distributed Transaction Controller TIP DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>4674</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0084</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 8B|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1746</id>
        <msg>RPC portmap cachefsd request UDP</msg>
        <nessus>10951</nessus>
      </rule>
      <rule>
        <bugtraq>4674</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0084</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 8B|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1747</id>
        <msg>RPC portmap cachefsd request TCP</msg>
        <nessus>10951</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4398</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62b93df0-8b02-11ce-876c-00805f842837; content:&quot;|05|&quot;; byte_test:1,&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; byte_test:1,&amp;,128,0,relative; content:&quot;|00 00|&quot;; within:2; distance:19; pcre:&quot;/^.{16}/sR&quot;; byte_test:4,&gt;,64,12,little,relative; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17634</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 little endian object call overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4398</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62b93df0-8b02-11ce-876c-00805f842837; content:&quot;|05|&quot;; byte_test:1,&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; content:&quot;|00 00|&quot;; within:2; distance:19; byte_test:4,&gt;,64,12,little,relative; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17635</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 little endian overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4398</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:established,to_server; dce_iface:62b93df0-8b02-11ce-876c-00805f842837; content:&quot;|05|&quot;; byte_test:1,!&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; byte_test:1,&amp;,128,0,relative; content:&quot;|00 00|&quot;; within:2; distance:19; pcre:&quot;/^.{16}/sR&quot;; byte_test:4,&gt;,64,12,relative; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17636</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 object call overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4398</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6502</filter1>
        <filter2>flow:to_server; dce_iface:62b93df0-8b02-11ce-876c-00805f842837; content:&quot;|05|&quot;; byte_test:1,!&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; content:&quot;|00 00|&quot;; within:2; distance:19; byte_test:4,&gt;,64,12,relative; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17637</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 overflow attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143</url>
      </rule>
      <rule>
        <bugtraq>22005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:43; dce_stub_data; byte_test:4,&gt;,624,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>17640</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor opnum 43 overflow attempt</msg>
        <url>www.kb.cert.org/vuls/id/180336</url>
      </rule>
      <rule>
        <bugtraq>22639</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|47 00 03 00|&quot;; within:4; byte_test:4,&gt;,98,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>17707</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect trend_req_num buffer overflow attempt</msg>
        <url>esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</url>
      </rule>
      <rule>
        <bugtraq>22639</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|08 00 0A 00|&quot;; within:4; byte_test:4,&gt;,600,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>17714</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt</msg>
        <url>esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</url>
      </rule>
      <rule>
        <bugtraq>22639</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2007-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5168</filter1>
        <filter2>flow:established,to_server; dce_iface:25288888-BD5B-11D1-9D53-0080C83A5C2C; dce_opnum:0; dce_stub_data; content:&quot;|09 00 0A 00|&quot;; within:4; byte_test:4,&gt;,600,0,little,relative; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>17715</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt</msg>
        <url>esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <cve>2010-2732</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:policy-violation; metadata: engine shared, soid 3|18072;</filter2>
        <id>18072</id>
        <msg>WEB-MISC Microsoft Forefront UAG external redirect attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0666</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;%x %x&quot;; within:256; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1890</id>
        <msg>RPC status GHBN format string attack</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0666</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:16; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;%x %x&quot;; within:256; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1891</id>
        <msg>RPC status GHBN format string attack</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <bugtraq>614</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0704</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:12; content:&quot;|00 00 00 07|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,512,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1905</id>
        <msg>RPC AMD UDP amqproc_mount plog overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>614</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0704</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:16; content:&quot;|00 00 00 07|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,512,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1906</id>
        <msg>RPC AMD TCP amqproc_mount plog overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>524</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:12; content:&quot;|00 00 00 15|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1907</id>
        <msg>RPC CMSD UDP CMSD_CREATE buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>524</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:16; content:&quot;|00 00 00 15|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1908</id>
        <msg>RPC CMSD TCP CMSD_CREATE buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>524</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:16; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,1000,28,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1909</id>
        <msg>RPC CMSD TCP CMSD_INSERT buffer overflow attempt</msg>
        <url>www.cert.org/advisories/CA-99-08-cmsd.html</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>1999-0696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:12; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,1000,28,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1910</id>
        <msg>RPC CMSD udp CMSD_INSERT buffer overflow attempt</msg>
        <url>www.cert.org/advisories/CA-99-08-cmsd.html</url>
      </rule>
      <rule>
        <bugtraq>866</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0977</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 87 88|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,124,relative,align; byte_jump:4,20,relative,align; byte_test:4,&gt;,512,4,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1911</id>
        <msg>RPC sadmind UDP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>866</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 87 88|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,124,relative,align; byte_jump:4,20,relative,align; byte_test:4,&gt;,512,4,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1912</id>
        <msg>RPC sadmind TCP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0666</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,100,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1913</id>
        <msg>RPC STATD UDP stat mon_name format string exploit attempt</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0666</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,100,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1914</id>
        <msg>RPC STATD TCP stat mon_name format string exploit attempt</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0666</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,100,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1915</id>
        <msg>RPC STATD UDP monitor mon_name format string exploit attempt</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <bugtraq>1480</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0666</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 B8|&quot;; depth:4; offset:16; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,100,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1916</id>
        <msg>RPC STATD TCP monitor mon_name format string exploit attempt</msg>
        <nessus>10544</nessus>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1922</id>
        <msg>RPC portmap proxy attempt TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1923</id>
        <msg>RPC portmap proxy attempt UDP</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>1924</id>
        <msg>RPC mountd UDP export request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>1925</id>
        <msg>RPC mountd TCP exportall request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 06|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>1926</id>
        <msg>RPC mountd UDP exportall request</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1949</id>
        <msg>RPC portmap SET attempt TCP 111</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1950</id>
        <msg>RPC portmap SET attempt UDP 111</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0210</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>1951</id>
        <msg>RPC mountd TCP mount request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>1952</id>
        <msg>RPC mountd UDP mount request</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:16; content:&quot;|00 00 00 09|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1953</id>
        <msg>RPC AMD TCP pid request</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:12; content:&quot;|00 00 00 09|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1954</id>
        <msg>RPC AMD UDP pid request</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:16; content:&quot;|00 00 00 08|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1955</id>
        <msg>RPC AMD TCP version request</msg>
      </rule>
      <rule>
        <bugtraq>1554</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2000-0696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500:</filter1>
        <filter2>flow:to_server; content:&quot;|00 04 93 F3|&quot;; depth:4; offset:12; content:&quot;|00 00 00 08|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1956</id>
        <msg>RPC AMD UDP version request</msg>
      </rule>
      <rule>
        <bugtraq>866</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>1999-0977</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 01 87 88|&quot;; depth:4; offset:12; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:protocol-command-decode;</filter2>
        <id>1957</id>
        <msg>RPC sadmind UDP PING</msg>
        <nessus>10229</nessus>
      </rule>
      <rule>
        <bugtraq>866</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>1999-0977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 87 88|&quot;; depth:4; offset:16; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:protocol-command-decode;</filter2>
        <id>1958</id>
        <msg>RPC sadmind TCP PING</msg>
        <nessus>10229</nessus>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A3|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1959</id>
        <msg>RPC portmap NFS request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A3|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1960</id>
        <msg>RPC portmap NFS request TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 AB|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1961</id>
        <msg>RPC portmap RQUOTA request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 AB|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1962</id>
        <msg>RPC portmap RQUOTA request TCP</msg>
      </rule>
      <rule>
        <bugtraq>864</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0974</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 01 86 AB|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,128,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>1963</id>
        <msg>RPC RQUOTA getquota overflow attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>122</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0003</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 F3|&quot;; depth:4; offset:12; content:&quot;|00 00 00 07|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,128,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1964</id>
        <msg>RPC tooltalk UDP overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>122</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 F3|&quot;; depth:4; offset:16; content:&quot;|00 00 00 07|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,128,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>1965</id>
        <msg>RPC tooltalk TCP overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>6665</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0027</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87|}&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2006</id>
        <msg>RPC portmap kcms_server request TCP</msg>
        <url>www.kb.cert.org/vuls/id/850785</url>
      </rule>
      <rule>
        <bugtraq>1892</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2014</id>
        <msg>RPC portmap UNSET attempt TCP 111</msg>
      </rule>
      <rule>
        <bugtraq>1892</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2015</id>
        <msg>RPC portmap UNSET attempt UDP 111</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B8|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2016</id>
        <msg>RPC portmap status request TCP</msg>
      </rule>
      <rule>
        <bugtraq>2714</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0331</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F7|u&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2017</id>
        <msg>RPC portmap espd request UDP</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2018</id>
        <msg>RPC mountd TCP dump request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2019</id>
        <msg>RPC mountd UDP dump request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2020</id>
        <msg>RPC mountd TCP unmount request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2021</id>
        <msg>RPC mountd UDP unmount request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2022</id>
        <msg>RPC mountd TCP unmountall request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>2023</id>
        <msg>RPC mountd UDP unmountall request</msg>
      </rule>
      <rule>
        <bugtraq>864</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0974</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 AB|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,128,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>2024</id>
        <msg>RPC RQUOTA getquota overflow attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2025</id>
        <msg>RPC yppasswd username overflow attempt UDP</msg>
        <nessus>10684</nessus>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2026</id>
        <msg>RPC yppasswd username overflow attempt TCP</msg>
        <nessus>10684</nessus>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2031</id>
        <msg>RPC yppasswd user update UDP</msg>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2032</id>
        <msg>RPC yppasswd user update TCP</msg>
      </rule>
      <rule>
        <bugtraq>6016</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-1232</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A4|&quot;; depth:4; offset:12; content:&quot;|00 00 00 0B|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2033</id>
        <msg>RPC ypserv maplist request UDP</msg>
        <nessus>13976</nessus>
      </rule>
      <rule>
        <bugtraq>6016</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-1232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A4|&quot;; depth:4; offset:16; content:&quot;|00 00 00 0B|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2034</id>
        <msg>RPC ypserv maplist request TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 03 0D|p&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2035</id>
        <msg>RPC portmap network-status-monitor request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 03 0D|p&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2036</id>
        <msg>RPC portmap network-status-monitor request TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 03 0D|p&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2037</id>
        <msg>RPC network-status-monitor mon-callback request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 03 0D|p&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2038</id>
        <msg>RPC network-status-monitor mon-callback request TCP</msg>
      </rule>
      <rule>
        <bugtraq>1372</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2000-0508</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B5|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2079</id>
        <msg>RPC portmap nlockmgr request UDP</msg>
        <nessus>10220</nessus>
      </rule>
      <rule>
        <bugtraq>1372</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2000-0508</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B5|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2080</id>
        <msg>RPC portmap nlockmgr request TCP</msg>
        <nessus>10220</nessus>
      </rule>
      <rule>
        <bugtraq>5075</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0359</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F7|h&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2081</id>
        <msg>RPC portmap rpc.xfsmd request UDP</msg>
      </rule>
      <rule>
        <bugtraq>5075</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0359</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F7|h&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2082</id>
        <msg>RPC portmap rpc.xfsmd request TCP</msg>
      </rule>
      <rule>
        <bugtraq>5075</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0359</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 05 F7|h&quot;; depth:4; offset:12; content:&quot;|00 00 00 0D|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2083</id>
        <msg>RPC rpc.xfsmd xfs_export attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>5075</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0359</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 05 F7|h&quot;; depth:4; offset:16; content:&quot;|00 00 00 0D|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2084</id>
        <msg>RPC rpc.xfsmd xfs_export attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>28383</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0208</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 01 86 BC|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|7C|&quot;; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>2088</id>
        <msg>RPC ypupdated arbitrary command attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>1749</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0208</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 BC|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|7C|&quot;; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>2089</id>
        <msg>RPC ypupdated arbitrary command attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>7123</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0028</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0 00|&quot;; depth:5; offset:12; content:&quot;|00 00 00 05|&quot;; within:4; distance:3; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,2048,12,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2092</id>
        <msg>RPC portmap proxy integer overflow attempt UDP</msg>
        <nessus>11420</nessus>
      </rule>
      <rule>
        <bugtraq>7123</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2003-0028</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0 00|&quot;; depth:5; offset:16; content:&quot;|00 00 00 05|&quot;; within:4; distance:3; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,2048,12,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2093</id>
        <msg>RPC portmap proxy integer overflow attempt TCP</msg>
        <nessus>11420</nessus>
      </rule>
      <rule>
        <bugtraq>5356</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0391</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:12; content:&quot;|00 00 00 15|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,20,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>2094</id>
        <msg>RPC CMSD UDP CMSD_CREATE array buffer overflow attempt</msg>
        <nessus>11418</nessus>
      </rule>
      <rule>
        <bugtraq>5356</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0391</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 E4|&quot;; depth:4; offset:16; content:&quot;|00 00 00 15|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,20,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>2095</id>
        <msg>RPC CMSD TCP CMSD_CREATE array buffer overflow attempt</msg>
        <nessus>11418</nessus>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>2101</id>
        <msg>NETBIOS SMB Trans Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5807</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1214</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1723</filter1>
        <filter2>flow:to_server,established,no_stream; isdataat:156; content:&quot;|00 01|&quot;; depth:2; offset:2; content:&quot;|00 01|&quot;; depth:2; offset:8; classtype:attempted-admin;</filter2>
        <id>2126</id>
        <msg>MISC Microsoft PPTP Start Control Request buffer overflow attempt</msg>
        <nessus>11178</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB2&quot;; depth:5; offset:4; content:&quot;|5C 00|S|00|t|00|a|00|r|00|t|00| |00|M|00|e|00|n|00|u|00 5C 00|P|00|r|00|o|00|g|00|r|00|a|00|m|00|s|00 5C 00|S|00|t|00|a|00|r|00|t|00|u|00|p&quot;; distance:0; nocase; metadata:service netbios-ssn; classtype:attempted-recon;</filter2>
        <id>2177</id>
        <msg>NETBIOS SMB startup folder unicode access</msg>
      </rule>
      <rule>
        <bugtraq>8179</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0252</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5 00|&quot;; depth:5; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:3; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1023,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>2184</id>
        <msg>RPC mountd TCP mount path overflow attempt</msg>
        <nessus>11800</nessus>
      </rule>
      <rule>
        <bugtraq>8179</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0252</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5 00|&quot;; depth:5; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:3; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1023,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:misc-attack;</filter2>
        <id>2185</id>
        <msg>RPC mountd UDP mount path overflow attempt</msg>
        <nessus>11800</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:to_server,established; content:&quot;|05|&quot;; depth:1; content:&quot;|0B|&quot;; within:1; distance:1; byte_test:1,&amp;,1,0,relative; content:&quot;|00|&quot;; within:1; distance:21; classtype:attempted-dos;</filter2>
        <id>2190</id>
        <msg>NETBIOS DCERPC invalid bind attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB%&quot;; depth:5; offset:4; nocase; content:&quot;&amp;|00|&quot;; within:2; distance:56; content:&quot;|5C 00|P|00|I|00|P|00|E|00 5C 00|&quot;; within:12; distance:5; nocase; content:&quot;|05|&quot;; within:1; distance:2; content:&quot;|0B|&quot;; within:1; distance:1; byte_test:1,&amp;,1,0,relative; content:&quot;|00|&quot;; within:1; distance:21; classtype:attempted-dos;</filter2>
        <id>2191</id>
        <msg>NETBIOS SMB DCERPC invalid bind attempt</msg>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>2382</id>
        <msg>NETBIOS SMB Session Setup NTMLSSP asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>2383</id>
        <msg>NETBIOS SMB-DS Session Setup NTMLSSP asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; classtype:protocol-command-decode;</filter2>
        <id>2402</id>
        <msg>NETBIOS SMB-DS Session Setup andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; classtype:protocol-command-decode;</filter2>
        <id>2404</id>
        <msg>NETBIOS SMB-DS Session Setup unicode andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;D|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2467</id>
        <msg>NETBIOS SMB D$ unicode share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;D|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2468</id>
        <msg>NETBIOS SMB-DS D$ share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;C|00 24 00 00 00|&quot;; distance:2; nocase; content:!&quot;I|00|P|00|C|00 24 00 00 00|&quot;; within:10; distance:-10; nocase; classtype:protocol-command-decode;</filter2>
        <id>2470</id>
        <msg>NETBIOS SMB C$ unicode share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;C|24 00|&quot;; distance:2; nocase; content:!&quot;IPC|24 00|&quot;; within:5; distance:-5; nocase; classtype:protocol-command-decode;</filter2>
        <id>2471</id>
        <msg>NETBIOS SMB-DS C$ share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;A|00|D|00|M|00|I|00|N|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2473</id>
        <msg>NETBIOS SMB ADMIN$ unicode share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;ADMIN|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2474</id>
        <msg>NETBIOS SMB-DS ADMIN$ share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;A|00|D|00|M|00|I|00|N|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2475</id>
        <msg>NETBIOS SMB-DS ADMIN$ unicode share access</msg>
      </rule>
      <rule>
        <bugtraq>10333</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0444</cve>
        <filter1>udp $EXTERNAL_NET 137 -&gt; $HOME_NET 137</filter1>
        <filter2>byte_test:1,&amp;,0x80,2; content:&quot;|00 01|&quot;; depth:2; offset:6; byte_test:1,&gt;,32,12; classtype:attempted-admin;</filter2>
        <id>2563</id>
        <msg>NETBIOS NS lookup response name overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040512A.html</url>
      </rule>
      <rule>
        <bugtraq>10335</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0444</cve>
        <filter1>udp $EXTERNAL_NET 137 -&gt; $HOME_NET 137</filter1>
        <filter2>dsize:&lt;56; byte_test:1,&amp;,0x80,2; content:&quot;|00 01|&quot;; depth:2; offset:6; classtype:attempted-admin;</filter2>
        <id>2564</id>
        <msg>NETBIOS NS lookup short response attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040512C.html</url>
      </rule>
      <rule>
        <bugtraq>11372</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:2f5f3220-c126-1076-b549-074d078619da; dce_opnum:12; dce_stub_data; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; distance:12; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>2936</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP nddeapi NDdeSetTrustedShareW overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-031.asp</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;D|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2973</id>
        <msg>NETBIOS SMB D$ unicode andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;D|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2974</id>
        <msg>NETBIOS SMB-DS D$ andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;D|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2975</id>
        <msg>NETBIOS SMB-DS D$ unicode andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;C|24 00|&quot;; distance:2; nocase; content:!&quot;IPC|24 00|&quot;; within:5; distance:-5; nocase; classtype:protocol-command-decode;</filter2>
        <id>2976</id>
        <msg>NETBIOS SMB C$ andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;C|00 24 00 00 00|&quot;; distance:2; nocase; content:!&quot;I|00|P|00|C|00 24 00 00 00|&quot;; within:10; distance:-10; nocase; classtype:protocol-command-decode;</filter2>
        <id>2977</id>
        <msg>NETBIOS SMB C$ unicode andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;C|24 00|&quot;; distance:2; nocase; content:!&quot;IPC|24 00|&quot;; within:5; distance:-5; nocase; classtype:protocol-command-decode;</filter2>
        <id>2978</id>
        <msg>NETBIOS SMB-DS C$ andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;C|00 24 00 00 00|&quot;; distance:2; nocase; content:!&quot;I|00|P|00|C|00 24 00 00 00|&quot;; within:10; distance:-10; nocase; classtype:protocol-command-decode;</filter2>
        <id>2979</id>
        <msg>NETBIOS SMB-DS C$ unicode andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;ADMIN|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2980</id>
        <msg>NETBIOS SMB ADMIN$ andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;A|00|D|00|M|00|I|00|N|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2981</id>
        <msg>NETBIOS SMB ADMIN$ unicode andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;ADMIN|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2982</id>
        <msg>NETBIOS SMB-DS ADMIN$ andx share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;u&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_jump:2,7,little,relative; content:&quot;A|00|D|00|M|00|I|00|N|00 24 00 00 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>2983</id>
        <msg>NETBIOS SMB-DS ADMIN$ unicode andx share access</msg>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>3001</id>
        <msg>NETBIOS SMB Session Setup NTMLSSP andx asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>3002</id>
        <msg>NETBIOS SMB Session Setup NTMLSSP unicode andx asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>3004</id>
        <msg>NETBIOS SMB-DS Session Setup NTMLSSP andx asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&amp;,2147483648,21,relative,little; content:!&quot;NTLMSSP&quot;; within:7; distance:27; asn1:double_overflow, bitstring_overflow, relative_offset 27, oversize_length 2048; classtype:protocol-command-decode;</filter2>
        <id>3005</id>
        <msg>NETBIOS SMB-DS Session Setup NTMLSSP unicode andx asn1 overflow attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>11763</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1080</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>flow:to_server,established; byte_test:1,&amp;,64,6; byte_test:1,&amp;,32,6; byte_test:1,&amp;,16,6; byte_test:1,&amp;,8,6; pcre:!&quot;/^.{8}(\x05\x37(\x1E[\x90-\xFF]|[\x1F-\x2F].|\x30[\x00-\x70])|\x00\x00\x00[\x00-\x65]|\x02\x68\x05\xC0)/s&quot;; classtype:misc-attack;</filter2>
        <id>3017</id>
        <msg>EXPLOIT WINS overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS04-045.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>3040</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>3041</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3042</id>
        <msg>NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3043</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3044</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3045</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3046</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3047</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3048</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3049</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3050</id>
        <msg>NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3051</id>
        <msg>NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3052</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3053</id>
        <msg>NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3054</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3055</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3056</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|01 00|&quot;; within:2; distance:37; byte_jump:4,-7,little,relative,from_beginning; pcre:&quot;/^.{4}/R&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; content:&quot;|00 00|&quot;; within:2; distance:-10; classtype:protocol-command-decode;</filter2>
        <id>3057</id>
        <msg>NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt</msg>
      </rule>
      <rule>
        <bugtraq>12481</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0050</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:342cfd40-3c6c-11ce-a893-08002b2e9c6d; dce_opnum:0; dce_stub_data; byte_test:4,&gt;,52,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>3114</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP llsrpc LlsrConnect overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>9624</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0825</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 137</filter1>
        <filter2>flow:to_server,established; byte_test:1,&amp;,64,2; content:&quot; &quot;; offset:12; isdataat:56,relative; classtype:attempted-admin;</filter2>
        <id>3195</id>
        <msg>NETBIOS name query overflow attempt TCP</msg>
        <nessus>15912</nessus>
      </rule>
      <rule>
        <bugtraq>9624</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0825</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 137</filter1>
        <filter2>byte_test:1,&amp;,64,2; content:&quot; &quot;; offset:12; isdataat:56,relative; classtype:attempted-admin;</filter2>
        <id>3196</id>
        <msg>NETBIOS name query overflow attempt UDP</msg>
        <nessus>15912</nessus>
      </rule>
      <rule>
        <bugtraq>9624</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0825</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>flow:established; byte_test:1,&amp;,64,2; content:&quot; &quot;; offset:12; isdataat:56,relative; classtype:attempted-admin;</filter2>
        <id>3199</id>
        <msg>EXPLOIT WINS name query overflow attempt TCP</msg>
        <nessus>15912</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>9624</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0825</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 42</filter1>
        <filter2>flow:to_server; byte_test:1,&amp;,64,2; content:&quot; &quot;; offset:12; isdataat:56,relative; classtype:attempted-admin;</filter2>
        <id>3200</id>
        <msg>EXPLOIT WINS name query overflow attempt UDP</msg>
        <nessus>15912</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>8826</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0717</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>content:&quot;|04 00|&quot;; depth:2; byte_test:1,&amp;,16,2,relative; content:&quot;|F8 91|{Z|00 FF D0 11 A9 B2 00 C0|O|B6 E6 FC|&quot;; within:16; distance:22; content:&quot;|00 00|&quot;; within:2; distance:28; byte_jump:4,18,little,align,relative; byte_jump:4,8,little,align,relative; byte_test:4,&gt;,1024,8,little,relative; classtype:attempted-admin;</filter2>
        <id>3234</id>
        <msg>NETBIOS Messenger message little endian overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8826</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0717</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>content:&quot;|04 00|&quot;; depth:2; byte_test:1,!&amp;,16,2,relative; content:&quot;|F8 91|{Z|00 FF D0 11 A9 B2 00 C0|O|B6 E6 FC|&quot;; within:16; distance:22; content:&quot;|00 00|&quot;; within:2; distance:28; byte_jump:4,18,align,relative; byte_jump:4,8,align,relative; byte_test:4,&gt;,1024,8,relative; classtype:attempted-admin;</filter2>
        <id>3235</id>
        <msg>NETBIOS Messenger message overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>6005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:b9e79e60-3d52-11ce-aaa1-00006901293f; dce_opnum:1,2; dce_stub_data; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; byte_test:4,&gt;,1024,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>3238</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP irot IrotIsRunning/Revoke overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms03-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>6005</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1561</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:b9e79e60-3d52-11ce-aaa1-00006901293f; dce_opnum:1,2; dce_stub_data; pcre:&quot;/^(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; byte_test:4,&gt;,1024,0,relative,dce; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>3239</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP irot IrotIsRunning/Revoke overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms03-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0059</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>flow:established,to_server; dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:9; dce_stub_data; content:&quot;|01 00 00 00|&quot;; within:4; distance:4; content:&quot;|03 00 00 00|&quot;; within:4; distance:4; byte_test:4,&gt;,256,8; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>3590</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP mqqm QMDeleteObject overflow attempt</msg>
        <nessus>18027</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0059</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [2103,2105,2107]</filter1>
        <filter2>dce_iface:FDB3A030-065F-11D1-BB9B-00A024EA5525; dce_opnum:9; dce_stub_data; content:&quot;|01 00 00 00|&quot;; within:4; distance:4; content:&quot;|03 00 00 00|&quot;; within:4; distance:4; byte_test:4,&gt;,256,8; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>3591</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP mqqm QMDeleteObject overflow attempt</msg>
        <nessus>18027</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3639</id>
        <msg>NETBIOS SMB Trans andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3640</id>
        <msg>NETBIOS SMB Trans data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3641</id>
        <msg>NETBIOS SMB Trans unicode data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3642</id>
        <msg>NETBIOS SMB Trans unicode andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3643</id>
        <msg>NETBIOS SMB-DS Trans andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3644</id>
        <msg>NETBIOS SMB-DS Trans data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3645</id>
        <msg>NETBIOS SMB-DS Trans unicode data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3646</id>
        <msg>NETBIOS SMB-DS Trans unicode andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3647</id>
        <msg>NETBIOS-DG SMB Trans andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3648</id>
        <msg>NETBIOS-DG SMB Trans data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3649</id>
        <msg>NETBIOS-DG SMB Trans unicode data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>13504</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $EXTERNAL_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|08|&quot;; within:1; content:&quot;|00 00|&quot;; within:2; distance:14; classtype:protocol-command-decode;</filter2>
        <id>3650</id>
        <msg>NETBIOS-DG SMB Trans unicode andx data displacement null pointer DOS attempt</msg>
        <url>www.ethereal.com/news/item_20050504_01.html</url>
      </rule>
      <rule>
        <bugtraq>10726</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0728</cve>
        <filter1>tcp $HOME_NET any -&gt; $HOME_NET 2702</filter1>
        <filter2>flow:to_server,established; content:&quot;RCH0&quot;; fast_pattern:only; content:&quot;RCHE&quot;; nocase; byte_test:2,&gt;,131,-8,relative,little; isdataat:131,relative; classtype:attempted-user;</filter2>
        <id>3673</id>
        <msg>MISC Microsoft SMS remote control client DoS overly long length attempt</msg>
      </rule>
      <rule>
        <bugtraq>15065</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:10; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>4334</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>14514</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1984</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:12345678-1234-abcd-ef00-0123456789ab; dce_opnum:70; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,96,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>4413</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP spoolss AddPrinterEx overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>15066</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1985</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:e67ab081-9844-3521-9d32-834f038001c0; dce_opnum:43; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,512,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>4608</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netware_cs function 43 overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-046.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4651</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4652</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4653</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4654</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4655</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4656</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4657</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4658</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4659</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4660</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4661</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:12; byte_jump:4,12,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4662</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4663</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4664</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4665</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4666</id>
        <msg>NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4667</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4668</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4669</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4670</id>
        <msg>NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4671</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4672</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A0|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4673</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2004-1154</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A0|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03 00|&quot;; within:2; distance:37; byte_jump:4,-7,relative,from_beginning,little; pcre:&quot;/^.{4}/sR&quot;; content:!&quot;|00 00 00 00|&quot;; within:4; distance:16; byte_jump:4,16,relative,little; byte_test:4,&gt;,32,-16,relative,little; classtype:protocol-command-decode;</filter2>
        <id>4674</id>
        <msg>NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15460</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-3644</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:7; dce_stub_data; byte_test:4,&gt;,256,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>4826</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetRootDeviceInstance attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/911052.mspx</url>
      </rule>
      <rule>
        <bugtraq>15460</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-3644</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:10; dce_stub_data; byte_test:4,&gt;,256,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>4918</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList dos attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/911052.mspx</url>
      </rule>
      <rule>
        <bugtraq>10108</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0533</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,138,1024:]</filter1>
        <filter2>dce_iface:3919286a-b10c-11d0-9ba8-00c04fd92ef5; dce_opnum:0; content:&quot;|04 00|&quot;; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>5096</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP lsass DsRolerGetPrimaryDomainInformation attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:4b324fc8-1670-01d3-1278-5a47bf6ee188; dce_opnum:15; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; content:&quot;|00 00 00 00|&quot;; within:4; distance:8; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>529</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrShareEnum null policy handle attempt</msg>
      </rule>
      <rule>
        <bugtraq>1163</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0347</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|W|00|i|00|n|00|d|00|o|00|w|00|s|00| |00|N|00|T|00| |00|1|00|3|00|8|00|1&quot;; classtype:attempted-recon;</filter2>
        <id>530</id>
        <msg>NETBIOS NT NULL session</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;ADMIN|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>532</id>
        <msg>NETBIOS SMB ADMIN$ share access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;C|24 00|&quot;; distance:2; nocase; content:!&quot;IPC|24 00|&quot;; within:5; distance:-5; nocase; classtype:protocol-command-decode;</filter2>
        <id>533</id>
        <msg>NETBIOS SMB C$ share access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|5C|../|00 00 00|&quot;; classtype:attempted-recon;</filter2>
        <id>534</id>
        <msg>NETBIOS SMB CD..</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|5C|...|00 00 00|&quot;; classtype:attempted-recon;</filter2>
        <id>535</id>
        <msg>NETBIOS SMB CD...</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBu&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/R&quot;; byte_jump:2,7,little,relative; content:&quot;D|24 00|&quot;; distance:2; nocase; classtype:protocol-command-decode;</filter2>
        <id>536</id>
        <msg>NETBIOS SMB D$ share access</msg>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5678</id>
        <msg>NETBIOS SMB-DS Session Setup username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:stateless; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5679</id>
        <msg>NETBIOS SMB-DS Session Setup unicode username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5680</id>
        <msg>NETBIOS-DG SMB Session Setup username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMBs&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5681</id>
        <msg>NETBIOS-DG SMB Session Setup unicode username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00|&quot;; within:255; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5683</id>
        <msg>NETBIOS-DG SMB Session Setup andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>9752</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;s&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,!&amp;,2147483648,21,relative,little; content:!&quot;|00 00|&quot;; within:510; distance:29; classtype:protocol-command-decode;</filter2>
        <id>5684</id>
        <msg>NETBIOS-DG SMB Session Setup unicode andx username overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040226.html</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5717</id>
        <msg>NETBIOS SMB-DS Trans Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5719</id>
        <msg>NETBIOS-DG SMB Trans Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>122</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>1999-0003</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32771:34000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 01 86 F3 00 00 00 01 00 00 00 0F 00 00 00 01|&quot;; depth:32; offset:16; metadata:service sunrpc; classtype:attempted-dos;</filter2>
        <id>572</id>
        <msg>RPC DOS ttdbserv Solaris</msg>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5720</id>
        <msg>NETBIOS-DG SMB Trans unicode Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5721</id>
        <msg>NETBIOS SMB Trans andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5722</id>
        <msg>NETBIOS SMB Trans unicode andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5723</id>
        <msg>NETBIOS SMB-DS Trans andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5724</id>
        <msg>NETBIOS SMB-DS Trans unicode andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5725</id>
        <msg>NETBIOS-DG SMB Trans andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>5556</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0724</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|00 00 00 00|&quot;; within:4; distance:5; classtype:protocol-command-decode;</filter2>
        <id>5726</id>
        <msg>NETBIOS-DG SMB Trans unicode andx Max Param/Count DOS attempt</msg>
        <nessus>11110</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5727</id>
        <msg>NETBIOS SMB Trans unicode Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5728</id>
        <msg>NETBIOS-DG SMB Trans Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5729</id>
        <msg>NETBIOS SMB Trans Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5730</id>
        <msg>NETBIOS SMB-DS Trans Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5731</id>
        <msg>NETBIOS SMB-DS Trans unicode Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5732</id>
        <msg>NETBIOS-DG SMB Trans unicode Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5733</id>
        <msg>NETBIOS SMB Trans unicode andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5734</id>
        <msg>NETBIOS-DG SMB Trans andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5735</id>
        <msg>NETBIOS SMB Trans andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5736</id>
        <msg>NETBIOS SMB-DS Trans andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5737</id>
        <msg>NETBIOS SMB-DS Trans unicode andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>13942</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-1206</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:2,&gt;,4376,5,relative,little; classtype:protocol-command-decode;</filter2>
        <id>5738</id>
        <msg>NETBIOS-DG SMB Trans unicode andx Max Param DOS attempt</msg>
        <nessus>18483</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 05|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>574</id>
        <msg>RPC mountd TCP export request</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 F7|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>575</id>
        <msg>RPC portmap admind request UDP</msg>
      </rule>
      <rule>
        <bugtraq>614</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0704</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 03|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>576</id>
        <msg>RPC portmap amountd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0647</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 BA|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>577</id>
        <msg>RPC portmap bootparam request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 E4|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>578</id>
        <msg>RPC portmap cmsd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A5|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>579</id>
        <msg>RPC portmap mountd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0008</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 CC|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>580</id>
        <msg>RPC portmap nisd request UDP</msg>
      </rule>
      <rule>
        <bugtraq>4816</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-0910</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 02|I|F1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>581</id>
        <msg>RPC portmap pcnfsd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>582</id>
        <msg>RPC portmap rexd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A1|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>583</id>
        <msg>RPC portmap rstatd request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0626</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A2|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>584</id>
        <msg>RPC portmap rusers request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 88|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>585</id>
        <msg>RPC portmap sadmind request UDP</msg>
      </rule>
      <rule>
        <bugtraq>8</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0209</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 AF|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>586</id>
        <msg>RPC portmap selection_svc request UDP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 B8|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>587</id>
        <msg>RPC portmap status request UDP</msg>
      </rule>
      <rule>
        <bugtraq>3382</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0717</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 F3|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>588</id>
        <msg>RPC portmap ttdbserv request UDP</msg>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A9|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>589</id>
        <msg>RPC portmap yppasswd request UDP</msg>
      </rule>
      <rule>
        <bugtraq>6016</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2002-1232</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 A4|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; classtype:rpc-portmap-decode;</filter2>
        <id>590</id>
        <msg>RPC portmap ypserv request UDP</msg>
      </rule>
      <rule>
        <bugtraq>1749</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>1999-0208</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 86 BC|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>591</id>
        <msg>RPC portmap ypupdated request TCP</msg>
      </rule>
      <rule>
        <bugtraq>2714</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0331</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 05 F7|u&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>595</id>
        <msg>RPC portmap espd request TCP</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>598</id>
        <msg>RPC portmap listing TCP 111</msg>
      </rule>
      <rule>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32771</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 04|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>599</id>
        <msg>RPC portmap listing TCP 32771</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0626</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 01 86 A2|&quot;; depth:4; offset:12; content:&quot;|00 00 00 02|&quot;; within:4; distance:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-recon;</filter2>
        <id>612</id>
        <msg>RPC rusers query UDP</msg>
      </rule>
      <rule>
        <bugtraq>18325</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2370</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:20610036-fa22-11cf-9823-00a0c911e5df; dce_opnum:12; dce_stub_data; byte_test:4,&gt;,8192,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>6584</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSubmitRequest overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6702</id>
        <msg>NETBIOS SMB NT Trans Secondary Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6703</id>
        <msg>NETBIOS SMB NT Trans Secondary unicode Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6704</id>
        <msg>NETBIOS SMB-DS NT Trans Secondary Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6705</id>
        <msg>NETBIOS SMB-DS NT Trans Secondary unicode Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6706</id>
        <msg>NETBIOS-DG SMB NT Trans Secondary Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A1|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6707</id>
        <msg>NETBIOS-DG SMB NT Trans Secondary unicode Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6708</id>
        <msg>NETBIOS SMB NT Trans Secondary andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6709</id>
        <msg>NETBIOS SMB NT Trans Secondary unicode andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6710</id>
        <msg>NETBIOS SMB-DS NT Trans Secondary andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6711</id>
        <msg>NETBIOS SMB-DS NT Trans Secondary unicode andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6712</id>
        <msg>NETBIOS-DG SMB NT Trans Secondary andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7106</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0085</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A1|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; byte_test:4,&gt;,1000,20,relative; classtype:protocol-command-decode;</filter2>
        <id>6713</id>
        <msg>NETBIOS-DG SMB NT Trans Secondary unicode andx Param Count overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18358</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2371</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:20610036-fa22-11cf-9823-00a0c911e5df; dce_opnum:10; dce_stub_data; pcre:&quot;/^.{68}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,relative,align,dce; byte_test:4,&gt;,258,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>6810</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences area/country overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03|&quot;; within:1; distance:27; content:&quot;|01 00 00 00|&quot;; within:4; distance:1; content:!&quot;|00|&quot;; within:25; distance:4; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>7037</id>
        <msg>NETBIOS-DG SMB Trans mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB%&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|03|&quot;; within:1; distance:27; content:!&quot;|00 00|&quot;; within:50; distance:9; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>7038</id>
        <msg>NETBIOS-DG SMB Trans unicode mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>18864</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2006-3942</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;%&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|03|&quot;; within:1; distance:27; content:!&quot;|00 00|&quot;; within:50; distance:9; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>7042</id>
        <msg>NETBIOS-DG SMB Trans unicode andx mailslot heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-2372</cve>
        <filter1>udp any any -&gt; any 68</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|7196;</filter2>
        <id>7196</id>
        <msg>EXPLOIT Microsoft DHCP option overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>19417</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;res|3A|//mmcndmgr.dll&quot;; classtype:attempted-user;</filter2>
        <id>7422</id>
        <msg>EXPLOIT Microsoft MMC mmcndmgr.dll cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>19417</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;res|3A|//mmc.exe&quot;; classtype:attempted-user;</filter2>
        <id>7423</id>
        <msg>EXPLOIT Microsoft MMC mmc.exe cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>19417</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;res|3A|//createcab.cmd&quot;; classtype:attempted-user;</filter2>
        <id>7424</id>
        <msg>EXPLOIT Microsoft MMC createcab.cmd cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>16636</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0013</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:C8CB7687-E6D3-11D2-A958-00C04F682E16; dce_opnum:0; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>8157</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP webdav DavrCreateConnection hostname overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8449</id>
        <msg>NETBIOS SMB Rename invalid buffer type andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8450</id>
        <msg>NETBIOS SMB Rename invalid buffer type attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8451</id>
        <msg>NETBIOS SMB Rename invalid buffer type unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8452</id>
        <msg>NETBIOS SMB Rename invalid buffer type unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8453</id>
        <msg>NETBIOS SMB-DS Rename invalid buffer type andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8454</id>
        <msg>NETBIOS SMB-DS Rename invalid buffer type attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8455</id>
        <msg>NETBIOS SMB-DS Rename invalid buffer type unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8456</id>
        <msg>NETBIOS SMB-DS Rename invalid buffer type unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8457</id>
        <msg>NETBIOS-DG SMB Rename invalid buffer type andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8458</id>
        <msg>NETBIOS-DG SMB Rename invalid buffer type attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|07|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8459</id>
        <msg>NETBIOS-DG SMB Rename invalid buffer type unicode andx attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-4696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|07|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; pcre:&quot;/^.{5}([^\x03\x04]|.[^\x00]+\x00\x00[^\x03\x04])/Rs&quot;; classtype:attempted-dos;</filter2>
        <id>8460</id>
        <msg>NETBIOS-DG SMB Rename invalid buffer type unicode attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-063.mspx</url>
      </rule>
      <rule>
        <bugtraq>9011</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0812</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:6bffd098-a112-3610-9833-46c3f87e345a; dce_opnum:27; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,256,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>8925</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrAddAlternateComputerName overflow attempt</msg>
        <nessus>11921</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-049.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4689</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:e67ab081-9844-3521-9d32-834f038001c0; dce_opnum:9; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,128,0,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>9132</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netware_cs NwrOpenEnumNdsStubTrees_Any overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-066.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4689</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:e67ab081-9844-3521-9d32-834f038001c0; dce_opnum:1; dce_stub_data; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; byte_test:4,&gt;,128,4,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>9228</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP netware_cs NwGetConnectionInformation overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-066.mspx</url>
      </rule>
      <rule>
        <bugtraq>13951</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1213</cve>
        <filter1>tcp $EXTERNAL_NET 119 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;215 &quot;; depth:4; content:&quot;|0D 0A|&quot;; distance:0; content:&quot; &quot;; distance:0; pcre:&quot;/^[^\s\x00]{16}/R&quot;; classtype:attempted-user;</filter2>
        <id>9431</id>
        <msg>EXPLOIT Microsoft NNTP response overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-030.mspx</url>
      </rule>
      <rule>
        <bugtraq>21034</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3445</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|C4 AB CD AB|&quot;; byte_test:4,&lt;,500,0,relative,little; classtype:attempted-user;</filter2>
        <id>9432</id>
        <msg>WEB-CLIENT Microsoft Agent buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-068.mspx</url>
      </rule>
      <rule>
        <bugtraq>20365</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5143</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6503</filter1>
        <filter2>flow:established,to_server; dce_iface:DC246BF0-7A7A-11CE-9F88-00805FE43838; dce_opnum:43; dce_stub_data; isdataat:672,relative; content:!&quot;|00|&quot;; within:672; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>9441</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath overflow attempt</msg>
        <url>www.lssec.com/advisories/LS-20060313.pdf</url>
      </rule>
      <rule>
        <bugtraq>20941</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5780</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:8; byte_test:4,&gt;,255,8,relative; isdataat:264,relative; metadata:service sunrpc; classtype:attempted-user;</filter2>
        <id>9623</id>
        <msg>RPC UNIX authentication machinename string overflow attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>20941</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5780</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A5|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:8; byte_test:4,&gt;,255,8,relative; isdataat:264,relative; metadata:service sunrpc; classtype:attempted-user;</filter2>
        <id>9624</id>
        <msg>RPC UNIX authentication machinename string overflow attempt UDP</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:975201B0-59CA-11D0-A8D5-00A0C90D8051; dce_opnum:1; dce_stub_data; byte_test:4,&gt;,128,20,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>9772</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP msqueue function 1 overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [135,1024:]</filter1>
        <filter2>dce_iface:975201B0-59CA-11D0-A8D5-00A0C90D8051; dce_opnum:1; dce_stub_data; byte_test:4,&gt;,128,20,relative,dce; content:&quot;|04 00|&quot;; metadata:service dcerpc; classtype:attempted-admin;</filter2>
        <id>9773</id>
        <msg>NETBIOS DCERPC NCADG-IP-UDP msqueue function 1 overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14518</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0058</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; dce_iface:2f5f6520-ca46-1067-b319-00dd010662da; dce_opnum:1; dce_stub_data; content:&quot;E|00 00 00|&quot;; within:4; distance:32; byte_test:4,&gt;,1024,-16,relative,dce; content:&quot;|05 00 00|&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>9914</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP tapisrv ClientRequest LSetAppPriority overflow attempt</msg>
        <url>www.microsoft.com/technet/Security/bulletin/ms05-040.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>33113</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0065</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:132; content:&quot;|C0 00|&quot;; depth:2; offset:12; byte_test:2,&gt;,500,0,relative,big; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15490</id>
        <msg>EXPLOIT Linux SCTP malformed forward-tsn chunk arbitrary code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>31133</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-3915</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 00 22|&quot;; content:&quot;|00 00 00 01 00 00 10 00 00 00 03|D|00 00 00 1A|&quot;; within:16; distance:16; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16352</id>
        <msg>EXPLOIT Linux Kernel NFSD Subsystem overflow attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|31 DB 53 43 53 6A 02 6A 66 58 89 E1 CD 80|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17324</id>
        <msg>SHELLCODE x86 Linux reverse connect shellcode</msg>
      </rule>
      <rule>
        <bugtraq>18081</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-2444</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>content:&quot;|01 04|&quot;; depth:2; offset:4; byte_jump:1,0,relative; content:&quot;|A4 02 61 61|&quot;; within:4; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17738</id>
        <msg>SPECIFIC-THREATS Linux Kernel SNMP Netfilter Memory Corruption attempt</msg>
      </rule>
    </attacks>
    <groupid>120</groupid>
    <groupname>OS / Linux</groupname>
    <warnings>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6000</filter1>
        <filter2>flow:established; content:&quot;MIT-MAGIC-COOKIE-1&quot;; fast_pattern:only; metadata:service x11; classtype:attempted-user;</filter2>
        <id>1225</id>
        <msg>X11 MIT Magic Cookie detected</msg>
      </rule>
      <rule>
        <classtype>unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6000</filter1>
        <filter2>flow:established; content:&quot;l|00 0B 00 00 00 00 00 00 00 00 00|&quot;; fast_pattern:only; metadata:service x11; classtype:unknown;</filter2>
        <id>1226</id>
        <msg>X11 xopen</msg>
      </rule>
      <rule>
        <bugtraq>30704</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2008-3276</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:33; content:&quot; &quot;; depth:1; offset:29; byte_test:1,&lt;,4,0,relative; classtype:denial-of-service;</filter2>
        <id>15906</id>
        <msg>EXPLOIT Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30704</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2008-3276</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:33; content:&quot;|22|&quot;; depth:1; offset:29; byte_test:1,&lt;,4,0,relative; classtype:denial-of-service;</filter2>
        <id>15907</id>
        <msg>EXPLOIT Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>39794</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-1173</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:132; content:&quot;|01|&quot;; depth:1; offset:12; byte_test:2,&gt;,0xC000,19,relative; pcre:!&quot;/^.{19}\xC0[\x05\x06\x09\x0B\x0C]/sR&quot;; byte_jump:2,21,relative,align,post_offset -4; byte_test:2,&gt;,0xC000,0,relative; pcre:!&quot;/^\xC0[\x05\x06\x09\x0B\x0C]/R&quot;; classtype:attempted-admin;</filter2>
        <id>16724</id>
        <msg>EXPLOIT Linux kernel sctp_process_unk_param SCTPChunkInit buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24376</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-2876</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:132; dsize:&gt;12; byte_test:1,&gt;,14,12; classtype:attempted-dos;</filter2>
        <id>17302</id>
        <msg>DOS Linux kernel SCTP Unknown Chunk Types denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $TELNET_SERVERS 23</filter1>
        <filter2>flow:to_server,established; content:&quot;wh00t!&quot;; classtype:attempted-admin;</filter2>
        <id>213</id>
        <msg>BACKDOOR MISC Linux rootkit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $TELNET_SERVERS 23</filter1>
        <filter2>flow:to_server,established; content:&quot;lrkr0x&quot;; classtype:attempted-admin;</filter2>
        <id>214</id>
        <msg>BACKDOOR MISC Linux rootkit attempt lrkr0x</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $TELNET_SERVERS 23</filter1>
        <filter2>flow:to_server,established; content:&quot;d13hh[&quot;; nocase; classtype:attempted-admin;</filter2>
        <id>215</id>
        <msg>BACKDOOR MISC Linux rootkit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $TELNET_SERVERS 23</filter1>
        <filter2>flow:to_server,established; content:&quot;satori&quot;; classtype:attempted-admin;</filter2>
        <id>216</id>
        <msg>BACKDOOR MISC Linux rootkit satori attempt</msg>
      </rule>
      <rule>
        <bugtraq>536</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0811</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB|/_|EB|J^|89 FB 89|&gt;|89 F2|&quot;; classtype:attempted-admin;</filter2>
        <id>292</id>
        <msg>EXPLOIT x86 Linux samba overflow</msg>
      </rule>
      <rule>
        <bugtraq>1712</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0917</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;XXXX%.172u%300|24|n&quot;; classtype:attempted-admin;</filter2>
        <id>302</id>
        <msg>EXPLOIT Redhat 7.0 lprd overflow</msg>
      </rule>
      <rule>
        <bugtraq>210</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 518</filter1>
        <filter2>flow:to_server; content:&quot;|01 03 00 00 00 00 00 01 00 02 02 E8|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>313</id>
        <msg>EXPLOIT ntalkd x86 Linux overflow</msg>
      </rule>
      <rule>
        <bugtraq>121</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0002</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 635</filter1>
        <filter2>flow:to_server; content:&quot;^|B0 02 89 06 FE C8 89|F|04 B0 06 89|F&quot;; classtype:attempted-admin;</filter2>
        <id>315</id>
        <msg>EXPLOIT x86 Linux mountd overflow</msg>
      </rule>
      <rule>
        <bugtraq>121</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0002</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 635</filter1>
        <filter2>flow:to_server; content:&quot;|EB|V^VVV1|D2 88|V|0B 88|V|1E|&quot;; classtype:attempted-admin;</filter2>
        <id>316</id>
        <msg>EXPLOIT x86 Linux mountd overflow</msg>
      </rule>
      <rule>
        <bugtraq>121</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0002</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 635</filter1>
        <filter2>flow:to_server; content:&quot;|EB|@^1|C0|@|89|F|04 89 C3|@|89 06|&quot;; classtype:attempted-admin;</filter2>
        <id>317</id>
        <msg>EXPLOIT x86 Linux mountd overflow</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 513</filter1>
        <filter2>flow:to_server,established; content:&quot;|3A 3A 3A 3A 3A 3A 3A 3A 00 3A 3A 3A 3A 3A 3A 3A 3A|&quot;; fast_pattern:only; classtype:bad-unknown;</filter2>
        <id>601</id>
        <msg>RSERVICES rlogin LinuxNIS</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|90 90 90 E8 C0 FF FF FF|/bin/sh&quot;; fast_pattern:only; classtype:shellcode-detect;</filter2>
        <id>652</id>
        <msg>SHELLCODE Linux shellcode</msg>
      </rule>
      <rule>
        <bugtraq>18755</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-2934</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:132; dsize:12; classtype:attempted-dos;</filter2>
        <id>7021</id>
        <msg>DOS linux kernel SCTP chunkless packet denial of service attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>12491</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0260</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|B0 8E 80 23|&quot;; content:!&quot;|00|&quot;; within:1399; isdataat:1400; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>10134</id>
        <msg>SPECIFIC-THREATS CA Brightstor discovery service buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23556</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2171</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7205:7211</filter1>
        <filter2>flow:established,to_server; content:&quot;Authorization&quot;; nocase; content:&quot;Basic&quot;; distance:0; nocase; pcre:&quot;/Authorization\s*\x3A\s*Basic\s*[^\n]{437}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>10998</id>
        <msg>EXPLOIT Novell GroupWise WebAccess authentication overflow</msg>
      </rule>
      <rule>
        <bugtraq>23047</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-1542</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;INVITE&quot;; depth:6; nocase; content:&quot;Remote-Party-Id&quot;; nocase; content:&quot;csip|3A|&quot;; distance:0; nocase; pcre:&quot;/Remote-Party-ID\x3A\scsip\x3A[^@]+@\d{1,3}\x2E\d{1,3}\x2E\xD1/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>11970</id>
        <msg>VOIP-SIP Cisco 7940/7960 INVITE Remote-Party-ID denial of service attempt</msg>
        <url>www.cisco.com/warp/public/707/cisco-sr-20070320-sip.shtml</url>
      </rule>
      <rule>
        <bugtraq>27313</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0027</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2444</filter1>
        <filter2>flow:established,to_server; content:&quot;|17 03 01|&quot;; depth:3; byte_test:2,&gt;,16383,0,relative,big; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13363</id>
        <msg>EXPLOIT Cisco Unified Communications Manager heap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2001-0797</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 23</filter1>
        <filter2>flow:established,to_server; content:&quot;c c c c c c c c c&quot;; metadata:policy security-ips drop, service telnet; classtype:attempted-admin;</filter2>
        <id>13613</id>
        <msg>SPECIFIC-THREATS Solaris username overflow authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>16870</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;isComponentInstalled|28|boom&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13912</id>
        <msg>SPECIFIC-THREATS isComponentInstalled Metasploit attack attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4479</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8030,8028,8008,8010]</filter1>
        <filter2>flow:to_server,established; content:&quot;Accept-Language|3A|&quot;; nocase; pcre:&quot;/^Accept\x2dLanguage\x3a\s*(\w{1,36}\s*(\x2e|\x2d|\x3b|\x3d|\x2c)\s*)*[^\x2d\x3b\x2c\x3d\n]{37}/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>14989</id>
        <msg>WEB-MISC Novell eDirectory SOAP Accept Language header overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31553</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5094</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8008,8028]</filter1>
        <filter2>flow:to_server,established; content:&quot;/nds&quot;; nocase; content:&quot;Accept-Language&quot;; distance:0; nocase; content:&quot;|3A|&quot;; distance:0; pcre:&quot;/^\s*Accept-Language\s*\x3a\s*([^\r\n]*?\x2c){20}/mi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15446</id>
        <msg>WEB-MISC Novell eDirectory management console Accept-Language buffer overflow attempt</msg>
        <url>download.novell.com/Download?buildid=Cf15mVyA3GI~</url>
      </rule>
      <rule>
        <bugtraq>13678</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1543</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1761</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; offset:16; byte_jump:2,0,relative,big; byte_jump:2,0,relative,big; byte_jump:2,0,relative,big; content:&quot;|00 01 00 02|&quot;; within:4; distance:2; byte_test:2,&gt;,28,0,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15958</id>
        <msg>WEB-MISC Novell ZENworks Remote Management overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-2327</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3017</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 8F 9C 19 00 00 00 0C|SLAWEKSERVER&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16019</id>
        <msg>SPECIFIC-THREATS Novell Distributed Print Services integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4478</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8008,8010,8028,8030]</filter1>
        <filter2>flow:to_server,established; content:&quot;POST /SOAP&quot;; depth:10; nocase; pcre:&quot;/^Content-Length\s*\x3A\s*[1-9][0-9]{8}/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16194</id>
        <msg>WEB-MISC Novell eDirectory HTTP request content-length heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4478</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8008,8010,8028,8030]</filter1>
        <filter2>flow:to_server,established; content:&quot;POST /SOAP&quot;; depth:10; nocase; pcre:&quot;/^Content-Length\s*\x3A\s*/mi&quot;; content:&quot;-&quot;; within:1; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16195</id>
        <msg>WEB-MISC Novell eDirectory HTTP request content-length heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>37672</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-4486</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; nocase; http_method; content:&quot;/nps/servlet/&quot;; nocase; http_uri; content:&quot;taskId=base.ExtendSchema&quot;; nocase; http_uri; pcre:&quot;/(((DestFile|encryptPass)\x3D[^\x26]{50})|((BaseDN|SearchFilter)\x3D[^\x26]{128}))/Ui&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16429</id>
        <msg>WEB-MISC Novell iManager eDirectory plugin schema buffer overflow attempt - GET request</msg>
      </rule>
      <rule>
        <bugtraq>37672</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-4486</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; nocase; http_method; content:&quot;/nps/servlet/&quot;; nocase; http_uri; content:&quot;taskId=base.ExtendSchema&quot;; nocase; http_uri; pcre:&quot;/(((DestFile|encryptPass)\x3D[^\x26]{50})|((BaseDN|SearchFilter)\x3D[^\x26]{128}))/Pi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16430</id>
        <msg>WEB-MISC Novell iManager eDirectory plugin schema buffer overflow attempt - POST request</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2009-0611</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;AdminServlet&quot;; nocase; http_uri; pcre:&quot;/AdminServlet.*(userid|adminurl)[^\x26\x20\x0a]*&lt;script/smiU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16522</id>
        <msg>WEB-CLIENT Novell QuickFinder server cross-site-scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>36698</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;object classid='clsid|3A|B44D252D-98FC-4D5C-948C-BE868392A004'&quot;; fast_pattern:only; nocase; content:&quot;=String|28|310,|22|A|22 29|&quot;; distance:0; content:&quot;=unescape&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16587</id>
        <msg>SPECIFIC-THREATS Symantec multiple products AeXNSConsoleUtilities buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>37092</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|2E|RunCMD|28|&quot;; fast_pattern:only; nocase; content:&quot;catch|28| e |29 20 7B| window|2E|location|20 3D|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16787</id>
        <msg>SPECIFIC-THREATS Symantec multiple products AeXNSConsoleUtilities RunCMD buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34400</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1350</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|02 00 00 00 FF FF FF FF|PPPPAAAA&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17057</id>
        <msg>SPECIFIC-THREATS Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20364</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5143</cve>
        <filter1>tcp $EXTERNAL_NET 41523 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isnotset,CA.response; flowbits:set,CA.response; flowbits:noalert;  content:&quot;TESTTESTTESTTESTTESTTESTTEST&quot;; fast_pattern:only; isdataat:990; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17620</id>
        <msg>SPECIFIC-THREATS Products Discovery Service Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>20364</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5143</cve>
        <filter1>tcp $EXTERNAL_NET 41523 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isnotset,CA.response; flowbits:set,CA.response; flowbits:noalert;  content:&quot;|9B 17 F6 4A 1D 01 E7 52 11 C3 61 7B 9B B0 62 52|&quot;; fast_pattern:only; isdataat:990; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17621</id>
        <msg>SPECIFIC-THREATS Products Discovery Service Buffer Overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| OSSProxy&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5760</id>
        <msg>SPYWARE-PUT Hijacker marketscore runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=43974</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mdh/adcr2.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;API=&quot;; nocase; http_uri; content:&quot;UID=&quot;; nocase; http_uri; content:&quot;TZ=&quot;; nocase; http_uri; content:&quot;LC=&quot;; nocase; http_uri; content:&quot;APL=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5798</id>
        <msg>SPYWARE-PUT Adware mydailyhoroscope runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088207</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;07637823-C894-4A52-B3F9-5D77FD8E36A&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*07637823-C894-4A52-B3F9-5D77FD8E36A/si&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5799</id>
        <msg>SPYWARE-PUT mydailyhoroscope update or installation in progress</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088207</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a/Corr.sen?StubName=conscorr&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| Stubby&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5834</id>
        <msg>SPYWARE-PUT Trickler conscorr runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1034</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 800: -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,DSK_Lite_1.0_TCP; content:&quot;disconnect&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6017</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - disconnect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; 255.255.255.255 15164</filter1>
        <filter2>flow:to_server; content:&quot;|00|]B|00 0A 02 08 FE 01 FC 12 00|&quot;; depth:12;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6384</id>
        <msg>SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent discover broadcast</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075982</url>
      </rule>
      <rule>
        <bugtraq>16870</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;isComponentInstalled&quot;; nocase; isdataat:256,relative; pcre:&quot;/isComponentInstalled\s*\([^,\)]{256}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7020</id>
        <msg>WEB-CLIENT isComponentInstalled function buffer overflow</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7250 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;DTS-300|0D 0A|&quot;; depth:9; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7720</id>
        <msg>BACKDOOR desktop scout runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074737</url>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/freeIPaddrs.ovpl&quot;; nocase; http_uri; content:&quot;netid=&quot;; nocase; http_uri; pcre:&quot;/freeIPaddrs.ovpl[^\r\n]*netid=[^\r\n]*(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>8090</id>
        <msg>WEB-MISC HP Openview NNM freeIPaddrs.ovpl Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>21502</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6379</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9B|&quot;; depth:1; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>9635</id>
        <msg>EXPLOIT Computer Associates Product Discovery Service type 9B remote buffer overflow attempt UDP</msg>
      </rule>
    </attacks>
    <groupid>130</groupid>
    <groupname>OS / Other</groupname>
    <warnings>
      <rule>
        <bugtraq>14510</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-4797</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; flowbits:isset,lp.controlfile; content:&quot;|02|&quot;; depth:1; content:&quot;dfA&quot;; nocase; pcre:&quot;/^\x02\d+ dfA/smi&quot;; classtype:misc-attack;</filter2>
        <id>10418</id>
        <msg>EXPLOIT lpd Solaris unlink file attempt</msg>
      </rule>
      <rule>
        <bugtraq>908</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0744</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 457</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB|_|9A FF FF FF FF 07 FF C3|^1|C0 89|F|9D|&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1132</id>
        <msg>WEB-MISC Netscape Unixware overflow</msg>
      </rule>
      <rule>
        <bugtraq>879</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GWWEB.EXE&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1165</id>
        <msg>WEB-MISC Novell Groupwise gwweb.exe access</msg>
        <nessus>10877</nessus>
      </rule>
      <rule>
        <bugtraq>24002</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1173</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5003</filter1>
        <filter2>flow:established,to_server; content:&quot;|ED ED|&quot;; depth:2; offset:2; content:!&quot;|ED|&quot;; depth:1; isdataat:1176; content:!&quot;|00|&quot;; depth:976; offset:200; classtype:attempted-admin;</filter2>
        <id>11670</id>
        <msg>EXPLOIT Symantec Discovery logging buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>14510</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-4797</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|U&quot;; content:&quot;../..&quot;; fast_pattern:only; content:&quot;|0A|&quot;; classtype:misc-attack;</filter2>
        <id>12080</id>
        <msg>EXPLOIT Sun Solaris printd arbitrary file deletion vulnerability</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.nsconfig&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1209</id>
        <msg>WEB-MISC .nsconfig access</msg>
        <url>www.osvdb.org/5709</url>
      </rule>
      <rule>
        <bugtraq>22857</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1350</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 89</filter1>
        <filter2>flow:to_server,established; content:&quot;POST /f&quot;; depth:8; content:&quot;username=&quot;; content:!&quot;&amp;&quot;; within:80; classtype:attempted-admin;</filter2>
        <id>12223</id>
        <msg>EXPLOIT Novell WebAdmin long user name</msg>
      </rule>
      <rule>
        <bugtraq>25238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4286</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:47; content:&quot; |01|&quot;; depth:2; offset:2; content:&quot;|FF FF|&quot;; depth:2; offset:14; classtype:attempted-user;</filter2>
        <id>12299</id>
        <msg>EXPLOIT Cisco NHRP incorrect packet size</msg>
      </rule>
      <rule>
        <bugtraq>25238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4286</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ip_proto:54; content:&quot;|FF FF|&quot;; depth:2; offset:10; classtype:attempted-user;</filter2>
        <id>12300</id>
        <msg>EXPLOIT Cisco NHRP incorrect packet size</msg>
      </rule>
      <rule>
        <bugtraq>2936</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0537</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/level/&quot;; http_uri; pcre:&quot;/\x2flevel\x2f\d+\x2f(exec|configure)/iU&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1250</id>
        <msg>WEB-MISC Cisco IOS HTTP configuration attempt</msg>
        <nessus>10700</nessus>
      </rule>
      <rule>
        <bugtraq>20663</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4509</cve>
        <filter1>tcp any any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13510;</filter2>
        <id>13510</id>
        <msg>EXPLOIT Novell eDirectory EventsRequest heap overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=427</url>
      </rule>
      <rule>
        <bugtraq>20663</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4510</cve>
        <filter1>tcp any any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13511;</filter2>
        <id>13511</id>
        <msg>EXPLOIT Novell eDirectory EventsRequest invalid event count exploit attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=428</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0260</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server,established; content:&quot;|99 99 99 99 99 99 99 99 99 99|&quot;; pcre:&quot;/\x99{40}\xeb\x12\x01\x99{4}\x18A{5}.{4}A{6}/sm&quot;; classtype:attempted-admin;</filter2>
        <id>13620</id>
        <msg>SPECIFIC-THREATS CA Brightstor discovery service alternate buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8888</filter1>
        <filter2>flow:to_server,established; content:&quot;/SiteScope/cgi/go.exe/SiteScope&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1499</id>
        <msg>WEB-MISC SiteScope Service access</msg>
        <nessus>10778</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4479</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8030,8028,8008,8010]</filter1>
        <filter2>flow:to_server,established; content:&quot;Accept-Charset|3A|&quot;; nocase; pcre:&quot;/^Accept\x2dCharset\x3a\s*([^\x3b\x3d\x2c]{1,36}\s*(\x2d|\x3b|\x3d|\x2c)\s*)*[^\x2d\x3b\x2c\x3d\n]{37}/smi&quot;; classtype:attempted-user;</filter2>
        <id>14990</id>
        <msg>WEB-MISC Novell eDirectory SOAP Accept Charset header overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>1846</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0945</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exec/show/config/cr&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1544</id>
        <msg>WEB-MISC Cisco Catalyst command execution attempt</msg>
        <nessus>10545</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; dsize:1; content:&quot;|13|&quot;; classtype:web-application-attack;</filter2>
        <id>1545</id>
        <msg>DOS Cisco attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2005-1729</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8008</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /COM1&quot;; depth:9; metadata:service http; classtype:attempted-dos;</filter2>
        <id>15960</id>
        <msg>SPECIFIC-THREATS Novell eDirectory MS-DOS device name DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>30175</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1809</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15973;</filter2>
        <id>15973</id>
        <msg>EXPLOIT Novell eDirectory LDAP null search parameter buffer overflow attempt</msg>
        <url>www.novell.com/support/viewContent.do?externalId=3843876</url>
      </rule>
      <rule>
        <bugtraq>28757</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-0927</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8008,8028]</filter1>
        <filter2>flow:to_server,established; content:&quot;Connection&quot;; fast_pattern:only; pcre:&quot;/^Connection\s*\x3a\s*\S+(.*^Connection\s*\x3a\s*\S+|[^\n]*\x2c\s*\S+).*\n\r?\n/msi&quot;; metadata:service http; classtype:attempted-dos;</filter2>
        <id>16014</id>
        <msg>DOS Novell eDirectory HTTP headers denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>879</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GWWEB.EXE?HELP=&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1614</id>
        <msg>WEB-MISC Novell Groupwise gwweb.exe attempt</msg>
        <nessus>10877</nessus>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabscotti71i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16950</id>
        <msg>PHISHING-SPAM tabscotti71i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;scoreenjoy.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17027</id>
        <msg>PHISHING-SPAM scoreenjoy.ru known spam email attempt</msg>
      </rule>
      <rule>
        <bugtraq>15602</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-3921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;href|3D 22 2E 2F 2E 2E 2F 2E 2F 2F 2E 2E 2F 2E 2E 2F 2E 2E 2F 2E 2E 2F 2E 2E 2F 2F|&quot;; classtype:attempted-dos;</filter2>
        <id>17287</id>
        <msg>WEB-MISC Cisco IOS HTTP service HTML injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>14510</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-4797</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; flowbits:isset,lp.controlfile; content:&quot;|0A 55|&quot;; content:&quot;|2F|&quot;; distance:0; classtype:misc-attack;</filter2>
        <id>17353</id>
        <msg>EXPLOIT Sun Solaris printd Daemon Arbitrary File Deletion attempt</msg>
      </rule>
      <rule>
        <bugtraq>14687</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2870</cve>
        <filter1>udp $EXTERNAL_NET 67 -&gt; $HOME_NET 68</filter1>
        <filter2>content:&quot;|63 82 53 63|&quot;; content:&quot;|35 01 05|&quot;; distance:0; fast_pattern; content:&quot;|0F|&quot;; distance:0; content:&quot;|20|&quot;; within:100; classtype:attempted-user;</filter2>
        <id>17433</id>
        <msg>EXPLOIT Sun Solaris DHCP Client Arbitrary Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>21395</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6299</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [7460,7461,7465]</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF FF|&quot;; depth:4; offset:59; classtype:attempted-admin;</filter2>
        <id>17504</id>
        <msg>EXPLOIT Novell ZENworks Asset Management buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>21725</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6424</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [689,1001]</filter1>
        <filter2>flow:established,to_server; content:&quot;STOR &quot;; depth:5; nocase; isdataat:128,relative; content:!&quot;|00|&quot;; within:128; classtype:attempted-admin;</filter2>
        <id>17713</id>
        <msg>EXPLOIT Novell NetMail NMAP STOR buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>4794</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0882</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/StreamingStatistics&quot;; http_uri; metadata:service http; classtype:misc-attack;</filter2>
        <id>1814</id>
        <msg>WEB-MISC CISCO VoIP DOS ATTEMPT</msg>
        <nessus>11013</nessus>
      </rule>
      <rule>
        <bugtraq>691</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0158</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pixfir~1/how_to_login.html&quot;; http_uri; metadata:service http; classtype:misc-attack;</filter2>
        <id>1858</id>
        <msg>WEB-MISC CISCO PIX Firewall Manager directory traversal attempt</msg>
        <nessus>10819</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $TELNET_SERVERS 23</filter1>
        <filter2>flow:to_server,established; content:&quot;friday&quot;; classtype:attempted-user;</filter2>
        <id>218</id>
        <msg>BACKDOOR MISC Solaris 2.5 attempt</msg>
      </rule>
      <rule>
        <bugtraq>2319</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2766</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB 23|^3|C0 88|F|FA 89|F|F5 89|6&quot;; classtype:attempted-admin;</filter2>
        <id>300</id>
        <msg>EXPLOIT nlps x86 Solaris overflow</msg>
      </rule>
      <rule>
        <bugtraq>2353</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0306</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6373</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB 7F|]U|FE|M|98 FE|M|9B|&quot;; classtype:attempted-admin;</filter2>
        <id>304</id>
        <msg>EXPLOIT SCO calserver overflow</msg>
      </rule>
      <rule>
        <bugtraq>4798</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0882</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/PortInformation&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3467</id>
        <msg>WEB-MISC CISCO VoIP Portinformation access</msg>
      </rule>
      <rule>
        <bugtraq>3274</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|02|//////////&quot;; depth:11; dsize:&gt;1000;  classtype:attempted-admin;</filter2>
        <id>3527</id>
        <msg>EXPLOIT Solaris LPD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14548</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2551</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8008,8028]</filter1>
        <filter2>flow:to_server,established; content:&quot;/nds/&quot;; pcre:&quot;/\x2fnds\x2f[^&amp;\r\n\x3b]{500}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>4127</id>
        <msg>EXPLOIT Novell eDirectory Server iMonitor overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13678</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1543</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1761</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; offset:16; byte_jump:2,0,relative; byte_jump:2,0,relative; byte_test:2,&gt;,1499,0,relative; classtype:attempted-dos;</filter2>
        <id>4129</id>
        <msg>EXPLOIT Novell ZenWorks Remote Management Agent large login packet DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>13678</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1543</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1761</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; offset:16; byte_jump:2,0,relative; byte_jump:2,0,relative; byte_jump:2,0,relative; content:&quot;|00 01 00 01 00 02|&quot;; within:6; isdataat:30,relative; byte_test:2,&gt;,28,0,relative; classtype:attempted-dos;</filter2>
        <id>4130</id>
        <msg>EXPLOIT Novell ZenWorks Remote Management Agent buffer overflow Attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; flowbits:isset,lp.cascade; content:&quot;|02|&quot;; depth:1; content:&quot;cfA&quot;; nocase; pcre:&quot;/^\x02\d+ cfA/smi&quot;; flowbits:set,lp.controlfile; flowbits:noalert;  classtype:misc-attack;</filter2>
        <id>4144</id>
        <msg>EXPLOIT lpd Solaris control file upload attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;O|FF FB 82|O|FF FB 82|O|FF FB 82|O|FF FB 82|&quot;; fast_pattern:only; classtype:shellcode-detect;</filter2>
        <id>640</id>
        <msg>SHELLCODE AIX NOOP</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;G|FF 04 1F|G|FF 04 1F|G|FF 04 1F|G|FF 04 1F|&quot;; fast_pattern:only; classtype:shellcode-detect;</filter2>
        <id>641</id>
        <msg>SHELLCODE Digital UNIX NOOP</msg>
      </rule>
      <rule>
        <bugtraq>17503</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0992</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8300</filter1>
        <filter2>flow:to_server,established; content:&quot;Accept-Language&quot;; nocase; pcre:&quot;/^Accept-Language\x3A[^\r\n]{17}/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>6414</id>
        <msg>WEB-MISC Novell GroupWise Messenger Accept-Language header buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18026</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2496</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8028</filter1>
        <filter2>flow:to_server,established; content:&quot;/nds&quot;; nocase; http_uri; pcre:&quot;/\x2fnds[^\r\n]{1000}/Usmi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>6507</id>
        <msg>WEB-MISC novell edirectory imonitor overflow attempt</msg>
      </rule>
      <rule>
        <classtype>network-scan</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5000</filter1>
        <filter2>flow:to_server,established; content:&quot;M-SEARCH &quot;; depth:9; content:&quot;ssdp|3A|discover&quot;; fast_pattern:only; classtype:network-scan;</filter2>
        <id>8081</id>
        <msg>SCAN UPnP service discover attempt</msg>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3443</filter1>
        <filter2>flow:to_server,established; content:&quot;/connectedNodes.ovpl&quot;; nocase; http_uri; content:&quot;node=&quot;; nocase; http_uri; pcre:&quot;/connectedNodes.ovpl[^\r\n]*node=[^\r\n]*(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8085</id>
        <msg>WEB-MISC HP Openview NNM connectedNodes.ovpl port 3443 Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3443</filter1>
        <filter2>flow:to_server,established; content:&quot;/cdpView.ovpl&quot;; nocase; http_uri; content:&quot;cdpnode=&quot;; nocase; http_uri; pcre:&quot;/cdpView.ovpl[^\r\n]*cdpnode=[^\r\n]*%(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8086</id>
        <msg>WEB-MISC HP Openview NNM cdpView.ovpl port 3443 Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3443</filter1>
        <filter2>flow:to_server,established; content:&quot;/freeIPaddrs.ovpl&quot;; nocase; http_uri; content:&quot;netid=&quot;; nocase; http_uri; pcre:&quot;/freeIPaddrs.ovpl[^\r\n]*netid=[^\r\n]*%(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8087</id>
        <msg>WEB-MISC HP Openview NNM freeIPaddrs.ovpl port 3443 Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/connectedNodes.ovpl&quot;; nocase; http_uri; content:&quot;node=&quot;; nocase; http_uri; pcre:&quot;/connectedNodes.ovpl[^\r\n]*node=[^\r\n]*(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8088</id>
        <msg>WEB-MISC HP Openview NNM connectedNodes.ovpl Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14662</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cdpView.ovpl&quot;; nocase; http_uri; content:&quot;cdpnode=&quot;; nocase; http_uri; pcre:&quot;/cdpView.ovpl[^\r\n]*cdpnode=[^\r\n]*(\x2c|\x24|\x7c|\x3b|\x22|\x26|\x3c|\x3f)/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8089</id>
        <msg>WEB-MISC HP Openview NNM cdpView.ovpl Unix command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>20655</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5478</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8028</filter1>
        <filter2>flow:established,to_server; content:&quot;Host|3A|&quot;; nocase; isdataat:63,relative; content:!&quot;|0A|&quot;; within:63; pcre:&quot;/^(GET|POST)\s+[^\s]*(\x2fnds|\x2fdhost)[^\n]*\nHost\x3a\s*[^\n]{63}/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>8711</id>
        <msg>WEB-MISC Novell eDirectory HTTP redirection buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>21502</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6379</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9B|&quot;; depth:1; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; classtype:attempted-admin;</filter2>
        <id>9633</id>
        <msg>EXPLOIT Computer Associates Product Discovery Service type 9B remote buffer overflow attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>21502</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6379</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9C|&quot;; depth:1; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; classtype:attempted-admin;</filter2>
        <id>9634</id>
        <msg>EXPLOIT Computer Associates Product Discovery Service type 9C remote buffer overflow attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>21502</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6379</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9C|&quot;; depth:1; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; classtype:attempted-admin;</filter2>
        <id>9636</id>
        <msg>EXPLOIT Computer Associates Product Discovery Service type 9C remote buffer overflow attempt UDP</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>200</groupid>
    <groupname>Server</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>210</groupid>
    <groupname>Server / HTTP</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3BFFE033-BF43-11D5-A271-00A024A51325&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3BFFE033-BF43-11D5-A271-00A024A51325\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(InstallBrowserHelperDll)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3BFFE033-BF43-11D5-A271-00A024A51325\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(InstallBrowserHelperDll))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13258</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|B|00|F|00|F|00|E|00|0|00|3|00|3|00|-|00|B|00|F|00|4|00|3|00|-|00|1|00|1|00|D|00|5|00|-|00|A|00|2|00|7|00|1|00|-|00|0|00|0|00|A|00|0|00|2|00|4|00|A|00|5|00|1|00|3|00|2|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13259</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;iNotes6.iNotes6&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22iNotes6\.iNotes6\x22|\x27iNotes6\.iNotes6\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*InstallBrowserHelperDll\s*|.*(?P=v)\s*\.\s*InstallBrowserHelperDll\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22iNotes6\.iNotes6\x22|\x27iNotes6\.iNotes6\x27)\s*\)(\s*\.\s*InstallBrowserHelperDll\s*|.*(?P=n)\s*\.\s*InstallBrowserHelperDll\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13260</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;i|00|N|00|o|00|t|00|e|00|s|00|6|00|.|00|i|00|N|00|o|00|t|00|e|00|s|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)i\x00N\x00o\x00t\x00e\x00s\x006\x00.\x00i\x00N\x00o\x00t\x00e\x00s\x006\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)i\x00N\x00o\x00t\x00e\x00s\x006\x00.\x00i\x00N\x00o\x00t\x00e\x00s\x006\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13261</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E008A543-CEFB-4559-912F-C27C2B89F13B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E008A543-CEFB-4559-912F-C27C2B89F13B\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(InstallBrowserHelperDll)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E008A543-CEFB-4559-912F-C27C2B89F13B\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\.(InstallBrowserHelperDll))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13262</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|0|00|0|00|8|00|A|00|5|00|4|00|3|00|-|00|C|00|E|00|F|00|B|00|-|00|4|00|5|00|5|00|9|00|-|00|9|00|1|00|2|00|F|00|-|00|C|00|2|00|7|00|C|00|2|00|B|00|8|00|9|00|F|00|1|00|3|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q8&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13263</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;dwa7.dwa7&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22dwa7\.dwa7\x22|\x27dwa7\.dwa7\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*InstallBrowserHelperDll\s*|.*(?P=v)\s*\.\s*InstallBrowserHelperDll\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22dwa7\.dwa7\x22|\x27dwa7\.dwa7\x27)\s*\)(\s*\.\s*InstallBrowserHelperDll\s*|.*(?P=n)\s*\.\s*InstallBrowserHelperDll\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13264</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d|00|w|00|a|00|7|00|.|00|d|00|w|00|a|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)d\x00w\x00a\x007\x00.\x00d\x00w\x00a\x007\x00(?P=q9)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)d\x00w\x00a\x007\x00.\x00d\x00w\x00a\x007\x00(?P=q10)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13265</id>
        <msg>WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>13418</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1383</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7778</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /server-status&quot;; depth:18; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15956</id>
        <msg>ORACLE http Server mod_access restriction bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>23174</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1739</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>flow:to_server,established; content:&quot;0|84 00 01 00|5|02 01 04|h|84 00 01 00|,|04 84 00 01 00| cn=&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16017</id>
        <msg>SPECIFIC-THREATS IBM Lotus Domino LDAP server invalid DN message buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>20841</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-4517</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nps/servlet/webacc&quot;; nocase; http_uri; content:&quot;tree=&quot;; nocase; http_cookie; pcre:&quot;/tree\s*\x3d\s*(\d{4}|25[6-9]|2[6-9]|[3-9])/mi&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16052</id>
        <msg>WEB-CLIENT Novell iManager Tomcat http post handling DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>16523</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-0580</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>flow:to_server,established; content:&quot;0|0C 02 01 01|`|07 02 00 DD 04 00 80 00|&quot;; depth:14; metadata:policy security-ips drop, service ldap; classtype:attempted-dos;</filter2>
        <id>16060</id>
        <msg>SPECIFIC-THREATS IBM Lotus Domino LDAP server memory exception attempt</msg>
      </rule>
      <rule>
        <bugtraq>27387</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0401</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 443</filter1>
        <filter2>flow:to_server,established; content:&quot;|17 03 01 00| |AB CA A4| q|EC|IW|F2|&amp;G|CD 1D 08 F9 F5 E9|^F|BF B8 DC|F|C8|K|FC|D|99|o|9A|X|AD|&quot;; depth:37; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16216</id>
        <msg>SPECIFIC-THREATS IBM Tivoli Provisioning Manager for OS deployment HTTP server buffer attempt</msg>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid=|27|clsid|3A|E008A543-CEFB-4559-912F-C27C2B89F13B|27|&quot;; fast_pattern:only; content:&quot;classid=|27|clsid|3A|3BFFE033-BF43-11D5-A271-00A024A51325|27|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16671</id>
        <msg>SPECIFIC-THREATS IBM Lotus Domino Web Access ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;/%5C../&quot;; fast_pattern:only; content:&quot;/%5C../&quot;; nocase; http_raw_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17391</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>26972</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E008A543-CEFB-4559-912F-C27C2B89F13B&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 27 25 75 34|&quot;; nocase; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>17466</id>
        <msg>SPECIFIC-THREATS IBM Lotus Domino Web Access 7 ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;/|5C|../&quot;; fast_pattern:only; content:&quot;/|5C|../&quot;; nocase; http_raw_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17498</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;/..|5C|/&quot;; fast_pattern:only; content:&quot;/..|5C|/&quot;; http_raw_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17499</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;/..%5C/&quot;; fast_pattern:only; content:&quot;/..%5C/&quot;; http_raw_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17500</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;/%2E%2E&quot;; fast_pattern:only; content:&quot;/%2E%2E&quot;; nocase; http_raw_uri; pcre:&quot;/\/%2E%2E(\\|%5C)\//&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17501</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>22960</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0450</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;%2E%2E/&quot;; fast_pattern:only; content:&quot;%2E%2E/&quot;; nocase; http_raw_uri; pcre:&quot;/\/(\\|%5C)%2E%2E\//&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17502</id>
        <msg>WEB-MISC Tomcat UNIX platform directory traversal</msg>
        <url>tomcat.apache.org/tomcat-6.0-doc/changelog.html</url>
      </rule>
      <rule>
        <bugtraq>38457</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; isdataat:1024; content:&quot;ctrl.InstallBrowserHelperDll&quot;; nocase; content:&quot;General_ServerName&quot;; nocase; content:!&quot;&gt;&quot;; within:1024; pcre:&quot;/(3BFFE033-BF43-11d5-A271-00A024A51325|iNotes6\.iNotes6|E008A543-CEFB-4559-912F-C27C2B89F13B|dwa7\.dwa7|983A9C21-8207-4B58-BBB8-0EBC3D7C5505|dwa85?\.dwa85?|75AA409D-05F9-4f27-BD53-C7339D4B1D0A)/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17545</id>
        <msg>WEB-ACTIVEX Lotus Domino Web Access ActiveX Controls buffer overflow attempt</msg>
        <url>www-01.ibm.com/support/docview.wss?uid=swg21421808</url>
      </rule>
    </attacks>
    <groupid>211</groupid>
    <groupname>Server / HTTP / Common</groupname>
    <warnings>
      <rule>
        <bugtraq>2527</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0590</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;%252ejsp&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1056</id>
        <msg>WEB-MISC Tomcat view source attempt</msg>
      </rule>
      <rule>
        <bugtraq>2173</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0009</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.nsf/&quot;; http_uri; content:&quot;../&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1072</id>
        <msg>WEB-MISC Lotus Domino directory traversal</msg>
        <nessus>12248</nessus>
      </rule>
      <rule>
        <bugtraq>1532</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jsp/snp/&quot;; http_uri; content:&quot;.snp&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1108</id>
        <msg>WEB-MISC Tomcat server snoop access</msg>
        <nessus>10478</nessus>
      </rule>
      <rule>
        <bugtraq>1548</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0672</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/contextAdmin/contextAdmin.html&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1111</id>
        <msg>WEB-MISC Tomcat server exploit access</msg>
        <nessus>10477</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>1999-0474</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.html/......&quot;; nocase; http_uri; metadata:service http; classtype:attempted-dos;</filter2>
        <id>1115</id>
        <msg>WEB-MISC ICQ webserver DOS</msg>
        <url>www.securiteam.com/exploits/2ZUQ1QAQOG.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/catalog.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1150</id>
        <msg>WEB-MISC Domino catalog.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/domcfg.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1151</id>
        <msg>WEB-MISC Domino domcfg.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/domlog.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1152</id>
        <msg>WEB-MISC Domino domlog.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/log.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1153</id>
        <msg>WEB-MISC Domino log.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/names.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1154</id>
        <msg>WEB-MISC Domino names.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Mode=debug&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1540</id>
        <msg>WEB-COLDFUSION ?Mode=debug attempt</msg>
        <nessus>10797</nessus>
      </rule>
      <rule>
        <bugtraq>4022</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mab.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1575</id>
        <msg>WEB-MISC Domino mab.nsf access</msg>
        <nessus>10953</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cersvr.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1576</id>
        <msg>WEB-MISC Domino cersvr.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setup.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1577</id>
        <msg>WEB-MISC Domino setup.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/statrep.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1578</id>
        <msg>WEB-MISC Domino statrep.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <bugtraq>9901</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webadmin.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1579</id>
        <msg>WEB-MISC Domino webadmin.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/events4.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1580</id>
        <msg>WEB-MISC Domino events4.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ntsync4.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1581</id>
        <msg>WEB-MISC Domino ntsync4.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/collect4.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1582</id>
        <msg>WEB-MISC Domino collect4.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailw46.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1583</id>
        <msg>WEB-MISC Domino mailw46.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bookmark.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1584</id>
        <msg>WEB-MISC Domino bookmark.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/agentrunner.nsf&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1585</id>
        <msg>WEB-MISC Domino agentrunner.nsf access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <bugtraq>881</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mail.box&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1586</id>
        <msg>WEB-MISC Domino mail.box access</msg>
        <nessus>10629</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sendmail.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1659</id>
        <msg>WEB-COLDFUSION sendmail.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>5193</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0682</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/servlet/&quot;; http_uri; content:&quot;/org.apache.&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1827</id>
        <msg>WEB-MISC Tomcat servlet mapping cross site scripting attempt</msg>
        <nessus>11041</nessus>
      </rule>
      <rule>
        <bugtraq>4575</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/examples/servlet/TroubleShooter&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1829</id>
        <msg>WEB-MISC Tomcat TroubleShooter servlet access</msg>
        <nessus>11046</nessus>
      </rule>
      <rule>
        <bugtraq>4575</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/examples/servlet/SnoopServlet&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1830</id>
        <msg>WEB-MISC Tomcat SnoopServlet servlet access</msg>
        <nessus>11046</nessus>
      </rule>
      <rule>
        <bugtraq>6721</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-0042</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|.jsp&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2061</id>
        <msg>WEB-MISC Tomcat null byte directory listing attempt</msg>
        <nessus>11438</nessus>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFNEWINTERNALADMINSECURITY|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>8485</id>
        <msg>WEB-COLDFUSION CFNEWINTERNALADMINSECURITY access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFNEWINTERNALREGISTRY|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>8486</id>
        <msg>WEB-COLDFUSION CFNEWINTERNALREGISTRY access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFADMIN_REGISTRY_SET|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>8487</id>
        <msg>WEB-COLDFUSION CFADMIN_REGISTRY_SET access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFADMIN_REGISTRY_GET|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>8488</id>
        <msg>WEB-COLDFUSION CFADMIN_REGISTRY_GET access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFADMIN_REGISTRY_DELETE|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>8489</id>
        <msg>WEB-COLDFUSION CFADMIN_REGISTRY_DELETE access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/snippets/viewexample.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>8490</id>
        <msg>WEB-COLDFUSION viewexample.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/expeval/eval.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>8491</id>
        <msg>WEB-COLDFUSION eval.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/expeval/openfile.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>8492</id>
        <msg>WEB-COLDFUSION openfile.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0922</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/docs/sourcewindow.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>8493</id>
        <msg>WEB-COLDFUSION sourcewindow.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>917</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0057</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfcache.map&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>903</id>
        <msg>WEB-COLDFUSION cfcache.map access</msg>
      </rule>
      <rule>
        <bugtraq>1021</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/email/application.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>904</id>
        <msg>WEB-COLDFUSION exampleapp application.cfm</msg>
      </rule>
      <rule>
        <bugtraq>1021</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/publish/admin/application.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>905</id>
        <msg>WEB-COLDFUSION application.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>229</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/email/getfile.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>906</id>
        <msg>WEB-COLDFUSION getfile.cfm access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/publish/admin/addcontent.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>907</id>
        <msg>WEB-COLDFUSION addcontent.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>1314</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0538</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfide/administrator/index.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>908</id>
        <msg>WEB-COLDFUSION administrator access</msg>
        <nessus>10581</nessus>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CF_SETDATASOURCEUSERNAME|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>909</id>
        <msg>WEB-COLDFUSION datasource username attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/snippets/fileexists.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>910</id>
        <msg>WEB-COLDFUSION fileexists.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/expeval/exprcalc.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>911</id>
        <msg>WEB-COLDFUSION exprcalc access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/examples/parks/detail.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>912</id>
        <msg>WEB-COLDFUSION parks access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfappman/index.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>913</id>
        <msg>WEB-COLDFUSION cfappman access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/examples/cvbeans/beaninfo.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>914</id>
        <msg>WEB-COLDFUSION beaninfo access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/snippets/evaluate.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>915</id>
        <msg>WEB-COLDFUSION evaluate.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_GETODBCDSN|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>916</id>
        <msg>WEB-COLDFUSION getodbcdsn access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_DBCONNECTIONS_FLUSH|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>917</id>
        <msg>WEB-COLDFUSION db connections flush attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/expeval/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>918</id>
        <msg>WEB-COLDFUSION expeval access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CF_SETDATASOURCEPASSWORD|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>919</id>
        <msg>WEB-COLDFUSION datasource passwordattempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CF_ISCOLDFUSIONDATASOURCE|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>920</id>
        <msg>WEB-COLDFUSION datasource attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_ENCRYPT|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>921</id>
        <msg>WEB-COLDFUSION admin encrypt attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/expeval/displayopenedfile.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>922</id>
        <msg>WEB-COLDFUSION displayfile access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_GETODBCINI|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>923</id>
        <msg>WEB-COLDFUSION getodbcin attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_DECRYPT|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>924</id>
        <msg>WEB-COLDFUSION admin decrypt attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/examples/mainframeset.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>925</id>
        <msg>WEB-COLDFUSION mainframeset access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_SETODBCINI|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>926</id>
        <msg>WEB-COLDFUSION set odbc ini attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_SETTINGS_REFRESH|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>927</id>
        <msg>WEB-COLDFUSION settings refresh attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>2001-0535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/exampleapp/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>928</id>
        <msg>WEB-COLDFUSION exampleapp access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CFUSION_VERIFYMAIL|28 29|&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>929</id>
        <msg>WEB-COLDFUSION CFUSION_VERIFYMAIL access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/snippets/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>930</id>
        <msg>WEB-COLDFUSION snippets attempt</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/cfmlsyntaxcheck.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>931</id>
        <msg>WEB-COLDFUSION cfmlsyntaxcheck.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/application.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>932</id>
        <msg>WEB-COLDFUSION application.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/onrequestend.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>933</id>
        <msg>WEB-COLDFUSION onrequestend.cfm access</msg>
      </rule>
      <rule>
        <bugtraq>247</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0756</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfide/administrator/startstop.html&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>935</id>
        <msg>WEB-COLDFUSION startstop DOS access</msg>
      </rule>
      <rule>
        <bugtraq>550</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0760</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfdocs/snippets/gettempdirectory.cfm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>936</id>
        <msg>WEB-COLDFUSION gettempdirectory.cfm access </msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4008</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; depth:4; nocase; content:&quot;Transfer-Encoding|3A|&quot;; distance:0; nocase; isdataat:256,relative; pcre:&quot;/^Transfer-Encoding\x3A\s*[^\r\n]{256}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>14771</id>
        <msg>WEB-MISC BEA WebLogic Apache Oracle connector Transfer-Encoding buffer overflow</msg>
        <url>support.bea.com/application_content/product_portlets/securityadvisories/2806.html</url>
      </rule>
      <rule>
        <bugtraq>16153</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-3656</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A| Basic dGVzdCVuJW4lbjpmb29iYXI=&quot;; http_header; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16198</id>
        <msg>SPECIFIC-THREATS Apache mod_auth_pgsql module logging facility format string exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>38494</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0425</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;1|C0|1|C9|d|8B|q0|8B|v|0C 8B|v|1C 8B|V|08 8B|~ |8B|6f9O|14|u|F2|f|B9 01|mf|81 E9 94|lf9|0F|f|89 C1|u|E1 89 E5 EB|q`|8B|l|24 24 8B|E&lt;|8B|T|05|x|01 EA 8B|J|18 8B|Z |01 EB E3|4I|8B|4|8B 01 EE|1|FF|1|C0 FC AC 84 C0|t|07 C1 CF 0D 01 C7 EB F4 3B 7C 24 28|u|E1 8B|Z|24 01 EB|f|8B 0C|K|8B|Z|1C 01 EB 8B 04 8B 01 E8 89|D|24 1C|a|C3 AD|PR|E8 AA FF FF FF 89 07|f|81 C4 0C 01|f|81 EC 04 01|f|81 C7 08 01|f|81 EF 04 01|9|CE|u|DE C3 EB 10|^|8D|}|04 89 F1 80 C1 0C E8 CD FF FF FF EB 3B E8 EB FF FF FF|n|7C|.|E1 1E|&lt;?|D7|t|1E|H|CD|1|D2|X|88|P|07 EB|/1|D2|Y|88|Q|01 EB|.QP|FF|U|04 EB|,1|D2|Y|88|Q|09 EB|3QP|89 C6 FF|U|08|S|FF|U|0C E8 D1 FF FF FF|sos.txtN|E8 CC FF FF FF|wN|E8 CD FF FF FF E8 CF FF FF FF|pwn-isapiN|E8 C8 FF FF FF 90 90 90 90|&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16479</id>
        <msg>SPECIFIC-THREATS Apache mod_isapi dangling pointer exploit attempt - public shell code</msg>
      </rule>
      <rule>
        <bugtraq>38494</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0425</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Proxy-Connection|3A| Keep-Alive|0D 0A|Okytuasd|3A| AAAA&quot;; http_header; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16480</id>
        <msg>SPECIFIC-THREATS Apache mod_isapi dangling pointer exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26663</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-6203</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;&lt;PROCHECKUP&gt;&quot;; depth:12; nocase; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16611</id>
        <msg>WEB-MISC Apache 413 error HTTP request method cross-site scripting attack</msg>
      </rule>
      <rule>
        <bugtraq>36954</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-3548</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8081</filter1>
        <filter2>flow:to_server,established; content:&quot;/manager&quot;; nocase; content:&quot;Authorization&quot;; distance:0; nocase; content:&quot;Basic&quot;; within:50; nocase; content:&quot;b3Z3ZWJ1c3I6T3ZXKmJ1c3Ix&quot;; within:100; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17156</id>
        <msg>EXPLOIT HP Performance Manager Apache Tomcat policy bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>30633</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-2938</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|25|ae|2F|&quot;; pcre:&quot;/(((\xc0|\xe0\x80|\xf0\x80\x80)\xaf|\x2f)((\xc0|\xe0\x80|\xf0\x80\x80)\xae|\x2e){2}|(((\xc0|\xe0\x80|\xf0\x80\x80)\xae|\x2e){2}(\xc0|\xe0\x80|\xf0\x80\x80)\xaf|\x2f))/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17387</id>
        <msg>WEB-MISC Apache Tomcat allowLinking URIencoding directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>32104</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2008-6505</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/struts/&quot;; nocase; content:&quot;|25|252f&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>17533</id>
        <msg>WEB-MISC Apache Struts Information Disclosure Attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3747</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ldap:/&quot;; nocase; http_uri; pcre:&quot;/\x3F[^\x3F]*\x3F[^\x3F]*\x3F[^\x3F]*\x3F[^\x3F]*\x3F/U&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17656</id>
        <msg>WEB-MISC Apache HTTP server mod_rewrite module LDAP scheme handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35196</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2009-0580</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;j_username=&quot;; nocase; content:&quot;j_password=%&quot;; nocase; metadata:policy security-ips alert, service http; classtype:attempted-recon;</filter2>
        <id>18096</id>
        <msg>WEB-MISC Apache Tomcat username enumeration attempt</msg>
      </rule>
    </attacks>
    <groupid>212</groupid>
    <groupname>Server / HTTP / Apache</groupname>
    <warnings>
      <rule>
        <bugtraq>1457</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0628</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/site/eg/source.asp&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1110</id>
        <msg>WEB-MISC apache source.asp file access</msg>
        <nessus>10480</nessus>
      </rule>
      <rule>
        <bugtraq>7254</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-0132</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|0D 0A 0D 0A|&quot;; pcre:&quot;/(\x0d\x0a){100}/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>11272</id>
        <msg>WEB-MISC Apache newline exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2004-0942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/1.&quot;; pcre:&quot;/HTTP\/1.[01]\n.*[\x20\t]{200}/si&quot;; metadata:service http; classtype:attempted-dos;</filter2>
        <id>11273</id>
        <msg>WEB-MISC Apache header parsing space saturation denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-3747</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 80</filter1>
        <filter2>flow:established,to_server; content:&quot;GET&quot;; nocase; content:&quot;ldap|3A|&quot;; distance:0; pcre:&quot;/ldap\x3A\x2F\x2F[^\x0A]*(%3f|\x3F)[^\x0A]*(%3f|\x3F)[^\x0A]*(%3f|\x3F)[^\x0A]*(%3f|\x3F)/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>11679</id>
        <msg>WEB-MISC Apache mod_rewrite buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7723</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0245</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;propfind xmlns|3A|&quot;; isdataat:514,relative; pcre:&quot;/propfind xmlns\x3A[^\x3D]*\x3d\x22[^\x22]{512}/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12465</id>
        <msg>EXPLOIT Apache APR memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>24649</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2007-1863</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 80</filter1>
        <filter2>flow:established,to_server; content:&quot;Cache-Control|3A|&quot;; fast_pattern:only; nocase; pcre:&quot;/^Cache-Control\x3A\s*(max-(age|stale)|min-fresh|s-maxage)\s*\x3D[^\d]+\x0A/smi&quot;; classtype:denial-of-service;</filter2>
        <id>12591</id>
        <msg>DOS Apache mod_cache denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>26070</bugtraq>
        <classtype>successful-recon-limited</classtype>
        <cve>2007-5461</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:established,to_server; content:&quot;&lt;!ENTITY RemoteX SYSTEM&quot;; nocase; classtype:successful-recon-limited;</filter2>
        <id>12711</id>
        <msg>WEB-MISC Apache Tomcat WebDAV system tag remote file disclosure attempt</msg>
        <url>issues.apache.org/jira/browse/GERONIMO-3549</url>
      </rule>
      <rule>
        <bugtraq>26838</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-5000</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.map/&quot;; nocase; http_uri; content:&quot;script&quot;; nocase; pcre:&quot;/.map/[^\n]*script[^\n]*script/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>13302</id>
        <msg>WEB-CLIENT Apache mod_imagemap cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>3009</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0731</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?M=D&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1519</id>
        <msg>WEB-MISC apache ?M=D directory list attempt</msg>
        <nessus>10704</nessus>
      </rule>
      <rule>
        <bugtraq>30273</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3257</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; nocase; http_method; content:&quot;AAAAAAAAAAAAAAAAAAAA&quot;; depth:100; metadata:service http; classtype:attempted-admin;</filter2>
        <id>15511</id>
        <msg>SPECIFIC-THREATS Oracle WebLogic Apache Connector buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2007-0086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| Mozilla/4.0 |28|compatible|3B| MSIE 7.0|3B| Windows NT 5.1|3B| Trident/4.0|3B| .NET CLR 1.1.4322|3B| .NET CLR 2.0.503l3|3B| .NET CLR 3.0.4506.2152|3B| .NET CLR 3.5.30729|3B| MSOffice 12|29 0D 0A|&quot;; http_header; content:&quot;Content-Length|3A| 42&quot;; http_header;  metadata:service http; classtype:attempted-dos;</filter2>
        <id>15578</id>
        <msg>SPECIFIC-THREATS Slowloris http DoS tool</msg>
      </rule>
      <rule>
        <bugtraq>10736</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0700</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;https&quot;; nocase; http_uri; pcre:&quot;/^[a-z]+\s+https\x3a\x2f\x2f[^\x2f\x3a\x25\s]*\x25[sn]/i&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15980</id>
        <msg>WEB-MISC Apache mod_ssl hook functions format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>20527</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;application/x-www-form-urlencoded&quot;; http_header; content:&quot;abc=%25s%25s&quot;; fast_pattern; metadata:service http; classtype:attempted-user;</filter2>
        <id>16021</id>
        <msg>SPECIFIC-THREATS Apache http Server mod_tcl format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>22791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0774</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; urilen:&gt;1024; content:&quot;AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; http_uri; classtype:attempted-admin;</filter2>
        <id>17107</id>
        <msg>SPECIFIC-THREATS Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>22791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0774</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; urilen:&gt;1440; content:&quot;GET /&quot;; depth:5; pcre:&quot;/^\x2F[a-z0-9]{16}[^a-z0-9\x2F\x3F\x26]/iU&quot;; classtype:attempted-admin;</filter2>
        <id>17108</id>
        <msg>SPECIFIC-THREATS Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>14660</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-2728</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established, to_server; content:&quot;POST&quot;; nocase; http_method; content:&quot;Range|3A| bytes|3D|&quot;; nocase; http_header; classtype:attempted-dos;</filter2>
        <id>17354</id>
        <msg>SPECIFIC-THREATS Apache Byte-Range Filter denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>5033</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0392</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;|C0|PR|89 E1|PQRP|B8 3B 00 00 00 CD 80|&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1808</id>
        <msg>WEB-MISC apache chunked encoding memory corruption exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>5033</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0392</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CCCCCCC|3A| AAAAAAAAAAAAAAAAAAA&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1809</id>
        <msg>WEB-MISC Apache Chunked-Encoding worm attempt</msg>
        <nessus>10932</nessus>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cmd.exe&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>1002</id>
        <msg>WEB-IIS cmd.exe access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0080</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,asp.upload; metadata: engine shared, soid 3|15470, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15470</id>
        <msg>WEB-MISC IIS ASP/ASP.NET potentially malicious file upload attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-012.mspx</url>
      </rule>
      <rule>
        <bugtraq>27676</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-0075</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:web-application-attack; metadata: engine shared, soid 3|15974, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15974</id>
        <msg>EXPLOIT Microsoft IIS ASP handling buffer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>15921</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-4360</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.dll/%3a/~9&quot;; depth:11; offset:18; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>16147</id>
        <msg>SPECIFIC-THREATS Microsoft IIS malformed URL .dll denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16312, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16312</id>
        <msg>WEB-IIS ADFS custom header arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-070.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2009-4444</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.asp|3B|.&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16356</id>
        <msg>WEB-IIS multiple extension code execution attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cmd32.exe&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>1661</id>
        <msg>WEB-IIS cmd32.exe access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2010-2731</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;$i30:$INDEX_ALLOCATION&quot;; nocase; http_uri; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17103</id>
        <msg>WEB-IIS IIS 5.1 alternate data stream authentication bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-065.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-1899</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|17254, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17254</id>
        <msg>WEB-MISC Microsoft IIS stack exhaustion DoS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-065.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-2730</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17255, service http, policy security-ips drop;</filter2>
        <id>17255</id>
        <msg>EXPLOIT Microsoft IIS FastCGI heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-065.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-0085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 443</filter1>
        <filter2>flow:to_server,established; content:&quot;|1D 1D 55 69 8B 83 B2 CF 4A 71 6F A1 45 62 8C 7C BD 98 79 15 E5 85 EB 87 5B FC 06 04 D7 14 03 01 00 01 01 16 03|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service ssl; classtype:misc-activity;</filter2>
        <id>17431</id>
        <msg>EXPLOIT Microsoft IIS SChannel improper certificate verification</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>35232</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1122</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; nocase; content:&quot;|25 32 35 25 33 37 25 33 30 25 32 35 25 33 37 25|&quot;; within:16; distance:2; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17525</id>
        <msg>SPECIFIC-THREATS Microsoft IIS 5.0 WebDav Request Directory Security Bypass</msg>
      </rule>
      <rule>
        <bugtraq>34993</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1535</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/%c0%af/&quot;; pcre:&quot;/^(GET|OPTIONS|HEAD|POST|PUT|DELETE|CONNECT|PROPFIND|PROPPATCH|MKCOL|COPY|MOVE|LOCK|UNLOCK)[^\r\n]*\s+[^\r\n]*\x2f\x25c0\x25af\x2f/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17564</id>
        <msg>WEB-IIS WebDAV Request Directory Security Bypass attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2005-2678</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;http|3A 2F|localhost&quot;; nocase; http_uri; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>17652</id>
        <msg>WEB-MISC Microsoft IIS source code disclosure attempt</msg>
        <url>secunia.com/advisories/16548</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2005-2678</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;host&quot;; nocase; http_header; content:&quot;localhost&quot;; nocase; http_header; pcre:&quot;/^Host\s*\x3A\s*localhost\s/miH&quot;; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>17653</id>
        <msg>WEB-MISC Microsoft IIS source code disclosure attempt</msg>
        <url>secunia.com/advisories/16548</url>
      </rule>
      <rule>
        <bugtraq>45542</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;|EF 83 B0 EF 83 B0 EF 83 B0 EF 83 B0 EF 83 B0 EF 83 B0 EF 83|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service ftp; classtype:attempted-admin;</filter2>
        <id>18243</id>
        <msg>SPECIFIC-THREATS Microsoft Windows 7 IIS7.5 FTPSVC buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7116</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0109</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SEARCH / HTTP/1.1|0D 0A|Host|3A|&quot;; content:&quot;|0D 0A 0D 0A|&quot;; within:255; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>2091</id>
        <msg>WEB-IIS WEBDAV nessus safe scan attempt</msg>
        <nessus>11413</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms03-007.mspx</url>
      </rule>
    </attacks>
    <groupid>213</groupid>
    <groupname>Server / HTTP / Microsoft IIS</groupname>
    <warnings>
      <rule>
        <bugtraq>2280</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bdir.htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1000</id>
        <msg>WEB-IIS bdir.htr access</msg>
        <nessus>10577</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.cmd?&amp;&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1003</id>
        <msg>WEB-IIS cmd? access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0815</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iissamples/exair/howitworks/codebrws.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1004</id>
        <msg>WEB-IIS codebrowser Exair access</msg>
      </rule>
      <rule>
        <bugtraq>167</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0736</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iissamples/sdk/asp/docs/codebrws.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1005</id>
        <msg>WEB-IIS codebrowser SDK access</msg>
      </rule>
      <rule>
        <bugtraq>1595</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1104</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Form_JScript.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1007</id>
        <msg>WEB-IIS Form_JScript.asp access</msg>
        <nessus>10572</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-060.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;&amp;del+/s+c|3A 5C|*.*&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1008</id>
        <msg>WEB-IIS del attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ServerVariables_Jscript.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1009</id>
        <msg>WEB-IIS directory listing</msg>
        <nessus>10573</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|23|filename=*.exe&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1011</id>
        <msg>WEB-IIS exec-src access</msg>
      </rule>
      <rule>
        <bugtraq>2252</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1376</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fpcount.exe&quot;; fast_pattern; nocase; http_uri; content:&quot;Digits=&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1012</id>
        <msg>WEB-IIS fpcount attempt</msg>
      </rule>
      <rule>
        <bugtraq>2252</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1376</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fpcount.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1013</id>
        <msg>WEB-IIS fpcount access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/tools/getdrvs.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1015</id>
        <msg>WEB-IIS getdrvs.exe access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-0778</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/global.asa&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1016</id>
        <msg>WEB-IIS global.asa access</msg>
        <nessus>10991</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>1999-0874</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|23|filename=*.idc&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1017</id>
        <msg>WEB-IIS idc-srch attempt</msg>
      </rule>
      <rule>
        <bugtraq>2110</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0407</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisadmpwd/aexp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1018</id>
        <msg>WEB-IIS iisadmpwd attempt</msg>
        <nessus>10371</nessus>
      </rule>
      <rule>
        <bugtraq>950</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0097</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;CiWebHitsFile=&quot;; nocase; http_uri; pcre:&quot;/CiWebHitsFile=\/?([^\r\n\x3b\&amp;]*\.\.\/)?/i&quot;; content:&quot;CiRestriction=none&quot;; fast_pattern; nocase; http_uri; content:&quot;ciHiliteType=Full&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1019</id>
        <msg>WEB-IIS Malformed Hit-Highlighting Argument File Access Attempt</msg>
        <url>www.securityfocus.com/archive/1/43762</url>
      </rule>
      <rule>
        <bugtraq>307</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0874</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.idc|3A 3A 24|data&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1020</id>
        <msg>WEB-IIS isc$data attempt</msg>
        <nessus>10116</nessus>
      </rule>
      <rule>
        <bugtraq>1193</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0457</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; .htr&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\s{230,}.htr/U&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1021</id>
        <msg>WEB-IIS ism.dll attempt</msg>
        <nessus>10680</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-031.mspx</url>
      </rule>
      <rule>
        <bugtraq>286</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0874</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/advworks/equipment/catalog_type.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1022</id>
        <msg>WEB-IIS jet vba access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms99-030.mspx</url>
      </rule>
      <rule>
        <bugtraq>529</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1011</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/msadcs.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1023</id>
        <msg>WEB-IIS msadcs.dll access</msg>
        <nessus>10357</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>1818</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0191</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/tools/newdsn.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1024</id>
        <msg>WEB-IIS newdsn.exe access</msg>
        <nessus>10360</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/perl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1025</id>
        <msg>WEB-IIS perl access</msg>
      </rule>
      <rule>
        <bugtraq>6833</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1026</id>
        <msg>WEB-IIS perl-browse newline attempt</msg>
      </rule>
      <rule>
        <bugtraq>6833</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; .pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1027</id>
        <msg>WEB-IIS perl-browse space attempt</msg>
      </rule>
      <rule>
        <bugtraq>193</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0449</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/issamples/query.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1028</id>
        <msg>WEB-IIS query.asp access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/ &quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1029</id>
        <msg>WEB-IIS scripts-browse access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>162</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search97.vts&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1030</id>
        <msg>WEB-IIS search97.vts access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SiteServer/Publishing/viewcode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1031</id>
        <msg>WEB-IIS /SiteServer/Publishing/viewcode.asp access</msg>
        <nessus>10576</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Sites/Knowledge/Membership/Inspired/ViewCode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1032</id>
        <msg>WEB-IIS showcode access</msg>
        <nessus>10576</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-013.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Sites/Knowledge/Membership/Inspiredtutorial/ViewCode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1033</id>
        <msg>WEB-IIS viewcode access</msg>
        <nessus>10576</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-013.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Sites/Samples/Knowledge/Membership/Inspiredtutorial/ViewCode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1034</id>
        <msg>WEB-IIS viewcode access</msg>
        <nessus>10576</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-013.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Sites/Samples/Knowledge/Push/ViewCode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1035</id>
        <msg>WEB-IIS viewcode access</msg>
        <nessus>10576</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-013.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Sites/Samples/Knowledge/Search/ViewCode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1036</id>
        <msg>WEB-IIS viewcode access</msg>
        <nessus>10576</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms99-013.mspx</url>
      </rule>
      <rule>
        <bugtraq>167</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0736</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/showcode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1037</id>
        <msg>WEB-IIS showcode.asp access</msg>
        <nessus>10007</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS99-013.mspx</url>
      </rule>
      <rule>
        <bugtraq>256</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1520</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adsamples/config/site.csc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1038</id>
        <msg>WEB-IIS site server config access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/samples/isapi/srch.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1039</id>
        <msg>WEB-IIS srch.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/srchadm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1040</id>
        <msg>WEB-IIS srchadm access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>1811</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0360</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/uploadn.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1041</id>
        <msg>WEB-IIS uploadn.asp access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0737</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/viewcode.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1043</id>
        <msg>WEB-IIS viewcode.asp access</msg>
        <nessus>10576</nessus>
      </rule>
      <rule>
        <bugtraq>950</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0097</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htw&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1044</id>
        <msg>WEB-IIS webhits access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;403&quot;; content:&quot;Forbidden|3A|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1045</id>
        <msg>WEB-IIS Unauthorized IP Access Attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/site/iisamples&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1046</id>
        <msg>WEB-IIS site/iisamples access</msg>
        <nessus>10370</nessus>
      </rule>
      <rule>
        <bugtraq>1811</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0360</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/postinfo.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1075</id>
        <msg>WEB-IIS postinfo.asp access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/repost.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1076</id>
        <msg>WEB-IIS repost.asp access</msg>
        <nessus>10372</nessus>
      </rule>
      <rule>
        <bugtraq>22861</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0938</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/NR/exeres/&quot;; fast_pattern; nocase; http_uri; content:&quot;frameless&quot;; http_uri; content:!&quot;,frameless&quot;; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>11191</id>
        <msg>WEB-IIS Microsoft Content Management Server memory corruption</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>11384</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2003-0718</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;PROPFIND&quot;; depth:8; nocase; pcre:&quot;/(xmlns\x3A.*?){15}/&quot;; classtype:denial-of-service;</filter2>
        <id>12043</id>
        <msg>DOS Microsoft XML parser IIS WebDAV attack attempt</msg>
      </rule>
      <rule>
        <bugtraq>15921</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-4360</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/_vti_bin/.dll/&quot;; pcre:&quot;/\/_vti_bin\/\.dll\/(%(0[1-9]|1[0-f])|%3f|\x22|\x2a|\x3a|&lt;|&gt;)[\\\/]~[0-9]/Ui&quot;; metadata:service http; classtype:attempted-dos;</filter2>
        <id>12064</id>
        <msg>WEB-IIS w3svc _vti_bin null pointer dereference attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-041.mspx</url>
      </rule>
      <rule>
        <bugtraq>1065</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0071</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.ida&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1242</id>
        <msg>WEB-IIS ISAPI .ida access</msg>
      </rule>
      <rule>
        <bugtraq>1065</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0500</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.ida?&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1243</id>
        <msg>WEB-IIS ISAPI .ida attempt</msg>
      </rule>
      <rule>
        <bugtraq>968</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0500</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.idq?&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1244</id>
        <msg>WEB-IIS ISAPI .idq attempt</msg>
        <nessus>10115</nessus>
      </rule>
      <rule>
        <bugtraq>1065</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0071</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.idq&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1245</id>
        <msg>WEB-IIS ISAPI .idq access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/root.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1256</id>
        <msg>WEB-IIS CodeRed v2 root.exe access</msg>
        <url>www.cert.org/advisories/CA-2001-19.html</url>
      </rule>
      <rule>
        <bugtraq>18858</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0026</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;Content-Disposition|3A| form-data&quot;; http_header; content:&quot;filename=&quot;; nocase; http_header; content:&quot;&lt;!--|23|include&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/filename\x3d\x22[^\x22]*asp/smiH&quot;; pcre:&quot;/\x3c\x21\x2d\x2d\x23include\s+file\s*=\s*.{250,}--&gt;/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>12595</id>
        <msg>WEB-IIS malicious ASP file upload attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-034.mspx</url>
      </rule>
      <rule>
        <bugtraq>3223</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exchange/LogonFrm.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;mailbox=&quot;; nocase; content:&quot;%%%&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1283</id>
        <msg>WEB-IIS outlook web dos</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/msdac/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1285</id>
        <msg>WEB-IIS msdac access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_mem_bin/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1286</id>
        <msg>WEB-IIS _mem_bin access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>1595</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1104</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Form_VBScript.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1380</id>
        <msg>WEB-IIS Form_VBScript.asp access</msg>
        <nessus>10572</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-060.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2008-0075</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:web-application-attack; metadata: engine shared, soid 3|13922;</filter2>
        <id>13922</id>
        <msg>WEB-IIS Microsoft IIS HTMLEncode Unicode string buffer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-006.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/samples/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1400</id>
        <msg>WEB-IIS /scripts/samples/ access</msg>
        <nessus>10370</nessus>
      </rule>
      <rule>
        <bugtraq>167</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0736</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/msadc/samples/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1401</id>
        <msg>WEB-IIS /msadc/samples/ access</msg>
        <nessus>1007</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iissamples/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1402</id>
        <msg>WEB-IIS iissamples access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mkilog.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1485</id>
        <msg>WEB-IIS mkilog.exe access</msg>
        <nessus>10359</nessus>
        <url>www.osvdb.org/274</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ctss.idc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1486</id>
        <msg>WEB-IIS ctss.idc access</msg>
        <nessus>10359</nessus>
      </rule>
      <rule>
        <bugtraq>4236</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0421</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisadmpwd/aexp2.htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1487</id>
        <msg>WEB-IIS /iisadmpwd/aexp2.htr access</msg>
        <nessus>10371</nessus>
      </rule>
      <rule>
        <bugtraq>3301</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0660</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exchange/root.asp?acs=anon&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1567</id>
        <msg>WEB-IIS /exchange/root.asp attempt</msg>
        <nessus>10781</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS01-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>3301</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0660</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exchange/root.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1568</id>
        <msg>WEB-IIS /exchange/root.asp access</msg>
        <nessus>10781</nessus>
      </rule>
      <rule>
        <bugtraq>964</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0256</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htimage.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1595</id>
        <msg>WEB-IIS htimage.exe access</msg>
        <nessus>10376</nessus>
      </rule>
      <rule>
        <bugtraq>4485</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0079</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.asp&quot;; nocase; http_uri; content:&quot;Transfer-Encoding|3A|&quot;; nocase; http_header; content:&quot;chunked&quot;; nocase; http_header; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1618</id>
        <msg>WEB-IIS .asp chunked Transfer-Encoding</msg>
        <nessus>10932</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/StoreCSVS/InstantOrder.asmx&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1626</id>
        <msg>WEB-IIS /StoreCSVS/InstantOrder.asmx request</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/trace.axd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1660</id>
        <msg>WEB-IIS trace.axd access</msg>
        <nessus>10993</nessus>
      </rule>
      <rule>
        <bugtraq>1488</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0630</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; .htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1725</id>
        <msg>WEB-IIS +.htr code fragment attempt</msg>
        <nessus>10680</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-044.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;doctodep.btr&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1726</id>
        <msg>WEB-IIS doctodep.btr access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/users.xml&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1750</id>
        <msg>WEB-IIS users.xml access</msg>
      </rule>
      <rule>
        <bugtraq>4670</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/as_web.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1753</id>
        <msg>WEB-IIS as_web.exe access</msg>
      </rule>
      <rule>
        <bugtraq>4670</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/as_web4.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1754</id>
        <msg>WEB-IIS as_web4.exe access</msg>
      </rule>
      <rule>
        <bugtraq>4672</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1734</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;logged,true&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1756</id>
        <msg>WEB-IIS NewsPro administration authentication attempt</msg>
      </rule>
      <rule>
        <bugtraq>14764</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Translate|3A| &quot;; nocase; byte_test:1,=,102,0,relative; pcre:&quot;/%.*%/smiI&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>17648</id>
        <msg>WEB-IIS source code disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>13524</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-1471</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; nocase; http_method; content:&quot;/WebID/IISWebAgentIF.dll&quot;; fast_pattern; nocase; http_uri; content:&quot;Transfer-Encoding|3A| chunked&quot;; nocase; http_header; content:&quot;|0D 0A 0D 0A|&quot;; byte_test:4,&gt;,16,0,relative,string,hex; metadata:service http; classtype:web-application-attack;</filter2>
        <id>17705</id>
        <msg>WEB-IIS web agent chunked encoding overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-1089</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pbserver/pbserver.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1772</id>
        <msg>WEB-IIS pbserver access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-094.mspx</url>
      </rule>
      <rule>
        <bugtraq>4476</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0150</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/&quot;; nocase; content:&quot;.asa&quot;; fast_pattern; nocase; http_uri; content:&quot;|3A|&quot;; content:&quot;|0A|&quot;; content:&quot;|00|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1802</id>
        <msg>WEB-IIS .asa HTTP header buffer overflow attempt</msg>
        <nessus>10936</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>4476</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0150</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/&quot;; nocase; content:&quot;.cer&quot;; fast_pattern; nocase; http_uri; content:&quot;|3A|&quot;; content:&quot;|0A|&quot;; content:&quot;|00|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1803</id>
        <msg>WEB-IIS .cer HTTP header buffer overflow attempt</msg>
        <nessus>10936</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>4476</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0150</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/&quot;; nocase; content:&quot;.cdx&quot;; fast_pattern; nocase; http_uri; content:&quot;|3A|&quot;; content:&quot;|0A|&quot;; content:&quot;|00|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1804</id>
        <msg>WEB-IIS .cdx HTTP header buffer overflow attempt</msg>
        <nessus>10936</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>5003</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0364</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htr&quot;; nocase; http_uri; content:&quot;Transfer-Encoding|3A|&quot;; nocase; http_header; content:&quot;chunked&quot;; nocase; http_header; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1806</id>
        <msg>WEB-IIS .htr chunked Transfer-Encoding</msg>
        <nessus>11028</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SiteServer/Admin/knowledge/persmbr/&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/^Authorization|3A|\s*Basic\s+TERBUF9Bbm9ueW1vdXM6TGRhcFBhc3N3b3JkXzE=/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1817</id>
        <msg>WEB-IIS MS Site Server default login attempt</msg>
        <nessus>11018</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Site Server/Admin/knowledge/persmbr/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1818</id>
        <msg>WEB-IIS MS Site Server admin attempt</msg>
        <nessus>11018</nessus>
      </rule>
      <rule>
        <bugtraq>6214</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1142</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/msadcs.dll&quot;; nocase; http_uri; content:&quot;Content-Type|3A|&quot;; nocase; isdataat:50,relative; content:!&quot;|0A|&quot;; within:50; pcre:&quot;/^POST\s/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1970</id>
        <msg>WEB-IIS MDAC Content-Type overflow attempt</msg>
        <nessus>11161</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS98-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>7716</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0109</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/1.1|0A|Content-type|3A| text/xml|0A|HOST|3A|&quot;; http_header; content:&quot;Accept|3A| */*|0A|Translate|3A| f|0A|Content-length|3A|5276|0A 0A|&quot;; http_header; metadata:service http; classtype:attempted-admin;</filter2>
        <id>2090</id>
        <msg>WEB-IIS WEBDAV exploit attempt</msg>
        <nessus>11413</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms03-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>7416</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0215</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;myaccount/login.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2117</id>
        <msg>WEB-IIS Battleaxe Forum login.asp access</msg>
        <nessus>11548</nessus>
      </rule>
      <rule>
        <bugtraq>8035</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0349</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nsiislog.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2129</id>
        <msg>WEB-IIS nsiislog.dll access</msg>
        <nessus>11664</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms03-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>7675</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0377</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisprotect/admin/SiteAdmin.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2130</id>
        <msg>WEB-IIS IISProtect siteadmin.asp access</msg>
        <nessus>11662</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisprotect/admin/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2131</id>
        <msg>WEB-IIS IISProtect access</msg>
        <nessus>11661</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/en/admin/aggregate.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2132</id>
        <msg>WEB-IIS Synchrologic Email Accelerator userid list access attempt</msg>
        <nessus>11657</nessus>
      </rule>
      <rule>
        <bugtraq>7470</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0118</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/biztalkhttpreceive.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2133</id>
        <msg>WEB-IIS MS BizTalk server access</msg>
        <nessus>11638</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-016.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisprotect/admin/GlobalAdmin.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2157</id>
        <msg>WEB-IIS IISProtect globaladmin.asp access</msg>
        <nessus>11661</nessus>
      </rule>
      <rule>
        <bugtraq>3608</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0938</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/UploadScript11.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2247</id>
        <msg>WEB-IIS UploadScript11.asp access</msg>
        <nessus>11746</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2001-0938</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/DirectoryListing.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2248</id>
        <msg>WEB-IIS DirectoryListing.asp access</msg>
      </rule>
      <rule>
        <bugtraq>8103</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pcadmin/login.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2249</id>
        <msg>WEB-IIS /pcadmin/login.asp access</msg>
        <nessus>11785</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/foxweb.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2321</id>
        <msg>WEB-IIS foxweb.exe access</msg>
        <nessus>11939</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/foxweb.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2322</id>
        <msg>WEB-IIS foxweb.dll access</msg>
        <nessus>11939</nessus>
      </rule>
      <rule>
        <bugtraq>9134</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shopsearch.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2324</id>
        <msg>WEB-IIS VP-ASP shopsearch.asp access</msg>
        <nessus>11942</nessus>
      </rule>
      <rule>
        <bugtraq>9134</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ShopDisplayProducts.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2325</id>
        <msg>WEB-IIS VP-ASP ShopDisplayProducts.asp access</msg>
        <nessus>11942</nessus>
      </rule>
      <rule>
        <bugtraq>4720</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0375</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sgdynamo.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2326</id>
        <msg>WEB-IIS sgdynamo.exe access</msg>
        <nessus>11955</nessus>
      </rule>
      <rule>
        <bugtraq>9635</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2003-0818</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A| Negotiate YIQAAABiBoMAAAYrBgEFBQKgggBTMIFQoA4wDAYKKwYBBAGCNwICCqM&quot;; http_header; metadata:service http; classtype:attempted-dos;</filter2>
        <id>2386</id>
        <msg>WEB-IIS NTLM ASN1 vulnerability scan attempt</msg>
        <nessus>12065</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-007.mspx</url>
      </rule>
      <rule>
        <bugtraq>9805</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/frmGetAttachment.aspx&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2571</id>
        <msg>WEB-IIS SmarterTools SmarterMail frmGetAttachment.aspx access</msg>
      </rule>
      <rule>
        <bugtraq>9805</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login.aspx&quot;; nocase; http_uri; content:&quot;txtusername=&quot;; isdataat:980,relative; content:!&quot;|0A|&quot;; within:980; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2572</id>
        <msg>WEB-IIS SmarterTools SmarterMail login.aspx buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9805</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/frmCompose.aspx&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2573</id>
        <msg>WEB-IIS SmarterTools SmarterMail frmCompose.asp access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ping.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2667</id>
        <msg>WEB-IIS ping.asp access</msg>
        <nessus>10968</nessus>
      </rule>
      <rule>
        <bugtraq>11820</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1134</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/w3who.dll?&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/w3who.dll\x3F[^\r\n]{519}/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>3087</id>
        <msg>WEB-IIS w3who.dll buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>5004</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0186</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; pcre:&quot;/\.x[sm]l/Ui&quot;; content:&quot;contenttype=&quot;; http_uri; pcre:&quot;/contenttype=[^\r\n\x3b\x38]{100}/smiU&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>3150</id>
        <msg>WEB-IIS SQLXML content type overflow</msg>
        <nessus>11304</nessus>
        <url>www.westpoint.ltd.uk/advisories/wp-02-0007.txt</url>
      </rule>
      <rule>
        <bugtraq>1912</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0886</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.cmd|22|&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/.cmd\x22.*\x26.*/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3193</id>
        <msg>WEB-IIS .cmd executable file parsing attack</msg>
      </rule>
      <rule>
        <bugtraq>1912</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0886</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.bat|22|&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/.bat\x22.*\x26.*/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3194</id>
        <msg>WEB-IIS .bat executable file parsing attack</msg>
      </rule>
      <rule>
        <bugtraq>2708</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0333</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/httpodbc.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3201</id>
        <msg>WEB-IIS httpodbc.dll access - nimda</msg>
      </rule>
      <rule>
        <bugtraq>13524</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-1471</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WebID/IISWebAgentIF.dll&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2fWebID\x2fIISWebAgentIF.dll[^\n\x26\x3f]*\x3fRedirect\x3furl=[^\n\x26\x3f]{1024}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>5695</id>
        <msg>WEB-IIS web agent redirect overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17452</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0015</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_vti_bin/_vti_adm/fpadmdll.dll&quot;; fast_pattern:only; content:&quot;name=|22|operation|22|&quot;; nocase; content:&quot;value=|22|--&gt;&quot;; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>7027</id>
        <msg>WEB-IIS frontpage server extensions 2002 cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>17452</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0015</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_vti_bin/_vti_adm/fpadmdll.dll&quot;; fast_pattern:only; content:&quot;name=|22|command|22|&quot;; nocase; content:&quot;value=|22|--&gt;&quot;; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>7028</id>
        <msg>WEB-IIS frontpage server extensions 2002 cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>17452</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0015</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_vti_bin/_vti_adm/fpadmdll.dll&quot;; fast_pattern:only; content:&quot;name=|22|name|22|&quot;; nocase; content:&quot;value=|22|--&gt;&quot;; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>7029</id>
        <msg>WEB-IIS frontpage server extensions 2002 cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>19927</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-0032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;default.idq&quot;; nocase; content:&quot;ciRestriction&quot;; distance:0; nocase; content:&quot;script&quot;; distance:0; nocase; pcre:&quot;/default.idq[^\r\n]*ciRestriction[^\r\n]*script/smi&quot;; metadata:service http; classtype:misc-attack;</filter2>
        <id>8349</id>
        <msg>WEB-IIS Indexing Service ciRestriction cross-site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>20337</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3436</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;__LASTFOCUS=&quot;; fast_pattern:only; pcre:&quot;/__LASTFOCUS=(?!([_a-z]\w*|)([\x26\x3B]|$))/i&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>8700</id>
        <msg>WEB-IIS ASP.NET 2.0 cross-site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS06-056.mspx</url>
      </rule>
      <rule>
        <bugtraq>2674</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0241</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.printer&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>971</id>
        <msg>WEB-IIS ISAPI .printer access</msg>
        <nessus>10661</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS01-023.mspx</url>
      </rule>
      <rule>
        <bugtraq>1448</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0661</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/*.idc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>973</id>
        <msg>WEB-IIS *.idc attempt</msg>
      </rule>
      <rule>
        <bugtraq>2218</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0229</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;..|5C|..&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>974</id>
        <msg>WEB-IIS Directory transversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>149</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0278</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.asp|3A 3A 24|DATA&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>975</id>
        <msg>WEB-IIS Alternate Data streams ASP file access attempt</msg>
        <nessus>10362</nessus>
        <url>support.microsoft.com/default.aspx?scid=kb\;EN-US\;q188806</url>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>977</id>
        <msg>WEB-IIS .cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <bugtraq>1084</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0302</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;%20&quot;; content:&quot;&amp;CiRestriction=none&quot;; nocase; content:&quot;&amp;CiHiliteType=Full&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>978</id>
        <msg>WEB-IIS ASP contents view</msg>
        <nessus>10356</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>1861</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0942</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htw?CiWebHitsFile&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>979</id>
        <msg>WEB-IIS ASP contents view</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS00-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>1623</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/CGImail.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>980</id>
        <msg>WEB-IIS CGImail.exe access</msg>
        <nessus>11721</nessus>
      </rule>
      <rule>
        <bugtraq>307</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0874</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/samples/ctguestb.idc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>984</id>
        <msg>WEB-IIS JET VBA access</msg>
        <nessus>10116</nessus>
      </rule>
      <rule>
        <bugtraq>286</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0874</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/samples/details.idc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>985</id>
        <msg>WEB-IIS JET VBA access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/proxy/w3proxy.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>986</id>
        <msg>WEB-IIS MSProxy access</msg>
        <url>support.microsoft.com/?kbid=331066</url>
      </rule>
      <rule>
        <bugtraq>1488</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0630</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>987</id>
        <msg>WEB-IIS .htr access</msg>
        <nessus>10680</nessus>
      </rule>
      <rule>
        <bugtraq>2110</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0407</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisadmpwd/achg.htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>991</id>
        <msg>WEB-IIS achg.htr access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/msadc/samples/adctest.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>992</id>
        <msg>WEB-IIS adctest.asp access</msg>
      </rule>
      <rule>
        <bugtraq>189</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1538</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisadmin&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>993</id>
        <msg>WEB-IIS iisadmin access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/iisadmin/default.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>994</id>
        <msg>WEB-IIS /scripts/iisadmin/default.htm access</msg>
      </rule>
      <rule>
        <bugtraq>189</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0630</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/iisadmin/ism.dll?http/dir&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>995</id>
        <msg>WEB-IIS ism.dll access</msg>
      </rule>
      <rule>
        <bugtraq>2110</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0407</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iisadmpwd/anot&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>996</id>
        <msg>WEB-IIS anot.htr access</msg>
      </rule>
      <rule>
        <bugtraq>1814</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.asp.&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>997</id>
        <msg>WEB-IIS asp-dot attempt</msg>
        <nessus>10363</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|23|filename=*.asp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>998</id>
        <msg>WEB-IIS asp-srch attempt</msg>
      </rule>
      <rule>
        <bugtraq>2280</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/iisadmin/bdir.htr&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>999</id>
        <msg>WEB-IIS bdir access</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>214</groupid>
    <groupname>Server / HTTP / Other</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>215</groupid>
    <groupname>Server / HTTP / Coldfusion</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>216</groupid>
    <groupname>Server / HTTP / Frontpage</groupname>
    <warnings>
      <rule>
        <bugtraq>2906</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0822</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fp30reg.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1248</id>
        <msg>WEB-FRONTPAGE rad fp30reg.dll access</msg>
        <nessus>10699</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS01-035.mspx</url>
      </rule>
      <rule>
        <bugtraq>2906</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0341</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fp4areg.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1249</id>
        <msg>WEB-FRONTPAGE frontpage rad fp4areg.dll access</msg>
        <nessus>10699</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_bin/&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1288</id>
        <msg>WEB-FRONTPAGE /_vti_bin/ access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>9008</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0824</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;shtml.dll&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; pcre:&quot;/^Host\x3A\s[^\r\n]{300,}/smiH&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>6409</id>
        <msg>WEB-FRONTPAGE frontpage server extension long host string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS03-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>9008</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0824</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;fp30reg.dll&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; isdataat:300,relative; pcre:&quot;/^Host\x3A\s[^\r\n]{300}/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>6410</id>
        <msg>WEB-FRONTPAGE frontpage server extension long host string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS03-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>9008</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0824</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;fp40reg.dll&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; isdataat:300,relative; pcre:&quot;/^Host\x3A\s[^\r\n]{300}/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>6411</id>
        <msg>WEB-FRONTPAGE frontpage server extension long host string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS03-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>2144</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0096</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_rpc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>937</id>
        <msg>WEB-FRONTPAGE _vti_rpc access</msg>
        <nessus>10585</nessus>
      </rule>
      <rule>
        <bugtraq>2144</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0096</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; content:&quot;/author.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>939</id>
        <msg>WEB-FRONTPAGE posting</msg>
        <nessus>10585</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-100.mspx</url>
      </rule>
      <rule>
        <bugtraq>1595</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0746</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_bin/shtml.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>940</id>
        <msg>WEB-FRONTPAGE shtml.dll access</msg>
        <nessus>11395</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms00-060.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admcgi/contents.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>941</id>
        <msg>WEB-FRONTPAGE contents.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/orders.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>942</id>
        <msg>WEB-FRONTPAGE orders.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fpsrvadm.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>943</id>
        <msg>WEB-FRONTPAGE fpsrvadm.exe access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fpremadm.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>944</id>
        <msg>WEB-FRONTPAGE fpremadm.exe access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admisapi/fpadmin.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>945</id>
        <msg>WEB-FRONTPAGE fpadmin.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/Fpadmcgi.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>946</id>
        <msg>WEB-FRONTPAGE fpadmcgi.exe access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/orders.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>947</id>
        <msg>WEB-FRONTPAGE orders.txt access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1052</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/form_results.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>948</id>
        <msg>WEB-FRONTPAGE form_results access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/registrations.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>949</id>
        <msg>WEB-FRONTPAGE registrations.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cfgwiz.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>950</id>
        <msg>WEB-FRONTPAGE cfgwiz.exe access</msg>
      </rule>
      <rule>
        <bugtraq>989</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0386</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/authors.pwd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>951</id>
        <msg>WEB-FRONTPAGE authors.pwd access</msg>
        <nessus>10078</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_bin/_vti_aut/author.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>952</id>
        <msg>WEB-FRONTPAGE author.exe access</msg>
      </rule>
      <rule>
        <bugtraq>1205</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/administrators.pwd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>953</id>
        <msg>WEB-FRONTPAGE administrators.pwd access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1052</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/form_results.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>954</id>
        <msg>WEB-FRONTPAGE form_results.htm access</msg>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/access.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>955</id>
        <msg>WEB-FRONTPAGE access.cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/register.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>956</id>
        <msg>WEB-FRONTPAGE register.txt access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/registrations.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>957</id>
        <msg>WEB-FRONTPAGE registrations.txt access</msg>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/service.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>958</id>
        <msg>WEB-FRONTPAGE service.cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <bugtraq>1205</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/service.pwd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>959</id>
        <msg>WEB-FRONTPAGE service.pwd</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/service.stp&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>960</id>
        <msg>WEB-FRONTPAGE service.stp access</msg>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/services.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>961</id>
        <msg>WEB-FRONTPAGE services.cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <bugtraq>5804</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0692</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_bin/shtml.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>962</id>
        <msg>WEB-FRONTPAGE shtml.exe access</msg>
        <nessus>11311</nessus>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/svcacl.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>963</id>
        <msg>WEB-FRONTPAGE svcacl.cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/users.pwd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>964</id>
        <msg>WEB-FRONTPAGE users.pwd access</msg>
      </rule>
      <rule>
        <bugtraq>4078</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_pvt/writeto.cnf&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>965</id>
        <msg>WEB-FRONTPAGE writeto.cnf access</msg>
        <nessus>10575</nessus>
      </rule>
      <rule>
        <bugtraq>989</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0153</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;..../&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>966</id>
        <msg>WEB-FRONTPAGE .... request</msg>
        <nessus>10142</nessus>
      </rule>
      <rule>
        <bugtraq>1109</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0260</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dvwssr.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>967</id>
        <msg>WEB-FRONTPAGE dvwssr.dll access</msg>
        <nessus>10369</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms00-025.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_private/register.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>968</id>
        <msg>WEB-FRONTPAGE register.htm access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_inf.html&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>990</id>
        <msg>WEB-FRONTPAGE _vti_inf.html access</msg>
        <nessus>11455</nessus>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>22797</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2007-1277</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;wp-includes/feed.php&quot;; nocase; http_uri; content:&quot;ix=&quot;; nocase; http_uri; pcre:&quot;/wp-includes\x2Ffeed\x2Ephp\x3F[^\r\n]*ix=/Ui&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10196</id>
        <msg>BACKDOOR Wordpress backdoor feed.php code execution attempt</msg>
        <url>www.securityfocus.com/archive/1/461794</url>
      </rule>
      <rule>
        <bugtraq>22797</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2007-1277</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;wp-includes/theme.php&quot;; nocase; http_uri; content:&quot;iz=&quot;; nocase; http_uri; pcre:&quot;/wp-includes\x2Ftheme\x2Ephp\x3F[^\r\n]*iz=/Ui&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10197</id>
        <msg>BACKDOOR Wordpress backdoor theme.php code execution attempt</msg>
        <url>www.securityfocus.com/archive/1/461794</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; depth:4; content:&quot;xml version&quot;; distance:0; content:&quot;&lt;methodCall&gt;&lt;methodName&gt;&quot;; distance:0; content:&quot;&lt;/methodName&gt;&lt;params&gt;&lt;param&gt;&lt;name&gt;&quot;; distance:0; content:&quot;'|29 3B|echo|28|'&quot;; distance:0; content:&quot;'|29 3B| passthru|28|chr|28|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13816</id>
        <msg>SPECIFIC-THREATS Metasploit Framework xmlrpc.php command injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; depth:4; content:&quot;xml version&quot;; distance:0; content:&quot;&lt;methodCall&gt;&lt;methodName&gt;&quot;; distance:0; content:&quot;&lt;/methodName&gt;&lt;params&gt;&lt;param&gt;&lt;value&gt;&lt;name&gt;&quot;; distance:0; content:&quot;',''|29 29 3B|echo '_begin_|0A|'|3B|echo&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13817</id>
        <msg>SPECIFIC-THREATS xmlrpc.php command injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; depth:4; content:&quot;xml version&quot;; distance:0; content:&quot;&lt;methodCall&gt;&lt;methodName&gt;&quot;; distance:0; content:&quot;&lt;/methodName&gt;&lt;params&gt;&lt;param&gt;&lt;value&gt;&lt;string&gt;&lt;/string&gt;&lt;/value&gt;&lt;/param&gt;&lt;param&gt;&lt;value&gt;&lt;string&gt;&quot;; distance:0; content:&quot;AND ascii|28|substring|28|pass,1,1|29 29 0A|/**/BETWEEN/**/52/**/AND/**/58|29|/*&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13818</id>
        <msg>SPECIFIC-THREATS alternate xmlrpc.php command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>30667</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3681</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;task=confirmreset&quot;; nocase; http_uri; content:&quot;option=com_user&quot;; http_uri; content:&quot;token=%27&amp;&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>14610</id>
        <msg>WEB-PHP Joomla invalid token administrative password reset attempt</msg>
        <url>developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;common.php&quot;; http_uri; content:&quot;rbtool=&quot;; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15257</id>
        <msg>ORACLE Secure Backup common.php variable based command injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-5449</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php&quot;; http_uri; content:&quot;rbtool=&quot;; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15258</id>
        <msg>ORACLE Secure Backup login.php variable based command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>32123</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-6301</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;shoutbox_view.php&quot;; fast_pattern; nocase; http_uri; content:&quot;mode=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; pcre:&quot;/shoutbox_view.php\x3F[^\r\n]*mode\s*=\s*(delete|edit)[^\r\n]*id\s*=\s*[^\r\n\x26]*[^\d]+/Usmi&quot;; metadata:policy security-ips alert, service http; classtype:web-application-attack;</filter2>
        <id>15424</id>
        <msg>WEB-PHP phpBB mod shoutbox sql injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>32701</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-6314</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;tag_board.php&quot;; fast_pattern; nocase; http_uri; content:&quot;action=delete&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; pcre:&quot;/tag_board.php\x3F[^\r\n]*action=delete[^\r\n]*id=[^\r\n\x26]*(select|insert|delete)/Usmi&quot;;  metadata:policy security-ips alert, service http; classtype:web-application-attack;</filter2>
        <id>15425</id>
        <msg>WEB-PHP phpBB mod tag board sql injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>28845</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-4769</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/wordpress/&quot;; fast_pattern; nocase; http_uri; content:&quot;cat=&quot;; nocase; content:&quot;../&quot;; distance:0; pcre:&quot;/\x2Fwordpress\x2F\x3F[^\r\n]*cat\s*=\s*[^\r\n\x26]*\x2F\x2E\x2E/smi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15432</id>
        <msg>WEB-PHP wordpress cat parameter arbitrary file execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>10724</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0595</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/strip/getPoc.php?note=%3Cs%00cript%3Ealert%28%27Oops!%27%29%3B%3C%2Fs%00cript%3E&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15977</id>
        <msg>SPECIFIC-THREATS PHP strip_tags bypass vulnerability exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>35678</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1978</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;property_box.php?&quot;; http_uri; content:&quot;type=Sections&quot;; http_uri; content:&quot;other=&quot;; http_uri; pcre:&quot;/other=[^\x26]*[\x21-\x24\x27\x28-\x2a\x2d\x2f\x3b\x3c\x3e\x3f\x40\x5b-\x5d\x7b-\x7e]/U&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16190</id>
        <msg>ORACLE Oracle Secure Backup Administration server property_box.php command injection attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2009-4511</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;helppage.php&quot;; fast_pattern; nocase; http_uri; content:&quot;page=&quot;; nocase; http_uri; content:&quot;..&quot;; http_uri; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16678</id>
        <msg>WEB-PHP Tandberg VCS local file disclosure attempt</msg>
        <url>secunia.com/advisories/39275/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/inst.php?fff=&quot;; nocase; http_uri; content:&quot;coid=&quot;; nocase; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16924</id>
        <msg>BLACKLIST URI request for known malicious URI - /inst.php?fff=</msg>
        <url>labs.snort.org/docs/16924.html</url>
      </rule>
      <rule>
        <bugtraq>19819</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/jhot.php&quot;; nocase; http_uri; content:&quot;Content-Disposition|3A|&quot;; nocase; content:&quot;filename=&quot;; nocase; pcre:&quot;/^Content-Disposition\x3A[^\r\n]*filename=(?P&lt;q1&gt;\x22|\x27|)[^\r\n]*?\x2Ephp(?P=q1)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17597</id>
        <msg>WEB-PHP TikiWiki jhot.php script file upload attempt</msg>
        <url>tikiwiki.org/tiki-read_article.php?articleid=136</url>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-4006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;login.php&quot;; http_uri; content:&quot;button|3D|Logout&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17638</id>
        <msg>Oracle Secure Backup Administration Server login.php Cookies Command Injection attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/online.php?&quot;; nocase; http_uri; content:&quot;Host|3A| actualnames.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5744</id>
        <msg>SPYWARE-PUT Hijacker actualnames runtime detection - online.php request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074941</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cache/ip.php&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Warez Beta Client&quot;; fast_pattern:only; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5848</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - ip.php request</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/crakzpackz/sys/add.php?&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;vicname=&quot;; nocase; http_uri; content:&quot;server=DSK&quot;; nocase; http_uri; content:&quot;password=&quot;; nocase; http_uri; content:&quot;usrname=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6020</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - php notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;body=FeaR&quot;; nocase; http_uri; pcre:&quot;/body=FeaR\x25200\x2E2\x2E0\x2520Online\x3A\x2520\x5BIP_\d+\x2E\d+\x2E\d+\x2E\d+\x5D\x2520\x5BPort_/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6042</id>
        <msg>BACKDOOR fear 0.2 runtime detection - php notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <bugtraq>17292</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2006-1491</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/services/help/&quot;; http_uri; pcre:&quot;/[\?\x20\x3b\x26]module=[a-zA-Z0-9]*[\x3b\x26]/Ui&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>6403</id>
        <msg>WEB-PHP horde help module arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?action=post&quot;; fast_pattern; nocase; http_uri; content:&quot;log=&quot;; http_uri; pcre:&quot;/log\=\x7BIP\x3A[^\x7B\r\n]*\x7D\x7BOS\x3A[^\x7B\r\n]*\x7D\x7BSysuptime\x3A[^\x7B\r\n]*\x7D\x7BTrojan\x3A[^\x7B\r\n]*\x7D\x7BPort\x3A[^\x7B\r\n]*\x7D\x7BPassword\x3A[^\x7B\r\n]*\x7D\x7BUser\x3A/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7149</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - php notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/roach/notify/getip.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.kornputers.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7639</id>
        <msg>BACKDOOR air runtime detection - php notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076794</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Notificacion.php&quot;; nocase; http_uri; content:&quot;puerto=&quot;; nocase; http_uri; content:&quot;version=1.0&quot;; nocase; http_uri; content:&quot;nombre=&quot;; nocase; http_uri; content:&quot;pc=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9653</id>
        <msg>BACKDOOR apofis 1.0 runtime detection - php notification</msg>
        <url>www.megasecurity.org/trojans/a/apofis/Apofis1.0.html</url>
      </rule>
    </attacks>
    <groupid>217</groupid>
    <groupname>Server / HTTP / PHP</groupname>
    <warnings>
      <rule>
        <bugtraq>802</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|BA|I|FE FF FF F7 D2 B9 BF FF FF FF F7 D1|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1085</id>
        <msg>WEB-PHP strings overflow</msg>
      </rule>
      <rule>
        <bugtraq>1786</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0967</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?STRENGUR&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1086</id>
        <msg>WEB-PHP strings overflow</msg>
      </rule>
      <rule>
        <bugtraq>2271</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.php3&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1134</id>
        <msg>WEB-PHP Phorum admin access</msg>
      </rule>
      <rule>
        <bugtraq>2274</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;PHP_AUTH_USER=boogieman&quot;; fast_pattern:only; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1137</id>
        <msg>WEB-PHP Phorum authentication access</msg>
      </rule>
      <rule>
        <bugtraq>1149</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0322</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/passwd.php3&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1161</id>
        <msg>WEB-PHP piranha passwd.php3 access</msg>
      </rule>
      <rule>
        <bugtraq>14667</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2733</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; content:&quot;sphpblog&quot;; http_uri; content:&quot;password.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>11664</id>
        <msg>WEB-PHP sphpblog password.txt access attempt</msg>
      </rule>
      <rule>
        <bugtraq>14667</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2733</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; content:&quot;sphpblog&quot;; http_uri; content:&quot;install03_cgi.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>11665</id>
        <msg>WEB-PHP sphpblog install03_cgi access attempt</msg>
      </rule>
      <rule>
        <bugtraq>14667</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2733</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; content:&quot;sphpblog&quot;; http_uri; content:&quot;upload_img_cgi.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>11666</id>
        <msg>WEB-PHP sphpblog upload_img_cgi access attempt</msg>
      </rule>
      <rule>
        <bugtraq>14667</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2733</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; content:&quot;sphpblog&quot;; http_uri; content:&quot;comment_delete_cgi.php&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/comment=[^\x26\s]*[\x2f\x5c]/sUmi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11667</id>
        <msg>WEB-PHP sphpblog arbitrary file delete attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-0511</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 80</filter1>
        <filter2>flow:to_server,established; content:&quot;misc.php&quot;; http_uri; pcre:&quot;/template\s*=\s*\x7b\x24/sUmi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11668</id>
        <msg>WEB-PHP vbulletin php code injection</msg>
        <url>marc.info/?l=bugtraq&amp;m=110910899415763&amp;w=2</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/read.php3&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1178</id>
        <msg>WEB-PHP Phorum read access</msg>
      </rule>
      <rule>
        <bugtraq>2272</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/violation.php3&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1179</id>
        <msg>WEB-PHP Phorum violation access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/code.php3&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1197</id>
        <msg>WEB-PHP Phorum code access</msg>
      </rule>
      <rule>
        <bugtraq>15250</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-3390</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A| multipart/form-data&quot;; http_header; content:&quot;name=&quot;; nocase; content:&quot;GLOBALS&quot;; within:7; distance:1; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12221</id>
        <msg>WEB-PHP file upload GLOBAL variable overwrite attempt</msg>
      </rule>
      <rule>
        <bugtraq>3079</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-1370</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_PHPLIB[libdir]&quot;; fast_pattern:only; metadata:service http; classtype:attempted-user;</filter2>
        <id>1254</id>
        <msg>WEB-PHP PHPLIB remote command attempt</msg>
        <nessus>14910</nessus>
      </rule>
      <rule>
        <bugtraq>3079</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-1370</cve>
        <filter1>tcp $HTTP_SERVERS any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db_mysql.inc&quot;; http_uri; metadata:service http; classtype:attempted-user;</filter2>
        <id>1255</id>
        <msg>WEB-PHP PHPLIB remote command attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2004-1315</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;viewtopic.php&quot;; http_uri; content:&quot;highlight=&quot;; http_uri; content:&quot;%25&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12610</id>
        <msg>WEB-PHP phpBB viewtopic double URL encoding attempt</msg>
      </rule>
      <rule>
        <bugtraq>3361</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-1032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.php&quot;; fast_pattern; nocase; http_uri; content:&quot;file_name=&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>1300</id>
        <msg>WEB-PHP admin.php file upload attempt</msg>
      </rule>
      <rule>
        <bugtraq>9270</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1301</id>
        <msg>WEB-PHP admin.php access</msg>
      </rule>
      <rule>
        <bugtraq>3889</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php&quot;; fast_pattern; nocase; http_uri; content:&quot;file=&quot;; pcre:&quot;/file=(https?|ftps?|php)/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1399</id>
        <msg>WEB-PHP PHP-Nuke remote file include attempt</msg>
      </rule>
      <rule>
        <bugtraq>3982</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0220</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/smssend.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1407</id>
        <msg>WEB-PHP smssend.php access</msg>
      </rule>
      <rule>
        <bugtraq>4183</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Disposition|3A|&quot;; nocase; http_header; content:&quot;name=|22 CC CC CC CC CC|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1423</id>
        <msg>WEB-PHP content-disposition memchr overflow</msg>
        <nessus>10867</nessus>
      </rule>
      <rule>
        <bugtraq>1997</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/support/common.php&quot;; http_uri; content:&quot;ForumLang=../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1490</id>
        <msg>WEB-PHP Phorum /support/common.php attempt</msg>
      </rule>
      <rule>
        <bugtraq>9361</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/support/common.php&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1491</id>
        <msg>WEB-PHP Phorum /support/common.php access</msg>
      </rule>
      <rule>
        <bugtraq>10725</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0594</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;---------------------------153501500631101&quot;; http_header; metadata:service http; classtype:attempted-user;</filter2>
        <id>16078</id>
        <msg>SPECIFIC-THREATS PHP memory_limit vulnerability exploit attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/32647543ygwvrhbjt3h4evjrbgnrt.php&quot;; http_uri; content:&quot;Host|3A| all1count.net&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16243</id>
        <msg>BACKDOOR downloader-ash.gen.b runtime detection - 3264.php</msg>
        <url>www.threatexpert.com/report.aspx?md5=bffe465b5949e78821ffb76b0ed25bb4</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=cmd&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16613</id>
        <msg>BACKDOOR c99shell.php command request - cmd</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=search&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16614</id>
        <msg>BACKDOOR c99shell.php command request - search</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=upload&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16615</id>
        <msg>BACKDOOR c99shell.php command request - upload</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=about&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16616</id>
        <msg>BACKDOOR c99shell.php command request - about</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=encoder&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16617</id>
        <msg>BACKDOOR c99shell.php command request - encoder</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=bind&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16618</id>
        <msg>BACKDOOR c99shell.php command request - bind</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=ps_aux&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16619</id>
        <msg>BACKDOOR c99shell.php command request - ps_aux</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=ftpquickbrute&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16620</id>
        <msg>BACKDOOR c99shell.php command request - ftpquickbrute</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=security&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16621</id>
        <msg>BACKDOOR c99shell.php command request - security</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=sql&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16622</id>
        <msg>BACKDOOR c99shell.php command request - sql</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=eval&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16623</id>
        <msg>BACKDOOR c99shell.php command request - eval</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=feedback&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16624</id>
        <msg>BACKDOOR c99shell.php command request - feedback</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=selfremove&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16625</id>
        <msg>BACKDOOR c99shell.php command request - selfremove</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=fsbuff&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16626</id>
        <msg>BACKDOOR c99shell.php command request - fsbuff</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=ls&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16627</id>
        <msg>BACKDOOR c99shell.php command request - ls</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;act=phpinfo&quot;; http_uri; classtype:policy-violation;</filter2>
        <id>16628</id>
        <msg>BACKDOOR c99shell.php command request - phpinfo</msg>
        <url>vil.nai.com/vil/content/v_136948.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;count_log/log/boot.php?p=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16913</id>
        <msg>BLACKLIST URI request for known malicious URI - count_log/log/boot.php?p=</msg>
        <url>labs.snort.org/docs/16913.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?username=coolweb07&amp;keywords=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16923</id>
        <msg>BLACKLIST URI request for known malicious URI - /search.php?username=coolweb07&amp;keywords=</msg>
        <url>labs.snort.org/docs/16923.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/message.php?subid=&quot;; nocase; http_uri; content:&quot;version=_nn2&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16925</id>
        <msg>BLACKLIST URI request for known malicious URI - /message.php?subid=</msg>
        <url>labs.snort.org/docs/16925.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;MGWEB.php?c=TestUrl&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16927</id>
        <msg>BLACKLIST URI request for known malicious URI - MGWEB.php?c=TestUrl</msg>
        <url>labs.snort.org/docs/16927.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;gate.php?guid=&quot;; nocase; http_uri; content:&quot;stat=ONLINE&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16929</id>
        <msg>BLACKLIST URI request for known malicious URI - gate.php?guid=</msg>
        <url>labs.snort.org/docs/16929.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;feedbigfoot.php?m=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16931</id>
        <msg>BLACKLIST URI request for known malicious URI - feedbigfoot.php?m=</msg>
        <url>labs.snort.org/docs/16931.html</url>
      </rule>
      <rule>
        <bugtraq>3952</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/squirrelspell/modules/check_me.mod.php&quot;; fast_pattern; nocase; http_uri; content:&quot;SQSPELL_APP[&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1736</id>
        <msg>WEB-PHP squirrel mail spell-check arbitrary command attempt</msg>
      </rule>
      <rule>
        <bugtraq>4385</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0516</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/left_main.php&quot;; nocase; http_uri; content:&quot;cmdd=&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1737</id>
        <msg>WEB-PHP squirrel mail theme arbitrary command attempt</msg>
      </rule>
      <rule>
        <bugtraq>4617</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0613</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dnstools.php&quot;; nocase; http_uri; content:&quot;user_logged_in=true&quot;; nocase; content:&quot;user_dnstools_administrator=true&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1739</id>
        <msg>WEB-PHP DNSTools administrator authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>4617</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0613</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dnstools.php&quot;; fast_pattern; nocase; http_uri; content:&quot;user_logged_in=true&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1740</id>
        <msg>WEB-PHP DNSTools authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>4617</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0613</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dnstools.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1741</id>
        <msg>WEB-PHP DNSTools access</msg>
      </rule>
      <rule>
        <bugtraq>4618</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0599</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dostuff.php?action=modify_user&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1742</id>
        <msg>WEB-PHP Blahz-DNS dostuff.php modify user attempt</msg>
      </rule>
      <rule>
        <bugtraq>4618</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0599</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dostuff.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1743</id>
        <msg>WEB-PHP Blahz-DNS dostuff.php access</msg>
      </rule>
      <rule>
        <bugtraq>4635</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/supp_membre.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1745</id>
        <msg>WEB-PHP Messagerie supp_membre.php access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/php.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1773</id>
        <msg>WEB-PHP php.exe access</msg>
        <url>www.securitytracker.com/alerts/2002/Jan/1003104.html</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb_smilies.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1774</id>
        <msg>WEB-PHP bb_smilies.php access</msg>
        <url>www.securiteam.com/securitynews/Serious_security_hole_in_PHP-Nuke__bb_smilies_.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get2.php?c=VTOXUGUI&amp;d=26606B6739343F216560&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17898</id>
        <msg>BLACKLIST URI request for known malicious URI - /get2.php?c=VTOXUGUI&amp;d=26606B6739343F216560</msg>
        <url>labs.snort.org/docs/17898.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;1de49069b6044785e9dfcd4c035cfd0c.php&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17905</id>
        <msg>BLACKLIST URI request for known malicious URI - 1de49069b6044785e9dfcd4c035cfd0c.php</msg>
        <url>labs.snort.org/docs/17905.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;2x/&quot;; nocase; http_uri; pcre:&quot;/2x/.*php/Ui&quot;; content:&quot;p=ck&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17906</id>
        <msg>BLACKLIST URI request for known malicious URI - 2x/.*php</msg>
        <url>labs.snort.org/docs/17906.html</url>
      </rule>
      <rule>
        <bugtraq>4278</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0434</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/directory.php&quot;; http_uri; content:&quot;dir=&quot;; content:&quot;|3B|&quot;; metadata:service http; classtype:misc-attack;</filter2>
        <id>1815</id>
        <msg>WEB-PHP directory.php arbitrary command attempt</msg>
        <nessus>11017</nessus>
      </rule>
      <rule>
        <bugtraq>4278</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0434</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/directory.php&quot;; http_uri; metadata:service http; classtype:misc-attack;</filter2>
        <id>1816</id>
        <msg>WEB-PHP directory.php access</msg>
      </rule>
      <rule>
        <bugtraq>5254</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/modules.php?&quot;; http_uri; content:&quot;name=Wiki&quot;; fast_pattern; nocase; http_uri; content:&quot;&lt;script&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1834</id>
        <msg>WEB-PHP PHP-Wiki cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>6173</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/quick-reply.php&quot;; http_uri; content:&quot;phpbb_root_path=&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1967</id>
        <msg>WEB-PHP phpbb quick-reply.php arbitrary command attempt</msg>
      </rule>
      <rule>
        <bugtraq>6173</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/quick-reply.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1968</id>
        <msg>WEB-PHP phpbb quick-reply.php access</msg>
      </rule>
      <rule>
        <bugtraq>3288</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1020</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/edit_image.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1999</id>
        <msg>WEB-PHP edit_image.php access</msg>
        <nessus>11104</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2001-1408</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/readmsg.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2000</id>
        <msg>WEB-PHP readmsg.php access</msg>
        <nessus>11073</nessus>
      </rule>
      <rule>
        <bugtraq>6572</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-1204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/uploadimage.php&quot;; http_uri; content:&quot;userfile_name=&quot;; content:&quot;.php&quot;; distance:1; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2074</id>
        <msg>WEB-PHP Mambo uploadimage.php upload php file attempt</msg>
        <nessus>16315</nessus>
      </rule>
      <rule>
        <bugtraq>6572</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-1204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upload.php&quot;; http_uri; content:&quot;userfile_name=&quot;; content:&quot;.php&quot;; distance:1; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2075</id>
        <msg>WEB-PHP Mambo upload.php upload php file attempt</msg>
        <nessus>16315</nessus>
      </rule>
      <rule>
        <bugtraq>6572</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-1204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/uploadimage.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2076</id>
        <msg>WEB-PHP Mambo uploadimage.php access</msg>
        <nessus>16315</nessus>
      </rule>
      <rule>
        <bugtraq>6634</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/privmsg.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2078</id>
        <msg>WEB-PHP phpBB privmsg.php access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/p-news.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2140</id>
        <msg>WEB-PHP p-news.php access</msg>
        <nessus>11669</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shoutbox.php&quot;; http_uri; content:&quot;conf=&quot;; content:&quot;../&quot;; distance:0; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2141</id>
        <msg>WEB-PHP shoutbox.php directory traversal attempt</msg>
        <nessus>11668</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shoutbox.php&quot;; fast_pattern; nocase; http_uri; content:&quot;conf=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2142</id>
        <msg>WEB-PHP shoutbox.php access</msg>
        <nessus>11668</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gm-2-b2.php&quot;; fast_pattern; nocase; http_uri; content:&quot;b2inc=&quot;; pcre:&quot;/b2inc=(https?|ftps?|php)/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2143</id>
        <msg>WEB-PHP b2 cafelog gm-2-b2.php remote file include attempt</msg>
        <nessus>11667</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gm-2-b2.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2144</id>
        <msg>WEB-PHP b2 cafelog gm-2-b2.php access</msg>
        <nessus>11667</nessus>
      </rule>
      <rule>
        <bugtraq>7673</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.php&quot;; http_uri; content:&quot;op=admin_enter&quot;; content:&quot;password=admin&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2145</id>
        <msg>WEB-PHP TextPortal admin.php default password admin attempt</msg>
        <nessus>11660</nessus>
      </rule>
      <rule>
        <bugtraq>7673</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.php&quot;; http_uri; content:&quot;op=admin_enter&quot;; content:&quot;password=12345&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2146</id>
        <msg>WEB-PHP TextPortal admin.php default password 12345 attempt</msg>
        <nessus>11660</nessus>
      </rule>
      <rule>
        <bugtraq>7677</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-0394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/objects.inc.php4&quot;; http_uri; content:&quot;Server[path]=&quot;; pcre:&quot;/Server\x5bpath\x5d=(https?|ftps?|php)/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2147</id>
        <msg>WEB-PHP BLNews objects.inc.php4 remote file include attempt</msg>
        <nessus>11647</nessus>
      </rule>
      <rule>
        <bugtraq>7677</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0394</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/objects.inc.php4&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2148</id>
        <msg>WEB-PHP BLNews objects.inc.php4 access</msg>
        <nessus>11647</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/turba/status.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2149</id>
        <msg>WEB-PHP Turba status.php access</msg>
        <nessus>11646</nessus>
      </rule>
      <rule>
        <bugtraq>7625</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin/templates/header.php&quot;; fast_pattern; nocase; http_uri; content:&quot;admin_root=&quot;; pcre:&quot;/admin_root=(https?|ftps?|php)/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2150</id>
        <msg>WEB-PHP ttCMS header.php remote file include attempt</msg>
        <nessus>11636</nessus>
      </rule>
      <rule>
        <bugtraq>7625</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin/templates/header.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2151</id>
        <msg>WEB-PHP ttCMS header.php access</msg>
        <nessus>11636</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2152</id>
        <msg>WEB-PHP test.php access</msg>
        <nessus>11617</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/autohtml.php&quot;; fast_pattern; nocase; http_uri; content:&quot;name=&quot;; content:&quot;../../&quot;; distance:0; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2153</id>
        <msg>WEB-PHP autohtml.php directory traversal attempt</msg>
        <nessus>11630</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/autohtml.php&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2154</id>
        <msg>WEB-PHP autohtml.php access</msg>
        <nessus>11630</nessus>
      </rule>
      <rule>
        <bugtraq>7543</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;forum/index.php&quot;; http_uri; content:&quot;template=&quot;; pcre:&quot;/template=(https?|ftps?|php)/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2155</id>
        <msg>WEB-PHP ttforum remote file include attempt</msg>
        <nessus>11615</nessus>
      </rule>
      <rule>
        <bugtraq>7919</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;lib.inc.php&quot;; fast_pattern; nocase; http_uri; content:&quot;pm_path=&quot;; pcre:&quot;/pm_path=(https?|ftps?|php)/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2226</id>
        <msg>WEB-PHP pmachine remote file include attempt</msg>
        <nessus>11739</nessus>
      </rule>
      <rule>
        <bugtraq>7933</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;forum_details.php&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2227</id>
        <msg>WEB-PHP forum_details.php access</msg>
        <nessus>11760</nessus>
      </rule>
      <rule>
        <bugtraq>7965</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;db_details_importdocsql.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2228</id>
        <msg>WEB-PHP phpMyAdmin db_details_importdocsql.php access</msg>
        <nessus>11761</nessus>
      </rule>
      <rule>
        <bugtraq>7979</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-0486</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/viewtopic.php&quot;; fast_pattern; nocase; http_uri; content:&quot;days=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2229</id>
        <msg>WEB-PHP viewtopic.php access</msg>
        <nessus>11767</nessus>
      </rule>
      <rule>
        <bugtraq>9057</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/UpdateClasses.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2279</id>
        <msg>WEB-PHP UpdateClasses.php access</msg>
      </rule>
      <rule>
        <bugtraq>9057</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GlobalFunctions.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2282</id>
        <msg>WEB-PHP GlobalFunctions.php access</msg>
      </rule>
      <rule>
        <bugtraq>9057</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/DatabaseFunctions.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2283</id>
        <msg>WEB-PHP DatabaseFunctions.php access</msg>
      </rule>
      <rule>
        <bugtraq>9057</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/insert.inc.php&quot;; fast_pattern; nocase; http_uri; content:&quot;path=&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2284</id>
        <msg>WEB-PHP rolis guestbook remote file include attempt</msg>
      </rule>
      <rule>
        <bugtraq>9057</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/insert.inc.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2285</id>
        <msg>WEB-PHP rolis guestbook access</msg>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_comment.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2287</id>
        <msg>WEB-PHP Advanced Poll admin_comment.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_edit.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2288</id>
        <msg>WEB-PHP Advanced Poll admin_edit.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_embed.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2289</id>
        <msg>WEB-PHP Advanced Poll admin_embed.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_help.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2290</id>
        <msg>WEB-PHP Advanced Poll admin_help.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_license.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2291</id>
        <msg>WEB-PHP Advanced Poll admin_license.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_logout.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2292</id>
        <msg>WEB-PHP Advanced Poll admin_logout.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_password.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2293</id>
        <msg>WEB-PHP Advanced Poll admin_password.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_preview.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2294</id>
        <msg>WEB-PHP Advanced Poll admin_preview.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_settings.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2295</id>
        <msg>WEB-PHP Advanced Poll admin_settings.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_stats.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2296</id>
        <msg>WEB-PHP Advanced Poll admin_stats.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_templates_misc.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2297</id>
        <msg>WEB-PHP Advanced Poll admin_templates_misc.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_templates.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2298</id>
        <msg>WEB-PHP Advanced Poll admin_templates.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_tpl_misc_new.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2299</id>
        <msg>WEB-PHP Advanced Poll admin_tpl_misc_new.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_tpl_new.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2300</id>
        <msg>WEB-PHP Advanced Poll admin_tpl_new.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/booth.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2301</id>
        <msg>WEB-PHP Advanced Poll booth.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/poll_ssi.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2302</id>
        <msg>WEB-PHP Advanced Poll poll_ssi.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8890</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/popup.php&quot;; fast_pattern; nocase; http_uri; content:&quot;include_path=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2303</id>
        <msg>WEB-PHP Advanced Poll popup.php access</msg>
        <nessus>11487</nessus>
      </rule>
      <rule>
        <bugtraq>8910</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files.inc.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2304</id>
        <msg>WEB-PHP files.inc.php access</msg>
      </rule>
      <rule>
        <bugtraq>8930</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/chatbox.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2305</id>
        <msg>WEB-PHP chatbox.php access</msg>
      </rule>
      <rule>
        <bugtraq>8814</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setup/&quot;; http_uri; content:&quot;GALLERY_BASEDIR=&quot;; http_uri; pcre:&quot;/GALLERY_BASEDIR=(https?|ftps?|php)/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2306</id>
        <msg>WEB-PHP gallery remote file include attempt</msg>
        <nessus>11876</nessus>
      </rule>
      <rule>
        <bugtraq>8791</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;do=ext&quot;; http_uri; content:&quot;page=&quot;; http_uri; pcre:&quot;/page=(https?|ftps?|php)/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2307</id>
        <msg>WEB-PHP PayPal Storefront remote file include attempt</msg>
        <nessus>11873</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2004-0032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/authentication_index.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2328</id>
        <msg>WEB-PHP authentication_index.php access</msg>
        <nessus>11982</nessus>
      </rule>
      <rule>
        <bugtraq>8430</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;new_rights=admin&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2331</id>
        <msg>WEB-PHP MatrikzGB privilege escalation attempt</msg>
      </rule>
      <rule>
        <bugtraq>6525</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/library/editor/editor.php&quot;; fast_pattern; nocase; http_uri; content:&quot;root=&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2341</id>
        <msg>WEB-PHP DCP-Portal remote file include editor script attempt</msg>
      </rule>
      <rule>
        <bugtraq>6525</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/library/lib.php&quot;; fast_pattern; nocase; http_uri; content:&quot;root=&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2342</id>
        <msg>WEB-PHP DCP-Portal remote file include lib script attempt</msg>
      </rule>
      <rule>
        <bugtraq>9369</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-0032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php&quot;; nocase; http_uri; content:&quot;action=soundex&quot;; fast_pattern; nocase; http_uri; content:&quot;firstname=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2345</id>
        <msg>WEB-PHP PhpGedView search.php access</msg>
      </rule>
      <rule>
        <bugtraq>6544</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/chatheader.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2346</id>
        <msg>WEB-PHP myPHPNuke chatheader.php access</msg>
      </rule>
      <rule>
        <bugtraq>7488</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php&quot;; nocase; http_uri; content:&quot;ideaDir=&quot;; fast_pattern:only; content:&quot;cord.php&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2353</id>
        <msg>WEB-PHP IdeaBox cord.php file include</msg>
      </rule>
      <rule>
        <bugtraq>7488</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php&quot;; nocase; http_uri; content:&quot;gorumDir=&quot;; fast_pattern:only; content:&quot;notification.php&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2354</id>
        <msg>WEB-PHP IdeaBox notification.php file include</msg>
      </rule>
      <rule>
        <bugtraq>7204</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad_member.php&quot;; fast_pattern; nocase; http_uri; content:&quot;emailer.php&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2355</id>
        <msg>WEB-PHP Invision Board emailer.php file include</msg>
      </rule>
      <rule>
        <bugtraq>7000</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/defines.php&quot;; nocase; http_uri; content:&quot;WEBCHATPATH=&quot;; nocase; content:&quot;db_mysql.php&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2356</id>
        <msg>WEB-PHP WebChat db_mysql.php file include</msg>
      </rule>
      <rule>
        <bugtraq>7000</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/defines.php&quot;; nocase; http_uri; content:&quot;WEBCHATPATH=&quot;; nocase; content:&quot;english.php&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2357</id>
        <msg>WEB-PHP WebChat english.php file include</msg>
      </rule>
      <rule>
        <bugtraq>6984</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/translations.php&quot;; fast_pattern; nocase; http_uri; content:&quot;ONLY=&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2358</id>
        <msg>WEB-PHP Typo3 translations.php file include</msg>
      </rule>
      <rule>
        <bugtraq>6976</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ipchat.php&quot;; nocase; http_uri; content:&quot;root_path=&quot;; content:&quot;conf_global.php&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2359</id>
        <msg>WEB-PHP Invision Board ipchat.php file include</msg>
      </rule>
      <rule>
        <bugtraq>6744</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/doc/admin&quot;; nocase; http_uri; content:&quot;ptinclude=&quot;; nocase; content:&quot;pt_config.inc&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2360</id>
        <msg>WEB-PHP myphpPagetool pt_config.inc file include</msg>
      </rule>
      <rule>
        <bugtraq>6674</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/news.php&quot;; fast_pattern; nocase; http_uri; content:&quot;template=&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2361</id>
        <msg>WEB-PHP news.php file include</msg>
      </rule>
      <rule>
        <bugtraq>6663</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/packages.php&quot;; fast_pattern; nocase; http_uri; content:&quot;packer.php&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2362</id>
        <msg>WEB-PHP YaBB SE packages.php file include</msg>
      </rule>
      <rule>
        <bugtraq>6597</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/default_header.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2363</id>
        <msg>WEB-PHP Cyboards default_header.php access</msg>
      </rule>
      <rule>
        <bugtraq>6597</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/options_form.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2364</id>
        <msg>WEB-PHP Cyboards options_form.php access</msg>
      </rule>
      <rule>
        <bugtraq>8488</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nphpd.php&quot;; fast_pattern; nocase; http_uri; content:&quot;LangFile&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2365</id>
        <msg>WEB-PHP newsPHP Language file include attempt</msg>
      </rule>
      <rule>
        <bugtraq>9368</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0030</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/authentication_index.php&quot;; nocase; http_uri; content:&quot;PGV_BASE_DIRECTORY&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2366</id>
        <msg>WEB-PHP PhpGedView PGV authentication_index.php base directory manipulation attempt</msg>
      </rule>
      <rule>
        <bugtraq>9368</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0030</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/functions.php&quot;; nocase; http_uri; content:&quot;PGV_BASE_DIRECTORY&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2367</id>
        <msg>WEB-PHP PhpGedView PGV functions.php base directory manipulation attempt</msg>
      </rule>
      <rule>
        <bugtraq>9368</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0030</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config_gedcom.php&quot;; nocase; http_uri; content:&quot;PGV_BASE_DIRECTORY&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2368</id>
        <msg>WEB-PHP PhpGedView PGV config_gedcom.php base directory manipulation attempt</msg>
      </rule>
      <rule>
        <bugtraq>9557</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/showphoto.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2372</id>
        <msg>WEB-PHP Photopost PHP Pro showphoto.php access</msg>
      </rule>
      <rule>
        <bugtraq>9537</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_admin/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2393</id>
        <msg>WEB-PHP /_admin access</msg>
        <nessus>12032</nessus>
      </rule>
      <rule>
        <bugtraq>6965</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;newsletter.php&quot;; nocase; http_uri; content:&quot;waroot&quot;; fast_pattern:only; content:&quot;start.php&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2398</id>
        <msg>WEB-PHP WAnewsletter newsletter.php file include attempt</msg>
      </rule>
      <rule>
        <bugtraq>6964</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sql/db_type.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2399</id>
        <msg>WEB-PHP WAnewsletter db_type.php access</msg>
      </rule>
      <rule>
        <bugtraq>9737</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/phptest.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2405</id>
        <msg>WEB-PHP phptest.php access</msg>
      </rule>
      <rule>
        <bugtraq>9773</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/page.php&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2410</id>
        <msg>WEB-PHP IGeneric Free Shopping Cart page.php access</msg>
      </rule>
      <rule>
        <bugtraq>9866</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/viewforum.php&quot;; nocase; http_uri; content:&quot;topic_id=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2566</id>
        <msg>WEB-PHP PHPBB viewforum.php access</msg>
        <nessus>12093</nessus>
      </rule>
      <rule>
        <bugtraq>9732</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/header.php&quot;; nocase; http_uri; content:&quot;systempath=&quot;; fast_pattern:only; pcre:&quot;/systempath=(https?|ftps?|php)/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2575</id>
        <msg>WEB-PHP Opt-X header.php remote file include attempt</msg>
      </rule>
      <rule>
        <bugtraq>10129</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/note_overview.php&quot;; http_uri; content:&quot;id=&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2588</id>
        <msg>WEB-PHP TUTOS path disclosure attempt</msg>
        <url>www.securiteam.com/unixfocus/5FP0J15CKE.html</url>
      </rule>
      <rule>
        <bugtraq>7193</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/modules.php&quot;; nocase; http_uri; content:&quot;name=Forums&quot;; content:&quot;file=viewtopic&quot;; fast_pattern:only; pcre:&quot;/forum=.*'/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2654</id>
        <msg>WEB-PHP PHPNuke Forum viewtopic SQL insertion attempt</msg>
      </rule>
      <rule>
        <bugtraq>9368</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_conf.php&quot;; nocase; http_uri; content:&quot;PGV_BASE_DIRECTORY&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2926</id>
        <msg>WEB-PHP PhpGedView PGV base directory manipulation</msg>
      </rule>
      <rule>
        <bugtraq>12592</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-0481</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8090</filter1>
        <filter2>flow:to_server,established; content:&quot;/ComGetLogFile.php3&quot;; nocase; pcre:&quot;/fn=\x2e\x2e(\x2f|\x5c)/Rmsi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3544</id>
        <msg>WEB-MISC TrackerCam ComGetLogFile.php3 directory traversal attempt</msg>
        <nessus>17160</nessus>
      </rule>
      <rule>
        <bugtraq>12592</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2005-0481</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8090</filter1>
        <filter2>flow:to_server,established; content:&quot;/ComGetLogFile.php3&quot;; nocase; pcre:&quot;/fn=Eye\d{4}_\d{2}.log/Rmsi&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3545</id>
        <msg>WEB-MISC TrackerCam ComGetLogFile.php3 log information disclosure</msg>
        <nessus>17160</nessus>
      </rule>
      <rule>
        <bugtraq>12592</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-0481</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8090</filter1>
        <filter2>flow:to_server,established; content:&quot;php&quot;; nocase; pcre:&quot;/php.*\x3f[^\n]{256}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3547</id>
        <msg>WEB-MISC TrackerCam overly long php parameter overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10798</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-2056</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;action.php&quot;; fast_pattern; nocase; http_uri; content:&quot;itemid=&quot;; nocase; pcre:&quot;/itemid=\d*[^\d\&amp;\;\r\n]/i&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3690</id>
        <msg>WEB-CGI Nucleus CMS action.php itemid SQL injection</msg>
        <nessus>14194</nessus>
      </rule>
      <rule>
        <bugtraq>14088</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-1921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xmlrpc.php&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/^POST\s/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3827</id>
        <msg>WEB-PHP xmlrpc.php post attempt</msg>
      </rule>
      <rule>
        <bugtraq>14042</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cacti/graph_image.php&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>4650</id>
        <msg>WEB-MISC cacti graph_image.php access</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; content:&quot;upload.php&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/^Content-Type\x3A\s+multipart\/form-data/smiH&quot;; content:&quot;Content-Disposition|3A|&quot;; nocase; http_header; pcre:&quot;/filename=\S*\x2e\x2e\x2f/smiH&quot;; content:&quot;|0A|&quot;; distance:0; metadata:service http; classtype:misc-attack;</filter2>
        <id>5709</id>
        <msg>WEB-PHP file upload directory traversal</msg>
        <url>bugs.php.net/bug.php?id=28456</url>
      </rule>
      <rule>
        <bugtraq>712</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0238</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/php.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>824</id>
        <msg>WEB-CGI php.cgi access</msg>
        <nessus>10178</nessus>
      </rule>
      <rule>
        <bugtraq>14533</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2612</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;wp_filter&quot;; pcre:&quot;/cache_lastpostdate\[[^\]]+\]=[^\x00\x3B\x3D]{30}/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>8708</id>
        <msg>WEB-PHP Wordpress cache_lastpostdate code injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>14129</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-1524</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;graph_image.php&quot;; nocase; http_uri; pcre:&quot;/graph_(start|end|height|width)=(?!(\d+|)[\x26\s])/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8712</id>
        <msg>WEB-PHP cacti graph_image arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14129</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;graph_image.php&quot;; nocase; http_uri; pcre:&quot;/rra_id=(?!(\d+|all|)([\x26\s]|$))/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8713</id>
        <msg>WEB-PHP cacti graph_image SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>14129</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;graph_image.php&quot;; nocase; http_uri; pcre:&quot;/local_graph_id=(?!(\d+|)([\x26\s]|$))/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8714</id>
        <msg>WEB-PHP cacti graph_image SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>14129</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;graph.php&quot;; nocase; http_uri; pcre:&quot;/rra_id=(?!(\d+|all|)([\x26\s]|$))/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8715</id>
        <msg>WEB-PHP cacti graph_image SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>14129</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-2148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;graph.php&quot;; nocase; http_uri; pcre:&quot;/local_graph_id=(?!(\d+|)([\x26\s]|$))/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>8716</id>
        <msg>WEB-PHP cacti graph_image SQL injection attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>26741</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0067</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;|2F|OvCgi|2F|&quot;; fast_pattern; nocase; http_uri; isdataat:1024; pcre:&quot;/^\x2FOvCgi\x2F[^\x2E]*?\x2Eexe[^\h]{1024}/iU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13161</id>
        <msg>EXPLOIT HP OpenView CGI parameter buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28020</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-1365</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiablogon.exe&quot;; fast_pattern:only; content:&quot;CRYPT&quot;; nocase; isdataat:512,relative; pcre:&quot;/pwd=(\!|\%21)CRYPT(\!|\%21)[A-Z0-9]{512}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:web-application-attack;</filter2>
        <id>13591</id>
        <msg>WEB-CGI Trend Micro OfficeScan CGI password decryption buffer overflow attempt</msg>
        <url>secunia.com/advisories/29124</url>
      </rule>
      <rule>
        <bugtraq>28222</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0532</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CSuserCGI.exe?Logout&quot;; nocase; http_uri; pcre:&quot;/\x2FCSuserCGI\x2Eexe\x3FLogout.[^\s]{96}/Ui&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13656</id>
        <msg>WEB-MISC Cisco Secure Access Control Server UCP Application CSuserCGI.exe buffer overflow attempt</msg>
        <url>www.cisco.com/warp/public/707/cisco-sa-20080312-ucp.shtml</url>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5440</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 17000</filter1>
        <filter2>flow:to_server,established; content:&quot;GET &quot;; depth:4; nocase; content:&quot;evtdump?&quot;; distance:0; nocase; pcre:&quot;/evtdump\x3f.*?\x2525[^\x20]*?\x20HTTP/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15264</id>
        <msg>WEB-CGI Oracle TimesTen In-Memory Database evtdump CGI module format string exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>31139</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2437</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi/cgiRecvFile.exe&quot;; http_uri; content:&quot;ComputerName&quot;; pcre:&quot;/ComputerName\s*\x3d\s*\x22[^\x22]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15510</id>
        <msg>WEB-CLIENT Trend Micro OfficeScan Server cgiRecvFile overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15703</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-4031</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/wiki&quot;; nocase; http_uri; content:&quot;?uselang=&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2fwiki[^\n]*\x3fuselang=[^\n\x26\x3f]*[a-zA-Z\x2d]/Usmi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16079</id>
        <msg>WEB-CGI uselang code injection</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1555</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; nocase; http_method; content:&quot;|2F|OvCgi|2F|&quot;; fast_pattern; http_uri; content:&quot;Content|2D|Length|3A|&quot;; byte_test:4,&gt;,500,1,relative,hex,string; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16674</id>
        <msg>WEB-MISC HP OpenView CGI parameter buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25622</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SCRIPT_FILENAME/etc/passwd|06 80 00|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17386</id>
        <msg>SPECIFIC-THREATS Lighttpd mod_fastcgi Extension CGI Variable Overwriting Vulnerability attempt</msg>
      </rule>
      <rule>
        <bugtraq>28020</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2008-1365</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8081</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiablogon.exe&quot;; fast_pattern:only; content:&quot;CRYPT&quot;; nocase; isdataat:512,relative; pcre:&quot;/pwd=(\!|\%21)CRYPT(\!|\%21)[^\r|\n|&amp;]{513}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:web-application-attack;</filter2>
        <id>17605</id>
        <msg>WEB-CGI Trend Micro OfficeScan CGI password decryption buffer overflow attempt</msg>
        <url>secunia.com/advisories/29124</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/&quot;; nocase; http_uri; content:&quot;.fcgi&quot;; nocase; http_uri; pcre:&quot;/\x2Fcgi-bin\x2F[a-zA-Z0-9_]*\.fcgi/Ui&quot;; content:&quot;Host|3A| begin2search.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5764</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - fcgi query</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/track.cgi?&quot;; nocase; http_uri; content:&quot;prov=INTERNAL&quot;; nocase; http_uri; content:&quot;prog=&quot;; nocase; http_uri; content:&quot;siteid=&quot;; nocase; http_uri; content:&quot;group=&quot;; nocase; http_uri; content:&quot;Host|3A| track.aadserver.net&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5945</id>
        <msg>SPYWARE-PUT Adware weirdontheweb runtime detection - track.cgi request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094260</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/log.cgi?&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;vicname=&quot;; nocase; http_uri; content:&quot;server=DSK&quot;; nocase; http_uri; content:&quot;password=&quot;; nocase; http_uri; content:&quot;usrname=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6019</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - cgi notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;id=FeaR-Server&quot;; nocase; http_uri; content:&quot;win=&quot;; nocase; http_uri; content:&quot;rpass=&quot;; nocase; http_uri; content:&quot;connection=&quot;; nocase; http_uri; content:&quot;s7pass=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6043</id>
        <msg>BACKDOOR fear 0.2 runtime detection - cgi notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;win=&quot;; nocase; http_uri; content:&quot;pass=&quot;; nocase; http_uri; content:&quot;connection=&quot;; nocase; http_uri; content:&quot;id=NEUROTICKA&quot;; nocase; http_uri; content:&quot;s7pass=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6059</id>
        <msg>BACKDOOR neurotickat1.3 runtime detection - cgi notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=31859</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;nick=minibeta&quot;; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;visible=&quot;; nocase; http_uri; content:&quot;protected=&quot;; nocase; http_uri; content:&quot;about=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7076</id>
        <msg>BACKDOOR minimo v0.6 runtime detection - cgi notification</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?action=log&quot;; fast_pattern; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;rpass=&quot;; nocase; http_uri; content:&quot;connection=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7148</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - cgi notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/counter3.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;p=moneytreck&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7524</id>
        <msg>SPYWARE-PUT Hijacker moneybar runtime detection - cgispy counter</msg>
        <url>www.aladdin.com/home/csrt/grayware-list2.asp?GraywareNo=277</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;action=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| http protocol&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7540</id>
        <msg>SPYWARE-PUT Hacker-Tool unify runtime detection - cgi notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074224</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/prorat.cgi&quot;; nocase; http_uri; content:&quot;bilgisayaradi=&quot;; nocase; http_uri; content:&quot;ipadresi=&quot;; nocase; http_uri; content:&quot;serverportu=&quot;; nocase; http_uri; content:&quot;kurban=&quot;; nocase; http_uri; content:&quot;servermodeli=&quot;; nocase; http_uri; content:&quot;serversaati=&quot;; nocase; http_uri; content:&quot;servertarihi=&quot;; nocase; http_uri; content:&quot;serversifre=&quot;; nocase; http_uri; content:&quot;islem=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7722</id>
        <msg>BACKDOOR prorat 1.9 cgi notification detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082779</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;nick=&quot;; nocase; http_uri; content:&quot;os=&quot;; nocase; http_uri; content:&quot;compname=&quot;; nocase; http_uri; content:&quot;protected=&quot;; nocase; http_uri; flowbits:set,nova_cgi_cts; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7742</id>
        <msg>BACKDOOR nova 1.0 runtime detection - cgi notification client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073030</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,nova_cgi_cts; content:&quot;|23| Nova CGI Notification Script&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7743</id>
        <msg>BACKDOOR nova 1.0 runtime detection - cgi notification server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073030</url>
      </rule>
    </attacks>
    <groupid>218</groupid>
    <groupname>Server / HTTP / CGI</groupname>
    <warnings>
      <rule>
        <bugtraq>2156</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0075</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/technote/main.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;filename=&quot;; nocase; content:&quot;../../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1051</id>
        <msg>WEB-CGI technote main.cgi file directory traversal attempt</msg>
        <nessus>10584</nessus>
      </rule>
      <rule>
        <bugtraq>2156</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0075</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/technote/print.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;board=&quot;; nocase; content:&quot;../../&quot;; content:&quot;%00&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1052</id>
        <msg>WEB-CGI technote print.cgi directory traversal attempt</msg>
        <nessus>10584</nessus>
      </rule>
      <rule>
        <bugtraq>2103</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0025</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ads.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;file=&quot;; nocase; content:&quot;../../&quot;; content:&quot;|7C|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1053</id>
        <msg>WEB-CGI ads.cgi command execution attempt</msg>
        <nessus>11464</nessus>
      </rule>
      <rule>
        <bugtraq>1774</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/web_store.cgi&quot;; http_uri; content:&quot;page=../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1088</id>
        <msg>WEB-CGI eXtropia webstore directory traversal</msg>
        <nessus>10532</nessus>
      </rule>
      <rule>
        <bugtraq>1777</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shop.cgi&quot;; http_uri; content:&quot;page=../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1089</id>
        <msg>WEB-CGI shopping cart directory traversal</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/authenticate.cgi?PASSWORD&quot;; fast_pattern; nocase; http_uri; content:&quot;config.ini&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1090</id>
        <msg>WEB-CGI Allaire Pro Web Shell attempt</msg>
      </rule>
      <rule>
        <bugtraq>1772</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0924</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi?keys&quot;; http_uri; content:&quot;catigory=../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1092</id>
        <msg>WEB-CGI Armada Style Master Index directory traversal</msg>
        <nessus>10562</nessus>
        <url>www.synnergy.net/downloads/advisories/SLA-2000-16.masterindex.txt</url>
      </rule>
      <rule>
        <bugtraq>1762</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0906</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cached_feed.cgi&quot;; http_uri; content:&quot;../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1093</id>
        <msg>WEB-CGI cached_feed.cgi moreover shopping cart directory traversal</msg>
      </rule>
      <rule>
        <bugtraq>1725</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus.cgi?Script=/webplus/webping/webping.wml&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1097</id>
        <msg>WEB-CGI Talentsoft Web+ exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>6472</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2006-6679</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;chetcpasswd.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>10999</id>
        <msg>WEB-CGI chetcpasswd access</msg>
      </rule>
      <rule>
        <bugtraq>1431</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0590</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pollit/Poll_It_SSI_v2.0.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1106</id>
        <msg>WEB-CGI Poll-it access</msg>
        <nessus>10459</nessus>
      </rule>
      <rule>
        <bugtraq>128</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0021</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/count.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1149</id>
        <msg>WEB-CGI count.cgi access</msg>
        <nessus>10049</nessus>
      </rule>
      <rule>
        <bugtraq>374</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webdist.cgi&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1163</id>
        <msg>WEB-CGI webdist.cgi access</msg>
        <nessus>10299</nessus>
      </rule>
      <rule>
        <bugtraq>778</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1550</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bigconf.cgi&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1172</id>
        <msg>WEB-CGI bigconf.cgi access</msg>
        <nessus>10027</nessus>
      </rule>
      <rule>
        <bugtraq>2002</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0260</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/jj&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1174</id>
        <msg>WEB-CGI /cgi-bin/jj access</msg>
        <nessus>10131</nessus>
      </rule>
      <rule>
        <bugtraq>11043</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-0798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_maincfgret.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>11817</id>
        <msg>WEB-CGI WhatsUpGold configuration access</msg>
      </rule>
      <rule>
        <bugtraq>1104</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0287</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bizdb1-search.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;mail&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1185</id>
        <msg>WEB-CGI bizdbsearch attempt</msg>
        <nessus>10383</nessus>
      </rule>
      <rule>
        <bugtraq>1052</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0180</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sojourn.cgi?cat=&quot;; fast_pattern; nocase; http_uri; content:&quot;%00&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1194</id>
        <msg>WEB-CGI sojourn.cgi File attempt</msg>
        <nessus>10349</nessus>
      </rule>
      <rule>
        <bugtraq>1052</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0180</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sojourn.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1195</id>
        <msg>WEB-CGI sojourn.cgi access</msg>
        <nessus>10349</nessus>
      </rule>
      <rule>
        <bugtraq>1031</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0207</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/infosrch.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;fname=&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1196</id>
        <msg>WEB-CGI SGI InfoSearch fname attempt</msg>
        <nessus>10128</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ax-admin.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1204</id>
        <msg>WEB-CGI ax-admin.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/axs.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1205</id>
        <msg>WEB-CGI axs.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>11043</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;/_maincfgret.cgi&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/instancename=[^&amp;\x3b\r\n]{513}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12056</id>
        <msg>WEB-CGI WhatsUpGold instancename overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11043</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-0798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;/_maincfgret.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>12057</id>
        <msg>WEB-CGI WhatsUpGold configuration access</msg>
      </rule>
      <rule>
        <bugtraq>2059</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0710</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cachemgr.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1206</id>
        <msg>WEB-CGI cachemgr.cgi access</msg>
        <nessus>10034</nessus>
      </rule>
      <rule>
        <bugtraq>3155</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/responder.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1208</id>
        <msg>WEB-CGI responder.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/web-map.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1211</id>
        <msg>WEB-CGI web-map.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ministats/admin.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1215</id>
        <msg>WEB-CGI ministats admin access</msg>
      </rule>
      <rule>
        <bugtraq>564</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0913</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dfire.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1219</id>
        <msg>WEB-CGI dfire.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2374</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0224</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/empower?DB&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1221</id>
        <msg>WEB-MISC Muscat Empower cgi access</msg>
        <nessus>10609</nessus>
      </rule>
      <rule>
        <bugtraq>2372</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0217</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pals-cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;documentName=&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1222</id>
        <msg>WEB-CGI pals-cgi arbitrary file access attempt</msg>
        <nessus>10611</nessus>
      </rule>
      <rule>
        <bugtraq>4448</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1750</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;csGuestbook.cgi&quot;; http_uri; content:&quot;command=savesetup&amp;setup=&quot;; http_uri; classtype:web-application-activity;</filter2>
        <id>12255</id>
        <msg>WEB-CGI CSGuestbook setup attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/txt2html.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1304</id>
        <msg>WEB-CGI txt2html.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/txt2html.cgi&quot;; http_uri; content:&quot;/../../../../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1305</id>
        <msg>WEB-CGI txt2html.cgi directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>2385</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0305</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/store.cgi&quot;; nocase; http_uri; content:&quot;product=&quot;; content:&quot;../..&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1306</id>
        <msg>WEB-CGI store.cgi product directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>2385</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0305</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/store.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1307</id>
        <msg>WEB-CGI store.cgi access</msg>
        <nessus>10639</nessus>
      </rule>
      <rule>
        <bugtraq>3673</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1100</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sendmessage.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1308</id>
        <msg>WEB-CGI sendmessage.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/zsh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1309</id>
        <msg>WEB-CGI zsh access</msg>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <bugtraq>3755</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1206</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/lastlines.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1392</id>
        <msg>WEB-CGI lastlines.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>3759</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1209</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/zml.cgi&quot;; http_uri; content:&quot;file=../&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1395</id>
        <msg>WEB-CGI zml.cgi attempt</msg>
        <nessus>10830</nessus>
      </rule>
      <rule>
        <bugtraq>3759</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1209</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/zml.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1396</id>
        <msg>WEB-CGI zml.cgi access</msg>
        <nessus>10830</nessus>
      </rule>
      <rule>
        <bugtraq>2370</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0214</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/way-board/way-board.cgi&quot;; http_uri; content:&quot;db=&quot;; content:&quot;../..&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1397</id>
        <msg>WEB-CGI wayboard attempt</msg>
        <nessus>10610</nessus>
      </rule>
      <rule>
        <bugtraq>3985</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/publisher/search.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;template=&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1405</id>
        <msg>WEB-CGI AHG search.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>3976</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0215</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/store/agora.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1406</id>
        <msg>WEB-CGI agora.cgi access</msg>
        <nessus>10836</nessus>
      </rule>
      <rule>
        <bugtraq>2728</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0527</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dcboard.cgi&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1410</id>
        <msg>WEB-CGI dcboard.cgi access</msg>
        <nessus>10583</nessus>
      </rule>
      <rule>
        <bugtraq>2563</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0400</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nph-maillist.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1451</id>
        <msg>WEB-CGI NPH-maillist access</msg>
        <nessus>10164</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1180</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/args.cmd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1452</id>
        <msg>WEB-CGI args.cmd access</msg>
        <nessus>11465</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/AT-generated.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1453</id>
        <msg>WEB-CGI AT-generated.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>2001-0223</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwwwais&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1454</id>
        <msg>WEB-CGI wwwwais access</msg>
        <nessus>10597</nessus>
      </rule>
      <rule>
        <bugtraq>1215</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;calendar&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/calendar(|[-_]admin)\.pl/Ui&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1455</id>
        <msg>WEB-CGI calendar.pl access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>2000-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/calender_admin.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1456</id>
        <msg>WEB-CGI calender_admin.pl access</msg>
        <nessus>10506</nessus>
      </rule>
      <rule>
        <bugtraq>1486</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/user_update_admin.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1457</id>
        <msg>WEB-CGI user_update_admin.pl access</msg>
      </rule>
      <rule>
        <bugtraq>1486</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/user_update_passwd.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1458</id>
        <msg>WEB-CGI user_update_passwd.pl access</msg>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-histlog.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1459</id>
        <msg>WEB-CGI bb-histlog.sh access</msg>
        <nessus>10025</nessus>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-histsvc.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1460</id>
        <msg>WEB-CGI bb-histsvc.sh access</msg>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-rep.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1461</id>
        <msg>WEB-CGI bb-rep.sh access</msg>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-replog.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1462</id>
        <msg>WEB-CGI bb-replog.sh access</msg>
      </rule>
      <rule>
        <bugtraq>2367</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0212</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/auktion.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1465</id>
        <msg>WEB-CGI auktion.cgi access</msg>
        <nessus>10638</nessus>
      </rule>
      <rule>
        <bugtraq>1963</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1171</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiforum.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1466</id>
        <msg>WEB-CGI cgiforum.pl access</msg>
        <nessus>10552</nessus>
      </rule>
      <rule>
        <bugtraq>2793</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0780</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/directorypro.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1467</id>
        <msg>WEB-CGI directorypro.cgi access</msg>
        <nessus>10679</nessus>
      </rule>
      <rule>
        <bugtraq>1776</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0922</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shopper.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;newpage=../&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1468</id>
        <msg>WEB-CGI Web Shopper shopper.cgi attempt</msg>
        <nessus>10533</nessus>
      </rule>
      <rule>
        <bugtraq>1776</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0922</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shopper.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1469</id>
        <msg>WEB-CGI Web Shopper shopper.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>3328</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0997</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/listrec.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1470</id>
        <msg>WEB-CGI listrec.pl access</msg>
        <nessus>10769</nessus>
      </rule>
      <rule>
        <bugtraq>2391</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0271</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailnews.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1471</id>
        <msg>WEB-CGI mailnews.cgi access</msg>
        <nessus>10641</nessus>
      </rule>
      <rule>
        <bugtraq>3178</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1114</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/book.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1472</id>
        <msg>WEB-CGI book.cgi access</msg>
        <nessus>10721</nessus>
      </rule>
      <rule>
        <bugtraq>2172</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsdesk.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1473</id>
        <msg>WEB-CGI newsdesk.cgi access</msg>
        <nessus>10586</nessus>
      </rule>
      <rule>
        <bugtraq>2663</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0463</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cal_make.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1474</id>
        <msg>WEB-CGI cal_make.pl access</msg>
        <nessus>10664</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailit.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1475</id>
        <msg>WEB-CGI mailit.pl access</msg>
        <nessus>10417</nessus>
      </rule>
      <rule>
        <bugtraq>1658</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1130</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sdbsearch.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1476</id>
        <msg>WEB-CGI sdbsearch.cgi access</msg>
        <nessus>10720</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/swc&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1478</id>
        <msg>WEB-CGI swc access</msg>
        <nessus>10493</nessus>
      </rule>
      <rule>
        <bugtraq>2890</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0805</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ttawebtop.cgi&quot;; nocase; content:&quot;pg=../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1479</id>
        <msg>WEB-CGI ttawebtop.cgi arbitrary file attempt</msg>
        <nessus>10696</nessus>
      </rule>
      <rule>
        <bugtraq>2890</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0805</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ttawebtop.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1480</id>
        <msg>WEB-CGI ttawebtop.cgi access</msg>
        <nessus>10696</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upload.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1481</id>
        <msg>WEB-CGI upload.cgi access</msg>
        <nessus>10290</nessus>
      </rule>
      <rule>
        <bugtraq>2251</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0174</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/view_source&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1482</id>
        <msg>WEB-CGI view_source access</msg>
        <nessus>10294</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2001-0466</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ustorekeeper.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1483</id>
        <msg>WEB-CGI ustorekeeper.pl access</msg>
        <nessus>10645</nessus>
      </rule>
      <rule>
        <bugtraq>2385</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0305</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/store.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1488</id>
        <msg>WEB-CGI store.cgi directory traversal attempt</msg>
        <nessus>10639</nessus>
      </rule>
      <rule>
        <bugtraq>3175</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-1115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/generate.cgi&quot;; http_uri; content:&quot;content=../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1494</id>
        <msg>WEB-CGI SIX webboard generate.cgi attempt</msg>
        <nessus>10725</nessus>
      </rule>
      <rule>
        <bugtraq>3175</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/generate.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1495</id>
        <msg>WEB-CGI SIX webboard generate.cgi access</msg>
        <nessus>10725</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/spin_client.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1496</id>
        <msg>WEB-CGI spin_client.cgi access</msg>
        <nessus>10393</nessus>
      </rule>
      <rule>
        <bugtraq>2705</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a1disp3.cgi?/../../&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1501</id>
        <msg>WEB-CGI a1stats a1disp3.cgi directory traversal attempt</msg>
        <nessus>10669</nessus>
      </rule>
      <rule>
        <bugtraq>2705</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a1disp3.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1502</id>
        <msg>WEB-CGI a1stats a1disp3.cgi access</msg>
        <nessus>10669</nessus>
      </rule>
      <rule>
        <bugtraq>4152</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0308</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admentor/admin/admin.asp&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1503</id>
        <msg>WEB-CGI admentor admin.asp access</msg>
        <nessus>10880</nessus>
        <url>www.securiteam.com/windowsntfocus/5DP0N1F6AW.html</url>
      </rule>
      <rule>
        <bugtraq>3599</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0871</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/PRN/../../&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1505</id>
        <msg>WEB-CGI alchemy http server PRN arbitrary command execution attempt</msg>
        <nessus>10818</nessus>
      </rule>
      <rule>
        <bugtraq>3599</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0871</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/NUL/../../&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1506</id>
        <msg>WEB-CGI alchemy http server NUL arbitrary command execution attempt</msg>
        <nessus>10818</nessus>
      </rule>
      <rule>
        <bugtraq>770</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0885</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/alibaba.pl|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1507</id>
        <msg>WEB-CGI alibaba.pl arbitrary command execution attempt</msg>
        <nessus>10013</nessus>
      </rule>
      <rule>
        <bugtraq>770</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0885</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/alibaba.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1508</id>
        <msg>WEB-CGI alibaba.pl access</msg>
        <nessus>10013</nessus>
      </rule>
      <rule>
        <bugtraq>896</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/query?mss=..&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1509</id>
        <msg>WEB-CGI AltaVista Intranet Search directory traversal attempt</msg>
        <nessus>10015</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test.bat|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1510</id>
        <msg>WEB-CGI test.bat arbitrary command execution attempt</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1511</id>
        <msg>WEB-CGI test.bat access</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/input.bat|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1512</id>
        <msg>WEB-CGI input.bat arbitrary command execution attempt</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/input.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1513</id>
        <msg>WEB-CGI input.bat access</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/input2.bat|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1514</id>
        <msg>WEB-CGI input2.bat arbitrary command execution attempt</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/input2.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1515</id>
        <msg>WEB-CGI input2.bat access</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/envout.bat|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1516</id>
        <msg>WEB-CGI envout.bat arbitrary command execution attempt</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>762</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/envout.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1517</id>
        <msg>WEB-CGI envout.bat access</msg>
        <nessus>10016</nessus>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-hist.sh?HISTFILE=../..&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1531</id>
        <msg>WEB-CGI bb-hist.sh attempt</msg>
        <nessus>10025</nessus>
      </rule>
      <rule>
        <bugtraq>1455</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0638</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-hostsvc.sh?HOSTSVC?../..&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1532</id>
        <msg>WEB-CGI bb-hostscv.sh attempt</msg>
        <nessus>10460</nessus>
      </rule>
      <rule>
        <bugtraq>1455</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0638</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-hostsvc.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1533</id>
        <msg>WEB-CGI bb-hostscv.sh access</msg>
        <nessus>10460</nessus>
      </rule>
      <rule>
        <bugtraq>3976</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0215</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/store/agora.cgi?cart_id=&lt;SCRIPT&gt;&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1534</id>
        <msg>WEB-CGI agora.cgi attempt</msg>
        <nessus>10836</nessus>
      </rule>
      <rule>
        <bugtraq>1104</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0287</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bizdb1-search.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1535</id>
        <msg>WEB-CGI bizdbsearch access</msg>
        <nessus>10383</nessus>
      </rule>
      <rule>
        <bugtraq>1215</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/calendar_admin.pl?config=|7C|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1536</id>
        <msg>WEB-CGI calendar_admin.pl arbitrary command execution attempt</msg>
        <nessus>10506</nessus>
      </rule>
      <rule>
        <bugtraq>1215</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/calendar_admin.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1537</id>
        <msg>WEB-CGI calendar_admin.pl access</msg>
        <nessus>10506</nessus>
      </rule>
      <rule>
        <bugtraq>936</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0079</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/ls&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1539</id>
        <msg>WEB-CGI /cgi-bin/ls access</msg>
        <nessus>10037</nessus>
      </rule>
      <rule>
        <bugtraq>1623</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgimail&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1542</id>
        <msg>WEB-CGI cgimail access</msg>
        <nessus>11721</nessus>
      </rule>
      <rule>
        <bugtraq>777</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0987</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiwrap&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1543</id>
        <msg>WEB-CGI cgiwrap access</msg>
        <nessus>10041</nessus>
      </rule>
      <rule>
        <bugtraq>4368</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0495</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/csSearch.cgi&quot;; http_uri; content:&quot;setup=&quot;; content:&quot;`&quot;; content:&quot;`&quot;; distance:1; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1547</id>
        <msg>WEB-CGI csSearch.cgi arbitrary command execution attempt</msg>
        <nessus>10924</nessus>
      </rule>
      <rule>
        <bugtraq>4368</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0495</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/csSearch.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1548</id>
        <msg>WEB-CGI csSearch.cgi access</msg>
        <nessus>10924</nessus>
      </rule>
      <rule>
        <bugtraq>1178</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0381</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dbman/db.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1554</id>
        <msg>WEB-CGI dbman db.cgi access</msg>
        <nessus>10403</nessus>
      </rule>
      <rule>
        <bugtraq>2889</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0821</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dcshop&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1555</id>
        <msg>WEB-CGI DCShop access</msg>
      </rule>
      <rule>
        <bugtraq>2889</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0821</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/orders/orders.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1556</id>
        <msg>WEB-CGI DCShop orders.txt access</msg>
      </rule>
      <rule>
        <bugtraq>2889</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0821</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/auth_data/auth_user_file.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1557</id>
        <msg>WEB-CGI DCShop auth_user_file.txt access</msg>
      </rule>
      <rule>
        <bugtraq>3340</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-1014</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/eshop.pl?seite=|3B|&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1565</id>
        <msg>WEB-CGI eshop.pl arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>3340</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1014</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/eshop.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1566</id>
        <msg>WEB-CGI eshop.pl access</msg>
      </rule>
      <rule>
        <bugtraq>2109</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1092</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/loadpage.cgi&quot;; http_uri; content:&quot;file=../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1569</id>
        <msg>WEB-CGI loadpage.cgi directory traversal attempt</msg>
        <nessus>10065</nessus>
      </rule>
      <rule>
        <bugtraq>2109</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1092</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/loadpage.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1570</id>
        <msg>WEB-CGI loadpage.cgi access</msg>
        <nessus>10065</nessus>
      </rule>
      <rule>
        <bugtraq>2611</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0437</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dcforum.cgi&quot;; http_uri; content:&quot;forum=../..&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1571</id>
        <msg>WEB-CGI dcforum.cgi directory traversal attempt</msg>
        <nessus>10583</nessus>
      </rule>
      <rule>
        <bugtraq>2361</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0210</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/commerce.cgi&quot;; http_uri; content:&quot;page=&quot;; content:&quot;/../&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1572</id>
        <msg>WEB-CGI commerce.cgi arbitrary file access attempt</msg>
        <nessus>10612</nessus>
      </rule>
      <rule>
        <bugtraq>1963</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1171</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiforum.pl?thesection=../..&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1573</id>
        <msg>WEB-CGI cgiforum.pl attempt</msg>
        <nessus>10552</nessus>
      </rule>
      <rule>
        <bugtraq>2793</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0780</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/directorypro.cgi&quot;; http_uri; content:&quot;show=&quot;; content:&quot;../..&quot;; distance:1; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1574</id>
        <msg>WEB-CGI directorypro.cgi attempt</msg>
        <nessus>10679</nessus>
      </rule>
      <rule>
        <bugtraq>3885</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0128</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgitest.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1587</id>
        <msg>WEB-MISC cgitest.exe access</msg>
        <nessus>11131</nessus>
      </rule>
      <rule>
        <bugtraq>3810</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/faqmanager.cgi?toc=&quot;; http_uri; content:&quot;|00|&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1590</id>
        <msg>WEB-CGI faqmanager.cgi arbitrary file access attempt</msg>
        <nessus>10837</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-3862</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; nocase; http_method; content:&quot;/officescan/cgi/cgi&quot;; nocase; http_uri; content:&quot;multipart/form-data&quot;; nocase; content:&quot;|0A|--&quot;; distance:0; isdataat:270; content:!&quot;|0A|--&quot;; within:270; metadata:service http; classtype:attempted-admin;</filter2>
        <id>15908</id>
        <msg>WEB-MISC Trend Micro OfficeScan multiple CGI modules HTTP form processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>3810</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/faqmanager.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1591</id>
        <msg>WEB-CGI faqmanager.cgi access</msg>
        <nessus>10837</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fcgi-bin/echo.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1592</id>
        <msg>WEB-CGI /fcgi-bin/echo.exe access</msg>
        <nessus>10838</nessus>
      </rule>
      <rule>
        <bugtraq>799</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1050</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FormHandler.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;redirect=http&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1593</id>
        <msg>WEB-CGI FormHandler.cgi external site redirection attempt</msg>
        <nessus>10075</nessus>
      </rule>
      <rule>
        <bugtraq>799</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1050</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FormHandler.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1594</id>
        <msg>WEB-CGI FormHandler.cgi access</msg>
        <nessus>10075</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0237</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/guestbook.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1597</id>
        <msg>WEB-CGI guestbook.cgi access</msg>
        <nessus>10098</nessus>
      </rule>
      <rule>
        <bugtraq>921</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi&quot;; http_uri; content:&quot;letter=../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1598</id>
        <msg>WEB-CGI Home Free search.cgi directory traversal attempt</msg>
        <nessus>10101</nessus>
      </rule>
      <rule>
        <bugtraq>921</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1599</id>
        <msg>WEB-CGI search.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>3410</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0834</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htsearch?-c&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1600</id>
        <msg>WEB-CGI htsearch arbitrary configuration file attempt</msg>
      </rule>
      <rule>
        <bugtraq>1026</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0208</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htsearch?exclude=`&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1601</id>
        <msg>WEB-CGI htsearch arbitrary file read attempt</msg>
        <nessus>10105</nessus>
      </rule>
      <rule>
        <bugtraq>1026</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0208</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htsearch&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1602</id>
        <msg>WEB-CGI htsearch access</msg>
        <nessus>10105</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1069</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/icat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1606</id>
        <msg>WEB-CGI icat access</msg>
      </rule>
      <rule>
        <bugtraq>2314</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0253</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hsx.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1607</id>
        <msg>WEB-CGI HyperSeek hsx.cgi access</msg>
        <nessus>10602</nessus>
      </rule>
      <rule>
        <bugtraq>2001</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0264</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htmlscript?../..&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1608</id>
        <msg>WEB-CGI htmlscript attempt</msg>
        <nessus>10106</nessus>
      </rule>
      <rule>
        <bugtraq>1774</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/web_store.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1611</id>
        <msg>WEB-CGI eXtropia webstore access</msg>
        <nessus>10532</nessus>
      </rule>
      <rule>
        <bugtraq>3800</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0011</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/doeditvotes.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1617</id>
        <msg>WEB-CGI Bugzilla doeditvotes.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>799</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1050</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FormHandler.cgi&quot;; nocase; http_uri; content:&quot;reply_message_attach=&quot;; fast_pattern:only; content:&quot;/../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1628</id>
        <msg>WEB-CGI FormHandler.cgi directory traversal attempt attempt</msg>
        <nessus>10075</nessus>
      </rule>
      <rule>
        <bugtraq>1668</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0853</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/YaBB&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1637</id>
        <msg>WEB-CGI yabb access</msg>
        <nessus>10512</nessus>
      </rule>
      <rule>
        <bugtraq>2017</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1110</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/document.d2w&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1642</id>
        <msg>WEB-CGI document.d2w access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-0677</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db2www&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1643</id>
        <msg>WEB-CGI db2www access</msg>
      </rule>
      <rule>
        <bugtraq>2003</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test-cgi/*?*&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1644</id>
        <msg>WEB-CGI test-cgi attempt</msg>
        <nessus>10282</nessus>
      </rule>
      <rule>
        <bugtraq>7214</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/testcgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1645</id>
        <msg>WEB-CGI testcgi access</msg>
        <nessus>11610</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1646</id>
        <msg>WEB-CGI test.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perl.exe?&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1648</id>
        <msg>WEB-CGI perl.exe command attempt</msg>
        <nessus>10173</nessus>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perl?&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1649</id>
        <msg>WEB-CGI perl command attempt</msg>
        <nessus>10173</nessus>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <bugtraq>770</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0885</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tst.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1650</id>
        <msg>WEB-CGI tst.bat access</msg>
        <nessus>10014</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/environ.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1651</id>
        <msg>WEB-CGI environ.pl access</msg>
      </rule>
      <rule>
        <bugtraq>1975</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0146</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/campas?|0A|&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1652</id>
        <msg>WEB-CGI campas attempt</msg>
        <nessus>10035</nessus>
      </rule>
      <rule>
        <bugtraq>1153</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cart32.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1654</id>
        <msg>WEB-CGI cart32.exe access</msg>
        <nessus>10389</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>1999-0270</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pfdispaly.cgi?'&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1655</id>
        <msg>WEB-CGI pfdispaly.cgi arbitrary command execution attempt</msg>
        <nessus>10174</nessus>
      </rule>
      <rule>
        <bugtraq>64</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0270</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pfdispaly.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1656</id>
        <msg>WEB-CGI pfdispaly.cgi access</msg>
        <nessus>10174</nessus>
      </rule>
      <rule>
        <bugtraq>1864</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0940</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pagelog.cgi&quot;; nocase; http_uri; content:&quot;name=../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1657</id>
        <msg>WEB-CGI pagelog.cgi directory traversal attempt</msg>
        <nessus>10591</nessus>
      </rule>
      <rule>
        <bugtraq>1864</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0940</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pagelog.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1658</id>
        <msg>WEB-CGI pagelog.cgi access</msg>
        <nessus>10591</nessus>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Index of /cgi-bin/&quot;; nocase; classtype:bad-unknown;</filter2>
        <id>1666</id>
        <msg>ATTACK-RESPONSES index of /cgi-bin/ response</msg>
        <nessus>10039</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/&quot;; http_uri; content:&quot;/cgi-bin/ HTTP&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1668</id>
        <msg>WEB-CGI /cgi-bin/ access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-dos/&quot;; http_uri; content:&quot;/cgi-dos/ HTTP&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1669</id>
        <msg>WEB-CGI /cgi-dos/ access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/rd.cgi?f=/vercfg.dat?AgentID=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16922</id>
        <msg>BLACKLIST URI request for known malicious URI - /cgi-bin/rd.cgi?f=/vercfg.dat?AgentID=</msg>
        <url>labs.snort.org/docs/16922.html</url>
      </rule>
      <rule>
        <bugtraq>739</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0951</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imagemap.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1700</id>
        <msg>WEB-CGI imagemap.exe access</msg>
        <nessus>10122</nessus>
      </rule>
      <rule>
        <bugtraq>1215</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/calendar-admin.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1701</id>
        <msg>WEB-CGI calendar-admin.pl access</msg>
        <nessus>10506</nessus>
      </rule>
      <rule>
        <bugtraq>2504</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0272</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sendtemp.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1702</id>
        <msg>WEB-CGI Amaya templates sendtemp.pl access</msg>
      </rule>
      <rule>
        <bugtraq>2367</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0212</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/auktion.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;menue=../../&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1703</id>
        <msg>WEB-CGI auktion.cgi directory traversal attempt</msg>
        <nessus>10638</nessus>
      </rule>
      <rule>
        <bugtraq>2663</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0463</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cal_make.pl&quot;; nocase; http_uri; content:&quot;p0=../../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1704</id>
        <msg>WEB-CGI cal_make.pl directory traversal attempt</msg>
        <nessus>10664</nessus>
      </rule>
      <rule>
        <bugtraq>1002</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0213</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/echo.bat&quot;; http_uri; content:&quot;&amp;&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1705</id>
        <msg>WEB-CGI echo.bat arbitrary command execution attempt</msg>
        <nessus>10246</nessus>
      </rule>
      <rule>
        <bugtraq>1002</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0213</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/echo.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1706</id>
        <msg>WEB-CGI echo.bat access</msg>
        <nessus>10246</nessus>
      </rule>
      <rule>
        <bugtraq>1002</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0213</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hello.bat&quot;; http_uri; content:&quot;&amp;&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1707</id>
        <msg>WEB-CGI hello.bat arbitrary command execution attempt</msg>
        <nessus>10246</nessus>
      </rule>
      <rule>
        <bugtraq>1002</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0213</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hello.bat&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1708</id>
        <msg>WEB-CGI hello.bat access</msg>
        <nessus>10246</nessus>
      </rule>
      <rule>
        <bugtraq>2103</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0025</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1709</id>
        <msg>WEB-CGI ad.cgi access</msg>
        <nessus>11464</nessus>
      </rule>
      <rule>
        <bugtraq>2177</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0123</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bbs_forum.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1710</id>
        <msg>WEB-CGI bbs_forum.cgi access</msg>
        <url>www.cgisecurity.com/advisory/3.1.txt</url>
      </rule>
      <rule>
        <bugtraq>2159</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0099</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bsguest.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1711</id>
        <msg>WEB-CGI bsguest.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2160</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0100</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bslist.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1712</id>
        <msg>WEB-CGI bslist.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>1951</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1132</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgforum.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1713</id>
        <msg>WEB-CGI cgforum.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newdesk&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1714</id>
        <msg>WEB-CGI newdesk access</msg>
      </rule>
      <rule>
        <bugtraq>2157</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0076</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/register.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1715</id>
        <msg>WEB-CGI register.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>1940</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1131</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gbook.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1716</id>
        <msg>WEB-CGI gbook.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2106</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/simplestguest.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1717</id>
        <msg>WEB-CGI simplestguest.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2211</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0113</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/statsconfig.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1718</id>
        <msg>WEB-CGI statsconfig.pl access</msg>
      </rule>
      <rule>
        <bugtraq>2547</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0420</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/talkbalk.cgi&quot;; nocase; http_uri; content:&quot;article=../../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1719</id>
        <msg>WEB-CGI talkback.cgi directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>2547</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0420</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/talkbalk.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1720</id>
        <msg>WEB-CGI talkback.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1067</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/MachineInfo&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1722</id>
        <msg>WEB-CGI MachineInfo access</msg>
      </rule>
      <rule>
        <bugtraq>5824</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1526</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/emumail.cgi&quot;; http_uri; content:&quot;type=&quot;; nocase; content:&quot;%00&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1723</id>
        <msg>WEB-CGI emumail.cgi NULL attempt</msg>
      </rule>
      <rule>
        <bugtraq>5824</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1526</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/emumail.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1724</id>
        <msg>WEB-CGI emumail.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>1031</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0207</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/infosrch.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1727</id>
        <msg>WEB-CGI SGI InfoSearch fname access</msg>
      </rule>
      <rule>
        <bugtraq>2536</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0466</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ustorekeeper.pl&quot;; nocase; http_uri; content:&quot;file=../../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1730</id>
        <msg>WEB-CGI ustorekeeper.pl directory traversal attempt</msg>
        <nessus>10645</nessus>
      </rule>
      <rule>
        <bugtraq>2705</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a1stats/&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1731</id>
        <msg>WEB-CGI a1stats access</msg>
        <nessus>10669</nessus>
      </rule>
      <rule>
        <bugtraq>629</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0067</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/phf&quot;; fast_pattern; nocase; http_uri; content:&quot;QALIAS&quot;; nocase; content:&quot;%0a&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1762</id>
        <msg>WEB-CGI phf arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>938</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0064</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiproc?Nocfile=&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1763</id>
        <msg>WEB-CGI Nortel Contivity cgiproc DOS attempt</msg>
        <nessus>10160</nessus>
      </rule>
      <rule>
        <bugtraq>938</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0064</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiproc?|24|&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1764</id>
        <msg>WEB-CGI Nortel Contivity cgiproc DOS attempt</msg>
        <nessus>10160</nessus>
      </rule>
      <rule>
        <bugtraq>938</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0064</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiproc&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1765</id>
        <msg>WEB-CGI Nortel Contivity cgiproc access</msg>
        <nessus>10160</nessus>
      </rule>
      <rule>
        <bugtraq>4889</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0918</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/csPassword.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1787</id>
        <msg>WEB-CGI csPassword.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>4889</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0920</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/password.cgi.tmp&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1788</id>
        <msg>WEB-CGI csPassword password.cgi.tmp access</msg>
      </rule>
      <rule>
        <bugtraq>4848</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0947</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rwcgi60&quot;; http_uri; content:&quot;setauth=&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1805</id>
        <msg>WEB-CGI Oracle reports CGI access</msg>
      </rule>
      <rule>
        <bugtraq>4983</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0934</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/alienform.cgi&quot;; http_uri; content:&quot;.|7C|./.|7C|.&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1822</id>
        <msg>WEB-CGI alienform.cgi directory traversal attempt</msg>
        <nessus>11027</nessus>
      </rule>
      <rule>
        <bugtraq>4983</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0934</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/af.cgi&quot;; http_uri; content:&quot;.|7C|./.|7C|.&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1823</id>
        <msg>WEB-CGI AlienForm af.cgi directory traversal attempt</msg>
        <nessus>11027</nessus>
      </rule>
      <rule>
        <bugtraq>4983</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0934</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/alienform.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1824</id>
        <msg>WEB-CGI alienform.cgi access</msg>
        <nessus>11027</nessus>
      </rule>
      <rule>
        <bugtraq>4983</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0934</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/af.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1825</id>
        <msg>WEB-CGI AlienForm af.cgi access</msg>
        <nessus>11027</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/way-board.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1850</id>
        <msg>WEB-CGI way-board.cgi access</msg>
        <nessus>10610</nessus>
      </rule>
      <rule>
        <bugtraq>4017</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mrtg.cgi&quot;; http_uri; content:&quot;cfg=/../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1862</id>
        <msg>WEB-CGI mrtg.cgi directory traversal attempt</msg>
        <nessus>11001</nessus>
      </rule>
      <rule>
        <bugtraq>374</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webdist.cgi&quot;; nocase; http_uri; content:&quot;distloc=|3B|&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1865</id>
        <msg>WEB-CGI webdist.cgi arbitrary command attempt</msg>
        <nessus>10299</nessus>
      </rule>
      <rule>
        <bugtraq>3028</bugtraq>
        <classtype>default-login-attempt</classtype>
        <cve>2001-0804</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;/story.pl&quot;; http_uri; content:&quot;next=../&quot;; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>1868</id>
        <msg>WEB-CGI story.pl arbitrary file read attempt</msg>
        <nessus>10817</nessus>
      </rule>
      <rule>
        <bugtraq>3028</bugtraq>
        <classtype>default-login-attempt</classtype>
        <cve>2001-0804</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;/story.pl&quot;; http_uri; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>1869</id>
        <msg>WEB-CGI story.pl access</msg>
        <nessus>10817</nessus>
      </rule>
      <rule>
        <bugtraq>951</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0117</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.cobalt/siteUserMod/siteUserMod.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1870</id>
        <msg>WEB-CGI siteUserMod.cgi access</msg>
        <nessus>10253</nessus>
      </rule>
      <rule>
        <bugtraq>6141</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1652</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgicso&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1875</id>
        <msg>WEB-CGI cgicso access</msg>
        <nessus>10780</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1177</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nph-publish.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1876</id>
        <msg>WEB-CGI nph-publish.cgi access</msg>
        <nessus>10164</nessus>
      </rule>
      <rule>
        <bugtraq>1658</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0868</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/printenv&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1877</id>
        <msg>WEB-CGI printenv access</msg>
        <nessus>10503</nessus>
      </rule>
      <rule>
        <bugtraq>1658</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0868</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sdbsearch.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1878</id>
        <msg>WEB-CGI sdbsearch.cgi access</msg>
        <nessus>10503</nessus>
      </rule>
      <rule>
        <bugtraq>3178</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-1114</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/book.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;current=|7C|&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1879</id>
        <msg>WEB-CGI book.cgi arbitrary command execution attempt</msg>
        <nessus>10721</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1278</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rpc-nlog.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1931</id>
        <msg>WEB-CGI rpc-nlog.pl access</msg>
        <url>marc.theaimsgroup.com/?l=bugtraq&amp;m=91471400632145&amp;w=2</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-1278</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rpc-smb.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1932</id>
        <msg>WEB-CGI rpc-smb.pl access</msg>
      </rule>
      <rule>
        <bugtraq>1115</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0252</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cart.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1933</id>
        <msg>WEB-CGI cart.cgi access</msg>
        <nessus>10368</nessus>
      </rule>
      <rule>
        <bugtraq>6038</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/vpasswd.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1994</id>
        <msg>WEB-CGI vpasswd.cgi access</msg>
        <nessus>11165</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/alya.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1995</id>
        <msg>WEB-CGI alya.cgi access</msg>
        <nessus>11118</nessus>
      </rule>
      <rule>
        <bugtraq>3495</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0849</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/viralator.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1996</id>
        <msg>WEB-CGI viralator.cgi access</msg>
        <nessus>11107</nessus>
      </rule>
      <rule>
        <bugtraq>7133</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/smartsearch.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2001</id>
        <msg>WEB-CGI smartsearch.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>1762</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0906</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cached_feed.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2051</id>
        <msg>WEB-CGI cached_feed.cgi moreover shopping cart access</msg>
      </rule>
      <rule>
        <bugtraq>6326</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1361</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/overflow.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2052</id>
        <msg>WEB-CGI overflow.cgi access</msg>
        <nessus>11190</nessus>
        <url>www.cert.org/advisories/CA-2002-35.html</url>
      </rule>
      <rule>
        <bugtraq>3272</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0008</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/process_bug.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2053</id>
        <msg>WEB-CGI process_bug.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>3272</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0008</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/enter_bug.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;who=&quot;; content:&quot;|3B|&quot;; distance:0; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2054</id>
        <msg>WEB-CGI enter_bug.cgi arbitrary command attempt</msg>
      </rule>
      <rule>
        <bugtraq>3272</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0008</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/enter_bug.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2055</id>
        <msg>WEB-CGI enter_bug.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>6960</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/parse_xml.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2085</id>
        <msg>WEB-CGI parse_xml.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>6960</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 1220</filter1>
        <filter2>flow:to_server,established; content:&quot;/parse_xml.cgi&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2086</id>
        <msg>WEB-CGI streaming server parse_xml.cgi access</msg>
        <nessus>11278</nessus>
      </rule>
      <rule>
        <bugtraq>7444</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/album.pl&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2115</id>
        <msg>WEB-CGI album.pl access</msg>
        <nessus>11581</nessus>
      </rule>
      <rule>
        <bugtraq>2767</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1341</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/chipcfg.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2116</id>
        <msg>WEB-CGI chipcfg.cgi access</msg>
        <url>archives.neohapsis.com/archives/bugtraq/2001-05/0233.html</url>
      </rule>
      <rule>
        <bugtraq>7361</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ikonboard.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2127</id>
        <msg>WEB-CGI ikonboard.cgi access</msg>
        <nessus>11605</nessus>
      </rule>
      <rule>
        <bugtraq>7510</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0217</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/swsrv.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2128</id>
        <msg>WEB-CGI swsrv.cgi access</msg>
        <nessus>11608</nessus>
      </rule>
      <rule>
        <bugtraq>6265</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0749</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CSMailto.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2194</id>
        <msg>WEB-CGI CSMailto.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0346</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/alert.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2195</id>
        <msg>WEB-CGI alert.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1212</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/alert.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2196</id>
        <msg>WEB-CGI catgy.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>5517</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0153</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cvsview2.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2197</id>
        <msg>WEB-CGI cvsview2.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>5517</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0153</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cvslog.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2198</id>
        <msg>WEB-CGI cvslog.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>5517</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0153</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/multidiff.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2199</id>
        <msg>WEB-CGI multidiff.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0423</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dnewsweb.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2200</id>
        <msg>WEB-CGI dnewsweb.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1196</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/edit_action.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2202</id>
        <msg>WEB-CGI edit_action.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0023</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/everythingform.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2203</id>
        <msg>WEB-CGI everythingform.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0263</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezadmin.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2204</id>
        <msg>WEB-CGI ezadmin.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0263</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezboard.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2205</id>
        <msg>WEB-CGI ezboard.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0263</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezman.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2206</id>
        <msg>WEB-CGI ezman.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>6784</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0611</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fileseek.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2207</id>
        <msg>WEB-CGI fileseek.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0230</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fom.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2208</id>
        <msg>WEB-CGI fom.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0288</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/getdoc.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2209</id>
        <msg>WEB-CGI getdoc.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0952</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/global.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2210</id>
        <msg>WEB-CGI global.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0180</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/guestserver.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2211</id>
        <msg>WEB-CGI guestserver.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>6265</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1334</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imageFolio.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2212</id>
        <msg>WEB-CGI imageFolio.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailfile.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2213</id>
        <msg>WEB-CGI mailfile.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0526</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailview.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2214</id>
        <msg>WEB-CGI mailview.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1023</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nsManager.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2215</id>
        <msg>WEB-CGI nsManager.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1283</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/readmail.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2216</id>
        <msg>WEB-CGI readmail.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1283</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/printmail.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2217</id>
        <msg>WEB-CGI printmail.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0346</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/service.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2218</id>
        <msg>WEB-CGI service.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0133</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setpasswd.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2219</id>
        <msg>WEB-CGI setpasswd.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0022</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/simplestmail.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2220</id>
        <msg>WEB-CGI simplestmail.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>4579</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1343</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ws_mail.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2221</id>
        <msg>WEB-CGI ws_mail.cgi access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <bugtraq>7913</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0434</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nph-exploitscanget.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2222</id>
        <msg>WEB-CGI nph-exploitscanget.cgi access</msg>
        <nessus>11740</nessus>
      </rule>
      <rule>
        <bugtraq>4994</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0923</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/csNews.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2223</id>
        <msg>WEB-CGI csNews.cgi access</msg>
        <nessus>11726</nessus>
      </rule>
      <rule>
        <bugtraq>6607</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/psunami.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2224</id>
        <msg>WEB-CGI psunami.cgi access</msg>
        <nessus>11750</nessus>
      </rule>
      <rule>
        <bugtraq>6086</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-1236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gozila.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2225</id>
        <msg>WEB-CGI gozila.cgi access</msg>
        <nessus>11773</nessus>
      </rule>
      <rule>
        <bugtraq>3216</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1150</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgiWebupdate.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2237</id>
        <msg>WEB-MISC cgiWebupdate.exe access</msg>
        <nessus>11722</nessus>
      </rule>
      <rule>
        <bugtraq>1657</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ddicgi.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2242</id>
        <msg>WEB-MISC ddicgi.exe access</msg>
        <nessus>11728</nessus>
      </rule>
      <rule>
        <bugtraq>3583</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0922</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ndcgi.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2243</id>
        <msg>WEB-MISC ndcgi.exe access</msg>
        <nessus>11730</nessus>
      </rule>
      <rule>
        <bugtraq>9038</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/psdoccgi&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2277</id>
        <msg>WEB-MISC PeopleSoft PeopleBooks psdoccgi access</msg>
      </rule>
      <rule>
        <bugtraq>9282</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/quickstore.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2323</id>
        <msg>WEB-CGI quickstore.cgi access</msg>
        <nessus>11975</nessus>
      </rule>
      <rule>
        <bugtraq>8257</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0422</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/view_broadcast.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2387</id>
        <msg>WEB-CGI view_broadcast.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>8257</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0422</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 1220</filter1>
        <filter2>flow:to_server,established; content:&quot;/view_broadcast.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2388</id>
        <msg>WEB-CGI streaming server view_broadcast.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>8095</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whereami.cgi?g=&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2396</id>
        <msg>WEB-CGI CCBill whereami.cgi arbitrary command execution attempt</msg>
        <url>secunia.com/advisories/9191/</url>
      </rule>
      <rule>
        <bugtraq>8095</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whereami.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2397</id>
        <msg>WEB-CGI CCBill whereami.cgi access</msg>
        <url>secunia.com/advisories/9191/</url>
      </rule>
      <rule>
        <bugtraq>9317</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2003-1200</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 3000</filter1>
        <filter2>flow:to_server,established; content:&quot;/form2raw.cgi&quot;; fast_pattern:only; pcre:&quot;/\Wfrom=[^\x3b&amp;\n]{100}/si&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2433</id>
        <msg>WEB-CGI MDaemon form2raw.cgi overflow attempt</msg>
        <url>secunia.com/advisories/10512/</url>
      </rule>
      <rule>
        <bugtraq>9317</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-1200</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/form2raw.cgi&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2434</id>
        <msg>WEB-CGI MDaemon form2raw.cgi access</msg>
        <url>secunia.com/advisories/10512/</url>
      </rule>
      <rule>
        <bugtraq>9861</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/init.emu&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2567</id>
        <msg>WEB-CGI Emumail init.emu access</msg>
        <nessus>12095</nessus>
      </rule>
      <rule>
        <bugtraq>9861</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/emumail.fcgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2568</id>
        <msg>WEB-CGI Emumail emumail.fcgi access</msg>
        <nessus>12095</nessus>
      </rule>
      <rule>
        <bugtraq>11043</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0798</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_maincfgret.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;instancename=&quot;; nocase; http_uri; isdataat:513,relative; pcre:&quot;/instancename=[^&amp;\x3b\r\n]{513}/Usmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2663</id>
        <msg>WEB-CGI WhatsUpGold instancename overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/processit.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2668</id>
        <msg>WEB-CGI processit access</msg>
        <nessus>10649</nessus>
      </rule>
      <rule>
        <bugtraq>3476</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0839</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ibillpm.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2669</id>
        <msg>WEB-CGI ibillpm.pl access</msg>
        <nessus>11083</nessus>
      </rule>
      <rule>
        <bugtraq>3605</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0937</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pgpmail.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2670</id>
        <msg>WEB-CGI pgpmail.pl access</msg>
        <nessus>11070</nessus>
      </rule>
      <rule>
        <bugtraq>9791</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-0347</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/delhomepage.cgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3062</id>
        <msg>WEB-CGI NetScreen SA 5000 delhomepage.cgi access</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2005-0202</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mailman/&quot;; http_uri; content:&quot;.../&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3131</id>
        <msg>WEB-CGI mailman directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>12572</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/awstats.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3463</id>
        <msg>WEB-CGI awstats access</msg>
        <nessus>16456</nessus>
      </rule>
      <rule>
        <bugtraq>12572</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/awstats.pl?&quot;; fast_pattern; nocase; http_uri; content:&quot;update=&quot;; http_uri; pcre:&quot;/update=[^\r\n\x26]+/Ui&quot;; content:&quot;logfile=&quot;; nocase; http_uri; pcre:&quot;/awstats.pl?[^\r\n]*logfile=\x7C/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3464</id>
        <msg>WEB-CGI awstats.pl command execution attempt</msg>
        <nessus>16456</nessus>
      </rule>
      <rule>
        <bugtraq>10812</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/show.pl&quot;; fast_pattern; nocase; http_uri; content:&quot;url=&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3465</id>
        <msg>WEB-CGI RiSearch show.pl proxy attempt</msg>
      </rule>
      <rule>
        <bugtraq>10831</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/math_sum.mscgi&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>3468</id>
        <msg>WEB-CGI math_sum.mscgi access</msg>
        <nessus>14182</nessus>
      </rule>
      <rule>
        <bugtraq>11110</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0799</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/prn&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\/prn\.(asp|cgi|html?)/Ui&quot;; metadata:service http; classtype:attempted-dos;</filter2>
        <id>3469</id>
        <msg>WEB-CGI Ipswitch WhatsUp Gold dos attempt</msg>
        <url>www.secunia.com/advisories/12578/</url>
      </rule>
      <rule>
        <bugtraq>10926</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2221</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/SoftCart.exe&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\/SoftCart.exe\?[^\s]{100}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3638</id>
        <msg>WEB-CGI SoftCart.exe CGI buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>5723</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1483</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db4web_c&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/db4web_c(\.exe)?\/.*(\.\.[\\|\/]|[a-z]\:)/smiU&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3674</id>
        <msg>WEB-CGI db4web_c directory traversal attempt</msg>
        <nessus>11182</nessus>
      </rule>
      <rule>
        <bugtraq>12298</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0116</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/awstats.pl?&quot;; fast_pattern; nocase; http_uri; content:&quot;configdir=&quot;; nocase; http_uri; pcre:&quot;/awstats.pl?[^\r\n]*configdir=\x7C/Ui&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>3813</id>
        <msg>WEB-CGI awstats.pl configdir command execution attempt</msg>
        <nessus>16189</nessus>
      </rule>
      <rule>
        <bugtraq>10721</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ShellExample.cgi&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/ShellExample.cgi\?[^\n\r\&amp;]*\x2a/Ui&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>4128</id>
        <msg>WEB-CGI 4DWebstar ShellExample.cgi information disclosure</msg>
        <url>www.atstake.com/research/advisories/2004/a071304-1.txt</url>
      </rule>
      <rule>
        <bugtraq>2314</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0253</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hsx.cgi&quot;; http_uri; content:&quot;../../&quot;; content:&quot;%00&quot;; distance:1; metadata:service http; classtype:web-application-attack;</filter2>
        <id>803</id>
        <msg>WEB-CGI HyperSeek hsx.cgi directory traversal attempt</msg>
        <nessus>10602</nessus>
      </rule>
      <rule>
        <bugtraq>2492</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0476</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/s.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;tmpl=&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>804</id>
        <msg>WEB-CGI SWSoft ASPSeek Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>969</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-0127</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wsisa.dll/WService=&quot;; fast_pattern; nocase; http_uri; content:&quot;WSMadmin&quot;; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>805</id>
        <msg>WEB-CGI webspeed access</msg>
        <nessus>10304</nessus>
      </rule>
      <rule>
        <bugtraq>1668</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0853</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/YaBB&quot;; fast_pattern; nocase; http_uri; content:&quot;../&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>806</id>
        <msg>WEB-CGI yabb directory traversal attempt</msg>
        <nessus>10512</nessus>
      </rule>
      <rule>
        <bugtraq>649</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0954</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwwboard/passwd.txt&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>807</id>
        <msg>WEB-CGI /wwwboard/passwd.txt access</msg>
        <nessus>10321</nessus>
      </rule>
      <rule>
        <bugtraq>2166</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webdriver&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>808</id>
        <msg>WEB-CGI webdriver access</msg>
        <nessus>10592</nessus>
      </rule>
      <rule>
        <bugtraq>10878</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2004-1456</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;filediff&quot;; fast_pattern; nocase; http_uri; content:&quot;f=&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>8084</id>
        <msg>WEB-CGI CVSTrac filediff function access</msg>
        <nessus>14238</nessus>
        <url>www.kb.cert.org/vuls/id/770816</url>
      </rule>
      <rule>
        <bugtraq>304</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-1063</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whois_raw.cgi?&quot;; http_uri; content:&quot;|0A|&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>809</id>
        <msg>WEB-CGI whois_raw.cgi arbitrary command execution attempt</msg>
        <nessus>10306</nessus>
      </rule>
      <rule>
        <bugtraq>304</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1063</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whois_raw.cgi&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>810</id>
        <msg>WEB-CGI whois_raw.cgi access</msg>
        <nessus>10306</nessus>
      </rule>
      <rule>
        <bugtraq>932</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0066</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; /HTTP/1.&quot;; fast_pattern:only; metadata:service http; classtype:attempted-recon;</filter2>
        <id>811</id>
        <msg>WEB-CGI websitepro path access</msg>
        <nessus>10303</nessus>
      </rule>
      <rule>
        <bugtraq>1102</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0282</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus?about&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>812</id>
        <msg>WEB-CGI webplus version access</msg>
      </rule>
      <rule>
        <bugtraq>1102</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0282</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus?script&quot;; fast_pattern; nocase; http_uri; content:&quot;../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>813</id>
        <msg>WEB-CGI webplus directory traversal</msg>
        <nessus>10367</nessus>
      </rule>
      <rule>
        <bugtraq>2077</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0196</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/websendmail&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>815</id>
        <msg>WEB-CGI websendmail access</msg>
        <nessus>10301</nessus>
      </rule>
      <rule>
        <bugtraq>2728</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0527</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dcboard.cgi&quot;; http_uri; content:&quot;command=register&quot;; content:&quot;%7cadmin&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>817</id>
        <msg>WEB-CGI dcboard.cgi invalid user addition attempt</msg>
        <nessus>10583</nessus>
      </rule>
      <rule>
        <bugtraq>2728</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0527</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dcforum.cgi&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>818</id>
        <msg>WEB-CGI dcforum.cgi access</msg>
        <nessus>10583</nessus>
      </rule>
      <rule>
        <bugtraq>2063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0021</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mmstdod.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>819</id>
        <msg>WEB-CGI mmstdod.cgi access</msg>
        <nessus>10566</nessus>
      </rule>
      <rule>
        <bugtraq>2388</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0308</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/apexec.pl&quot;; http_uri; content:&quot;template=../&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>820</id>
        <msg>WEB-CGI anaconda directory transversal attempt</msg>
        <nessus>10536</nessus>
      </rule>
      <rule>
        <bugtraq>739</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0951</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imagemap.exe?&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>821</id>
        <msg>WEB-CGI imagemap.exe overflow attempt</msg>
        <nessus>10122</nessus>
      </rule>
      <rule>
        <bugtraq>1469</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0670</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cvsweb.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>823</id>
        <msg>WEB-CGI cvsweb.cgi access</msg>
        <nessus>10465</nessus>
      </rule>
      <rule>
        <bugtraq>2026</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0147</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/glimpse&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>825</id>
        <msg>WEB-CGI glimpse access</msg>
        <nessus>10095</nessus>
      </rule>
      <rule>
        <bugtraq>2001</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0264</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htmlscript&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>826</id>
        <msg>WEB-CGI htmlscript access</msg>
        <nessus>10106</nessus>
      </rule>
      <rule>
        <bugtraq>1995</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0266</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/info2www&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>827</id>
        <msg>WEB-CGI info2www access</msg>
        <nessus>10127</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/maillist.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>828</id>
        <msg>WEB-CGI maillist.pl access</msg>
      </rule>
      <rule>
        <bugtraq>686</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0045</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nph-test-cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>829</id>
        <msg>WEB-CGI nph-test-cgi access</msg>
        <nessus>10165</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perl.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>832</id>
        <msg>WEB-CGI perl.exe access</msg>
        <nessus>10173</nessus>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <bugtraq>2024</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0287</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rguest.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>833</id>
        <msg>WEB-CGI rguest.exe access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rwwwshell.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>834</id>
        <msg>WEB-CGI rwwwshell.pl access</msg>
        <url>www.itsecurity.com/papers/p37.htm</url>
      </rule>
      <rule>
        <bugtraq>2003</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/test-cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>835</id>
        <msg>WEB-CGI test-cgi access</msg>
        <nessus>10282</nessus>
      </rule>
      <rule>
        <bugtraq>2265</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1479</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/textcounter.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>836</id>
        <msg>WEB-CGI textcounter.pl access</msg>
        <nessus>11451</nessus>
      </rule>
      <rule>
        <bugtraq>1611</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0769</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/uploader.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>837</id>
        <msg>WEB-CGI uploader.exe access</msg>
        <nessus>10291</nessus>
      </rule>
      <rule>
        <bugtraq>2058</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0176</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webgais&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>838</id>
        <msg>WEB-CGI webgais access</msg>
        <nessus>10300</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0612</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/finger&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>839</id>
        <msg>WEB-CGI finger access</msg>
        <nessus>10071</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1374</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perlshop.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>840</id>
        <msg>WEB-CGI perlshop.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2026</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0147</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/aglimpse&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>842</id>
        <msg>WEB-CGI aglimpse access</msg>
        <nessus>10095</nessus>
      </rule>
      <rule>
        <bugtraq>719</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0066</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/AnForm2&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>843</id>
        <msg>WEB-CGI anform2 access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1180</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/args.bat&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>844</id>
        <msg>WEB-CGI args.bat access</msg>
        <nessus>11465</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/AT-admin.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>845</id>
        <msg>WEB-CGI AT-admin.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2147</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0937</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bnbform.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>846</id>
        <msg>WEB-CGI bnbform.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>1975</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0146</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/campas&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>847</id>
        <msg>WEB-CGI campas access</msg>
        <nessus>10035</nessus>
      </rule>
      <rule>
        <bugtraq>8883</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0174</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/view-source&quot;; fast_pattern; nocase; http_uri; content:&quot;../&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>848</id>
        <msg>WEB-CGI view-source directory traversal</msg>
      </rule>
      <rule>
        <bugtraq>8883</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0174</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/view-source&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>849</id>
        <msg>WEB-CGI view-source access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wais.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>850</id>
        <msg>WEB-CGI wais.pl access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>851</id>
        <msg>WEB-CGI files.pl access</msg>
      </rule>
      <rule>
        <bugtraq>2024</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0467</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wguest.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>852</id>
        <msg>WEB-CGI wguest.exe access</msg>
      </rule>
      <rule>
        <bugtraq>2020</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0934</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/classifieds.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>854</id>
        <msg>WEB-CGI classifieds.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/environ.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>856</id>
        <msg>WEB-CGI environ.cgi access</msg>
      </rule>
      <rule>
        <bugtraq>2056</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0262</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/faxsurvey&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>857</id>
        <msg>WEB-CGI faxsurvey access</msg>
        <nessus>10067</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/filemail.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>858</id>
        <msg>WEB-CGI filemail access</msg>
      </rule>
      <rule>
        <bugtraq>2276</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1179</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/man.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>859</id>
        <msg>WEB-CGI man.sh access</msg>
      </rule>
      <rule>
        <bugtraq>2023</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0233</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/snork.bat&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>860</id>
        <msg>WEB-CGI snork.bat access</msg>
      </rule>
      <rule>
        <bugtraq>898</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0012</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/w3-msql/&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>861</id>
        <msg>WEB-CGI w3-msql access</msg>
        <nessus>10296</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/day5datacopier.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>863</id>
        <msg>WEB-CGI day5datacopier.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1232</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/day5datanotifier.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>864</id>
        <msg>WEB-CGI day5datanotifier.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ksh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>865</id>
        <msg>WEB-CGI ksh access</msg>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <bugtraq>6752</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0291</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/post-query&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>866</id>
        <msg>WEB-CGI post-query access</msg>
      </rule>
      <rule>
        <bugtraq>1808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0970</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/visadmin.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>867</id>
        <msg>WEB-CGI visadmin.exe access</msg>
        <nessus>10295</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rsh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>868</id>
        <msg>WEB-CGI rsh access</msg>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1178</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dumpenv.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>869</id>
        <msg>WEB-CGI dumpenv.pl access</msg>
        <nessus>10060</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/snorkerz.cmd&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>870</id>
        <msg>WEB-CGI snorkerz.cmd access</msg>
      </rule>
      <rule>
        <bugtraq>1817</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0936</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/survey.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>871</id>
        <msg>WEB-CGI survey.cgi access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tcsh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>872</id>
        <msg>WEB-CGI tcsh access</msg>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <bugtraq>2078</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0178</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/win-c-sample.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>875</id>
        <msg>WEB-CGI win-c-sample.exe access</msg>
        <nessus>10008</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rksh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>877</id>
        <msg>WEB-CGI rksh access</msg>
        <url>www.cert.org/advisories/CA-1996-11.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/w3tvars.pm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>878</id>
        <msg>WEB-CGI w3tvars.pm access</msg>
      </rule>
      <rule>
        <bugtraq>3839</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2002-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>879</id>
        <msg>WEB-CGI admin.pl access</msg>
        <url>online.securityfocus.com/archive/1/249355</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/LWGate&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>880</id>
        <msg>WEB-CGI LWGate access</msg>
        <url>www.wiretrip.net/rfp/p/doc.asp/i2/d6.htm</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/archie&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>881</id>
        <msg>WEB-CGI archie access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/flexform&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>883</id>
        <msg>WEB-CGI flexform access</msg>
        <url>www.wiretrip.net/rfp/p/doc.asp/i2/d6.htm</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/www-sql&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>887</id>
        <msg>WEB-CGI www-sql access</msg>
        <url>marc.theaimsgroup.com/?l=bugtraq&amp;m=88704258804054&amp;w=2</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwwadmin.pl&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>888</id>
        <msg>WEB-CGI wwwadmin.pl access</msg>
      </rule>
      <rule>
        <bugtraq>491</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ppdscgi.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>889</id>
        <msg>WEB-CGI ppdscgi.exe access</msg>
        <nessus>10187</nessus>
        <url>online.securityfocus.com/archive/1/16878</url>
      </rule>
      <rule>
        <bugtraq>5286</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2002-0710</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sendform.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>890</id>
        <msg>WEB-CGI sendform.cgi access</msg>
        <url>www.scn.org/help/sendform.txt</url>
      </rule>
      <rule>
        <bugtraq>719</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0066</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/AnyForm2&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>892</id>
        <msg>WEB-CGI AnyForm2 access</msg>
        <nessus>10277</nessus>
      </rule>
      <rule>
        <bugtraq>142</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-hist.sh&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>894</id>
        <msg>WEB-CGI bb-hist.sh access</msg>
        <nessus>10025</nessus>
      </rule>
      <rule>
        <bugtraq>2370</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0214</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/way-board&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>896</id>
        <msg>WEB-CGI way-board access</msg>
        <nessus>10610</nessus>
      </rule>
      <rule>
        <bugtraq>2372</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0217</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pals-cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>897</id>
        <msg>WEB-CGI pals-cgi access</msg>
        <nessus>10611</nessus>
      </rule>
      <rule>
        <bugtraq>2361</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0210</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/commerce.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>898</id>
        <msg>WEB-CGI commerce.cgi access</msg>
        <nessus>10612</nessus>
      </rule>
      <rule>
        <bugtraq>2504</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0272</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sendtemp.pl&quot;; fast_pattern; nocase; http_uri; content:&quot;templ=&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>899</id>
        <msg>WEB-CGI Amaya templates sendtemp.pl directory traversal attempt</msg>
        <nessus>10614</nessus>
      </rule>
      <rule>
        <bugtraq>2362</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webspirs.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;../../&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>900</id>
        <msg>WEB-CGI webspirs.cgi directory traversal attempt</msg>
        <nessus>10616</nessus>
      </rule>
      <rule>
        <bugtraq>2362</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webspirs.cgi&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>901</id>
        <msg>WEB-CGI webspirs.cgi access</msg>
        <nessus>10616</nessus>
      </rule>
      <rule>
        <bugtraq>2381</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0302</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;tstisapi.dll&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>902</id>
        <msg>WEB-CGI tstisapi.dll access</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>220</groupid>
    <groupname>Server / Mail</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>23808</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;content-classescalendarmessage&quot;; fast_pattern:only; pcre:&quot;/^X-MICROSOFT-CDO-MODPROPS\x3A[^\n]*(?P&lt;prop&gt;\w+),[^\n]*(?=prop)/Bmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>11222</id>
        <msg>SMTP Exchange MODPROPS denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-026.mspx</url>
      </rule>
      <rule>
        <bugtraq>17908</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0027</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [25,143]</filter1>
        <filter2>flow:established,to_server; content:&quot;DESCRIPTION|3A|&quot;; nocase; isdataat:268,relative; content:!&quot;|0A|&quot;; within:256; pcre:&quot;/^DESCRIPTION\x3A[^\n]{268}/smi&quot;; metadata:policy security-ips alert, service smtp; classtype:attempted-admin;</filter2>
        <id>12619</id>
        <msg>EXPLOIT Microsoft Exchange ical/vcal malformed property</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-0098</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15301, service smtp, policy security-ips drop;</filter2>
        <id>15301</id>
        <msg>SMTP Exchange compressed RTF remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-003.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-0099</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|15302, policy security-ips drop;</filter2>
        <id>15302</id>
        <msg>DOS Microsoft Exchange System Attendant denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-003.mspx</url>
      </rule>
      <rule>
        <bugtraq>17908</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0027</cve>
        <filter1>tcp $EXTERNAL_NET any &lt;&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15329, service smtp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15329</id>
        <msg>SMTP Microsoft Exchange MODPROPS memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-019.mspx</url>
      </rule>
      <rule>
        <bugtraq>10902</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0203</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;exchange/calendar/pick.asp?view=ppp%22&gt;&lt;/applet&gt;&lt;script&gt;alert|28|%22hi,%20this%20is%20javascript%20here%22|29|&lt;/script&gt;|22|&gt;click this&lt;/a&gt;&quot;; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>15964</id>
        <msg>SPECIFIC-THREATS Microsoft Exchange OWA XSS and spoofing attempt</msg>
      </rule>
      <rule>
        <bugtraq>16197</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0002</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:established,to_server; content:&quot;application/ms-tnef&quot;; nocase; content:&quot;AwMDAwMDQBdXNlckBleGFtcGxlLmNvbQE&quot;; content:&quot;I18jIA+zM2AegCpAPjA&quot;; distance:0; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>17481</id>
        <msg>SPECIFIC-THREATS Microsoft Exchange and Outlook TNEF Decoding Integer Overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 &lt;&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; content:&quot;chkLis&quot;; depth:6; flowbits:set,ABSystemSpy_Inforetrieve1; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7165</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 1</msg>
        <url>www.spywareguide.com/product_show.php?id=591</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 &lt;&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; flowbits:isset,ABSystemSpy_Inforetrieve1; content:&quot;chkShe&quot;; depth:6; flowbits:set,ABSystemSpy_Inforetrieve2; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7166</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 2</msg>
        <url>www.spywareguide.com/product_show.php?id=591</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 &lt;&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; flowbits:isset,ABSystemSpy_Inforetrieve2; content:&quot;chkCli&quot;; depth:6; flowbits:set,ABSystemSpy_Inforetrieve3; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7167</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 3</msg>
        <url>www.spywareguide.com/product_show.php?id=591</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 &lt;&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; flowbits:isset,ABSystemSpy_Inforetrieve3; content:&quot;chkCap&quot;; depth:6; flowbits:set,ABSystemSpy_Inforetrieve4; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7168</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 4</msg>
        <url>www.spywareguide.com/product_show.php?id=591</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 &lt;&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; flowbits:isset,ABSystemSpy_Inforetrieve4; content:&quot;chkCtr&quot;; depth:6;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7169</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076050</url>
      </rule>
    </attacks>
    <groupid>221</groupid>
    <groupname>Server / Mail / Microsoft Exchange</groupname>
    <warnings>
      <rule>
        <bugtraq>6407</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-1359</cve>
        <filter1>tcp $EXTERNAL_NET 22 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established,no_stream; content:&quot;SSH-&quot;; depth:4; isdataat:1000,relative; pcre:&quot;/SSH-0*([2-9]\d*|1\d+)\.[^-]*-[^\n]*\n\x00\x00.{3}\x14.{1000}/s&quot;; classtype:attempted-user;</filter2>
        <id>10010</id>
        <msg>EXPLOIT Putty Server key exchange buffer overflow attempt</msg>
        <url>www.rapid7.com/advisories/R7-0009.html</url>
      </rule>
      <rule>
        <bugtraq>23808</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A| text/calendar&quot;; nocase; pcre:&quot;/BEGIN\x3AVEVENT\x0D\x0A.*X-MICROSOFT-CDO-MODPROPS\x3A[^\n]*X-MICROSOFT-CDO-MODPROPS.+X-MICROSOFT-CDO-MODPROPS\x3A.+END\x3AVEVENT/smi&quot;; metadata:service smtp; classtype:attempted-dos;</filter2>
        <id>14742</id>
        <msg>SPECIFIC-THREATS Exchange MODPROPS denial of service PoC attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-026.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ldr/client01/ldrctl.php&quot;; http_uri; content:&quot;os=&quot;; nocase; content:&quot;ver=&quot;; nocase; content:&quot;idx=&quot;; nocase; content:&quot;user=&quot;; nocase; content:&quot;ioctl=&quot;; nocase; content:&quot;data=&quot;; nocase; pcre:&quot;/os\x3d.*\x26ver\x3d.*\x26idx\x3d.*\x26user\x3d.*\x26ioctl\x3d.*\x26data\x3d.*/smi&quot;; classtype:trojan-activity;</filter2>
        <id>16108</id>
        <msg>BACKDOOR trojan downloader exchanger.gen2 runtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453143306</url>
      </rule>
      <rule>
        <bugtraq>10180</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1945</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL&quot;; fast_pattern:only; pcre:&quot;/^\s*MAIL\s+[^\s\n][^\n]{1006,}/smi&quot;; metadata:service smtp; classtype:misc-attack;</filter2>
        <id>3815</id>
        <msg>SMTP eXchange POP3 mail server overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>1869</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2000-1006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;charset = |22 22|&quot;; nocase; metadata:service smtp; classtype:attempted-dos;</filter2>
        <id>658</id>
        <msg>SMTP exchange mime DOS</msg>
        <nessus>10558</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS00-082.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>222</groupid>
    <groupname>Server / Mail / Sendmail</groupname>
    <warnings>
      <rule>
        <bugtraq>2198</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1044</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/inc/sendmail.inc&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1526</id>
        <msg>WEB-MISC basilix sendmail.inc access</msg>
        <nessus>10601</nessus>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET 113 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|7C|sed|0A|'1,/^|24|/d'|7C|/bin/sh&quot;; nocase; metadata:service ident; classtype:attempted-admin;</filter2>
        <id>15936</id>
        <msg>SPECIFIC-THREATS Sendmail identd command parsing vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>17192</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0058</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:established,to_server; content:&quot;Subject|3A| AAAAAA|CC CC CC CC CC CC|&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>16057</id>
        <msg>SPECIFIC-THREATS sendmail smtp timeout buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SEND FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SEND FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2261</id>
        <msg>SMTP SEND FROM sendmail prescan too many addresses overflow</msg>
        <nessus>11316</nessus>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SEND FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SEND FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200}/smi&quot;; metadata:service smtp; classtype:misc-attack;</filter2>
        <id>2262</id>
        <msg>SMTP SEND FROM sendmail prescan too long addresses overflow</msg>
        <nessus>11499</nessus>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SAML FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SAML FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2263</id>
        <msg>SMTP SAML FROM sendmail prescan too many addresses overflow</msg>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SAML FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SAML FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200}/smi&quot;; metadata:service smtp; classtype:misc-attack;</filter2>
        <id>2264</id>
        <msg>SMTP SAML FROM sendmail prescan too long addresses overflow</msg>
        <nessus>11499</nessus>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SOML FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SOML FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2265</id>
        <msg>SMTP SOML FROM sendmail prescan too many addresses overflow</msg>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SOML FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^SOML FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200}/smi&quot;; metadata:service smtp; classtype:misc-attack;</filter2>
        <id>2266</id>
        <msg>SMTP SOML FROM sendmail prescan too long addresses overflow</msg>
        <nessus>11499</nessus>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^MAIL FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2267</id>
        <msg>SMTP MAIL FROM sendmail prescan too many addresses overflow</msg>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL FROM|3A|&quot;; fast_pattern:only; pcre:&quot;/^MAIL FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200}/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2268</id>
        <msg>SMTP MAIL FROM sendmail prescan too long addresses overflow</msg>
        <nessus>11499</nessus>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;RCPT TO|3A|&quot;; fast_pattern:only; pcre:&quot;/^RCPT TO\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2269</id>
        <msg>SMTP RCPT TO sendmail prescan too many addresses overflow</msg>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0694</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;RCPT TO|3A|&quot;; fast_pattern:only; pcre:&quot;/^RCPT TO\x3a\s*[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200}/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2270</id>
        <msg>SMTP RCPT TO sendmail prescan too long addresses overflow</msg>
        <nessus>11499</nessus>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET 113 -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|D/&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>655</id>
        <msg>SMTP sendmail 8.6.9 exploit</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>1999-0203</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;mail from|3A| |22 7C|&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>662</id>
        <msg>SMTP sendmail 5.5.5 exploit</msg>
        <nessus>10258</nessus>
      </rule>
      <rule>
        <bugtraq>2308</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0203</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL FROM|3A| |7C|/usr/ucb/tail&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>665</id>
        <msg>SMTP sendmail 5.6.5 exploit</msg>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Croot|0D 0A|Mprog, P=/bin/&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>667</id>
        <msg>SMTP sendmail 8.6.10 exploit</msg>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Croot|09 09 09 09 09 09 09|Mprog,P=/bin&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>668</id>
        <msg>SMTP sendmail 8.6.10 exploit</msg>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|Croot|0A|Mprog&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>669</id>
        <msg>SMTP sendmail 8.6.9 exploit</msg>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|C|3A|daemon|0A|R&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>670</id>
        <msg>SMTP sendmail 8.6.9 exploit</msg>
      </rule>
      <rule>
        <bugtraq>2311</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|Croot|0D 0A|Mprog&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>671</id>
        <msg>SMTP sendmail 8.6.9c exploit</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 110</filter1>
        <filter2>flow:to_server, established; content:&quot;STAT&quot;; nocase; flowbits:set,pop3.stat; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>16594</id>
        <msg>POP3 STAT command</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-3837</cve>
        <filter1>tcp any 110 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;-ERR&quot;; isdataat:718,relative; content:!&quot;|0A|&quot;; within:718; metadata:policy security-ips drop, service pop3; classtype:misc-attack;</filter2>
        <id>16799</id>
        <msg>POP3 Eureka Mail 2.2q server error response overflow attempt</msg>
        <url>archives.neohapsis.com/archives/bugtraq/2009-10/0170.html</url>
      </rule>
      <rule>
        <bugtraq>16576</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2618</cve>
        <filter1>tcp $EXTERNAL_NET 110 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Content-Disposition|3A| attachment&quot;; nocase; content:&quot;&lt;a &quot;; nocase; content:&quot;href=&quot;; distance:0; content:!&quot;|3E|&quot;; within:500; pcre:&quot;/&lt;a\s+[^&gt;]*href=[^&gt;]{500}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service pop3; classtype:attempted-user;</filter2>
        <id>17331</id>
        <msg>POP3 Lotus Notes HTML Speed Reader Long URL buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>2535</id>
        <msg>POP3 SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 995 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,sslv3.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,sslv3.server_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>2536</id>
        <msg>POP3 SSLv3 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3499</id>
        <msg>POP3 SSLv2 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&lt;,128,0; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;|00 02|&quot;; depth:2; offset:6; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3500</id>
        <msg>POP3 SSLv2 Client_Hello with pad request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3501</id>
        <msg>POP3 TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|03 01|&quot;; depth:2; offset:3; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3502</id>
        <msg>POP3 TLSv1 Client_Hello via SSLv2 handshake request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 995 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3503</id>
        <msg>POP3 SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 995 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; metadata:service pop3; classtype:protocol-command-decode;</filter2>
        <id>3504</id>
        <msg>POP3 TLSv1 Server_Hello request</msg>
      </rule>
    </attacks>
    <groupid>223</groupid>
    <groupname>Server / Mail / POP3</groupname>
    <warnings>
      <rule>
        <bugtraq>791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6605</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS&quot;; nocase; isdataat:50,relative; pcre:&quot;/^PASS\s[^\n]{50}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1634</id>
        <msg>POP3 PASS overflow attempt</msg>
        <nessus>10325</nessus>
      </rule>
      <rule>
        <bugtraq>1652</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0841</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;APOP&quot;; nocase; isdataat:256,relative; pcre:&quot;/^APOP\s[^\n]{256}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1635</id>
        <msg>POP3 APOP overflow attempt</msg>
        <nessus>10559</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0816</cve>
        <filter1>tcp $EXTERNAL_NET 110 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,pop3.stat; flowbits:unset,pop3.stat; metadata: engine shared, soid 3|16595;</filter2>
        <id>16595</id>
        <msg>POP3 Windows Mail remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-030.mspx</url>
      </rule>
      <rule>
        <bugtraq>789</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4364</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; isdataat:50,relative; pcre:&quot;/^USER\s[^\n]{50}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1866</id>
        <msg>POP3 USER overflow attempt</msg>
        <nessus>10311</nessus>
      </rule>
      <rule>
        <bugtraq>830</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0822</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;AUTH&quot;; nocase; isdataat:50,relative; pcre:&quot;/^AUTH\s[^\n]{50}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1936</id>
        <msg>POP3 AUTH overflow attempt</msg>
        <nessus>10184</nessus>
      </rule>
      <rule>
        <bugtraq>948</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0096</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;LIST&quot;; nocase; isdataat:10,relative; pcre:&quot;/^LIST\s[^\n]{10}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1937</id>
        <msg>POP3 LIST overflow attempt</msg>
        <nessus>10197</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;XTND&quot;; nocase; isdataat:50,relative; pcre:&quot;/^XTND\s[^\n]{50}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>1938</id>
        <msg>POP3 XTND overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;CAPA&quot;; nocase; isdataat:10,relative; pcre:&quot;/^CAPA\s[^\n]{10}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2108</id>
        <msg>POP3 CAPA overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;TOP&quot;; nocase; isdataat:50,relative; pcre:&quot;/^TOP\s[^\n]{50}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2109</id>
        <msg>POP3 TOP overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;STAT&quot;; nocase; isdataat:10,relative; pcre:&quot;/^STAT\s[^\n]{10}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2110</id>
        <msg>POP3 STAT overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;DELE&quot;; nocase; isdataat:10,relative; pcre:&quot;/^DELE\s[^\n]{10}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2111</id>
        <msg>POP3 DELE overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;RSET&quot;; nocase; isdataat:10,relative; pcre:&quot;/^RSET\s[^\n]{10}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2112</id>
        <msg>POP3 RSET overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7445</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-1539</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;DELE&quot;; fast_pattern:only; pcre:&quot;/^DELE\s+-\d/smi&quot;; metadata:service pop3; classtype:misc-attack;</filter2>
        <id>2121</id>
        <msg>POP3 DELE negative argument attempt</msg>
        <nessus>11570</nessus>
      </rule>
      <rule>
        <bugtraq>6053</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-1539</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;UIDL&quot;; fast_pattern:only; pcre:&quot;/^UIDL\s+-\d/smi&quot;; metadata:service pop3; classtype:misc-attack;</filter2>
        <id>2122</id>
        <msg>POP3 UIDL negative argument attempt</msg>
        <nessus>11570</nessus>
      </rule>
      <rule>
        <bugtraq>7667</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0391</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; fast_pattern:only; pcre:&quot;/^USER\s+[^\n]*?%/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2250</id>
        <msg>POP3 USER format string attempt</msg>
        <nessus>11742</nessus>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; fast_pattern:only; detection_filter:track by_dst, count 30, seconds 30; metadata:service pop3; classtype:suspicious-login;</filter2>
        <id>2274</id>
        <msg>POP3 login brute force attempt</msg>
      </rule>
      <rule>
        <bugtraq>9794</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;APOP&quot;; nocase; isdataat:256,relative; pcre:&quot;/^APOP\s+USER\s[^\n]{256}/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2409</id>
        <msg>POP3 APOP USER overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10115</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; content:!&quot;|03|&quot;; depth:1; offset:9; metadata:service pop3; classtype:attempted-dos;</filter2>
        <id>2502</id>
        <msg>POP3 SSLv3 invalid data version attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10116</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0719</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; content:&quot;|01|&quot;; depth:1; offset:2; byte_test:2,&gt;,0,5; byte_test:2,!,0,7; byte_test:2,!,16,7; byte_test:2,&gt;,20,9; content:&quot;|8F|&quot;; depth:1; offset:11; byte_test:2,&gt;,32768,0,relative; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2518</id>
        <msg>POP3 PCT Client_Hello overflow attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isset,sslv3.server_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; metadata:service pop3; classtype:attempted-dos;</filter2>
        <id>2537</id>
        <msg>POP3 SSLv3 invalid Client_Hello attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10976</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS&quot;; fast_pattern:only; pcre:&quot;/^PASS\s+[^\n]*?%/smi&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>2666</id>
        <msg>POP3 PASS format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>133</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;^|0E|1|C0 B0 3B 8D|~|0E 89 FA 89 F9|&quot;; fast_pattern:only; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>286</id>
        <msg>POP3 EXPLOIT x86 BSD overflow</msg>
        <nessus>10196</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;h]^|FF D5 FF D4 FF F5 8B F5 90|f1&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>287</id>
        <msg>POP3 EXPLOIT x86 BSD overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;|D8|@|CD 80 E8 D9 FF FF FF|/bin/sh&quot;; fast_pattern:only; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>288</id>
        <msg>POP3 EXPLOIT x86 Linux overflow</msg>
      </rule>
      <rule>
        <bugtraq>156</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0006</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;V|0E|1|C0 B0 3B 8D|~|12 89 F9 89 F9|&quot;; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>289</id>
        <msg>POP3 EXPLOIT x86 SCO overflow</msg>
      </rule>
      <rule>
        <bugtraq>830</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0822</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 110</filter1>
        <filter2>flow:to_server,established; content:&quot;|E8 D9 FF FF FF|/bin/sh&quot;; fast_pattern:only; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>290</id>
        <msg>POP3 EXPLOIT qpopper overflow</msg>
        <nessus>10184</nessus>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 00 02|&quot;; depth:3; offset:2; byte_test:2, &gt;, 256, 0, relative; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>8429</id>
        <msg>POP3 SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>25831</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; within:1; distance:2; content:&quot;|03 00|&quot;; within:2; distance:3; content:&quot;|00|&quot;; within:1; distance:32; byte_test:2, &gt;, 256, 0, relative; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>8430</id>
        <msg>POP3 SSLv3 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 995</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 03|&quot;; depth:2; offset:2; byte_test:2, &gt;, 256, 1, relative; metadata:service pop3; classtype:attempted-admin;</filter2>
        <id>8431</id>
        <msg>POP3 SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>21723</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-6425</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AP&quot;; nocase; isdataat:256,relative; pcre:&quot;/\sAP[A-Za-z]{4}\s[^\n]{256}/smi&quot;; metadata:policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>10011</id>
        <msg>IMAP Novell NetMail APPEND command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23172</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1675</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTHENTICATE CRAM-MD5&quot;; nocase; content:&quot;|0A|&quot;; within:2; isdataat:364,relative; content:!&quot;|0D 0A|&quot;; within:364; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>11004</id>
        <msg>IMAP CRAM-MD5 authentication method buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>24962</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3925</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;charset&quot;; fast_pattern:only; pcre:&quot;/^\S+\s+(uid\s+|)search\s+charset\s+[^\s]{250}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>12114</id>
        <msg>IMAP Ipswitch IMail search command buffer overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=563</url>
      </rule>
      <rule>
        <bugtraq>24962</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3925</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;charset&quot;; fast_pattern:only; pcre:&quot;/^\S+\s+(uid\s+|)search\s+charset\s*\{\s*/smi&quot;; byte_test:5,&gt;,250,0,string,dec,relative; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>12115</id>
        <msg>IMAP Ipswitch IMail search command buffer overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=563</url>
      </rule>
      <rule>
        <bugtraq>24962</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3925</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;search&quot;; fast_pattern:only; pcre:&quot;/^\S+\s+(uid\s+|)search\s[^\n]*(sent|)(on|before|since)\s*\{\s*/smi&quot;; byte_test:5,&gt;,64,0,string,dec,relative; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>12212</id>
        <msg>IMAP Ipswitch IMail literal search date command buffer overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=563</url>
      </rule>
      <rule>
        <bugtraq>24962</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3925</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;search&quot;; fast_pattern:only; pcre:&quot;/^\S+\s+(uid\s+|)search\s[^\n]*(sent|)(on|before|since)\s+[^\s]{64}/Osmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>12213</id>
        <msg>IMAP Ipswitch IMail search date command buffer overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=563</url>
      </rule>
      <rule>
        <bugtraq>28245</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1358</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;FETCH&quot;; fast_pattern:only; content:&quot;BODY&quot;; content:&quot;[&quot;; isdataat:256,relative; content:!&quot;]&quot;; within:256; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>13663</id>
        <msg>IMAP Alt-N MDaemon IMAP Server FETCH command buffer overflow attempt</msg>
        <url>files.altn.com/MDaemon/Release/RelNotes_en.txt</url>
      </rule>
      <rule>
        <bugtraq>23172</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1675</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTHENTICATE CRAM-MD5&quot;; nocase; content:&quot;|0A|&quot;; within:2; isdataat:300,relative; content:!&quot;|0D 0A|&quot;; within:300; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>15484</id>
        <msg>IMAP CRAM-MD5 authentication method buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0CEA3FB1-7F88-4803-AA8E-AD021566955D&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0CEA3FB1-7F88-4803-AA8E-AD021566955D\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(LicenseKey)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0CEA3FB1-7F88-4803-AA8E-AD021566955D\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(LicenseKey))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16779</id>
        <msg>WEB-ACTIVEX EasyMail IMAP4 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|C|00|E|00|A|00|3|00|F|00|B|00|1|00|-|00|7|00|F|00|8|00|8|00|-|00|4|00|8|00|0|00|3|00|-|00|A|00|A|00|8|00|E|00|-|00|A|00|D|00|0|00|2|00|1|00|5|00|6|00|6|00|9|00|5|00|5|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00C\x00E\x00A\x003\x00F\x00B\x001\x00-\x007\x00F\x008\x008\x00-\x004\x008\x000\x003\x00-\x00A\x00A\x008\x00E\x00-\x00A\x00D\x000\x002\x001\x005\x006\x006\x009\x005\x005\x00D\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16780</id>
        <msg>WEB-ACTIVEX EasyMail IMAP4 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EasyMail.IMAP4&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EasyMail\.IMAP4(\.\d)?\x22|\x27EasyMail\.IMAP4(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*LicenseKey\s*|.*(?P=v)\s*\.\s*LicenseKey\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EasyMail\.IMAP4(\.\d)?\x22|\x27EasyMail\.IMAP4(\.\d)?\x27)\s*\)(\s*\.\s*LicenseKey\s*|.*(?P=n)\s*\.\s*LicenseKey\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16781</id>
        <msg>WEB-ACTIVEX EasyMail IMAP4 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4607</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|a|00|s|00|y|00|M|00|a|00|i|00|l|00|.|00|I|00|M|00|A|00|P|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00a\x00s\x00y\x00M\x00a\x00i\x00l\x00.\x00I\x00M\x00A\x00P\x004\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00a\x00s\x00y\x00M\x00a\x00i\x00l\x00.\x00I\x00M\x00A\x00P\x004\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16782</id>
        <msg>WEB-ACTIVEX EasyMail IMAP4 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>14315</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot; CREATE &quot;; nocase; isdataat:180,relative; pcre:&quot;/^[0-9]+\s+CREATE\s[^\r\n]{180}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-dos;</filter2>
        <id>17239</id>
        <msg>IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14315</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot; CREATE &quot;; nocase; content:&quot;{&quot;; within:5; byte_test:8, &gt;, 180, 0, relative, string; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-dos;</filter2>
        <id>17240</id>
        <msg>IMAP Alt-N MDaemon IMAP server literal CREATE command buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 143 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;WorldMail IMAP4 Server&quot;; fast_pattern:only; nocase; flowbits:set,qualcom.worldmail.ok; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>17327</id>
        <msg>IMAP Qualcomm WorldMail Server Response</msg>
      </rule>
      <rule>
        <bugtraq>15980</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-4267</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; flowbits:isset,qualcom.worldmail.ok; dsize:&gt;668; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>17328</id>
        <msg>IMAP Qualcomm WorldMail IMAP Literal Token Parsing Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>21252</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;login|20 7B|&quot;; depth:7; offset:3; nocase; byte_test:10,&gt;,1023,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17503</id>
        <msg>IMAP MailEnable IMAP Service Invalid Command Buffer Overlow LOGIN</msg>
      </rule>
      <rule>
        <bugtraq>130</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0042</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTHENTICATE&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sAUTHENTICATE\s[^\n]{100}/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>1844</id>
        <msg>IMAP authenticate overflow attempt</msg>
        <nessus>10292</nessus>
      </rule>
      <rule>
        <bugtraq>21724</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-6424</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTH&quot;; fast_pattern:only; nocase; pcre:&quot;/({(?=\d+}[^\n]*?\sAUTH)|AUTH\s[^\n]*?{(?=\d+}))/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>1930</id>
        <msg>IMAP auth literal overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8861</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-1177</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTH&quot;; fast_pattern:only; nocase; pcre:&quot;/AUTH\s[^\n]{100}/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>2330</id>
        <msg>IMAP auth overflow attempt</msg>
        <nessus>11910</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>2529</id>
        <msg>IMAP SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 993 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,sslv3.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,sslv3.server_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>2530</id>
        <msg>IMAP SSLv3 Server_Hello request</msg>
      </rule>
      <rule>
        <bugtraq>10976</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0221</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LOGIN&quot;; fast_pattern:only; nocase; pcre:&quot;/\sLOGIN\s\w+\s\{\d+\}[\r]?\n[^\n]*?%/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>2665</id>
        <msg>IMAP login literal format string attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-026.mspx</url>
      </rule>
      <rule>
        <bugtraq>11775</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;EXAMINE&quot;; fast_pattern:only; pcre:&quot;/\sEXAMINE\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>3067</id>
        <msg>IMAP examine literal overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;EXAMINE&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sEXAMINE\s[^\n]{100}/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>3068</id>
        <msg>IMAP examine overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>11775</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;FETCH&quot;; fast_pattern:only; pcre:&quot;/\sFETCH\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service imap; classtype:misc-attack;</filter2>
        <id>3069</id>
        <msg>IMAP fetch literal overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>26219</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3510</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SUBSCRIBE&quot;; fast_pattern:only; pcre:&quot;/^\w+\s+SUBSCRIBE\s[^\n]*?\{/smi&quot;; byte_test:5,&gt;,256,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>3073</id>
        <msg>IMAP SUBSCRIBE literal overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>26219</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3510</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SUBSCRIBE&quot;; nocase; isdataat:100; pcre:&quot;/^\w+\s+SUBSCRIBE\s[^\n]{100}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service imap; classtype:attempted-admin;</filter2>
        <id>3074</id>
        <msg>IMAP SUBSCRIBE overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3487</id>
        <msg>IMAP SSLv2 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&lt;,128,0; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;|00 02|&quot;; depth:2; offset:6; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3488</id>
        <msg>IMAP SSLv2 Client_Hello with pad request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3489</id>
        <msg>IMAP TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|03 01|&quot;; depth:2; offset:3; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3490</id>
        <msg>IMAP TLSv1 Client_Hello via SSLv2 handshake request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 993 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3491</id>
        <msg>IMAP SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 993 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; metadata:service imap; classtype:protocol-command-decode;</filter2>
        <id>3492</id>
        <msg>IMAP TLSv1 Server_Hello request</msg>
      </rule>
    </attacks>
    <groupid>224</groupid>
    <groupname>Server / Mail / IMAP</groupname>
    <warnings>
      <rule>
        <bugtraq>13764</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1523</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;%&quot;; content:&quot;n&quot;; distance:0; pcre:&quot;/^\S*\x25(\d+\x24)?\d*h?n\s/sm&quot;; classtype:attempted-admin;</filter2>
        <id>12392</id>
        <msg>IMAP GNU Mailutils request tag format string vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>23058</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1578</cve>
        <filter1>tcp any any -&gt; $HOME_NET 143</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13921;</filter2>
        <id>13921</id>
        <msg>IMAP Altrium Software MERCUR IMAPD NTLMSSP command handling memory corruption attempt</msg>
        <url>secunia.com/advisories/24596</url>
      </rule>
      <rule>
        <bugtraq>22792</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0494</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;append&quot;; nocase; pcre:&quot;/^\d+\s+append\s[^\r\n]*\{[^\r\n}]{128}/i&quot;; classtype:attempted-admin;</filter2>
        <id>17369</id>
        <msg>IMAP MailEnable Service APPEND Command Handling Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>4713</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0379</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;PARTIAL&quot;; nocase; content:&quot;BODY[&quot;; distance:0; nocase; isdataat:1024,relative; pcre:&quot;/\sPARTIAL.*?BODY\[[^\]]{1024}/smi&quot;; classtype:misc-attack;</filter2>
        <id>1755</id>
        <msg>IMAP partial body buffer overflow attempt</msg>
        <nessus>10966</nessus>
      </rule>
      <rule>
        <bugtraq>502</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2795</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LOGIN&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sLOGIN\s[^\n]{100}/i&quot;; classtype:attempted-user;</filter2>
        <id>1842</id>
        <msg>IMAP login buffer overflow attempt</msg>
        <nessus>10125</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LIST&quot;; fast_pattern:only; pcre:&quot;/\sLIST\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>1845</id>
        <msg>IMAP list literal overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;LSUB&quot;; fast_pattern:only; pcre:&quot;/\sLSUB\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>1902</id>
        <msg>IMAP lsub literal overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;RENAME&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sRENAME\s[^\n]{100}/smi&quot;; classtype:misc-attack;</filter2>
        <id>1903</id>
        <msg>IMAP rename overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;FIND&quot;; nocase; isdataat:100,relative; pcre:&quot;/^\sFIND\s[^\n]{100}/smi&quot;; classtype:misc-attack;</filter2>
        <id>1904</id>
        <msg>IMAP find overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>6298</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-6424</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LOGIN&quot;; fast_pattern:only; pcre:&quot;/\sLOGIN\s[^\n]*?\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:service imap; classtype:misc-attack;</filter2>
        <id>1993</id>
        <msg>IMAP login literal buffer overflow attempt</msg>
        <nessus>12532</nessus>
      </rule>
      <rule>
        <bugtraq>4713</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0379</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;PARTIAL&quot;; nocase; content:&quot;BODY.PEEK[&quot;; distance:0; nocase; pcre:&quot;/\sPARTIAL.*BODY\.PEEK\[[^\]]{1024}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>2046</id>
        <msg>IMAP partial body.peek buffer overflow attempt</msg>
        <nessus>10966</nessus>
      </rule>
      <rule>
        <bugtraq>21724</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-6424</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;AUTHENTICATE&quot;; fast_pattern:only; nocase; pcre:&quot;/\sAUTHENTICATE\s[^\n]*?\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:service imap; classtype:misc-attack;</filter2>
        <id>2105</id>
        <msg>IMAP authenticate literal overflow attempt</msg>
        <nessus>10292</nessus>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;LSUB&quot;; isdataat:100,relative; pcre:&quot;/\sLSUB\s[^\n]{100}/smi&quot;; classtype:misc-attack;</filter2>
        <id>2106</id>
        <msg>IMAP lsub overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>7446</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;CREATE&quot;; isdataat:1024,relative; pcre:&quot;/\sCREATE\s[^\n]{1024}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>2107</id>
        <msg>IMAP create buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LIST&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sLIST\s[^\n]{100}/smi&quot;; classtype:misc-attack;</filter2>
        <id>2118</id>
        <msg>IMAP list overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;RENAME&quot;; fast_pattern:only; pcre:&quot;/\sRENAME\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>2119</id>
        <msg>IMAP rename literal overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>7446</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;CREATE&quot;; fast_pattern:only; pcre:&quot;/\sCREATE\s*\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; metadata:service imap; classtype:misc-attack;</filter2>
        <id>2120</id>
        <msg>IMAP create literal buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:to_server,established; content:&quot;LOGIN&quot;; fast_pattern:only; detection_filter:track by_dst, count 30, seconds 30; metadata:service imap; classtype:suspicious-login;</filter2>
        <id>2273</id>
        <msg>IMAP login brute force attempt</msg>
      </rule>
      <rule>
        <bugtraq>10115</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; content:!&quot;|03|&quot;; depth:1; offset:9; metadata:service imap; classtype:attempted-dos;</filter2>
        <id>2497</id>
        <msg>IMAP SSLv3 invalid data version attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isset,sslv3.server_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; metadata:service imap; classtype:attempted-dos;</filter2>
        <id>2531</id>
        <msg>IMAP SSLv3 invalid Client_Hello attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10976</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LOGIN&quot;; fast_pattern:only; nocase; pcre:&quot;/\sLOGIN\s[^\n]*?%/smi&quot;; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>2664</id>
        <msg>IMAP login format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;DELETE&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sDELETE\s[^\n]{100}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>3007</id>
        <msg>IMAP delete overflow attempt</msg>
        <nessus>15771</nessus>
      </rule>
      <rule>
        <bugtraq>11675</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1520</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;DELETE&quot;; fast_pattern:only; nocase; pcre:&quot;/\sDELETE\s[^\n]*?\{/smi&quot;; byte_test:5,&gt;,100,0,string,dec,relative; metadata:service imap; classtype:misc-attack;</filter2>
        <id>3008</id>
        <msg>IMAP delete literal overflow attempt</msg>
        <nessus>15771</nessus>
      </rule>
      <rule>
        <bugtraq>1110</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0284</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;COPY&quot;; fast_pattern:only; nocase; pcre:&quot;/\sCOPY\s[^\n]*?\{/smi&quot;; byte_test:5,&gt;,1024,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>3058</id>
        <msg>IMAP copy literal overflow attempt</msg>
        <nessus>10374</nessus>
      </rule>
      <rule>
        <bugtraq>21729</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-6425</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;APPEND&quot;; nocase; isdataat:256,relative; pcre:&quot;/\sAPPEND\s[^\n]{256}/smi&quot;; classtype:misc-attack;</filter2>
        <id>3066</id>
        <msg>IMAP append overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>11775</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;FETCH&quot;; nocase; isdataat:256,relative; pcre:&quot;/\sFETCH\s[^\n]{256}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>3070</id>
        <msg>IMAP fetch overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>15491</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;STATUS&quot;; fast_pattern:only; pcre:&quot;/\sSTATUS[^\n]*?\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>3071</id>
        <msg>IMAP status literal overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>15491</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3314</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;STATUS&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sSTATUS[^\n]{100}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>3072</id>
        <msg>IMAP status overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>11775</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-1211</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;UNSUBSCRIBE&quot;; fast_pattern:only; pcre:&quot;/\sUNSUBSCRIBE\s[^\n]*?\s\{/smi&quot;; byte_test:5,&gt;,256,0,string,dec,relative; classtype:misc-attack;</filter2>
        <id>3075</id>
        <msg>IMAP unsubscribe literal overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;UNSUBSCRIBE&quot;; nocase; isdataat:100; pcre:&quot;/^\w+\s+UNSUBSCRIBE\s[^\n]{100}/smi&quot;; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>3076</id>
        <msg>IMAP UNSUBSCRIBE overflow attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>10976</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SEARCH&quot;; fast_pattern:only; pcre:&quot;/\sSEARCH\s[^\n]*?%/smi&quot;; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>4645</id>
        <msg>IMAP search format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>10976</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SEARCH&quot;; fast_pattern:only; pcre:&quot;/\sSEARCH\s\w+\s\{\d+\}[\r]?\n[^\n]*?%/smi&quot;; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>4646</id>
        <msg>IMAP search literal format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;DELETE&quot;; fast_pattern:only; pcre:&quot;/\sDELETE\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5696</id>
        <msg>IMAP delete directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;EXAMINE&quot;; fast_pattern:only; pcre:&quot;/\sEXAMINE\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5697</id>
        <msg>IMAP examine directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LIST&quot;; fast_pattern:only; pcre:&quot;/\sLIST\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5698</id>
        <msg>IMAP list directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;LSUB&quot;; fast_pattern:only; pcre:&quot;/\sLSUB\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5699</id>
        <msg>IMAP lsub directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;RENAME&quot;; fast_pattern:only; pcre:&quot;/\sRENAME\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5700</id>
        <msg>IMAP rename directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;STATUS&quot;; fast_pattern:only; pcre:&quot;/\sSTATUS\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5701</id>
        <msg>IMAP status directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>26219</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3510</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SUBSCRIBE&quot;; fast_pattern:only; pcre:&quot;/^\w+\s+SUBSCRIBE\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>5702</id>
        <msg>IMAP SUBSCRIBE directory traversal attempt</msg>
        <nessus>15867</nessus>
      </rule>
      <rule>
        <bugtraq>15488</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3189</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;UNSUBSCRIBE&quot;; fast_pattern:only; pcre:&quot;/\sUNSUBSCRIBE\s*\S*\x2e\x2e\x2f/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5703</id>
        <msg>IMAP unsubscribe directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-1255</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;SELECT&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sSELECT\s[^\n]{100}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5704</id>
        <msg>IMAP SELECT overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15006</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-3155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 143</filter1>
        <filter2>flow:established,to_server; content:&quot;CAPABILITY&quot;; nocase; isdataat:100,relative; pcre:&quot;/\sCAPABILITY\s[^\n]{100}/smi&quot;; metadata:service imap; classtype:misc-attack;</filter2>
        <id>5705</id>
        <msg>IMAP CAPABILITY overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 00 02|&quot;; depth:3; offset:2; byte_test:2, &gt;, 256, 0, relative; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>8438</id>
        <msg>IMAP SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>25831</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 993</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; within:1; distance:2; content:&quot;|03 00|&quot;; within:2; distance:3; content:&quot;|00|&quot;; within:1; distance:32; byte_test:2, &gt;, 256, 0, relative; metadata:service imap; classtype:attempted-admin;</filter2>
        <id>8439</id>
        <msg>IMAP SSLv3 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>21931</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0033</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;DTSTART|3B|&quot;; nocase; content:!&quot;value&quot;; within:5; nocase; content:!&quot;TZID&quot;; within:4; nocase; pcre:&quot;/^DTSTART\x3B/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>10012</id>
        <msg>SMTP Microsoft Outlook VEVENT non-TZID overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-003.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i45MQBVUFghDQkCCOqHqPmgGbzTU9IAAA1jAAAArAAAJgAACeJY&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10065</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCOoZ0r3G4BoF+sIAADJgAAAArAAAJgAAuru3&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10066</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA71DL&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10067</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA7xSw&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10068</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA78Ej&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10069</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA73lo&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10070</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA7/dT&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10071</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA7+1C&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10072</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCEgAH0PRKH5o+uIAAF5sAAAAwgAAJgAAVW0u&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10073</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCEgAH0PRKH5o+uIAAF5sAAAAwgAAJgAAVee+&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10074</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCCaI2wFrGFEtU9IAAA5jAAAArAAAJgAALEir&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10075</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCCaI2wFrGFEtU9IAAA5jAAAArAAAJgAALNBp&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10076</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCCaI2wFrGFEtU9IAAA5jAAAArAAAJgAALNfY&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10077</id>
        <msg>SPECIFIC-THREATS Trojan Peacomm smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i45MQBVUFghDQkICKDx6PZ9cWtlZzUVAMY0AAAAZAAAJgAAqwTm&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10078</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i45MQBVUFghDQkICEywTzzbc2+gVYUVAIGpAAAA2AAAJgAARIj9&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10079</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i45MQBVUFghDQkICEywTzzbc2+gVYUVAIGpAAAA2AAAJgAARC1i&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10080</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA7/2n&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10081</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i4wMwBVUFghDQkCCHAOKRNyQeuyBeMAAHBsAAAAwgAAJgAA76VO&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10082</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i45MQBVUFghDQkCCOqHqPmgGbzTU9IAAA1jAAAArAAAJgAACWwe&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10083</id>
        <msg>SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Beyond&quot;; distance:0; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; content:&quot;Report&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*Beyond\s+Keylogger\s+Report\x2E\s+Id\x3d\x5b.*\x5d/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10088</id>
        <msg>SPYWARE-PUT Keylogger beyond Keylogger runtime detection - log sent by smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097340</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;|28 29|&quot;; distance:0; nocase; content:&quot;DivXProGainBundle&quot;; nocase; content:&quot;Registration&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*\x28\x29/smi&quot;; pcre:&quot;/DivXProGainBundle\s+registration/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10453</id>
        <msg>BACKDOOR zalivator 1.4.2 pro runtime detection - smtp notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084203</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Report&quot;; distance:0; nocase; content:&quot;from&quot;; distance:0; nocase; content:&quot;ChildWebGuardian&quot;; distance:0; nocase; content:&quot;filename=|22|report.html|22|&quot;; fast_pattern:only; pcre:&quot;/^Subject\x3a[^\r\n]*Report[^\r\n]*from[^\r\n]*ChildWebGuardian/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>11305</id>
        <msg>SPYWARE-PUT Snoopware childwebguardian runtime detection - send log through smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453099134</url>
      </rule>
      <rule>
        <bugtraq>27835</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2007-6593</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Disposition|3A|&quot;; content:&quot;.123&quot;; pcre:&quot;/filename\s*=[^\n]*\.123/si&quot;; metadata:policy security-ips drop, service smtp; classtype:suspicious-filename-detect;</filter2>
        <id>12807</id>
        <msg>SMTP Lotus 123 file attachment</msg>
        <url>www.coresecurity.com/index.php5?action=item&amp;id=2008</url>
      </rule>
      <rule>
        <bugtraq>4204</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0055</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13718, policy security-ips drop, service smtp;</filter2>
        <id>13718</id>
        <msg>SMTP BDAT buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms02-012.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-2247</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|13894, policy security-ips drop;</filter2>
        <id>13894</id>
        <msg>SMTP Microsoft Outlook Web Access From field cross-site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-039.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-2248</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|13895, service smtp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13895</id>
        <msg>SMTP Microsoft Outlook Web Access invalid CSS escape sequence script execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>18630</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-3277</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;HELO &quot;; depth:5; content:&quot;|00|&quot;; within:2; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>13923</id>
        <msg>SMTP MailEnable SMTP HELO command denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_client,established; content:&quot;JBIG2Decode&quot;; nocase; content:&quot;stream&quot;; distance:0; pcre:&quot;/JBIG2Decode.*?stream(\x0d\x0a|\x0a|\x0d)/smi&quot;; byte_test:1, &amp;, 64, 4, relative; byte_test:1, &lt;, 160, 5, relative; byte_test:4, &gt;, 35256, 6, relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15358</id>
        <msg>SMTP Adobe PDF JBIG2 remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;KQklHMkRlY29kZ&quot;; pcre:&quot;/[A-Za-z0-9_\x2f][A-Za-z0-9_\x2f][BFJNRVZdhlptx159]KQklHMkRlY29kZ[QRSTUVWXYZabcdef][A-Za-z0-9_\x2f][A-Za-z0-9_\x2f]/&quot;; flowbits:set,email.pdf.jbig2decode; flowbits:noalert;  flowbits:isset,email.pdf.javascript; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15359</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent via email</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;KYXZhU2NyaXB0&quot;; pcre:&quot;/[A-Za-z0-9_\x2f][A-Za-z0-9_\x2f][BFJNRVZdhlptx159]KYXZhU2NyaXB0/&quot;; flowbits:set,email.pdf.javascript; flowbits:noalert;  flowbits:isset,email.pdf.jbig2decode; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15360</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent in email</msg>
      </rule>
      <rule>
        <bugtraq>18381</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1193</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;text/html&quot;; distance:0; nocase; pcre:&quot;/\x3c[^\x3e]*\x00[^\x3e]*\x3e/Rsmi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15367</id>
        <msg>SMTP outlook web access script injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>895</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0042</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;HELO&quot;; nocase; isdataat:500,relative; pcre:&quot;/^HELO\s[^\n]{500}/smi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>1549</id>
        <msg>SMTP HELO overflow attempt</msg>
        <nessus>11674</nessus>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;pCSUcyRGVjb2Rl&quot;; pcre:&quot;/[A-Za-z0-9_\x2f][EUk0]pCSUcyRGVjb2Rl/&quot;; flowbits:set,email.pdf.jbig2decode; flowbits:noalert;  flowbits:isset,email.pdf.javascript; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15494</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent from email</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;SkJJRzJEZWNvZZ&quot;; pcre:&quot;/SkJJRzJEZWNvZZ[UVWX][A-Za-z0-9_\x2f]/&quot;; flowbits:set,email.pdf.jbig2decode; flowbits:noalert;  flowbits:isset,email.pdf.javascript; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15495</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent by email</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;phdmFTY3Jpcc&quot;; pcre:&quot;/[A-Za-z0-9_\x2f][EUk0]phdmFTY3Jpcc[QRST][A-Za-z0-9_\x2f]/&quot;; flowbits:set,email.pdf.javascript; flowbits:noalert;  flowbits:isset,email.pdf.jbig2decode; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15496</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent through email</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,email.pdf; content:&quot;SmF2YVNjcmlwd&quot;; pcre:&quot;/SmF2YVNjcmlwd[ABCDEFGHIJKLMNOP][A-Za-z0-9_\x2f][A-Za-z0-9_\x2f]/&quot;; flowbits:set,email.pdf.javascript; flowbits:noalert;  flowbits:isset,email.pdf.jbig2decode; flowbits:unset,email.pdf.jbig2decode; flowbits:unset,email.pdf.javascript; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15497</id>
        <msg>SMTP Suspicious JBIG2 pdf file sent with email</msg>
      </rule>
      <rule>
        <bugtraq>7506</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0399</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL&quot;; nocase; content:&quot;FROM&quot;; distance:1; nocase; content:&quot;|3A|&quot;; distance:0; nocase; isdataat:260; content:!&quot;|0A|&quot;; within:260; pcre:&quot;/^\s*MAIL\s+FROM\s*\x3A\s*\x3C?\s*[^\x3E\s]{257}\s*/mi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>15574</id>
        <msg>SMTP MAIL FROM command overflow attempt</msg>
        <url>www.guninski.com/exim1.html</url>
      </rule>
      <rule>
        <bugtraq>20091</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4616</cve>
        <filter1>tcp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 01|Q|80 04|9|06|v=spf1|0A|AAAAAAAAAA|0A|AAAAAAAAAA&quot;; metadata:policy security-ips drop, service dns; classtype:attempted-admin;</filter2>
        <id>16025</id>
        <msg>SPECIFIC-THREATS MailEnable SMTP service SPF lookup buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35065</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1636</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AUTH&quot;; nocase; content:&quot;LOGIN&quot;; distance:0; nocase; pcre:&quot;/^\s*AUTH\s+LOGIN[^\x0a\x0d]{100,}(?&lt;!\x0d)\x0a/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>16193</id>
        <msg>SMTP Novell GroupWise Internet Agent SMTP AUTH LOGIN command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15752</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2931</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL FROM|3A|c|3A 07|ppsipswitchstuser@%s%s%n%s%s%s&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>16201</id>
        <msg>SPECIFIC-THREATS Ipswitch Collaboration Suite SMTP format string exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>33560</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0410</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;RCPT TO|3A|&quot;; nocase; isdataat:256,relative; pcre:&quot;/^RCPT\x20TO\x3a\s*\x3c?[^\r\n\x3e]{256}(\x3e|\x0d|\x0a)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>16515</id>
        <msg>SMTP Novell Groupwise Internet Agent RCPT command overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-0024</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $SMTP_SERVERS any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16534, service dns, policy security-ips drop;</filter2>
        <id>16534</id>
        <msg>DOS Windows Server2000/2003/2008 SMTP service DNS MX lookup denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>35064</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1636</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MAIL&quot;; nocase; content:&quot;FROM&quot;; distance:0; nocase; pcre:&quot;/^\s*MAIL\s*FROM\s*\x3a\s*(\x3c[\x3e]*\x3e|\S+)\s+[^\x09\x0a\x0d\x20\x3d]{40}/mi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>16597</id>
        <msg>SMTP Novell GroupWise Internet Agent Email address processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0266</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17034, service smtp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17034</id>
        <msg>SMTP Outlook AttachMethods local file execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0266</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17035, service smtp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17035</id>
        <msg>SMTP Outlook AttachMethods local file execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0266</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17036, service smtp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17036</id>
        <msg>SMTP Outlook AttachMethods local file execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F8D07B72-B4B4-46A0-ACC0-C771D4614B82&quot;; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F8D07B72-B4B4-46A0-ACC0-C771D4614B82\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(AddAttachments)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F8D07B72-B4B4-46A0-ACC0-C771D4614B82\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddAttachments))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17099</id>
        <msg>WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX clsid access</msg>
        <url>osvdb.org/show/osvdb/64839</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|8|00|D|00|0|00|7|00|B|00|7|00|2|00|-|00|B|00|4|00|B|00|4|00|-|00|4|00|6|00|A|00|0|00|-|00|A|00|C|00|C|00|0|00|-|00|C|00|7|00|7|00|1|00|D|00|4|00|6|00|1|00|4|00|B|00|8|00|2|00|&quot;; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x008\x00D\x000\x007\x00B\x007\x002\x00-\x00B\x004\x00B\x004\x00-\x004\x006\x00A\x000\x00-\x00A\x00C\x00C\x000\x00-\x00C\x007\x007\x001\x00D\x004\x006\x001\x004\x00B\x008\x002\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17100</id>
        <msg>WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX clsid unicode access</msg>
        <url>osvdb.org/show/osvdb/64839</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AOSMTP.Mail&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AOSMTP\.Mail(\.\d)?\x22|\x27AOSMTP\.Mail(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddAttachments\s*|.*(?P=v)\s*\.\s*AddAttachments\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AOSMTP\.Mail(\.\d)?\x22|\x27AOSMTP\.Mail(\.\d)?\x27)\s*\)(\s*\.\s*AddAttachments\s*|.*(?P=n)\s*\.\s*AddAttachments\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17101</id>
        <msg>WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX function call access</msg>
        <url>osvdb.org/show/osvdb/64839</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|O|00|S|00|M|00|T|00|P|00|.|00|M|00|a|00|i|00|l|00|&quot;; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00O\x00S\x00M\x00T\x00P\x00.\x00M\x00a\x00i\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00O\x00S\x00M\x00T\x00P\x00.\x00M\x00a\x00i\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17102</id>
        <msg>WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX function call unicode access</msg>
        <url>osvdb.org/show/osvdb/64839</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-2728</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17251, service smtp, policy security-ips drop;</filter2>
        <id>17251</id>
        <msg>SMTP Outlook RTF remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-064.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;Content-Disposition|3A|&quot;; nocase; content:&quot;attachment&quot;; distance:0; nocase; pcre:&quot;/^Content-Disposition\x3A\s*attachment/smi&quot;; flowbits:set,smtp.contenttype.attachment; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>17332</id>
        <msg>SMTP Content-Disposition attachment</msg>
      </rule>
      <rule>
        <bugtraq>16576</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2618</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; flowbits:isset,smtp.contenttype.attachment; content:&quot;|0D 0A 0D 0A|begin|20|&quot;; isdataat:278,relative; content:!&quot;end|0D 0A|&quot;; within:278; nocase; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17333</id>
        <msg>SMTP Lotus Notes Attachment Viewer UUE file buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>20290</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5176</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17693, service smtp, policy security-ips alert;</filter2>
        <id>17693</id>
        <msg>SMTP MailEnable NTLM Authentication buffer overflow attempt</msg>
        <url>secunia.com/advisories/22179/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3746</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17697, service smtp, policy security-ips drop;</filter2>
        <id>17697</id>
        <msg>SMTP GnuPG Message Packet Length overflow attempt</msg>
        <url>secunia.com/advisories/21297/</url>
      </rule>
      <rule>
        <bugtraq>26200</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4222</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;input &quot;; nocase; isdataat:128,relative; pcre:&quot;/&lt;input\s+[^&gt;]*?name\s*=\s*(3D=)?[^\x20]{128}/smi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17717</id>
        <msg>SMTP IBM Lotus Notes HTML input tag buffer overflow attempt</msg>
        <url>www-1.ibm.com/support/docview.wss?rs=477&amp;uid=swg21272930</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Transfer-Encoding&quot;; nocase; content:&quot;|3A|&quot;; distance:0; isdataat:100,relative; content:!&quot;|0A|&quot;; within:100; pcre:&quot;/^\s*Content-Transfer-Encoding\s*\x3A\s*[^\n]{100}/mi&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>2183</id>
        <msg>SMTP Content-Transfer-Encoding overflow attempt</msg>
        <url>www.cert.org/advisories/CA-2003-12.html</url>
      </rule>
      <rule>
        <bugtraq>8838</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0714</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;XEXCH50&quot;; fast_pattern:only; pcre:&quot;/^XEXCH50\s+-\d/smi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>2253</id>
        <msg>SMTP XEXCH50 overflow attempt</msg>
        <nessus>11889</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS03-046.mspx</url>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;EXPN&quot;; nocase; isdataat:255,relative; pcre:&quot;/^EXPN[^\n]{255}/smi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>2259</id>
        <msg>SMTP EXPN overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7230</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0161</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;VRFY&quot;; nocase; isdataat:255,relative; pcre:&quot;/^VRFY[^\n]{255}/smi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>2260</id>
        <msg>SMTP VRFY overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;STARTTLS&quot;; pcre:&quot;/^STARTTLS/smi&quot;; flowbits:set,starttls.attempt; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>2527</id>
        <msg>SMTP STARTTLS attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>2542</id>
        <msg>SMTP SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $SMTP_SERVERS 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,sslv3.client_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,sslv3.server_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>2543</id>
        <msg>SMTP SSLv3 Server_Hello request</msg>
      </rule>
      <rule>
        <bugtraq>7419</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0113</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type&quot;; nocase; content:&quot;|3A|&quot;; distance:0; pcre:&quot;/^\s*Content-Type\s*\x3A\s*[^\r\n]{300}/mi&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>3461</id>
        <msg>SMTP Content-Type overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-015.mspx</url>
      </rule>
      <rule>
        <bugtraq>7419</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0113</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Encoding&quot;; nocase; content:&quot;|3A|&quot;; distance:0; pcre:&quot;/^\s*Content-Encoding\s*\x3A\s*[^\r\n]{300}/mi&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>3462</id>
        <msg>SMTP Content-Encoding overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-015.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3493</id>
        <msg>SMTP SSLv2 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&lt;,128,0; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;|00 02|&quot;; depth:2; offset:6; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3494</id>
        <msg>SMTP SSLv2 Client_Hello with pad request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3495</id>
        <msg>SMTP TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|03 01|&quot;; depth:2; offset:3; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3496</id>
        <msg>SMTP TLSv1 Client_Hello via SSLv2 handshake request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $SMTP_SERVERS 465 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3497</id>
        <msg>SMTP SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $SMTP_SERVERS 465 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>3498</id>
        <msg>SMTP TLSv1 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|03 01|&quot;; depth:2; offset:3; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5685</id>
        <msg>SMTP TLSv1 Client_Hello via SSLv2 handshake request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $SMTP_SERVERS 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5686</id>
        <msg>SMTP TLSv1 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5687</id>
        <msg>SMTP SSLv2 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&lt;,128,0; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;|00 02|&quot;; depth:2; offset:6; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5688</id>
        <msg>SMTP SSLv2 Client_Hello with pad request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5689</id>
        <msg>SMTP TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5690</id>
        <msg>SMTP SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $SMTP_SERVERS 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>5691</id>
        <msg>SMTP SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Sender|3A| ActMon&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5790</id>
        <msg>SPYWARE-PUT Keylogger pc actmon pro runtime detection - smtp</msg>
        <url>www.spywareguide.com/product_show.php?id=1989</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Computer IP Address|3A|&quot;; nocase; content:&quot;Attached to this email are the activity logs that you have requested&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5880</id>
        <msg>SPYWARE-PUT Keylogger spyagent runtime detect - smtp delivery</msg>
        <url>www.spywareguide.com/product_show.php?id=22</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;|BA DA B0 B5 CC EC CA B9| 2.41 &quot;; distance:0; nocase; pcre:&quot;/^Subject\x3A[^\r\n]*2\x2E41/smi&quot;; flowbits:set,DKangel_Email; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6125</id>
        <msg>BACKDOOR dkangel runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076278</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,DKangel_Email; content:&quot;yyt_hac&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6126</id>
        <msg>BACKDOOR dkangel runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076278</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;===========&gt;&quot;; nocase; content:&quot;WinSession Logger&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6207</id>
        <msg>SPYWARE-PUT Keylogger winsession runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097713</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;Im&quot;; distance:0; nocase; content:&quot;Online&quot;; distance:0; nocase; content:&quot;&lt;msn@msn.com&gt;&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Im&quot;; distance:0; nocase; content:&quot;Version|3A|&quot;; distance:0; nocase; content:&quot;CIA&quot;; distance:0; nocase; content:&quot;1.3&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3A[^\r\n]*Im\s+Online\s+\d+\x2E\d+\x2E\d+\x2E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6301</id>
        <msg>BACKDOOR cia 1.3 runtime detection - smtp notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076260</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;from|3A|&quot;; nocase; content:&quot;HTTP_RAT_&quot;; distance:0; nocase; content:&quot;subject|3A|&quot;; distance:0; nocase; content:&quot;there&quot;; distance:0; nocase; content:&quot;is&quot;; distance:0; nocase; content:&quot;a&quot;; distance:0; nocase; content:&quot;HTTPRAT&quot;; distance:0; nocase; content:&quot;waiting&quot;; distance:0; nocase; content:&quot;4&quot;; distance:0; nocase; content:&quot;u&quot;; distance:0; nocase; content:&quot;on&quot;; distance:0; nocase; pcre:&quot;/^FROM|3A|\s+HTTP_RAT_.*SUBJECT|3A|\s+there\s+is\s+a\s+HTTPRAT\s+waiting\s+4\s+u\s+on/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6397</id>
        <msg>BACKDOOR http rat runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076346</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-OEM|3A|&quot;; nocase; content:&quot;iOpus&quot;; distance:0; nocase; content:&quot;Software&quot;; distance:0; nocase; content:&quot;GmbH&quot;; distance:0; nocase; content:&quot;X-Sender|3A|&quot;; nocase; content:&quot;iOpus&quot;; distance:0; nocase; content:&quot;Software&quot;; distance:0; nocase; content:&quot;GmbH&quot;; distance:0; nocase; pcre:&quot;/^X-OEM\x3A[^\r\n]*iOpus\s+Software\s+GmbH.*X-Sender\x3A[^\r\n]*iOpus\s+Software\s+GmbH/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6477</id>
        <msg>SPYWARE-PUT Hacker-Tool beee runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060657</url>
      </rule>
      <rule>
        <bugtraq>9696</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0410</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;rcpt to|3A|&quot;; nocase; isdataat:256,relative; pcre:&quot;/^RCPT TO\x3a\s*\x3c?[^\n\x3e]{256}/im&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>654</id>
        <msg>SMTP RCPT TO overflow</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A| |22|007 Spy Agent|22|&quot;; nocase; content:&quot;Subject|3A| 007 Monitoring Log Report&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7184</id>
        <msg>SPYWARE-PUT Keylogger 007 spy software runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082794</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;title&gt;&quot;; nocase; content:&quot;Actual&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;software&quot;; distance:0; nocase; content:&quot;report&quot;; distance:0; nocase; content:&quot;&lt;/title&gt;&quot;; distance:0; nocase; pcre:&quot;/\&lt;title\&gt;Actual\s+Spy\s+software\s+report\&lt;|2F|title\&gt;/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7505</id>
        <msg>SPYWARE-PUT Keylogger actualspy runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086496</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;ATL&quot;; distance:0; nocase; content:&quot;CSmtp&quot;; distance:0; nocase; content:&quot;Class&quot;; distance:0; nocase; content:&quot;Mailer&quot;; distance:0; nocase; content:&quot;by&quot;; distance:0; nocase; content:&quot;Robert&quot;; distance:0; nocase; content:&quot;Simpson&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*ATL\s+CSmtp\s+Class\s+Mailer\s+by\s+Robert\s+Simpson\s+\x28robert\x40blackcastlesoft\x2Ecom\x29/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7551</id>
        <msg>SPYWARE-PUT Keylogger ardamax keylogger runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094248</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;JMail&quot;; distance:0; nocase; content:&quot;by&quot;; distance:0; nocase; content:&quot;Dimac&quot;; distance:0; nocase; content:&quot;NiceSpy's&quot;; nocase; content:&quot;email&quot;; distance:0; nocase; content:&quot;assistant&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*JMail[^\r\n]*by[^\r\n]*Dimac/smi&quot;; pcre:&quot;/^NiceSpy\x27s\s+email\s+assistant/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>8544</id>
        <msg>SPYWARE-PUT Keylogger nicespy runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097309</url>
      </rule>
      <rule>
        <classtype>not-suspicious</classtype>
        <filter1>tcp $HOME_NET 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;220 YahooPOPs!&quot;; flowbits:set,ypops.banner; flowbits:noalert; metadata:service smtp; classtype:not-suspicious;</filter2>
        <id>8704</id>
        <msg>SMTP YPOPS Banner</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Yid5ICdT|0D 0A|J2sneSdOJ2UndCcuJ0MnWicgJ0MnbydyJ3AqJwAAJ0QncidvJ3AncCdlJ2QnUydrJ3knTidl|0D 0A|J3QnACdTJ2sneSdOJ2UndCdGJ2knZydoJ3QncydCJ2EnYydrAAAAAHVzZXJj&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9326</id>
        <msg>SPECIFIC-THREATS netsky.p smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FNETSKY%2EP&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;QWxldmlydXMgTmV0U2t5LWIgQ3JhY2tlZCBBbmluaGFBTUFWQyE&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9327</id>
        <msg>SPECIFIC-THREATS netsky.af smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.AF</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;zhangpo&quot;; fast_pattern:only; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*zhangpo/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9328</id>
        <msg>SPECIFIC-THREATS zhangpo smtp propagation detection</msg>
        <url>www.spywareremove.com/removeZhangpo.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;Trojaner-Info&lt;webmaster@trojaner-info.de&gt;&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Trojaner-Info Newsletter&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*Trojaner-Info&lt;webmaster@trojaner-info\x2Ede&gt;/smi&quot;; pcre:&quot;/^Subject\x3A[^\r\n]*Trojaner-Info\sNewsletter/smi&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9329</id>
        <msg>SPECIFIC-THREATS yarner.b smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-021912-4244-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;o/lN3R5KdgmabpkbqcebrJGVMv/b3+ITcXF4dYrKKEjm3bi1PPcb8ZqKgf//hf6sWTRLdExjstH/|0D 0A|x69YBOSAkClWPEs4oEv//3+BfjW9C702c15JmOUe8W2ey1TAvxOujvc6/7/1/0UA4y/RTfLKo95+&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9330</id>
        <msg>SPECIFIC-THREATS mydoom.e smtp propagation detection</msg>
        <url>www.f-secure.com/v-descs/mydoom_e.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;lo5vuBR4VSCJ1pbUTU2ox8gc4A7MEBs3U817uUY7ImH0QRZX+0j2rTCxLjEuMiWWIIQOBqYHIChO|0D 0A|szw6IGwkHhEcctMplAHMtW17PTAB6V1wlG2EO/ggyW8ZTQYiUQdbzhMuIwM4aEvQxSUDthPd7S6&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9331</id>
        <msg>SPECIFIC-THREATS mydoom.m smtp propagation detection</msg>
        <url>www.f-secure.com/v-descs/mydoom_m.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;g8QMX15bw1WJ5VNWV1VqAGoAaJIQQAD/dQjoVkYAAF1fXluJ7F3D/FWJ5YPs|0A|CFNWV1WLXQyLRQijMEBHAIkdNEBHAPdABAYAAAB1colF+ItFEIlF/KM0QEcAjUX4iUP8&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9332</id>
        <msg>SPECIFIC-THREATS mimail.a smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimaila.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;don't be late!&quot;; distance:0; nocase; content:&quot;gBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGUuDQ0KJAAAAAAA|0A|AABQRQAATAEDAEKhoz8AAAAAAAAAAOAADwELAQI3ADAAAAAQAAAAIAcA0FIHAAAwBwAA&quot;; pcre:&quot;/^Subject\x3A[^\r\n]*don't\sbe\slate!/smi&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9333</id>
        <msg>SPECIFIC-THREATS mimail.e smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimaile.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;TeRqfPMR5vXWeeZ2NfAaLY1DVPPPFiBi5r34VPgF8sIEpG0shzV4b30euDVoQer6QFQy78snUIPq|0D 0A|EWuSIUAv+OGl1QNYkJXTV5/HzOViMIBfVAY2WQpM6/DVgZ5n8h0ILVu+fjHF1MpcoGgQjIjsDs68&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9334</id>
        <msg>SPECIFIC-THREATS lovgate.c smtp propagation detection</msg>
        <url>www.f-secure.com/v-descs/lovgate.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;0UMVleLfQgz|0D 0A|0jPJM/aAPwB0KVNqAVsr34ldCIr3/+3/H4D7LnUMiAwCi1UgyQPX6wWIXAYBQUZHJ/v/bXd1|0D 0A|4VsYgGQPAI1GAV9eXcOLRCQIU0xv/3+7fCQQTYH6AAgAAH06D7YIhc&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9335</id>
        <msg>SPECIFIC-THREATS netsky.b smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.B</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MS4yNAC20aXJDAkCCFGoGZhQ27pRMAYDAAE/AAAAfAAAJgUAOP//|0D 0A|//9Vi+yLRQxWV4t9CDPSM8kz9oA/AHQpU2oBWyvfiV0Iivf/7f8fgPsudQyIDAKLVSDJA9fr|0D 0A|BYhc&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9336</id>
        <msg>SPECIFIC-THREATS netsky.t smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;g8QMhcB1Fv////+DffwCdA5qZP8VYHBAAEaD/gJ81jPAXsnD|0D 0A|i0QkDIHsKN5+97cBKlNVVos1bB1XM+1oABAQVccA7d9s7xYA/9ZQNWiL2DvdD4RWAhL2N7f2|0D 0A|ahFqAgEV&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9337</id>
        <msg>SPECIFIC-THREATS netsky.x smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.X</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;LjI2BDAAorXCxzNJTUVPLDRQ04B9WAN1VEJ5QE1mwWlkOx4gVjm42kp3LOx0Ni1UeepAb S3soFBE|0D 0A|2eN0L/d4UADTtkc7IQkKO a/NWrhyPSJSInMFcbG2vdotVqfZNTFPGIKG5hzoQwecasmOtdZACjEX&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9338</id>
        <msg>SPECIFIC-THREATS mydoom.i smtp propagation detection</msg>
        <url>www.f-secure.com/v-descs/mydoom_i.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;PROSAC&quot;; distance:0; nocase; content:&quot;DQoJV2Vs|0D 0A|Y29tZSB0byBQUk9TQUMgKG11bHRpbWVkaWEgcGFjaykNCgkt&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9342</id>
        <msg>SPECIFIC-THREATS paroc.a smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-061121-1025-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Bin Ladenov zivot&quot;; distance:0; nocase; content:&quot;filename=&quot;; nocase; content:&quot;Bin Ladenov zivot&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9343</id>
        <msg>SPECIFIC-THREATS kadra smtp propagation detection</msg>
        <url>www.kaspersky.com/news?id=260&amp;ipcountry=CA#kadra</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;LUiv0xc0fDsKfdy6TB2EYeFCZcNNW9Fcgwxvsi/DSNbYGn8xV1NBSNxudS4jtCC5C7sLb3Ox|0D 0A|0DUKCK6zY6tuhRdoiOEtaER0YnkD4HJsDytowG4HfAwFd6v4YW9h1I54fvsQwTeyUEUGTAEG&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9344</id>
        <msg>SPECIFIC-THREATS kindal smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-073016-2910-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;xfs9Znq3mJL1CnQXg0epFP4RHBO0n6naXaPhHWdmQaxirccYvMqyYqxiVpY//VZeM7veQEB19ehg|0A|YFK0if9HLNsz9SBqjj/QOGh01hINh2u4f6VGfrwbNSTdzqkjQnZKcB1Ind/UezfRD6KGUHmZkXfy&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9345</id>
        <msg>SPECIFIC-THREATS kipis.a smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=41312</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X3uiXQhvcqrqewRXAmwUkkt+UZVKSCEfAJD16IpxOluoZPgwsCe6T1GNq38tD7G1LQylWfNIZQMc|0D 0A|9sKWsKp24Yz3UxXUVnc++jxshJFqXMM2hAlWyzoRY39o9hbXxNVHGfm7emXOlh8fZP2CLWIe1AHv&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9348</id>
        <msg>SPECIFIC-THREATS morbex smtp propagation detection</msg>
        <url>www.www.f-secure.com/v-descs/morbex.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;+FVQACNg1tXQABQV7hVQed3/9BWV7guaud3/9ALwHQW6IkPAADotxQAAOjqFAAA/7NPVkAAw42DZVVAAFBqAGoAuMTC53f/0I2DWVBAAGoAagBTUGoAagC4N6znd/&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9349</id>
        <msg>SPECIFIC-THREATS plemood smtp propagation detection</msg>
        <url>www.2-spyware.com/remove-i-worm-plemood.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;QIi1QkEIkCuAMAAADDU1ZXi0QkEFBq/mgAEEAAZP81AAAAAGSJJQAAAACLRCQgi1gIi3AM|0A|g/7/dCA7dCQkdBqNNHaLDLOLTCQIi0gMg3yzBAB11/9Uswjr0WSPBQAAAACDxAxfXl&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9350</id>
        <msg>SPECIFIC-THREATS mimail.k smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimailk.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;+3UubBZU6QPutdRcZrPEvAZmzZcNakN47VPYbNzc7Nrua2tqc5hULfvf2fjX3Ec6W|0D 0A|bgNaUl7vgcZCDx77BhbeP1Jav5WWRj/8Tjd7mGGE798zp8rczW6tVaQvEyw5Ww3WpU0MwG5nq6G5&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9352</id>
        <msg>SPECIFIC-THREATS lovgate.a smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=31576</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i8Zew4tMJAQzwDgBdAdAgDwIAHX5w1WL7ItFDFOLXRRWVzP/M/aJRQyFwIldFHUM/3UI6Mz///9Z|0D 0A|iUUMhdt1DP91EOi8////WYlFFItFFDlFDHdqg30YAHQjhcB2Uzt1DHNTi00Qi1UIigwPOgwWdQNG&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9358</id>
        <msg>SPECIFIC-THREATS fizzer smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-050821-0316-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;ogoKgD0WhnQSv/XEJq4JCv4wgevPaFDDmyXYndHSgSQEAaqXBpIrHzOgDxW/HTNqUNgsI75gYINA&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9359</id>
        <msg>SPECIFIC-THREATS zafi.b smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32zafib.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;HgAAAAAAAAAAAAAAAAAAQAAA|0D 0A|wDEuMjIAVVBYIQwJAgkUTDlhQxNezL9kAACkGQAAIEAAACYAABn+//L/McBA|0D 0A|i0wkBPdBBAYAdA+LRCQIi1QkEIkCuAO5/3fvEMNTVlc&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9360</id>
        <msg>SPECIFIC-THREATS cult.b smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32cultb.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Re[2]&quot;; nocase; content:&quot;Hi Greg its Wendy.&quot;; distance:0; nocase; content:&quot;I was shocked, when I found out that it wasn't you but|0D 0A|your twin brother!!!&quot;; distance:0; nocase; content:&quot;name=|22|wendy.zip|22|&quot;; distance:0; nocase;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9361</id>
        <msg>SPECIFIC-THREATS mimail.l smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimaill.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;f+xt2OHdR5d|0A|oYEgACjEdRRHXvYmP9iDPXUL7TXuZkm+6wfHeTAGsEn3sfxyGYt9/GE5yHe7tcZ/Hhj4ORt835ps|0A|Mx+zk+UMO/RnXp7d+QBQQEz4gFL098fbv+3/G3&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9362</id>
        <msg>SPECIFIC-THREATS mimail.m smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimailm.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;wJ0D69ErgiOVIAQiQK4|0D 0A|A8Ejw1NWV78nh1Bq/mgOzkADZP81Yi0OiSUTOjUgMFhgcAyDHv7/dNw7//Hs|0D 0A|GgONNHaLDLNkqzBID3xOBAF11/9U3/Dr0WQojwU2AIPEDF9eW8NVN4nlu2dq&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9365</id>
        <msg>SPECIFIC-THREATS cult.c smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32cultc.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AAAAAAAAAAx|0A|AMBAi0wkBPdB5gbhjwJ0D69ErgiOVIAQiQK4A8Ejw1NWV78nh1Bq/mgOzkADZP81Yi0OiSUTOj Ug|0A|MFhgcAyDHv7/dNw7//HsGgONNHaLDLNkqzBID3x&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9366</id>
        <msg>SPECIFIC-THREATS mimail.s smtp propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32mimailm.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i9iF2w+EggAAAItrCIvFA0MMi9CNDDcr0YP6DH8Ei/gr/ovGK8WD+Ax9FI1M|0D 0A|JAGL1itTCAPXi8Xoxfv//+sRjUwkAYvXg+oEjUYE6LL7//+LbCQBhe10NIvV&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9367</id>
        <msg>SPECIFIC-THREATS anset.b smtp propagation detection</msg>
        <url>www.bullguard.com/virus/default.aspx?id=51</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;0ZpkFIcReXCdLfAeEs4k5jglICV+BEij4zH+Xi5QwyfgLb+rO0XnE1xMuyBdVbgW95IPgAVLAnSC|0D 0A|g/5gJes8k0qLVgSAmSvKuNMATWIQ9+HB6gYajUIFsMBdgfogIBxSfyxQ0g6YSxpQiQ8WSQnT55rV&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9368</id>
        <msg>SPECIFIC-THREATS agist.a smtp propagation detection</msg>
        <url>www.sarc.com/avcenter/venc/data/w32.agist.a@mm.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;OwT4dgXDeVgnYHMODdBsTCbwmeciQpDLT1c3bLF1CDPoOT4eiUYEQgtW6Dyq/V0eWdlNFpXqMULp|0D 0A|QSWsmyBXNyoMu5xxWfoEcA/D8fxQV4hosCndivKbkCHoTCa6MLVnCwngBJFJlBHr7ka36Cpo/Mib&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9369</id>
        <msg>SPECIFIC-THREATS atak.a smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32ataka.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;22cYrYFsp1tV//KXbPbtRRQ4EnUCswFdIl62BQ6BxjtHcmMEwQ573GF0vGNi9B8wPXivfVoL|0D 0A|N9j04cZWzkL7aT31JBRq3/LZM/lJiQo0hUcu9GPvsGExeAQ1eAxsh/8gV4B9/iB1C7h0dRD3&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9370</id>
        <msg>SPECIFIC-THREATS bagle.b smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-021713-3625-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;ndAzKAZ0SFmzPdMu6kksSBpMnHn8vHAZLueGBstFWTfqLp3bQgJcaVOxM0W4oc81kinf/QiC|0D 0A|+bYxBaedDbd49u4ktkyUTrFK2ic8FKQI9pXU8vrTcz6RnwRxwAqTRZrKIhN6nL2ivbJIRTmf&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9371</id>
        <msg>SPECIFIC-THREATS bagle.e smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-022809-3232-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;JfzwQACLwP8lnPFAAIvA/yWY8UAAi8D/JZTxQACLwP8lkPFAAIvA/yWM8UAAi8D/JYjxQACLwFOD|0D 0A|xLy7CgAAAFToYf////ZEJCwBdAUPt1wkMIvDg8REW8OLwP8l+PBAAIvA/yX08EAAi8D/JfDwQACL&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9372</id>
        <msg>SPECIFIC-THREATS blebla.a smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32bleblaa.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;S|23|L1GP]U%A!BA-RBY5.|0A|ME&gt;|24|20PNL^|3A|79|24|U|3A|1'G`.+BZ6VD,4|5C|Q,T?!TID7%|3A|+T-SH5|23|K.7|24|^|22|G|5C|]NQ|22|=|0A|M'BUUUU@|5C|MBZ_D[^]&lt;&amp;L6R0/2B|3A|@8|23|!T`&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9373</id>
        <msg>SPECIFIC-THREATS clepa smtp propagation detection</msg>
        <url>www.logiguard.com/spyware/i/i-worm-clepa.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;i8iFyXUFM8BeW8OhUIREAIkBiQ1QhEQAM9KLwgPAjUTBBIseiRiJ|0D 0A|BkKD+mR17IsGixCJFl5bw5CJAIlABMOLwFNWi/KL2Oid////hcB1BTPAXlvDixaJUAiLVgSJUAyL&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9374</id>
        <msg>SPECIFIC-THREATS creepy.b smtp propagation detection</msg>
        <url>www.emsisoft.com/en/malware/?Email-Worm.Win32.Creepy.b</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;+QAEAE1FhFEAAaABBIAD/VCMgIADcAAAABJnSlP+aThqAAKRKqKioqDQAAABA|0D 0A|Q/hAAQDQfAIgACn/KoVAQACjzQ0IAE0AocDVAACa//81cw0IAP9RJUBAADNaKVL/qebQEAAaEtAQAP+opCAgAIUMdAYaEtAQAP+oxCAgADSQGoAA/xXkICAAQJ5EiAgA&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9375</id>
        <msg>SPECIFIC-THREATS duksten.c smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-122016-4223-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AAACAAAAQAAAAAQAAAANAAoAAAAAABgAAABcAGYAaQBzAGgAbABlAHQALgBiAGkAbgAAAAAAVgAA|0D 0A|AFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwASQBuAHQAZQByAG4AZQB0ACAA&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9376</id>
        <msg>SPECIFIC-THREATS fishlet.a smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=12285</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;B0QnUGCDNE08WiwoB4MNMsggGBAnBHf27GA//CMX7CNH5A/y7CBNQdTAI5e4I0jTDHaoB5xkkCCD|0D 0A|DTaIF4QvfIMNMth0H2xkB1wMMsggVExEMthgg0B/MEco0jSDDRwPFFoIybODDQAH/CIv9CLBXjPY&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9377</id>
        <msg>SPECIFIC-THREATS mydoom.g smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-030213-0918-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Zacc/sWcQrpGNGbPzJedST7hJMXZJVKNy7LLBP2V90UwX7IHSyhFxPPTlRpdlJtxYLAU3s+E|0D 0A|ekcFyTLIwRYHVjWm16JZXIxAhQROCT/c+L5SU8juIBBaGTg21xUr52qxnAfzmZdzLksQUE+0&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9378</id>
        <msg>SPECIFIC-THREATS netsky.q smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-032913-5722-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;xAJ2g9vb5s6MgEwifAAA99d2k9vrFPl057JOQIiRxvTw54r4l64U/qrFiXxGSJOoS9u77/mo|0D 0A|T/01iESEpu/wemHvlfNyYs+hogBpkojHr6r1w6r5OLdqdovbvwQmcoqsu7aPznGT+6qsCYET&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9379</id>
        <msg>SPECIFIC-THREATS netsky.s smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-040512-2436-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Lara Wallpaper Download Software&quot;; distance:0; nocase; content:&quot;I found on the net a new interesting software about Lara Croft&quot;; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9381</id>
        <msg>SPECIFIC-THREATS lara smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/mirclara.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;W4niV2CNlkzNbJ91T1IgkFpIUag2/cL3Sy5za4C8BhwOwEDr72oCP3sBuUkp0D0NoEh1djz3tvfr|0D 0A|PY2GLMgIGNbPfqP9LTUUqLLXdKC4DoH+8FHNt922QnUL9OtN9dKAdLrOtrM5zrElF1Bw9RA101DY&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9382</id>
        <msg>SPECIFIC-THREATS fearso.c smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=35646</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SzXgMkNWL9sVG+tK+PAvoGAHIBs6uGCk+LimunCOdVZetTLfshMihnVwSZSOMgbeJ1nQ2VuH|0D 0A|OE0A6SCpjgS431+O+Uwr0hbFwC0Tt9gjk5n006G2DLQ93fwnPbO2fmzcaPYFYNhTijcHgc6u&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9383</id>
        <msg>SPECIFIC-THREATS netsky.y smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-042011-2621-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;bszmmP1TlDRGFDA1uDG1GyF3fw7zQae3hTJk7dtK0xmjv339SvtDPLhswsFAGUQX34naqqcKxEjp|0A|yns2FwCn9oiRtoiyYFfwAsT6v/2SvioeIkj2WAb6lQoNyzLUhbQtpekiV9ZUpOW2u4Lv73FPrkud&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9384</id>
        <msg>SPECIFIC-THREATS beglur.a smtp propagation detection</msg>
        <url>www.viruslibrary.com/virusinfo/I-Worm.Beglur.a.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;UP8VWBIAAYPEDI1FoFBoAgEAAP91cP8VVBIAAf91cP8VUBIAAenf/v//aHQTAAFqCv81XIAAAf91|0D 0A|eOsTi0V8aHQTAAFqDP81XIAAAf9wDP8VCBIAATPAX15bg8VoycIQAFeLfCQMM8CD/wF2U1aLdCQM&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9385</id>
        <msg>SPECIFIC-THREATS collo.a smtp propagation detection</msg>
        <url>www.viruslist.com/en/viruses/encyclopedia?virusid=23787</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;LkRMTAAAAEdldFByb2NBZGRyZXNzAAAATG9hZExpYnJhcnlBAAAARXhpdFByb2Nlc3MAAABW|0D 0A|aXJ0dWFsQWxsb2MAAABWaXJ0dWFsRnJlZQAAAE1lc3NhZ2VCb3hBAAAAAABqe5M2t6ajjak1&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9386</id>
        <msg>SPECIFIC-THREATS bagle.f smtp propagation detection</msg>
        <url>www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?lst=det&amp;idvirus=45199</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;VdBjl&quot;; content:&quot;VdBjlpmHLVfqaPUitmytmlPwIiJiViqPhDwHsP8fO2CDfCpkZVVqQCfFgXUtB+gfgDUcrZZOjpqX|0A|l20NIkQDEwEOAOwgy2VA5OSAJBx7JeRs391cnLJAlivkZdzcmZBvNipSWthsl41k2B3UrdTsguvQ&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9388</id>
        <msg>SPECIFIC-THREATS mimail.g smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=37467</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;H3Vi96OpogVHcLpTQXO9Nsx0cnR1FCErIXOpKbYFbDzudjBsaQIXui4IaYZfDmRymAFceHlQ|0D 0A|RUwBBGJkRWT5f0ie4AAPAQsBBQwAMlZy9r13ED8EMA1ACwIn3SzYBDMHDMA9b2BnsYMeNBAH&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9389</id>
        <msg>SPECIFIC-THREATS bagle.i smtp propagation detection</msg>
        <url>www.sarc.com/avcenter/venc/data/w32.beagle.i@mm.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;A8Hjz&quot;; content:&quot;A8Hjz1XwgeLbymX/OMH6BAnTW4NTKTT7VvYLxgQ+PRHBjYpIBpIj7OxkWZbl8A8C7MD+SqZkBhTr|0A|VP9NDD+w5chL7D866BN1I2Vn7giaB2cqOQ1LZIaFNwpjlXTaJQ+TCqW4q6H&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9391</id>
        <msg>SPECIFIC-THREATS mimail.i smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-111317-1701-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AFM8bJHtPFvDEkEXcUExflY49kR1cEEIUkM9CVRyaW0/TddNAkkvfRRVUkxRaCWgRLFeZa2d|0D 0A|ppsmHIgcP6Qp8ve2TB1lRQtVcHAiPE23aXCUdGYrkyxJZUtwfXxuCusU7RVxrDNuboGBhT0s&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9392</id>
        <msg>SPECIFIC-THREATS bagle.j smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBAGLE%2EJ&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;RcJ0RFKbuZlqeaaoQ76D0Tf6ESD+RgjrN6QDtvvsvNXbR6BlXZviaG3d1NJtmU++UEmRCixX|0D 0A|RCaDz8IzdWIidAq1dzJwwTvIJglu/0IQwX8WrLD6EheQRlQhil5PQbv9oC3Y0HgAfIERnIb5&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9393</id>
        <msg>SPECIFIC-THREATS bagle.k smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBAGLE%2EK&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;UwFU9VVzpIrXAls0zlhDNOHldmMULkXDsJRNQZiPekC47DW5vF9mS3gKhBe2I0JSPouRMRBl|0D 0A|w8AJvAcDlRprEHbYgf+GOmWVzZa5XNbrM7AlDCyZfmBiCbABUFgAlCxXE2JRonBJRXLSoLAA&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9394</id>
        <msg>SPECIFIC-THREATS bagle.n smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE%5FBAGLE%2EN&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;1eO8sLlq7UIor1GwCmto7XsiMt9GchrcNlbVPh1GT18n0EDLTWKdYxpB5nZPeoxCHDzQuKOyEtsb|0D 0A|MCqnv2Y1wJoGWMGEslVIzj05hLSGDTLIbGy0uaslY66ENTqEiiXk5HxsL8KRnL2EpjwzDZScLR3G&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9397</id>
        <msg>SPECIFIC-THREATS neysid smtp propagation detection</msg>
        <url>www.spywareremove.com/removeIWormNeysid.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;YjpDKytIT09LkOkckUAAoQ+RQADB4AKjE5FAAFJqAOglfQAAi9DoMhgAAFroyAsAAOgrGAAAagDo|0D 0A|PCQAAFlouJBAAGoA6P98AACjF5FAAGoA6ddeAADpaiQAADPAoAGRQADDoReRQADDYLsAULC8U2it&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9398</id>
        <msg>SPECIFIC-THREATS totilix.a smtp propagation detection</msg>
        <url>www.viruslist.com/en/viruslist.html?id=4097</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AExhWABYYUwAWGFMAE5ld19GYW1vdVNfR2lyTHMAQS5TLk4uAFNNVFA6VGhlX0hhbmdlZEBqYXp6|0D 0A|ZnJlZS5jb20AU01UUDpUaGVfSGFuZ2VkQGhvdG1haWwuY29tAFNleF9TcGFtXyxfRXhjdXNFX01l&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9399</id>
        <msg>SPECIFIC-THREATS hanged smtp propagation detection</msg>
        <url>www.emsisoft.com/en/malware/?Worm.Win32.Hanged</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;cPf//1ChHGtAAFDokPv//6Eca0AAUOh1+///i0UIuhhnQAC5AAQAAOhn9v//M8BaWVlkiRBonzpA|0D 0A|AI1F+LoCAAAA6E31///D6b/v///r61tZWV3CBACLwFWL7DPAVWjHOkAAZP8wZIkgM8BaWVlkiRBo&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9400</id>
        <msg>SPECIFIC-THREATS abotus smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2001-082919-3906-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;NNQX1qMoBi2hCzN5hBb/0LqoYbyhKHgQBVpTEUeLLRgDTO6MTZFsBeto+Gr/qFzvz1uPXM5c|0D 0A|j1s8XFzuo1yuz1ysXPhc81zPXDxcXPNcz1w6XOs7XDxcXPNcz1yuzl7jXu4+XTpePF1d8136&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9403</id>
        <msg>SPECIFIC-THREATS netsky.aa smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FNETSKY%2EAA&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;cG51RlelhMtbU7QpjWKxOTvQLS+4wB20IzjrIlOWMc5XP3AcIgGMOETE8DI5fRIUfhDaJzhT|0D 0A|RPRpWWAQFKHEl02LHRYUHOqsbkd8SKZGHURgndMOfSCyIMVz/7cu1hIk3EZ8IEmLghDkO9/D&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9404</id>
        <msg>SPECIFIC-THREATS netsky.ac smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39026</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;QWxldmlydXMgTmV0U2t5LWIgQ3JhY2tlZCBBbmluaGFBTUFWQyE&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9405</id>
        <msg>SPECIFIC-THREATS netsky.af smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.AF</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;OziaMMstyp3ZvEfNLZDdGUotsJcU9AUzGyIbVCkkslc8AX44pHVQ7cFVd7zMsneJSAaBvoS3iUeo|0D 0A|hlEQ24NXuyvw8X2q88Vmjnqxjk0ouK8Fqb71DLdEZ2FbTDGrGuRodeFwiNi+pKq863l&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9406</id>
        <msg>SPECIFIC-THREATS lovgate.e smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-030416-4942-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;ZT0iTVMtNTYwOTVNX1BBVENILmV4ZSINCgAAAP////8XAAAAQ29udGVudC1JRDogPFNPTUVDSUQ+DQoA/////w4AAAAtLS0tQUJDREVGLS0NCgAA/////wUAAAANCi4NCgAAAP////8GAAAAUVVJVA0KAABDOlxNUy01NjA5NU1fUEFUQ0guZXhlAAD/////EwAAAEM6XExpc3Rl&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9408</id>
        <msg>SPECIFIC-THREATS lacrow smtp propagation detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=W32.Lacrow@mm&amp;threatid=53187</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;OsJMFEHYgBh19HlTYBliOtoPlfhIFVsjwTiRgBgMU+ZVSARWhclXidGWdED5LdJLArJcQ1DSfENl|0D 0A|cmgc0ooDhxdHUODyQ//V6tBJVtc2IBPS7SAmCAw7wXUWiRzJMEgI5UA/pM45Gl1qDJkPuJI/4V6j&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9409</id>
        <msg>SPECIFIC-THREATS atak.b smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-120309-3312-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;CpDwPVgF2ygS8h34dA18deYVsUYkiCjCrsbvJAcQwjPoYwKqVdMfCFQH/RrpYmxALn3s4A8S|0D 0A|hAMBMRpXBAZoVgfiM0gukIQZD8YQg+h6M3huCoaqDMuXcF0x&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9410</id>
        <msg>SPECIFIC-THREATS netsky.z smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=38949</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;on0MCbCSCWxk8BZK8Pbft5+D4wPB489V8IHiOMH6BAnTW7+wrVyDUyk0xgQ+PTmyb2URwUKK|0A|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9411</id>
        <msg>SPECIFIC-THREATS mimail.f smtp propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FMIMAIL%2EF&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;cXJ1dmFiemFickBob3RtYWlsLmNvbT4NCgA8cmVkQGZuYS5zZT4N|0D 0A|CgA8ZGViYXR0QHN2dC5zZT4NCgA8c3VzYW5uZS5zam9zdGVkdEB0aWRuaW5nZW4udG8+DQoAPHNr|0D 0A|b2x2ZXJrZXRAc2tvbHZlcmtldC5zZT4NCgA8bWFyeS5tYXJ0ZW5zc29uQGFmdG9uYmxhZGV0LnNl&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9413</id>
        <msg>SPECIFIC-THREATS ganda smtp propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32gandaa.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;dGpuby9meWYAT1VUTE9PSy5FWEVOZXRDYXB0b3IuZXhlbWlyYzMyLmV4ZWFpbS5leGVZcGFnZXIu|0D 0A|ZXhlAHV2anNidWRpYm9kdnBkZXBqb2J6QXpiaXBwL2RwbgBOUUhfTE9WRQBsb3ZlX2xvcm5AeWFo|0D 0A|b28uY29tAE5RSF9MT1ZFTE9STgB0aHV5cXV5ZW5AeWFob28uY29tAE5RSABsb3ZlbG9ybkB5YWhv&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9414</id>
        <msg>SPECIFIC-THREATS lovelorn.a smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=35041</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;YGVjaG9yIHdwdW4zJXMGZNs+6WEKUxRsRxYMIXDnZ2d04XN1cMku+XjqlhcKcXVpdA9HZoxeLSBzOowm80FoWlbIUi0/SXKAZnZiYTogMQYuMA&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9415</id>
        <msg>SPECIFIC-THREATS plexus.a smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39272</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;CFzisjUEyJsg4LLn9YPllwezsmCH/FoLDp8ttt5rlq2cy18Y2O3lemS1iy+B35D9veT2X3ys|0D 0A|6mupMisPtw82NJQBvU4U30nV3kdI4KNtHjiz9AUOmU+oQYcw9M3v9pJHb2MNmFxxkYvyqDWc&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9416</id>
        <msg>SPECIFIC-THREATS bagle.at smtp propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=41539</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;aWNyb3NvZnQAQGF2cC4AACVzP3A9JWx1JmlkPSVzAGh0dHA6Ly93d3cuZWxyYXNzaG9wLmRl|0D 0A|LzEucGhwAGh0dHA6Ly93d3cuaXQtbXNjLmRlLzEucGhwAGh0dHA6Ly93d3cuZ2V0eW91cmZy&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9417</id>
        <msg>SPECIFIC-THREATS bagle.a smtp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-011815-3332-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;.l|0D 0A|&quot;; within:200; fast_pattern; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*20\d{3,4}\x5f[123]?\d\x2El/mi&quot;;  metadata:policy security-ips alert, service smtp; classtype:successful-recon-limited;</filter2>
        <id>9827</id>
        <msg>SPYWARE-PUT Keylogger paq keylog runtime detection - smtp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098520</url>
      </rule>
      <rule>
        <bugtraq>21931</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0033</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;VEVENT&quot;; nocase; content:&quot;DTSTART|3B|TZID&quot;; fast_pattern:only; pcre:&quot;/DTSTART\x3BTZID(?![=\x22])/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>9841</id>
        <msg>SMTP Microsoft Outlook VEVENT overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-003.mspx</url>
      </rule>
    </attacks>
    <groupid>225</groupid>
    <groupname>Server / Mail / SMTP</groupname>
    <warnings>
      <rule>
        <bugtraq>22581</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0898</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Message/Partial&quot;; fast_pattern:only; pcre:&quot;/Content-Type\s*\x3a\s*Message\x2fPartial/smi&quot;; pcre:&quot;/id\s*=\s*[\x22\x27]?[^\x22\x27\n]*..[\x2f\x5c]/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>10186</id>
        <msg>SMTP ClamAV mime parsing directory traversal</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=476</url>
      </rule>
      <rule>
        <bugtraq>15067</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1987</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|0D 0A|DATA|0D 0A|&quot;; pcre:&quot;/\r\n\w{200,}\x3a.*\r\n/&quot;; classtype:attempted-admin;</filter2>
        <id>12423</id>
        <msg>SMTP Microsoft CDO long header name</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-048.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4379</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|12692;</filter2>
        <id>12692</id>
        <msg>SMTP RCPT TO IPSwitch proxy overflow attempt</msg>
        <url>www.ipswitch.com/support/imail/releases/im20061.asp</url>
      </rule>
      <rule>
        <bugtraq>26175</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5910</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;MIFFile&quot;; fast_pattern:only; content:&quot;|23|&quot;; isdataat:76,relative; content:!&quot;|0A|&quot;; within:76; classtype:attempted-user;</filter2>
        <id>12704</id>
        <msg>SMTP Lotus Notes MIF viewer MIFFILE comment overflow</msg>
      </rule>
      <rule>
        <bugtraq>26175</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5910</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MIFFile&quot;; fast_pattern:only; pcre:&quot;/\x3D[^\s\n]{88}/si&quot;; classtype:attempted-user;</filter2>
        <id>12705</id>
        <msg>SMTP Lotus Notes MIF viewer statement overflow</msg>
      </rule>
      <rule>
        <bugtraq>26175</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5910</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;MIFFile&quot;; fast_pattern:only; pcre:&quot;/\x3C[^\s]+\s[^\x3c\x3E]{80}/si&quot;; classtype:attempted-user;</filter2>
        <id>12706</id>
        <msg>SMTP Lotus Notes MIF viewer statement data overflow</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;thread-index|3A| Acio&quot;; nocase; content:&quot;Subject|3A| Email from Family Cyber Alert&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>13651</id>
        <msg>SPYWARE-PUT Keylogger family cyber alert runtime detection - smtp traffic for recorded activities</msg>
        <url>www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453117297</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0531</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;vrfy&quot;; nocase; content:&quot;root&quot;; distance:1; nocase; pcre:&quot;/^vrfy\s+root/smi&quot;; metadata:service smtp; classtype:attempted-recon;</filter2>
        <id>1446</id>
        <msg>SMTP vrfy root</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>1999-1200</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;expn&quot;; fast_pattern:only; content:&quot;*@&quot;; pcre:&quot;/^expn\s+\*@/smi&quot;; metadata:service smtp; classtype:misc-attack;</filter2>
        <id>1450</id>
        <msg>SMTP expn *@</msg>
      </rule>
      <rule>
        <bugtraq>7515</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0490</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;ETRN&quot;; nocase; isdataat:500,relative; pcre:&quot;/^ETRN\s[^\n]{500}/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>1550</id>
        <msg>SMTP ETRN overflow attempt</msg>
        <nessus>10438</nessus>
      </rule>
      <rule>
        <bugtraq>16742</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0559</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;RCPT&quot;; nocase; pcre:&quot;/^RCPT\s+TO\x3a\s+[^\r\n]*\x25[npd]/smi&quot;; classtype:attempted-admin;</filter2>
        <id>17224</id>
        <msg>SMTP McAfee WebShield SMTP bounce message format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>16396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4411</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 105</filter1>
        <filter2>flow:to_server,established,no_stream; isdataat:527; classtype:attempted-user;</filter2>
        <id>17283</id>
        <msg>SMTP Mercury Mail Transport System Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>6991</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1337</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&quot;; distance:0; content:&quot;|28|&quot;; distance:1; content:&quot;|29|&quot;; distance:1; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2087</id>
        <msg>SMTP From comment overflow attempt</msg>
        <url>www.kb.cert.org/vuls/id/398025</url>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $SMTP_SERVERS 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Authentication unsuccessful&quot;; offset:54; nocase; detection_filter:track by_dst, count 5, seconds 60; metadata:service smtp; classtype:suspicious-login;</filter2>
        <id>2275</id>
        <msg>SMTP AUTH LOGON brute force attempt</msg>
      </rule>
      <rule>
        <bugtraq>9758</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0333</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A|&quot;; fast_pattern:only; pcre:&quot;/name=[^\r\n]*?\.(mim|uue|uu|b64|bhx|hqx|xxe)/smi&quot;; pcre:&quot;/(name|id|number|total|boundary)=\s*[^\r\n\x3b\s\x2c]{300}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>2487</id>
        <msg>SMTP WinZip MIME content-type buffer overflow</msg>
        <nessus>12621</nessus>
      </rule>
      <rule>
        <bugtraq>9758</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0333</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A|&quot;; fast_pattern:only; pcre:&quot;/name=[^\r\n]*?\.(mim|uue|uu|b64|bhx|hqx|xxe)/smi&quot;; content:&quot;Content-Disposition|3A|&quot;; nocase; pcre:&quot;/name=\s*[^\r\n\x3b\s\x2c]{300}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>2488</id>
        <msg>SMTP WinZip MIME content-disposition buffer overflow</msg>
        <nessus>12621</nessus>
      </rule>
      <rule>
        <bugtraq>10115</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; content:!&quot;|03|&quot;; depth:1; offset:9; metadata:service smtp; classtype:attempted-dos;</filter2>
        <id>2504</id>
        <msg>SMTP SSLv3 invalid data version attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10116</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0719</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,starttls.attempt; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; content:&quot;|01|&quot;; depth:1; offset:2; byte_test:2,&gt;,0,5; byte_test:2,!,0,7; byte_test:2,!,16,7; byte_test:2,&gt;,20,9; content:&quot;|8F|&quot;; depth:1; offset:11; byte_test:2,&gt;,32768,0,relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>2528</id>
        <msg>SMTP PCT Client_Hello overflow attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10115</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,starttls.attempt; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; content:!&quot;|03|&quot;; depth:1; offset:9; metadata:service smtp; classtype:attempted-dos;</filter2>
        <id>2541</id>
        <msg>SMTP TLS SSLv3 invalid data version attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2004-0120</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isset,sslv3.server_hello.request; content:&quot;|16 03|&quot;; depth:2; content:&quot;|01|&quot;; depth:1; offset:5; metadata:service smtp; classtype:attempted-dos;</filter2>
        <id>2544</id>
        <msg>SMTP SSLv3 invalid Client_Hello attempt</msg>
        <nessus>12204</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10116</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0719</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; content:&quot;|01|&quot;; depth:1; offset:2; byte_test:2,&gt;,0,5; byte_test:2,!,0,7; byte_test:2,!,16,7; byte_test:2,&gt;,20,9; content:&quot;|8F|&quot;; depth:1; offset:11; byte_test:2,&gt;,32768,0,relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>3511</id>
        <msg>SMTP PCT Client_Hello overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>11238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1546</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;SAML&quot;; nocase; isdataat:246,relative; pcre:&quot;/^\s*SAML\s+[^\n]{246}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>3653</id>
        <msg>SMTP SAML overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1546</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;SOML&quot;; nocase; isdataat:246,relative; pcre:&quot;/^\s*SOML\s+[^\n]{246}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>3654</id>
        <msg>SMTP SOML overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1546</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;SEND&quot;; nocase; isdataat:246,relative; pcre:&quot;/^\s*SEND\s+[^\n]{246}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>3655</id>
        <msg>SMTP SEND overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1546</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;MAIL&quot;; nocase; isdataat:246,relative; pcre:&quot;/^\s*MAIL\s+[^\n]{246}/smi&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>3656</id>
        <msg>SMTP MDaemon 6.5.1 and prior versions MAIL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2524</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0154</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;audio/&quot;; fast_pattern:only; pcre:&quot;/Content-Type\x3A\s+audio\/(x-wav|mpeg|x-midi).*filename=[\x22\x27]?.{1,221}\.(vbs|exe|scr|pif|bat)/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>3682</id>
        <msg>SMTP spoofed MIME-Type auto-execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>13772</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4440</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;AUTH&quot;; nocase; isdataat:128,relative; pcre:&quot;/^AUTH\s+\S+\s+[^\n]{128}/mi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>3824</id>
        <msg>SMTP AUTH user overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17192</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>2006-0058</cve>
        <filter1>tcp $HOME_NET 25 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;552&quot;; content:&quot;Headers&quot;; fast_pattern:only; pcre:&quot;/^552[A-Z0-9\s\x5F\x2D\x2E\x28\x29\x22\x27]+Headers\s+too\s+large/smi&quot;; metadata:service smtp; classtype:bad-unknown;</filter2>
        <id>5739</id>
        <msg>SMTP headers too long server response</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>1999-0531</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;ehlo cybercop|0A|quit|0A|&quot;; fast_pattern:only; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>631</id>
        <msg>SMTP ehlo cybercop attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>1999-0531</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;expn cybercop&quot;; fast_pattern:only; metadata:service smtp; classtype:protocol-command-decode;</filter2>
        <id>632</id>
        <msg>SMTP expn cybercop attempt</msg>
      </rule>
      <rule>
        <bugtraq>17459</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2006-2386</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|9C CB CB 8D 13|u|D2 11 91|X|00 C0|OyV|A4|&quot;; metadata:service smtp; classtype:misc-activity;</filter2>
        <id>6412</id>
        <msg>SMTP Windows Address Book attachment detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-076.mspx</url>
      </rule>
      <rule>
        <bugtraq>17459</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2006-2386</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Transfer-Encoding&quot;; nocase; content:&quot;base64&quot;; distance:0; nocase; content:&quot;nMvLjRN10hGRWADAT3lWpA&quot;; distance:0; pcre:&quot;/^Content-Transfer-Encoding\s*\x3A\s*base64/smi&quot;; metadata:service smtp; classtype:misc-activity;</filter2>
        <id>6413</id>
        <msg>SMTP Base64 encoded Windows Address Book attachment detected</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-076.mspx</url>
      </rule>
      <rule>
        <bugtraq>2387</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0261</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;HELP&quot;; nocase; isdataat:500,relative; pcre:&quot;/^HELP\s[^\n]{500}/ism&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>657</id>
        <msg>SMTP chameleon overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0096</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;expn&quot;; nocase; content:&quot;decode&quot;; fast_pattern:only; pcre:&quot;/^expn\s+decode/smi&quot;; metadata:service smtp; classtype:attempted-recon;</filter2>
        <id>659</id>
        <msg>SMTP expn decode</msg>
        <nessus>10248</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0531</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;expn&quot;; nocase; content:&quot;root&quot;; fast_pattern:only; pcre:&quot;/^expn\s+root/smi&quot;; metadata:service smtp; classtype:attempted-recon;</filter2>
        <id>660</id>
        <msg>SMTP expn root</msg>
        <nessus>10249</nessus>
      </rule>
      <rule>
        <bugtraq>2310</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0207</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;eply-to|3A| a~.`/bin/&quot;; fast_pattern:only; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>661</id>
        <msg>SMTP majordomo ifs</msg>
      </rule>
      <rule>
        <bugtraq>1</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0095</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;rcpt to|3A|&quot;; fast_pattern:only; pcre:&quot;/^rcpt\s+to\:\s*[|\x3b]/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>663</id>
        <msg>SMTP rcpt to command attempt</msg>
      </rule>
      <rule>
        <bugtraq>2308</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0203</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;rcpt to|3A|&quot;; nocase; content:&quot;decode&quot;; distance:0; nocase; pcre:&quot;/^rcpt to\:\s*decode/smi&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>664</id>
        <msg>SMTP RCPT TO decode attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0096</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;vrfy&quot;; nocase; content:&quot;decode&quot;; distance:1; nocase; pcre:&quot;/^vrfy\s+decode/smi&quot;; metadata:service smtp; classtype:attempted-recon;</filter2>
        <id>672</id>
        <msg>SMTP vrfy decode</msg>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 00 02|&quot;; depth:3; offset:2; byte_test:2, &gt;, 256, 0, relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8432</id>
        <msg>SMTP SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 00 02|&quot;; depth:3; offset:2; byte_test:2, &gt;, 256, 0, relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8433</id>
        <msg>SMTP SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>25831</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; within:1; distance:2; content:&quot;|03 00|&quot;; within:2; distance:3; content:&quot;|00|&quot;; within:1; distance:32; byte_test:2, &gt;, 256, 0, relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8434</id>
        <msg>SMTP SSLv3 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>25831</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; within:1; distance:2; content:&quot;|03 00|&quot;; within:2; distance:3; content:&quot;|00|&quot;; within:1; distance:32; byte_test:2, &gt;, 256, 0, relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8435</id>
        <msg>SMTP SSLv3 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>22083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 465</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 03|&quot;; depth:2; offset:2; byte_test:2, &gt;, 256, 1, relative; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8436</id>
        <msg>SMTP SSLv2 openssl get shared ciphers overflow attempt</msg>
        <url>www.openssl.org/news/secadv_20060928.txt</url>
      </rule>
      <rule>
        <bugtraq>11256</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1558</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; flowbits:isset,ypops.banner; flowbits:unset,ypops.banner; pcre:&quot;/[^\x0d\x00\x0a]{509}/&quot;; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>8705</id>
        <msg>SMTP YPOPS buffer overflow attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>230</groupid>
    <groupname>Server / Database</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,backup_file.request; metadata: engine shared, soid 3|13888, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13888</id>
        <msg>SQL Microsoft SQL Server Backup Database File integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,backup_file.request; metadata: engine shared, soid 3|13889, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13889</id>
        <msg>SQL Microsoft SQL Server Backup Database File integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0107</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,backup_file.request; metadata: engine shared, soid 3|13890, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13890</id>
        <msg>SQL Microsoft SQL Server Backup Database File integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <bugtraq>31129</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FC13BAA2-9C1A-4069-A221-31A147636038&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q16&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FC13BAA2-9C1A-4069-A221-31A147636038\s*}?\s*(?P=q16)(\s|&gt;).*(?P=id1)\s*\.\s*(Connect)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FC13BAA2-9C1A-4069-A221-31A147636038\s*}?\s*(?P=q17)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(Connect))/Osi&quot;; metadata:policy balanced-ips drop, policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14756</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31129</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|C|00|1|00|3|00|B|00|A|00|A|00|2|00|-|00|9|00|C|00|1|00|A|00|-|00|4|00|0|00|6|00|9|00|-|00|A|00|2|00|2|00|1|00|-|00|3|00|1|00|A|00|1|00|4|00|7|00|6|00|3|00|6|00|0|00|3|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q18&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00C\x001\x003\x00B\x00A\x00A\x002\x00-\x009\x00C\x001\x00A\x00-\x004\x000\x006\x009\x00-\x00A\x002\x002\x001\x00-\x003\x001\x00A\x001\x004\x007\x006\x003\x006\x000\x003\x008\x00(}\x00)?(?P=q18)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14757</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31129</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SQLVDir.SQLVDirControl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SQLVDir\.SQLVDirControl\x22|\x27SQLVDir\.SQLVDirControl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Connect\s*|.*(?P=v)\s*\.\s*Connect\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SQLVDir\.SQLVDirControl\x22|\x27SQLVDir\.SQLVDirControl\x27)\s*\)(\s*\.\s*Connect\s*|.*(?P=n)\s*\.\s*Connect\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14758</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31129</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|Q|00|L|00|V|00|D|00|i|00|r|00|.|00|S|00|Q|00|L|00|V|00|D|00|i|00|r|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q19&gt;\x22|\x27|)S\x00Q\x00L\x00V\x00D\x00i\x00r\x00.\x00S\x00Q\x00L\x00V\x00D\x00i\x00r\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q19)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)S\x00Q\x00L\x00V\x00D\x00i\x00r\x00.\x00S\x00Q\x00L\x00V\x00D\x00i\x00r\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q20)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14759</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;S|00|E|00|L|00|E|00|C|00|T|00| |00|C|00|O|00|N|00|V|00|E|00|R|00|T|00 28 00|v|00|a|00|r|00|c|00|h|00|a|00|r|00|,|00|c|00|r|00|e|00|a|00|t|00|e|00|d|00|a|00|t|00|e|00|,|00|1|00|2|00|3|00|4|00|5|00|6|00|7|00|8|00|9|00|0|00 29 00| |00|F|00|R|00|O|00|M|00| |00|s|00|y|00|s|00|u|00|s|00|e|00|r|00|s&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16073</id>
        <msg>SPECIFIC-THREATS MS-SQL convert function unicode overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <cve>2008-0106</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;ansi_padding&quot;; pcre:&quot;/set\s+ansi_padding\s+off/smi&quot;; metadata:policy security-ips drop; classtype:policy-violation;</filter2>
        <id>16074</id>
        <msg>MS-SQL Suspicious SQL ansi_padding option</msg>
        <url>msdn.microsoft.com/en-us/library/ms187403.aspx</url>
      </rule>
      <rule>
        <bugtraq>25594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;object classid='clsid|3A|10020200-E260-11CF-AE68-00AA004A34D5' id='SQLServer' /&gt;&quot;; nocase; content:&quot;progid=|22|SQLDMO.SQLServer|22|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16208</id>
        <msg>WEB-CLIENT Microsoft SQL Server Distributed Management Objects overflow attempt</msg>
      </rule>
    </attacks>
    <groupid>231</groupid>
    <groupname>Server / Database / Microsoft</groupname>
    <warnings>
      <rule>
        <bugtraq>5411</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-1123</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433:1500</filter1>
        <filter2>flow:to_server,established; isdataat:514; content:&quot;|12 01|&quot;; depth:2; content:!&quot;|00|&quot;; within:512; distance:35; classtype:attempted-admin;</filter2>
        <id>11264</id>
        <msg>SQL Microsoft SQL Server 2000 Server hello buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS02-056.mspx</url>
      </rule>
      <rule>
        <bugtraq>14453</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1272</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6070</filter1>
        <filter2>flow:to_server,established; isdataat:1000; content:&quot;ABCDAAAA&quot;; classtype:attempted-admin;</filter2>
        <id>11683</id>
        <msg>SPECIFIC-THREATS CA BrightStor Agent for Microsoft SQL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;10020200-E260-11CF-AE68-00AA004A34D5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*10020200-E260-11CF-AE68-00AA004A34D5\s*}?\s*(?P=q9)(\s|&gt;).*(?P=id1)\s*\.\s*(Start)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*10020200-E260-11CF-AE68-00AA004A34D5\s*}?\s*(?P=q10)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(Start))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12444</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|0|00|0|00|2|00|0|00|2|00|0|00|0|00|-|00|E|00|2|00|6|00|0|00|-|00|1|00|1|00|C|00|F|00|-|00|A|00|E|00|6|00|8|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|A|00|3|00|4|00|D|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q11&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12445</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SQLDMO.SQLServer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22SQLDMO\.SQLServer\x22|\x27SQLDMO\.SQLServer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Start\s*|.*(?P=v)\s*\.\s*Start\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SQLDMO\.SQLServer\x22|\x27SQLDMO\.SQLServer\x27)\s*\)(\s*\.\s*Start\s*|.*(?P=n)\s*\.\s*Start\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12446</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4814</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|Q|00|L|00|D|00|M|00|O|00|.|00|S|00|Q|00|L|00|S|00|e|00|r|00|v|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)S\x00Q\x00L\x00D\x00M\x00O\x00.\x00S\x00Q\x00L\x00S\x00e\x00r\x00v\x00e\x00r\x00(?P=q12)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)S\x00Q\x00L\x00D\x00M\x00O\x00.\x00S\x00Q\x00L\x00S\x00e\x00r\x00v\x00e\x00r\x00(?P=q13)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12447</id>
        <msg>WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0085</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;TAPE&quot;; content:&quot;|00 12|&quot;; within:2; distance:82; classtype:misc-activity;</filter2>
        <id>13896</id>
        <msg>SQL Microsoft SQL server MTF file download</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-040.mspx</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <cve>2008-0106</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server, established; content:&quot;i|00|n|00|s|00|e|00|r|00|t|00 20 00|i|00|n|00|t|00|o|00 20 00|m|00|y|00|t|00|a|00|b|00|l|00|e|00 20 00|v|00|a|00|l|00|u|00|e|00|s|00 20 00 28 00|n|00|u|00|l|00|l|00 29|&quot;; classtype:policy-violation;</filter2>
        <id>17307</id>
        <msg>SPECIFIC-THREATS MS SQL Server INSERT Statement Buffer Overflow attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>232</groupid>
    <groupname>Server / Database / Oracle</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>27140</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|&quot;; content:&quot;|03 01|&quot;; within:2; distance:3; byte_jump:1,32,relative; byte_test:2,&gt;,64,0,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13593</id>
        <msg>SQL MySQL yaSSL SSL Hello Message Buffer Overflow attempt</msg>
        <url>bugs.mysql.com/bug.php?id=33814</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 3306 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>13709</id>
        <msg>MYSQL yaSSL SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET 3306 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>13710</id>
        <msg>MYSQL yaSSL TLSv1 Server_Hello request</msg>
      </rule>
      <rule>
        <bugtraq>27140</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:established,to_server; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01|&quot;; depth:1; offset:6; byte_test:2,&gt;,64,9; flowbits:set,sslv2.client_hello.request; flowbits:noalert;  metadata:policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>13711</id>
        <msg>MYSQL yaSSL SSLv2 Client Hello Message Cipher Length Buffer Overflow attempt</msg>
        <url>bugs.mysql.com/bug.php?id=33814</url>
      </rule>
      <rule>
        <bugtraq>27140</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:established,to_server; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01|&quot;; depth:1; offset:6; byte_test:2,&gt;,32,11; flowbits:set,sslv2.client_hello.request; flowbits:noalert;  metadata:policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>13712</id>
        <msg>MYSQL yaSSL SSLv2 Client Hello Message Session ID Buffer Overflow attempt</msg>
        <url>bugs.mysql.com/bug.php?id=33814</url>
      </rule>
      <rule>
        <bugtraq>27140</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:established,to_server; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01|&quot;; depth:1; offset:6; byte_test:2,&gt;,32,13; flowbits:set,sslv2.client_hello.request; flowbits:noalert;  metadata:policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>13713</id>
        <msg>MYSQL yaSSL SSLv2 Client Hello Message Challenge Buffer Overflow attempt</msg>
        <url>bugs.mysql.com/bug.php?id=33814</url>
      </rule>
      <rule>
        <bugtraq>27140</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:established,to_server; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; content:&quot;|01|&quot;; within:1; distance:2; content:&quot;|03 01|&quot;; within:2; distance:3; byte_jump:1,32,relative; byte_test:2,&gt;,64,0,relative; metadata:policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>13714</id>
        <msg>MYSQL yaSSL SSLv3 Client Hello Message Cipher Specs Buffer Overflow attempt</msg>
        <url>bugs.mysql.com/bug.php?id=33814</url>
      </rule>
      <rule>
        <bugtraq>33972</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0819</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|&quot;; depth:1; offset:4; content:&quot;SELECT&quot;; distance:0; nocase; content:&quot;ExtractValue&quot;; distance:1; nocase; pcre:&quot;/^.{4}\x03\s*SELECT\s+ExtractValue\s*\x28.*?\x2c\s*((\x22|\x27)?[0-9].*?|(?P&lt;q1&gt;(\x22|\x27)?)\x28.*?\x29(?P=q1)|.*?\x24\x40.*?|\x22.*?\x27.*?|\x27.*?\x22.*?)\s*\x29/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-dos;</filter2>
        <id>15442</id>
        <msg>MYSQL XML Functions ExtractValue Scalar XPath denial of service attempt</msg>
        <url>secunia.com/advisories/34115</url>
      </rule>
      <rule>
        <bugtraq>33972</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0819</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|&quot;; depth:1; offset:4; content:&quot;SELECT&quot;; distance:0; nocase; content:&quot;UpdateXML&quot;; distance:1; nocase; pcre:&quot;/^.{4}\x03\s*SELECT\s+UpdateXML\s*\x28.*?\x2c\s*((\x22|\x27)?[0-9].*?|(?P&lt;q1&gt;(\x22|\x27)?)\x28.*?\x29(?P=q1)|.*?\x24\x40.*?|\x22.*?\x27.*?|\x27.*?\x22.*?)\s*\x2c.*?\x29/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-dos;</filter2>
        <id>15443</id>
        <msg>MYSQL XML Functions UpdateXML Scalar XPath denial of service attempt</msg>
        <url>secunia.com/advisories/34115</url>
      </rule>
      <rule>
        <bugtraq>12781</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0709</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|create function&quot;; depth:16; offset:4; content:&quot;libc.so&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15952</id>
        <msg>MYSQL create function libc arbitrary code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17780</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2006-1516</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 0D A6 03 00 00 00 00 01 08|&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>16020</id>
        <msg>SPECIFIC-THREATS MySQL login handshake information disclosure attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-4019</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;'|00 00 00 03|select * from `v1` procedure analyse|28 29|&quot;; depth:43; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-dos;</filter2>
        <id>16348</id>
        <msg>SPECIFIC-THREATS Sun MySQL database PROCEDURE ANALYSE denial of service attempt - 1</msg>
        <url>dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-4019</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;,|00 00 00 03|select * from `theview` procedure analyse|28 29|&quot;; depth:48; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-dos;</filter2>
        <id>16349</id>
        <msg>SPECIFIC-THREATS Sun MySQL database Procedure Analyse denial of service attempt - 2</msg>
        <url>dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html</url>
      </rule>
      <rule>
        <bugtraq>37640</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4484</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|0B|&quot;; within:1; distance:2; content:&quot;*|86 00 84 00 00 04|&gt;&quot;; within:8; distance:56; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>16385</id>
        <msg>MYSQL yaSSL library cert parsing stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12781</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0710</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|&quot;; depth:5; content:&quot;mysql.func&quot;; distance:0; nocase; pcre:&quot;/(INSERT|UPDATE)\s*[\s\w]*((mysql\.)?func)[^\r\n]+values\s*\([^\)]+\x2c[\x22\x27][^\x22\x27]*\x2f/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17412</id>
        <msg>MYSQL CREATE FUNCTION mysql.func Arbitrary Library Injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $SQL_SERVERS 3306 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|00|&quot;; depth:1; offset:3; flowbits:set,mysql.server_greeting; flowbits:noalert; classtype:attempted-user;</filter2>
        <id>3665</id>
        <msg>MYSQL server greeting</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
    </attacks>
    <groupid>233</groupid>
    <groupname>Server / Database / MySQL</groupname>
    <warnings>
      <rule>
        <bugtraq>17780</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1517</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3306</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|11619;</filter2>
        <id>11619</id>
        <msg>MISC MySQL COM_TABLE_DUMP Function Stack Overflow attempt</msg>
        <url>www.wisec.it/vulns.php?page=8</url>
      </rule>
      <rule>
        <bugtraq>2198</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1044</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/class/mysql.class&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1527</id>
        <msg>WEB-MISC basilix mysql.class access</msg>
        <nessus>10601</nessus>
      </rule>
      <rule>
        <bugtraq>13368</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0684</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /%AAAAAAAA&quot;; depth:14; metadata:service http; classtype:attempted-user;</filter2>
        <id>15951</id>
        <msg>SPECIFIC-THREATS MySQL MaxDB Webtool GET command overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A 00 00 01 85 04 00 00 80|root|00|&quot;; fast_pattern:only; metadata:service mysql; classtype:protocol-command-decode;</filter2>
        <id>1775</id>
        <msg>MYSQL root login attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|0F 00 00 00 03|show databases&quot;; fast_pattern:only; metadata:service mysql; classtype:protocol-command-decode;</filter2>
        <id>1776</id>
        <msg>MYSQL show databases attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;root|00|&quot;; within:5; distance:5; nocase; metadata:service mysql; classtype:protocol-command-decode;</filter2>
        <id>3456</id>
        <msg>MYSQL 4.0 root login attempt</msg>
      </rule>
      <rule>
        <bugtraq>12265</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-0111</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;websql?logon&quot;; nocase; content:&quot;wqPassword=&quot;; distance:0; nocase; pcre:&quot;/wqPassword=[^\r\n\x26]{294}/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3518</id>
        <msg>WEB-MISC MySQL MaxDB WebSQL wppassword buffer overflow</msg>
        <url>www.osvdb.org/displayvuln.php?osvdb_id=12919</url>
      </rule>
      <rule>
        <bugtraq>12265</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-0111</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;websql?logon&quot;; nocase; content:&quot;wqPassword=&quot;; distance:0; nocase; pcre:&quot;/wqPassword=[^\r\n\x26]{294}/i&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>3519</id>
        <msg>WEB-MISC MySQL MaxDB WebSQL wppassword buffer overflow default port</msg>
        <url>www.osvdb.org/displayvuln.php?osvdb_id=12919</url>
      </rule>
      <rule>
        <bugtraq>12781</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2005-0709</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|create&quot;; offset:4; nocase; pcre:&quot;/\x03create\s+(aggregate\s+)*function/smi&quot;; metadata:service mysql; classtype:misc-activity;</filter2>
        <id>3528</id>
        <msg>MYSQL create function access attempt</msg>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $SQL_SERVERS 3306 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; byte_test:1,&gt;,0,3; flowbits:isset,mysql.server_greeting; flowbits:unset,mysql.server_greeting; flowbits:noalert; classtype:attempted-user;</filter2>
        <id>3666</id>
        <msg>MYSQL server greeting finished</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,&amp;,0x80,4; byte_test:1,&amp;,0x02,4; content:&quot;|00 14 00|&quot;; offset:36; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3667</id>
        <msg>MYSQL protocol 41 client authentication bypass attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,&amp;,0x80,4; byte_test:1,!&amp;,0x02,4; content:&quot;|00 14 00|&quot;; offset:9; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3668</id>
        <msg>MYSQL client authentication bypass attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,&amp;,0x80,4; byte_test:1,&amp;,0x02,4; content:&quot;|00 14|&quot;; offset:36; isdataat:74,relative; content:!&quot;|00|&quot;; within:74; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3669</id>
        <msg>MYSQL protocol 41 secure client overflow attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,&amp;,0x80,4; byte_test:1,!&amp;,0x02,4; content:&quot;|00 14|&quot;; offset:9; isdataat:74,relative; content:!&quot;|00|&quot;; within:74; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3670</id>
        <msg>MYSQL secure client overflow attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,!&amp;,0x80,4; byte_test:1,&amp;,0x02,4; content:&quot;|00|&quot;; offset:36; isdataat:74,relative; content:!&quot;|00|&quot;; within:74; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3671</id>
        <msg>MYSQL protocol 41 client overflow attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>10655</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0627</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; flowbits:isset,mysql.server_greeting; content:&quot;|01|&quot;; depth:1; offset:3; byte_test:1,!&amp;,0x80,4; byte_test:1,!&amp;,0x02,4; content:&quot;|00|&quot;; offset:9; isdataat:74,relative; content:!&quot;|00|&quot;; within:74; metadata:service mysql; classtype:misc-attack;</filter2>
        <id>3672</id>
        <msg>MYSQL client overflow attempt</msg>
        <nessus>12639</nessus>
        <url>www.nextgenss.com/advisories/mysql-authbypass.txt</url>
      </rule>
      <rule>
        <bugtraq>14509</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2005-2558</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|create&quot;; offset:4; nocase; pcre:&quot;/\x03create\s+(aggregate\s+)*function\s+\S{50}/smi&quot;; metadata:service mysql; classtype:misc-activity;</filter2>
        <id>4649</id>
        <msg>MYSQL create function buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>1557</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0707</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;pccsmysqladm/incs/dbconnect.inc&quot;; depth:36; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>509</id>
        <msg>WEB-MISC PCCS mysql database admin tool access</msg>
        <nessus>10783</nessus>
      </rule>
      <rule>
        <bugtraq>19032</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-3469</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 3306</filter1>
        <filter2>flow:to_server,established; content:&quot;DATE_FORMAT&quot;; pcre:&quot;/DATE_FORMAT\x28\s*(\x22[^\x22]+\x25[^\x22]*\x22|\x27[^\x27]+\x25[^\x27]*\x27)/smi&quot;; metadata:service mysql; classtype:attempted-dos;</filter2>
        <id>8057</id>
        <msg>MYSQL Date_Format denial of service attempt</msg>
        <url>dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SYS.DBMS_AQADM_SYS.GRANT_TYPE_ACCESS&quot;; nocase; pcre:&quot;/SYS\x2eDBMS\x5fAQADM\x5fSYS\x2eGRANT\x5fTYPE\x5fACCESS\s*\x28\s*\x27[^\x2c\x20\x27]*[\x2c\x20]/is&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>11204</id>
        <msg>ORACLE Oracle Database DBMS_AQADM_SYS package GRANT_TYPE_ACCESS procedure SQL injection attempt</msg>
        <url>www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqadm_sys.html</url>
      </rule>
      <rule>
        <bugtraq>24585</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3338</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21064</filter1>
        <filter2>flow:to_server,established; content:&quot;uuid_from_char&quot;; fast_pattern:only; pcre:&quot;/uuid_from_char\s*\(\s*(\x22|\x27)[^\1]{37}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12027</id>
        <msg>SQL Ingres Database uuid_from_char buffer overflow attempt</msg>
        <url>www.ngssoftware.com/advisories/high-risk-vulnerability-in-ingres-stack-overflow</url>
      </rule>
      <rule>
        <bugtraq>27206</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0244</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 7210</filter1>
        <filter2>flow:established,to_server; content:&quot;exec_sdbinfo&quot;; fast_pattern:only; pcre:&quot;/exec_sdbinfo\s+[\x26\x3b\x7c\x3e\x3c]/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13356</id>
        <msg>SQL SAP MaxDB shell command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>26098</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5511</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1521</filter1>
        <filter2>flow:to_server,established; content:&quot;SYS.LT.FINDRICSET&quot;; nocase; content:&quot;''|7C 7C|&quot;; distance:0; pcre:&quot;/SYS.LT.FINDRICSET\([^,\)]*\'\'\|\|/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13366</id>
        <msg>ORACLE Oracle database SYS.LT.FINDRICSET SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;exec&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/exec\s+master/Ui&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13512</id>
        <msg>SQL generic sql exec injection attempt - GET parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;insert&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/insert\s+into\s+[^\/\\]+/Ui&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13513</id>
        <msg>SQL generic sql insert injection atttempt - GET parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <bugtraq>27229</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0339</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;XDB.XDB_PITRIG_PKG.PITRIG_&quot;; nocase; pcre:&quot;/XDB\x2EXDB_PITRIG_PKG\x2EPITRIG_(DROP|TRUNCATE)\s*\x28[^\x29]*\x27[^\x27]*\x22/smi&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13551</id>
        <msg>ORACLE Oracle XDB.XDB_PITRIG_PKG sql injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;CAST|28|&quot;; nocase; isdataat:250,relative; content:!&quot;|29|&quot;; within:250; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13791</id>
        <msg>SQL oversized cast statement - possible sql injection obfuscation</msg>
        <url>isc.sans.org/diary.html?storyid=3823</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2008-2991</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;Help_Errors.asp&quot;; nocase; http_uri; pcre:&quot;/\x26r0\x3d\d*[^\x26\s\d]/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13928</id>
        <msg>SPECIFIC-THREATS Adobe RoboHelp r0 SQL injection attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2008-2991</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;Top_Unanswered_Customer_Questions.asp&quot;; nocase; http_uri; pcre:&quot;/\x26r\d\x3d[^\x26\s]*\x27/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13929</id>
        <msg>WEB-MISC Adobe RoboHelp rx SQL injection attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;CONVERT|28|&quot;; nocase; isdataat:250,relative; content:!&quot;|29|&quot;; within:250; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13987</id>
        <msg>SQL oversized convert statement - possible sql injection obfuscation</msg>
        <url>isc.sans.org/diary.html?storyid=3823</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;ASCII|28|&quot;; nocase; content:&quot;ASCII|28|&quot;; distance:0; nocase; content:&quot;ASCII|28|&quot;; distance:0; nocase; content:&quot;ASCII|28|&quot;; distance:0; nocase; content:&quot;ASCII|28|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>13988</id>
        <msg>SQL large number of calls to ascii function - possible sql injection obfuscation</msg>
        <url>isc.sans.org/diary.html?storyid=3823</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;union&quot;; fast_pattern; nocase; http_uri; content:&quot;select&quot;; nocase; http_uri; pcre:&quot;/union\s+select\s+[^\/\\]+from\s+[^\/\\]+/Ui&quot;; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>13990</id>
        <msg>SQL union select - possible sql injection attempt - GET parameter</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;CONCAT|28|&quot;; nocase; content:&quot;CONCAT|28|&quot;; distance:0; nocase; content:&quot;CONCAT|28|&quot;; distance:0; nocase; content:&quot;CONCAT|28|&quot;; distance:0; nocase; content:&quot;CONCAT|28|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>14008</id>
        <msg>SQL large number of calls to concat function - possible sql injection obfuscation</msg>
        <url>isc.sans.org/diary.html?storyid=3823</url>
      </rule>
      <rule>
        <bugtraq>29601</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3854</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:to_server,established; content:&quot;xmlquery&quot;; fast_pattern:only; content:&quot;select &quot;; nocase; pcre:&quot;/select\s+xmlquery\s*\x28\s*(\x27|\x22)[^\x27\x22]{512}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service mysql; classtype:attempted-user;</filter2>
        <id>14991</id>
        <msg>SQL IBM DB2 Universal Database xmlquery buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;s|00|p|00|_|00|r|00|e|00|p|00|l|00|w|00|r|00|i|00|t|00|e|00|t|00|o|00|v|00|a|00|r|00|b|00|i|00|n|00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15143</id>
        <msg>SQL sp_replwritetovarbin unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>32710</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;sp_replwritetovarbin&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15144</id>
        <msg>SQL sp_replwritetovarbin vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-004.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C|sql|5C|query|00|&quot;; within:12; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15319</id>
        <msg>NETBIOS-DG SMB /sql/query create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C 00|s|00|q|00|l|00 5C 00|q|00|u|00|e|00|r|00|y|00 00 00|&quot;; within:23; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15320</id>
        <msg>NETBIOS-DG SMB /sql/query unicode create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,!&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C|sql|5C|query|00|&quot;; within:12; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15321</id>
        <msg>NETBIOS SMB /sql/query create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; content:&quot;|5C 00|s|00|q|00|l|00 5C 00|q|00|u|00|e|00|r|00|y|00 00 00|&quot;; within:23; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15322</id>
        <msg>NETBIOS SMB /sql/query unicode create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C|sql|5C|query|00|&quot;; within:12; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15323</id>
        <msg>NETBIOS-DG SMB /sql/query andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|11|&quot;; depth:1; content:&quot;|00|&quot;; distance:13; content:&quot;|00|&quot;; distance:0; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C 00|s|00|q|00|l|00 5C 00|q|00|u|00|e|00|r|00|y|00 00 00|&quot;; within:23; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-dgm; classtype:protocol-command-decode;</filter2>
        <id>15324</id>
        <msg>NETBIOS-DG SMB /sql/query unicode andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,!&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C|sql|5C|query|00|&quot;; within:12; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15325</id>
        <msg>NETBIOS SMB /sql/query andx create tree attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB&quot;; within:4; distance:3; pcre:&quot;/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR&quot;; byte_test:1,&amp;,128,6,relative; content:&quot;|A2|&quot;; depth:1; offset:39; byte_jump:2,0,little,relative; content:&quot;|5C 00|s|00|q|00|l|00 5C 00|q|00|u|00|e|00|r|00|y|00 00 00|&quot;; within:23; distance:51; nocase; flowbits:set,smb.tree.create.sql.query; flowbits:noalert; metadata:service netbios-ssn; classtype:protocol-command-decode;</filter2>
        <id>15326</id>
        <msg>NETBIOS SMB /sql/query unicode andx create tree attempt</msg>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0978</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.RollbackWorkspace&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*\x27\s*[^\s\x2c\x29]/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15515</id>
        <msg>ORACLE Oracle Database Server RollbackWorkspace SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; pcre:&quot;/CHAR\(.*?CHAR\(.*?CHAR\(/smi&quot;; content:&quot;[sysobjects]&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15584</id>
        <msg>SQL char and sysobjects - possible sql injection recon attempt</msg>
        <url>isc.sans.org/diary.html?storyid=3823</url>
      </rule>
      <rule>
        <bugtraq>31683</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3982</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;GRAN|FF|T EXECUTE ON VZJSQ TO PUBLIC&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15722</id>
        <msg>SPECIFIC-THREATS Oracle database server Workspace Manager multiple SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html</url>
      </rule>
      <rule>
        <bugtraq>31683</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3982</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;.CompressWorkspaceTree&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*?\x27\s*[^\x2c\x29]/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15723</id>
        <msg>ORACLE Oracle database server CompressWorkspaceTree SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html</url>
      </rule>
      <rule>
        <bugtraq>31683</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3982</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;.MergeWorkspace&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*\x27\s*[^\x2c\x29]/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15724</id>
        <msg>ORACLE Oracle database server MergeWorkspace SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html</url>
      </rule>
      <rule>
        <bugtraq>31683</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3982</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;.RemoveWorkspace&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*\x27\s*[^\x2c\x29]/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15725</id>
        <msg>ORACLE Oracle database server RemoveWorkspace SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html</url>
      </rule>
      <rule>
        <bugtraq>29302</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2559</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 01|&quot;; depth:4; byte_jump:4,12,relative,align; content:&quot;|02|&quot;; within:1; distance:8; byte_test:1,&gt;,64,0,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15868</id>
        <msg>SQL Borland InterBase username buffer overflow</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;union &quot;; fast_pattern; nocase; http_client_body; content:&quot;select &quot;; nocase; http_client_body; pcre:&quot;/union\s+select\s+[^\/\\]+from\s+[^\/\\]+/Pi&quot;; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>15874</id>
        <msg>SQL union select - possible sql injection attempt - POST parameter</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;insert &quot;; fast_pattern; nocase; http_client_body; pcre:&quot;/insert\s+into\s+[^\/\\]+/Pi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15875</id>
        <msg>SQL generic sql insert injection atttempt - POST parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;update &quot;; fast_pattern; nocase; http_client_body; pcre:&quot;/update\s+[^\/\\]+set\s+[^\/\\]+/Pi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15876</id>
        <msg>SQL generic sql update injection attempt - POST parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;exec &quot;; fast_pattern; nocase; http_client_body; content:&quot;master &quot;; nocase; http_client_body; pcre:&quot;/exec\s+master/Pi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15877</id>
        <msg>SQL generic sql exec injection attempt - POST parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <bugtraq>35842</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2620</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00|5&quot;; depth:4; isdataat:11,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>15896</id>
        <msg>DOS Firebird SQL op_connect_request denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>21303</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4181</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1813</filter1>
        <filter2>flow:to_server; content:&quot;|04|&quot;; depth:1; content:&quot;|01 1A|%n%s%n%s%n%s%n%s%n%s%n%s&quot;; distance:19; metadata:policy security-ips drop, service radius; classtype:attempted-admin;</filter2>
        <id>16049</id>
        <msg>SPECIFIC-THREATS GNU Radius SQL accounting format string exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;27A3D328-D206-4106-8D33-1AA39B13394B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*27A3D328-D206-4106-8D33-1AA39B13394B\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16159</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 1 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|7|00|A|00|3|00|D|00|3|00|2|00|8|00|-|00|D|00|2|00|0|00|6|00|-|00|4|00|1|00|0|00|6|00|-|00|8|00|D|00|3|00|3|00|-|00|1|00|A|00|A|00|3|00|9|00|B|00|1|00|3|00|3|00|9|00|4|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x007\x00A\x003\x00D\x003\x002\x008\x00-\x00D\x002\x000\x006\x00-\x004\x001\x000\x006\x00-\x008\x00D\x003\x003\x00-\x001\x00A\x00A\x003\x009\x00B\x001\x003\x003\x009\x004\x00B\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16160</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 1 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DB640C86-731C-484A-AAAF-750656C9187D&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DB640C86-731C-484A-AAAF-750656C9187D\s*}?\s*(?P=q3)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16161</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 2 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|B|00|6|00|4|00|0|00|C|00|8|00|6|00|-|00|7|00|3|00|1|00|C|00|-|00|4|00|8|00|4|00|A|00|-|00|A|00|A|00|A|00|F|00|-|00|7|00|5|00|0|00|6|00|5|00|6|00|C|00|9|00|1|00|8|00|7|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q4&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00B\x006\x004\x000\x00C\x008\x006\x00-\x007\x003\x001\x00C\x00-\x004\x008\x004\x00A\x00-\x00A\x00A\x00A\x00F\x00-\x007\x005\x000\x006\x005\x006\x00C\x009\x001\x008\x007\x00D\x00(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16162</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 2 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;15721a53-8448-4731-8bfc-ed11e128e444&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*15721a53-8448-4731-8bfc-ed11e128e444\s*}?\s*(?P=q5)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16163</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 3 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|5|00|7|00|2|00|1|00|a|00|5|00|3|00|-|00|8|00|4|00|4|00|8|00|-|00|4|00|7|00|3|00|1|00|-|00|8|00|b|00|f|00|c|00|-|00|e|00|d|00|1|00|1|00|e|00|1|00|2|00|8|00|e|00|4|00|4|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q6&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x005\x007\x002\x001\x00a\x005\x003\x00-\x008\x004\x004\x008\x00-\x004\x007\x003\x001\x00-\x008\x00b\x00f\x00c\x00-\x00e\x00d\x001\x001\x00e\x001\x002\x008\x00e\x004\x004\x004\x00(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16164</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 3 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3267123E-530D-4E73-9DA7-79F01D86A89F&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3267123E-530D-4E73-9DA7-79F01D86A89F\s*}?\s*(?P=q7)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16165</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 4 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|2|00|6|00|7|00|1|00|2|00|3|00|E|00|-|00|5|00|3|00|0|00|D|00|-|00|4|00|E|00|7|00|3|00|-|00|9|00|D|00|A|00|7|00|-|00|7|00|9|00|F|00|0|00|1|00|D|00|8|00|6|00|A|00|8|00|9|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x002\x006\x007\x001\x002\x003\x00E\x00-\x005\x003\x000\x00D\x00-\x004\x00E\x007\x003\x00-\x009\x00D\x00A\x007\x00-\x007\x009\x00F\x000\x001\x00D\x008\x006\x00A\x008\x009\x00F\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16166</id>
        <msg>WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 4 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <bugtraq>35685</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1021</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;DBMS_REPCAT_RPC.VALIDATE_REMOTE_RC&quot;; nocase; pcre:&quot;/^\s*\x28[^\x2c]+\x2c[^\x2c]+?\x3b/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16189</id>
        <msg>ORACLE Oracle Database REPCAT_RPC.VALIDATE_REMOTE_RC SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</url>
      </rule>
      <rule>
        <bugtraq>36748</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1991</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;ctxsys.drvxtabc.create_tables&quot;; nocase; pcre:&quot;/^\s*\x28\s*(\x27[^\x27\x22]*\x27\s*\x2c\s*)?\x27[^\x27\x22]*\x22/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16290</id>
        <msg>ORACLE Oracle database server CREATE_TABLES SQL injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</url>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2009-0173</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:to_server,established; content:&quot;|24 14|&quot;; content:&quot;|D0|&quot;; within:1; distance:-8; byte_test:1, &amp;, 4, 0, relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>16364</id>
        <msg>DOS IBM DB2 database server SQLSTT denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>32189</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-6510</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [9090,9091]</filter1>
        <filter2>flow:to_server, established; content:&quot;sipark-log-summary.j&quot;; nocase; http_uri; pcre:&quot;/sipark-log-summary\.jsp\?(username|numa(a|b)|type)[^\s]*\s/Umi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16513</id>
        <msg>SQL Jive Software Openfire Jabber Server SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>33722</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server, established; content:&quot;USER&quot;; fast_pattern:only; pcre:&quot;/USER\s*[^\x0d]+\x25\x27/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service ftp; classtype:attempted-admin;</filter2>
        <id>16524</id>
        <msg>FTP ProFTPD username sql injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>39422</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0870</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE&quot;; nocase; pcre:&quot;/^\s*\x28\s*[^\x29\x2C]*?\x27\x27/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16722</id>
        <msg>ORACLE Oracle Database Server DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE procedure SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>39422</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0870</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;DBMS_CDC_PUBLISH.ALTER_CHANGE_SOURCE&quot;; nocase; pcre:&quot;/^\s*\x28[^\x29\x2C]*?\x27\x27/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16723</id>
        <msg>ORACLE Oracle Database Server DBMS_CDC_PUBLISH.ALTER_CHANGE_SOURCE procedure SQL injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2772</cve>
        <filter1>tcp any any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;WinCCConnect&quot;; content:&quot;2WSXcder&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17044</id>
        <msg>SQL WinCC DB default password security bypass attempt</msg>
        <url>support.automation.siemens.com/WW/view/en/43876783</url>
      </rule>
      <rule>
        <bugtraq>37976</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0462</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:to_server, established; content:&quot; REPEAT|28|&quot;; nocase; content:&quot;,&quot;; distance:0; byte_test:10,&gt;,1000,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17209</id>
        <msg>SQL IBM DB2 DATABASE SERVER SQL REPEAT Buffer Overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SYS.DBMS_METADATA.GET_DDL|28 27 27 27 7C 7C|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17270</id>
        <msg>ORACLE DBMS_METADATA Package SQL Injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3855</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $ORACLE_PORTS</filter1>
        <filter2>flow:to_server, established; flowbits:isset, oracle.connect; content:&quot;create view&quot;; fast_pattern; nocase; content:&quot;as select&quot;; distance:0; nocase; content:&quot;from sys.&quot;; distance:0; nocase; pcre:&quot;/create view\s*[^\s]*\s*as select\s+([^\x2e]+)\x2e.*\1\x2E.*from sys\x2E[^\s]*\s*\1\x2C\s*sys\x2E[^\s]*\s*([^\s]+)\s*where\s*\1\x2e[^\s\x3D]+\s*\x3D\s*\2\x2E/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17419</id>
        <msg>ORACLE Oracle database SQL compiler read-only join auth bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>15220</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-3315</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;/packages/default.asp?&quot;; nocase; http_uri; pcre:&quot;/sort\x3d[^\s]*\x3b+/Ui&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>17449</id>
        <msg>WEB-MISC Novell ZENworks patch management SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>19203</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_ASSERT.simple_sql_name|28|&quot;; fast_pattern:only; nocase; pcre:&quot;/DBMS_ASSERT\x2Esimple_sql_name\x28[^\x29\x22]*?\x22/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17590</id>
        <msg>ORACLE DBMS_ASSERT.simple_sql_name double quote SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>4797</bugtraq>
        <classtype>unsuccessful-user</classtype>
        <cve>2000-1209</cve>
        <filter1>tcp $SQL_SERVERS 1433 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Login failed for user 'sa'&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:unsuccessful-user;</filter2>
        <id>688</id>
        <msg>SQL sa login failed</msg>
        <nessus>10673</nessus>
      </rule>
    </attacks>
    <groupid>234</groupid>
    <groupname>Server / Database / Common SQL</groupname>
    <warnings>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ftp.exe&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1057</id>
        <msg>SQL ftp attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_enumdsn&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1058</id>
        <msg>SQL xp_enumdsn attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_filelist&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1059</id>
        <msg>SQL xp_filelist attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_availablemedia&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1060</id>
        <msg>SQL xp_availablemedia attempt</msg>
      </rule>
      <rule>
        <bugtraq>5309</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_cmdshell&quot;; fast_pattern:only; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1061</id>
        <msg>SQL xp_cmdshell attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regread&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1069</id>
        <msg>SQL xp_regread attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/samples/search/queryhit.htm&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1077</id>
        <msg>SQL queryhit.htm access</msg>
        <nessus>10370</nessus>
      </rule>
      <rule>
        <bugtraq>267</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1030</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/counter.exe&quot;; fast_pattern; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1078</id>
        <msg>SQL counter.exe access</msg>
      </rule>
      <rule>
        <bugtraq>9484</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; pcre:&quot;/action(=|\x3f)[^(\n|&amp;)]*\x3c[^(\n|&amp;)]+\x3e/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>11193</id>
        <msg>WEB-MISC Oracle iSQL Plus cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>9484</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; content:&quot;username=&quot;; nocase; http_uri; pcre:&quot;/username(=|\x3f)[^(\n|&amp;)]*\x3c[^(\n|&amp;)]+\x3e/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>11194</id>
        <msg>WEB-MISC Oracle iSQL Plus cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>16452</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0522</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/servlet/Sygate.Servlet.login&quot;; nocase; http_uri; pcre:&quot;/[^\x26\x20\x0a]*insert[^\x26\x20\x0a]*Login[^\x26\x20\x0a]*Admin/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>11616</id>
        <msg>WEB-MISC Symantec Sygate Policy Manager SQL injection</msg>
      </rule>
      <rule>
        <bugtraq>9484</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; content:&quot;password=&quot;; nocase; http_uri; pcre:&quot;/password(=|\x3f)[^(\n|&amp;)]*\x3c[^(\n|&amp;)]+\x3e/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>11685</id>
        <msg>WEB-MISC Oracle iSQL Plus cross site scripting attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3181</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 01|&quot;; depth:4; byte_jump:4,12,big,relative; byte_test:2,&gt;,10,1,big,relative; classtype:attempted-user;</filter2>
        <id>12009</id>
        <msg>SQL Firebird SQL Fbserver buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9484</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 7779</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; content:&quot;username=&quot;; nocase; http_uri; pcre:&quot;/username(=|\x3f)[^(\n|&amp;)]*\x3c[^(\n|&amp;)]+\x3e/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12059</id>
        <msg>WEB-MISC Oracle iSQL Plus cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>9484</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-2115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 7779</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; pcre:&quot;/action(=|\x3f)[^(\n|&amp;)]*\x3c[^(\n|&amp;)]+\x3e/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12060</id>
        <msg>WEB-MISC Oracle iSQL Plus cross site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>27914</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0912</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2439</filter1>
        <filter2>flow:to_server,established; content:&quot;|03 22 00|&quot;; byte_test:2,&gt;,128,0,relative,little; classtype:attempted-admin;</filter2>
        <id>13553</id>
        <msg>EXPLOIT Sybase SQL Anywhere Mobilink username string buffer overflow</msg>
        <url>aluigi.altervista.org/adv/mobilinkhof-adv.txt</url>
      </rule>
      <rule>
        <bugtraq>27914</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0912</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2439</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|&quot;; content:&quot;|03 22 00|&quot;; distance:0; byte_jump:2,0,relative,little; byte_test:2,&gt;,128,0,relative,little; classtype:attempted-admin;</filter2>
        <id>13554</id>
        <msg>EXPLOIT Sybase SQL Anywhere Mobilink version string buffer overflow</msg>
        <url>aluigi.altervista.org/adv/mobilinkhof-adv.txt</url>
      </rule>
      <rule>
        <bugtraq>27914</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0912</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2439</filter1>
        <filter2>flow:to_server,established; content:&quot;|03 22 00|&quot;; byte_jump:2,0,relative,little; byte_jump:2,0,relative,little; byte_test:2,&gt;,128,0,relative,little; classtype:attempted-admin;</filter2>
        <id>13555</id>
        <msg>EXPLOIT Sybase SQL Anywhere Mobilink remoteID string buffer overflow</msg>
        <url>aluigi.altervista.org/adv/mobilinkhof-adv.txt</url>
      </rule>
      <rule>
        <bugtraq>3727</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-1217</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_/&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1385</id>
        <msg>WEB-MISC mod-plsql administration access</msg>
        <nessus>10849</nessus>
      </rule>
      <rule>
        <bugtraq>3733</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;r|00|a|00|i|00|s|00|e|00|r|00|r|00|o|00|r|00|&quot;; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>1386</id>
        <msg>SQL raiserror possible buffer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-060.mspx</url>
      </rule>
      <rule>
        <bugtraq>3733</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;r|00|a|00|i|00|s|00|e|00|r|00|r|00|o|00|r|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>1387</id>
        <msg>SQL raiserror possible buffer overflow</msg>
        <nessus>11217</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0106</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13891;</filter2>
        <id>13891</id>
        <msg>SQL Memory page overwrite attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13892;</filter2>
        <id>13892</id>
        <msg>SQL Convert function style overwrite</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-040.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regaddmultistring&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13991</id>
        <msg>SQL xp_regaddmultistring attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regdeletevalue&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13992</id>
        <msg>SQL xp_regdeletevalue attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regenumkeys&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13993</id>
        <msg>SQL xp_regenumkeys attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regenumvalues&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13994</id>
        <msg>SQL xp_regenumvalues attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_regremovemultistring&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13995</id>
        <msg>SQL xp_regremovemultistring attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_servicecontrol&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13996</id>
        <msg>SQL xp_servicecontrol attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_loginconfig&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13997</id>
        <msg>SQL xp_loginconfig attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;xp_terminate_process&quot;; fast_pattern:only; metadata:service http; classtype:web-application-activity;</filter2>
        <id>13998</id>
        <msg>SQL xp_terminate_process attempt</msg>
      </rule>
      <rule>
        <bugtraq>37973</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0442</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5432</filter1>
        <filter2>flow:established,to_server; content:&quot;substring|28|B'&quot;; pcre:&quot;/substring\x28B'[^\x27\x29]+\x27\s*,\s*\d+\s*,\s*-([2-9][\s\x29]|\d{2})/smi&quot;; classtype:attempted-admin;</filter2>
        <id>16393</id>
        <msg>EXPLOIT Postgresql bit substring buffer overflow</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/*&quot;; http_uri; content:&quot;*/&quot;; http_uri; pcre:&quot;/(update|exec|insert|union)[^\/\\]*\/\*.*\*\//Uis&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>16431</id>
        <msg>SQL generic sql with comments injection attempt - GET parameter</msg>
        <url>www.securiteam.com/securityreviews/5DP0N1P76E.html</url>
      </rule>
      <rule>
        <bugtraq>5309</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 445</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|c|00|m|00|d|00|s|00|h|00|e|00|l|00|l|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>1759</id>
        <msg>SQL xp_cmdshell program execution 445</msg>
      </rule>
      <rule>
        <bugtraq>4290</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0568</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/XSQLConfig.xml&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1871</id>
        <msg>WEB-MISC Oracle XSQLConfig.xml access</msg>
        <nessus>10855</nessus>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1434</filter1>
        <filter2>flow:to_server; content:&quot;|02|&quot;; depth:1; classtype:misc-activity;</filter2>
        <id>2049</id>
        <msg>SQL ping attempt</msg>
        <nessus>10674</nessus>
      </rule>
      <rule>
        <bugtraq>4520</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0539</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dm/demarc&quot;; http_uri; content:&quot;s_key=&quot;; content:&quot;'&quot;; distance:0; content:&quot;'&quot;; distance:1; content:&quot;'&quot;; distance:0; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2063</id>
        <msg>WEB-MISC Demarc SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>10871</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; pcre:&quot;/sid=[^&amp;\x3b\r\n]{255}/si&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2701</id>
        <msg>WEB-MISC Oracle iSQLPlus sid overflow attempt</msg>
        <url>www.nextgenss.com/advisories/ora-isqlplus.txt</url>
      </rule>
      <rule>
        <bugtraq>10871</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/isqlplus&quot;; nocase; http_uri; pcre:&quot;/username=[^&amp;\x3b\r\n]{255}/si&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2702</id>
        <msg>WEB-MISC Oracle iSQLPlus username overflow attempt</msg>
        <url>www.nextgenss.com/advisories/ora-isqlplus.txt</url>
      </rule>
      <rule>
        <bugtraq>10871</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login.uix&quot;; nocase; http_uri; pcre:&quot;/username=[^&amp;\x3b\r\n]{250}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2703</id>
        <msg>WEB-MISC Oracle iSQLPlus login.uix username overflow attempt</msg>
        <url>www.nextgenss.com/advisories/ora-isqlplus.txt</url>
      </rule>
      <rule>
        <bugtraq>10871</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login.uix&quot;; nocase; http_uri; content:&quot;connectID=&quot;; nocase; isdataat:255,relative; pcre:&quot;/connectID=[^&amp;\x3b\r\n]{255}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2704</id>
        <msg>WEB-MISC Oracle 10g iSQLPlus login.unix connectID overflow attempt</msg>
        <url>www.nextgenss.com/advisories/ora-isqlplus.txt</url>
      </rule>
      <rule>
        <bugtraq>4797</bugtraq>
        <classtype>unsuccessful-user</classtype>
        <cve>2000-1209</cve>
        <filter1>tcp $SQL_SERVERS 1433 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Login failed for user 'sa'&quot;; fast_pattern:only; detection_filter:track by_src, count 5, seconds 2; classtype:unsuccessful-user;</filter2>
        <id>3152</id>
        <msg>SQL sa brute force failed login attempt</msg>
        <nessus>10673</nessus>
      </rule>
      <rule>
        <bugtraq>4797</bugtraq>
        <classtype>unsuccessful-user</classtype>
        <cve>2000-1209</cve>
        <filter1>tcp $SQL_SERVERS 1433 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;L|00|o|00|g|00|i|00|n|00| |00|f|00|a|00|i|00|l|00|e|00|d|00| |00|f|00|o|00|r|00| |00|u|00|s|00|e|00|r|00| |00|'|00|s|00|a|00|'|00|&quot;; detection_filter:track by_src, count 5, seconds 2; classtype:unsuccessful-user;</filter2>
        <id>3273</id>
        <msg>SQL sa brute force failed login unicode attempt</msg>
        <nessus>10673</nessus>
      </rule>
      <rule>
        <bugtraq>4797</bugtraq>
        <classtype>suspicious-login</classtype>
        <cve>2000-1209</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;|02|&quot;; depth:1; content:&quot;sa&quot;; depth:2; offset:39; nocase; detection_filter:track by_src, count 5, seconds 2; classtype:suspicious-login;</filter2>
        <id>3542</id>
        <msg>SQL SA brute force login attempt</msg>
        <nessus>10673</nessus>
      </rule>
      <rule>
        <bugtraq>4797</bugtraq>
        <classtype>unsuccessful-user</classtype>
        <cve>2000-1209</cve>
        <filter1>tcp $SQL_SERVERS 139 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;L|00|o|00|g|00|i|00|n|00| |00|f|00|a|00|i|00|l|00|e|00|d|00| |00|f|00|o|00|r|00| |00|u|00|s|00|e|00|r|00| |00|'|00|s|00|a|00|'|00|&quot;; detection_filter:track by_src, count 5, seconds 2; classtype:unsuccessful-user;</filter2>
        <id>4984</id>
        <msg>SQL sa brute force failed login unicode attempt</msg>
        <nessus>10673</nessus>
      </rule>
      <rule>
        <bugtraq>5310</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0649</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1434</filter1>
        <filter2>flow:to_server; content:&quot;|08|&quot;; depth:1; isdataat:50; content:&quot;|3A|&quot;; pcre:&quot;/[0-9]+/R&quot;; classtype:attempted-admin;</filter2>
        <id>4989</id>
        <msg>SQL heap-based overflow attempt</msg>
        <nessus>11214</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|s|00|t|00|a|00|r|00|t|00|_|00|j|00|o|00|b|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>673</id>
        <msg>SQL sp_start_job - program execution</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|s|00|t|00|a|00|r|00|t|00|_|00|j|00|o|00|b|00|&quot;; depth:32; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>676</id>
        <msg>SQL sp_start_job - program execution</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|p|00|a|00|s|00|s|00|w|00|o|00|r|00|d|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>677</id>
        <msg>SQL sp_password password change</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|d|00|e|00|l|00|e|00|t|00|e|00|_|00|a|00|l|00|e|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>678</id>
        <msg>SQL sp_delete_alert log file deletion</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|a|00|d|00|d|00|u|00|s|00|e|00|r|00|&quot;; depth:32; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>679</id>
        <msg>SQL sp_adduser database user creation</msg>
      </rule>
      <rule>
        <bugtraq>5309</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|c|00|m|00|d|00|s|00|h|00|e|00|l|00|l|00|&quot;; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>681</id>
        <msg>SQL xp_cmdshell program execution</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|p|00|a|00|s|00|s|00|w|00|o|00|r|00|d|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>683</id>
        <msg>SQL sp_password - password change</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|d|00|e|00|l|00|e|00|t|00|e|00|_|00|a|00|l|00|e|00|r|00|t|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>684</id>
        <msg>SQL sp_delete_alert log file deletion</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;s|00|p|00|_|00|a|00|d|00|d|00|u|00|s|00|e|00|r|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>685</id>
        <msg>SQL sp_adduser - database user creation</msg>
      </rule>
      <rule>
        <bugtraq>5205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0642</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|r|00|e|00|g|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>686</id>
        <msg>SQL xp_reg* - registry access</msg>
        <nessus>10642</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-034.mspx</url>
      </rule>
      <rule>
        <bugtraq>5309</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|c|00|m|00|d|00|s|00|h|00|e|00|l|00|l|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>687</id>
        <msg>SQL xp_cmdshell - program execution</msg>
      </rule>
      <rule>
        <bugtraq>5205</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0642</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|r|00|e|00|g|00|&quot;; depth:32; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>689</id>
        <msg>SQL xp_reg* registry access</msg>
        <nessus>10642</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-034</url>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;9 |D0 00 92 01 C2 00|R|00|U|00|9 |EC 00|&quot;; classtype:shellcode-detect;</filter2>
        <id>691</id>
        <msg>SQL shellcode attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;9 |D0 00 92 01 C2 00|R|00|U|00|9 |EC 00|&quot;; classtype:shellcode-detect;</filter2>
        <id>692</id>
        <msg>SQL shellcode attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;H|00|%|00|x|00|w|00 90 00 90 00 90 00 90 00 90 00|3|00 C0 00|P|00|h|00|.|00|&quot;; classtype:shellcode-detect;</filter2>
        <id>693</id>
        <msg>SQL shellcode attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;H|00|%|00|x|00|w|00 90 00 90 00 90 00 90 00 90 00|3|00 C0 00|P|00|h|00|.|00|&quot;; classtype:attempted-user;</filter2>
        <id>694</id>
        <msg>SQL shellcode attempt</msg>
      </rule>
      <rule>
        <bugtraq>1204</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|s|00|p|00|r|00|i|00|n|00|t|00|f|00|&quot;; offset:32; nocase; classtype:attempted-user;</filter2>
        <id>695</id>
        <msg>SQL xp_sprintf possible buffer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-060.mspx</url>
      </rule>
      <rule>
        <bugtraq>3733</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:to_server,established; content:&quot;x|00|p|00|_|00|s|00|p|00|r|00|i|00|n|00|t|00|f|00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>704</id>
        <msg>SQL xp_sprintf possible buffer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-060.mspx</url>
      </rule>
      <rule>
        <bugtraq>19054</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3702</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;dbms_export_extension&quot;; nocase; content:&quot;ODCIIndexGetMetadata&quot;; nocase; classtype:attempted-user;</filter2>
        <id>7207</id>
        <msg>ORACLE DBMS_EXPORT_EXTENSION SQL injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>19054</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3698</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SYS.KUPW|24|WORKER.MAIN&quot;; content:&quot;|7C 7C|'''&quot;; distance:0; classtype:attempted-admin;</filter2>
        <id>8059</id>
        <msg>ORACLE SYS.KUPW-WORKER sql injection attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2006.html</url>
      </rule>
      <rule>
        <bugtraq>3733</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;f|00|o|00|r|00|m|00|a|00|t|00|m|00|e|00|s|00|s|00|a|00|g|00|e|00|&quot;; classtype:attempted-admin;</filter2>
        <id>8494</id>
        <msg>SQL formatmessage possible buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>3733</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0542</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;f|00|o|00|r|00|m|00|a|00|t|00|m|00|e|00|s|00|s|00|a|00|g|00|e|00|&quot;; classtype:attempted-admin;</filter2>
        <id>8495</id>
        <msg>SQL formatmessage possible buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;s|00|p|00|_|00|o|00|a|00|c|00|r|00|e|00|a|00|t|00|e|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8496</id>
        <msg>SQL sp_oacreate unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;sp_oacreate&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8497</id>
        <msg>SQL sp_oacreate vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;s|00|p|00|_|00|o|00|a|00|c|00|r|00|e|00|a|00|t|00|e|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8498</id>
        <msg>SQL sp_oacreate unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2030</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|d|00|i|00|s|00|p|00|l|00|a|00|y|00|p|00|a|00|r|00|a|00|m|00|s|00|t|00|m|00|t|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8499</id>
        <msg>SQL xp_displayparamstmt unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2030</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|d|00|i|00|s|00|p|00|l|00|a|00|y|00|p|00|a|00|r|00|a|00|m|00|s|00|t|00|m|00|t|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8500</id>
        <msg>SQL xp_displayparamstmt unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2030</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_displayparamstmt&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8501</id>
        <msg>SQL xp_displayparamstmt vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2031</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1082</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|e|00|n|00|u|00|m|00|r|00|e|00|s|00|u|00|l|00|t|00|s|00|e|00|t|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8502</id>
        <msg>SQL xp_enumresultset unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2031</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1082</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|e|00|n|00|u|00|m|00|r|00|e|00|s|00|u|00|l|00|t|00|s|00|e|00|t|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8503</id>
        <msg>SQL xp_enumresultset unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2031</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1082</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_enumresultset&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8504</id>
        <msg>SQL xp_enumresultset vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|d|00|e|00|s|00|t|00|r|00|o|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8505</id>
        <msg>SQL xp_oadestroy unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|d|00|e|00|s|00|t|00|r|00|o|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8506</id>
        <msg>SQL xp_oadestroy unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_oadestroy&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8507</id>
        <msg>SQL xp_oadestroy vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|g|00|e|00|t|00|p|00|r|00|o|00|p|00|e|00|r|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8508</id>
        <msg>SQL xp_oagetproperty unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|g|00|e|00|t|00|p|00|r|00|o|00|p|00|e|00|r|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8509</id>
        <msg>SQL xp_oagetproperty unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_oagetproperty&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8510</id>
        <msg>SQL xp_oagetproperty vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|m|00|e|00|t|00|h|00|o|00|d|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8511</id>
        <msg>SQL xp_oamethod unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_oamethod&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8512</id>
        <msg>SQL xp_oamethod vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|m|00|e|00|t|00|h|00|o|00|d|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8513</id>
        <msg>SQL xp_oamethod unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|s|00|e|00|t|00|p|00|r|00|o|00|p|00|e|00|r|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8514</id>
        <msg>SQL xp_oasetproperty unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|o|00|a|00|s|00|e|00|t|00|p|00|r|00|o|00|p|00|e|00|r|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8515</id>
        <msg>SQL xp_oasetproperty unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_oasetproperty&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8516</id>
        <msg>SQL xp_oasetproperty vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|e|00|e|00|k|00|q|00|u|00|e|00|u|00|e|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8517</id>
        <msg>SQL xp_peekqueue unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|e|00|e|00|k|00|q|00|u|00|e|00|u|00|e|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8518</id>
        <msg>SQL xp_peekqueue unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1085</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_peekqueue&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8519</id>
        <msg>SQL xp_peekqueue vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|r|00|i|00|n|00|t|00|s|00|t|00|a|00|t|00|e|00|m|00|e|00|n|00|t|00|s|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8520</id>
        <msg>SQL xp_printstatements unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|r|00|i|00|n|00|t|00|s|00|t|00|a|00|t|00|e|00|m|00|e|00|n|00|t|00|s|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8521</id>
        <msg>SQL xp_printstatements unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_printstatements&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8522</id>
        <msg>SQL xp_printstatements vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2024</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1087</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|r|00|o|00|x|00|i|00|e|00|d|00|m|00|e|00|t|00|a|00|d|00|a|00|t|00|a|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8523</id>
        <msg>SQL xp_proxiedmetadata unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2024</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1087</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|p|00|r|00|o|00|x|00|i|00|e|00|d|00|m|00|e|00|t|00|a|00|d|00|a|00|t|00|a|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8524</id>
        <msg>SQL xp_proxiedmetadata unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2024</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1087</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_proxiedmetadata&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8525</id>
        <msg>SQL xp_proxiedmetadata vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2043</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|S|00|e|00|t|00|S|00|Q|00|L|00|S|00|e|00|c|00|u|00|r|00|i|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8526</id>
        <msg>SQL xp_SetSQLSecurity unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2043</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|S|00|e|00|t|00|S|00|Q|00|L|00|S|00|e|00|c|00|u|00|r|00|i|00|t|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8527</id>
        <msg>SQL xp_SetSQLSecurity unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2043</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1086</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_SetSQLSecurity&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8528</id>
        <msg>SQL xp_SetSQLSecurity vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2038</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1083</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|h|00|o|00|w|00|c|00|o|00|l|00|v|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8529</id>
        <msg>SQL xp_showcolv unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2038</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1083</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|h|00|o|00|w|00|c|00|o|00|l|00|v|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8530</id>
        <msg>SQL xp_showcolv unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2038</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1083</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_showcolv&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8531</id>
        <msg>SQL xp_showcolv vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|q|00|l|00|a|00|g|00|e|00|n|00|t|00|_|00|m|00|o|00|n|00|i|00|t|00|o|00|r|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8532</id>
        <msg>SQL xp_sqlagent_monitor unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_sqlagent_monitor&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8533</id>
        <msg>SQL xp_sqlagent_monitor vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|q|00|l|00|a|00|g|00|e|00|n|00|t|00|_|00|m|00|o|00|n|00|i|00|t|00|o|00|r|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8534</id>
        <msg>SQL xp_sqlagent_monitor unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|q|00|l|00|i|00|n|00|v|00|e|00|n|00|t|00|o|00|r|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8535</id>
        <msg>SQL xp_sqlinventory unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_sqlinventory&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8536</id>
        <msg>SQL xp_sqlinventory vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|s|00|q|00|l|00|i|00|n|00|v|00|e|00|n|00|t|00|o|00|r|00|y|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8537</id>
        <msg>SQL xp_sqlinventory unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2039</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1084</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|u|00|p|00|d|00|a|00|t|00|e|00|c|00|o|00|l|00|v|00|b|00|m|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8538</id>
        <msg>SQL xp_updatecolvbm unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2039</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1084</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 139</filter1>
        <filter2>flow:established,to_server; content:&quot;x|00|p|00|_|00|u|00|p|00|d|00|a|00|t|00|e|00|c|00|o|00|l|00|v|00|b|00|m|00|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8539</id>
        <msg>SQL xp_updatecolvbm unicode vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
      <rule>
        <bugtraq>2039</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-1084</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 1433</filter1>
        <filter2>flow:established,to_server; content:&quot;xp_updatecolvbm&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8540</id>
        <msg>SQL xp_updatecolvbm vulnerable function attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms00-092.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>235</groupid>
    <groupname>Server / Database / Common SQL</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>240</groupid>
    <groupname>Server / Misc</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>31881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2469</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15327, service dns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15327</id>
        <msg>BAD-TRAFFIC libspf2 DNS TXT record parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13729</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0036</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>content:&quot;|C0 0C|&quot;; depth:2; offset:12; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:attempted-dos;</filter2>
        <id>15991</id>
        <msg>DOS Multiple vendor DNS message decompression denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>19404</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3441</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|C0 0C 00 22 00 01 00 00 00|&lt;|00 00 01|&quot;; metadata:policy security-ips drop, service dns; classtype:attempted-admin;</filter2>
        <id>16029</id>
        <msg>SPECIFIC-THREATS Microsoft Windows DNS client ATMA buffer overrun attempt</msg>
      </rule>
      <rule>
        <bugtraq>19404</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3441</cve>
        <filter1>tcp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|C0 0C 00 10 00 01 00 00 00|&lt;*|AA 00 00 00 00|&quot;; metadata:policy security-ips drop, service dns; classtype:attempted-admin;</filter2>
        <id>16030</id>
        <msg>SPECIFIC-THREATS Microsoft Windows DNS client TXT buffer overrun attempt</msg>
      </rule>
      <rule>
        <bugtraq>25919</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2007-3898</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|03|www|07|example|03|com|00 00 01 00 01 C0 0C 00 01 00 01 00 00 0E 10 00 04|****&quot;; metadata:policy security-ips drop, service dns; classtype:misc-attack;</filter2>
        <id>16206</id>
        <msg>SPECIFIC-THREATS Microsoft Windows DNS server spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-062.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;butterfly|05|sinip|02|es&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:trojan-activity;</filter2>
        <id>16297</id>
        <msg>BOTNET-CNC Palevo bot DNS request for C&amp;C attempt</msg>
        <url>www.virustotal.com/analisis/c790a26f38070632759f481a87ed60c1628dea723ad63577cfe373de6b81e0a7-1249566492</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;qwertasdfg|05|sinip|02|es&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:misc-activity;</filter2>
        <id>16298</id>
        <msg>BOTNET-CNC Palevo bot DNS request attempt</msg>
        <url>www.virustotal.com/analisis/c790a26f38070632759f481a87ed60c1628dea723ad63577cfe373de6b81e0a7-1249566492</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;bfisback|05|no-ip|03|org&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:misc-activity;</filter2>
        <id>16299</id>
        <msg>BOTNET-CNC Palevo bot DNS request attempt</msg>
        <url>www.virustotal.com/analisis/c790a26f38070632759f481a87ed60c1628dea723ad63577cfe373de6b81e0a7-1249566492</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;irc|04|zief|02|pl&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:trojan-activity;</filter2>
        <id>16302</id>
        <msg>BOTNET-CNC Virut DNS request for C&amp;C attempt</msg>
        <url>threatexpert.com/report.aspx?md5=9ddbec6a5eda7af31e2f5461df8fe4df</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;put|05|ghura|02|pl&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:trojan-activity;</filter2>
        <id>16303</id>
        <msg>BOTNET-CNC Virut DNS request attempt</msg>
        <url>threatexpert.com/report.aspx?md5=9ddbec6a5eda7af31e2f5461df8fe4df</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;proxim|09|ircgalaxy|02|pl&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service dns; classtype:trojan-activity;</filter2>
        <id>16304</id>
        <msg>BOTNET-CNC Virut DNS request attempt</msg>
        <url>threatexpert.com/report.aspx?md5=9ddbec6a5eda7af31e2f5461df8fe4df</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;torpig-sinkhole|03|org&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:trojan-activity;</filter2>
        <id>16693</id>
        <msg>SPYWARE-PUT Torpig bot sinkhole server DNS lookup attempt</msg>
        <url>www.virustotal.com/analisis/598c0628fb40a17405ee0a3146621460daeee46ac863810af822695153416a3f-1270655846</url>
      </rule>
      <rule>
        <bugtraq>20804</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-5614</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,0xF8,2; content:&quot;|00 00|&quot;; depth:2; offset:4; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:attempted-dos;</filter2>
        <id>17294</id>
        <msg>DOS Microsoft Windows NAT Helper DNS query denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>12551</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0446</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 01 00 01|&quot;; content:&quot;|00 01 00 01|&quot;; within:4; distance:2; isdataat:6,relative; content:!&quot;|00 04|&quot;; within:2; distance:4; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:attempted-dos;</filter2>
        <id>17483</id>
        <msg>DNS squid proxy dns A record response denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>12551</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0446</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 0C 00 01|&quot;; content:&quot;|00 0C 00 01|&quot;; within:4; distance:2; content:&quot;|00 01 00|&quot;; within:3; distance:4; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:attempted-dos;</filter2>
        <id>17484</id>
        <msg>DNS squid proxy dns PTR record response denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2005-0817</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|C8 C8 C8 C8|&quot;; fast_pattern; content:&quot;|00 02 00 01|&quot;; within:10; distance:2; content:&quot;fake&quot;; within:20; distance:7; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:misc-attack;</filter2>
        <id>17485</id>
        <msg>DNS Symantec Gateway products DNS cache poisoning attempt</msg>
      </rule>
      <rule>
        <bugtraq>13592</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1519</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|C0 10 00 02 00 01 00 01 51 80 00 05 02 6E 73 C0 10|&quot;; detection_filter:track by_src, count 1000, seconds 1; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17495</id>
        <msg>SPECIFIC-THREATS Squid proxy DNS response spoofing attempt</msg>
      </rule>
      <rule>
        <bugtraq>22231</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-0494</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $DNS_SERVERS 53</filter1>
        <filter2>flow:to_server; content:&quot;|01 10|&quot;; depth:2; offset:2; content:&quot;|00 80 01 00 01 00 00 29|&quot;; isdataat:!9,relative; content:&quot;|03|com&quot;; content:&quot;|03|com&quot;; within:4; distance:4; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17680</id>
        <msg>SPECIFIC-THREATS ISC BIND DNSSEC Validation Multiple RRsets DoS</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-0234</cve>
        <filter1>udp $DNS_SERVERS 53 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; detection_filter:track by_src, count 20, seconds 20; metadata: engine shared, soid 3|17696, service dns, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17696</id>
        <msg>EXPLOIT Microsoft DNS Server ANY query cache weakness</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-008.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0532</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 FC|&quot;; offset:14; metadata:policy security-ips drop, service dns; classtype:attempted-recon;</filter2>
        <id>1948</id>
        <msg>DNS zone transfer UDP</msg>
        <nessus>10595</nessus>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|85 80 00 01 00 01 00 00 00 00|&quot;; content:&quot;|C0 0C 00 0C 00 01 00 00 00|&lt;|00 0F|&quot;; fast_pattern:only; metadata:policy security-ips drop, service dns; classtype:bad-unknown;</filter2>
        <id>253</id>
        <msg>DNS SPOOF query response PTR with TTL of 1 min. and no authority</msg>
      </rule>
      <rule>
        <bugtraq>2302</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0010</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; byte_test:1,&lt;,16,2; byte_test:1,&amp;,8,2; metadata:policy security-ips drop, service dns; classtype:attempted-recon;</filter2>
        <id>2921</id>
        <msg>DNS UDP inverse query</msg>
        <nessus>10605</nessus>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2006-5614</cve>
        <filter1>tcp any any -&gt; any 53</filter1>
        <filter2>flow:established,to_server; byte_test:2,&amp;,256,2; content:&quot;|00 00 00 00 00 00 00 00|&quot;; depth:8; offset:4; metadata:policy security-ips drop, service dns; classtype:misc-attack;</filter2>
        <id>8709</id>
        <msg>DNS Windows NAT helper components tcp denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2006-5614</cve>
        <filter1>udp any any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:2,&amp;,256,2; content:&quot;|00 00 00 00 00 00 00 00|&quot;; depth:8; offset:4; metadata:policy security-ips drop, service dns; classtype:misc-attack;</filter2>
        <id>8710</id>
        <msg>DNS Windows NAT helper components udp denial of service attempt</msg>
      </rule>
    </attacks>
    <groupid>241</groupid>
    <groupname>Server / Misc / DNS</groupname>
    <warnings>
      <rule>
        <bugtraq>23470</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:50ABC2A4-574D-40B3-9D66-EE4FD5FBA076; dce_opnum:7; dce_stub_data; content:!&quot;|00 00 00 00|&quot;; depth:4; offset:8; pcre:&quot;/^.{12}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; content:!&quot;|00 00 00 00|&quot;; within:4; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; fast_pattern; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>10603</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvUpdateRecord2 overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>23470</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:50ABC2A4-574D-40B3-9D66-EE4FD5FBA076; dce_opnum:1,3; dce_stub_data; content:!&quot;|00 00 00 00|&quot;; depth:4; pcre:&quot;/^.{4}(\x00\x00\x00\x00|.{12})/sR&quot;; byte_jump:4,-4,multiplier 2,relative,align,dce; content:!&quot;|00 00 00 00|&quot;; within:4; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; fast_pattern; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>10900</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvEnumRecords overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>25159</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3744</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 49152:65535</filter1>
        <filter2>flow:to_client; content:&quot;HTTP&quot;; depth:16; pcre:&quot;/^.*HTTP.*\r\n(.+\x3a\s+.+\r\n){31,}/&quot;; classtype:attempted-admin;</filter2>
        <id>12357</id>
        <msg>EXPLOIT Apple mDNSresponder excessive HTTP headers</msg>
      </rule>
      <rule>
        <bugtraq>590</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0745</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4242</filter1>
        <filter2>flow:to_server,established; isdataat:1000; content:&quot;|7F FF FB|x|7F FF FB|x|7F FF FB|x|7F FF FB|x&quot;; content:&quot;@|8A FF C8|@|82 FF D8 3B|6|FE 03 3B|v|FE 02|&quot;; classtype:attempted-user;</filter2>
        <id>1261</id>
        <msg>EXPLOIT AIX pdnsd overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|07|authors&quot;; offset:12; nocase; content:&quot;|04|bind|00|&quot;; offset:12; nocase; metadata:service dns; classtype:attempted-recon;</filter2>
        <id>1435</id>
        <msg>DNS named authors attempt</msg>
        <nessus>10728</nessus>
      </rule>
      <rule>
        <bugtraq>6186</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0029</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|D3 A9 85 80 00 01 00|2&quot;; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>15963</id>
        <msg>SPECIFIC-THREATS Red Hat Enterprise Linux DNS resolver buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11605</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0892</cve>
        <filter1>udp $EXTERNAL_NET 53 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;|C0 0C 00 0C 00 01 00 01|Q|80 00 0F 03|www|05|yahoo|03|com|00|&quot;; metadata:service dns; classtype:misc-attack;</filter2>
        <id>15988</id>
        <msg>SPECIFIC-THREATS Microsoft ISA Server DNS spoofing attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;|07|version&quot;; offset:12; nocase; content:&quot;|04|bind|00|&quot;; offset:12; nocase; metadata:service dns; classtype:attempted-recon;</filter2>
        <id>1616</id>
        <msg>DNS named version attempt</msg>
        <nessus>10028</nessus>
      </rule>
      <rule>
        <bugtraq>23470</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:50ABC2A4-574D-40B3-9D66-EE4FD5FBA076; dce_opnum:7; dce_stub_data; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:!&quot;|00 00 00 00|&quot;; within:4; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; fast_pattern; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16499</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvUpdateRecord2 overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>23470</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:50ABC2A4-574D-40B3-9D66-EE4FD5FBA076; dce_opnum:1,3; dce_stub_data; content:&quot;|00 00 00 00|&quot;; depth:4; content:!&quot;|00 00 00 00|&quot;; within:4; byte_test:4,&gt;,256,8,relative,dce; content:&quot;|05 00 00|&quot;; fast_pattern; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>16500</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvEnumRecords overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>35925</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2470</cve>
        <filter1>tcp $EXTERNAL_NET 1080 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|05 00 00 03|&quot;; depth:4; isdataat:16,relative; classtype:attempted-user;</filter2>
        <id>16612</id>
        <msg>WEB-CLIENT Firefox oversized SOCKS5 DNS reply memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|qd|07|netkill|03|com|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16834</id>
        <msg>BLACKLIST DNS request for known malware domain qd.netkill.com.cn - Trojan-Downloader.Win32.Adload.rzx</msg>
        <url>labs.snort.org/docs/16834.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|exe|06|146843|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16835</id>
        <msg>BLACKLIST DNS request for known malware domain exe.146843.com - Trojan.Win32.Opeg.a</msg>
        <url>labs.snort.org/docs/16835.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|ra03|05|e5732|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16836</id>
        <msg>BLACKLIST DNS request for known malware domain ra03.e5732.com - Trojan-Clicker.Win32.Small.afg</msg>
        <url>labs.snort.org/docs/16836.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0C|dangercheats|03|com|02|br&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16837</id>
        <msg>BLACKLIST DNS request for known malware domain dangercheats.com.br - Trojan.Win32.Refroso.arnq</msg>
        <url>labs.snort.org/docs/16837.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|xlm|05|ppvsr|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16838</id>
        <msg>BLACKLIST DNS request for known malware domain xlm.ppvsr.com - Trojan-GameThief.Win32.OnLineGames.wwcf</msg>
        <url>labs.snort.org/docs/16838.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|sh16|05|e8753|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16839</id>
        <msg>BLACKLIST DNS request for known malware domain sh16.e8753.com - Trojan.Win32.Scar.ccqb</msg>
        <url>labs.snort.org/docs/16839.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|rx11|05|e6532|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16840</id>
        <msg>BLACKLIST DNS request for known malware domain rx11.e6532.com - Trojan.Win32.Opeg.a</msg>
        <url>labs.snort.org/docs/16840.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|podgorz|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16841</id>
        <msg>BLACKLIST DNS request for known malware domain podgorz.org - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16841.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|sp19|05|e4578|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16842</id>
        <msg>BLACKLIST DNS request for known malware domain sp19.e4578.com - Trojan-Downloader.Win32.Genome.njz</msg>
        <url>labs.snort.org/docs/16842.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|1|04|7zsm|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16843</id>
        <msg>BLACKLIST DNS request for known malware domain 1.7zsm.com - Trojan-Downloader.Win32.Agent.dtuo</msg>
        <url>labs.snort.org/docs/16843.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|rm08|05|e4562|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16844</id>
        <msg>BLACKLIST DNS request for known malware domain rm08.e4562.com - Trojan-Downloader.Win32.Agent.dngx</msg>
        <url>labs.snort.org/docs/16844.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|rc04|05|e6532|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16845</id>
        <msg>BLACKLIST DNS request for known malware domain rc04.e6532.com - Trojan-Downloader.Win32.Genome.awld</msg>
        <url>labs.snort.org/docs/16845.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|bedayton|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16846</id>
        <msg>BLACKLIST DNS request for known malware domain bedayton.com - Trojan-Downloader.Win32.Agent.dlhe</msg>
        <url>labs.snort.org/docs/16846.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|rz12|05|e6805|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16847</id>
        <msg>BLACKLIST DNS request for known malware domain rz12.e6805.com - Trojan-Downloader.Win32.Genome.awld</msg>
        <url>labs.snort.org/docs/16847.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|in|09|chinaitlm|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16848</id>
        <msg>BLACKLIST DNS request for known malware domain in.chinaitlm.cn - Trojan.VBS.HideIcon.d</msg>
        <url>labs.snort.org/docs/16848.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|re05|05|e6532|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16849</id>
        <msg>BLACKLIST DNS request for known malware domain re05.e6532.com - Trojan-Downloader.Win32.Genome.awld</msg>
        <url>labs.snort.org/docs/16849.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|kldmten|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16850</id>
        <msg>BLACKLIST DNS request for known malware domain kldmten.net - Trojan-Spy.Win32.Zbot.akra</msg>
        <url>labs.snort.org/docs/16850.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|forelc|02|cc&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16851</id>
        <msg>BLACKLIST DNS request for known malware domain forelc.cc - Trojan-Ransom.Win32.XBlocker.ahe</msg>
        <url>labs.snort.org/docs/16851.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|v|05|yao63|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16852</id>
        <msg>BLACKLIST DNS request for known malware domain v.yao63.com - Trojan-Downloader.Win32.Agent.dqns</msg>
        <url>labs.snort.org/docs/16852.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|vh26|05|e4578|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16853</id>
        <msg>BLACKLIST DNS request for known malware domain vh26.e4578.com - Trojan.Win32.Opeg.a</msg>
        <url>labs.snort.org/docs/16853.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|up1|08|give2sms|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16854</id>
        <msg>BLACKLIST DNS request for known malware domain up1.give2sms.com - Trojan-Downloader.Win32.Genome.est</msg>
        <url>labs.snort.org/docs/16854.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|d|0A|123kuaihuo|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16855</id>
        <msg>BLACKLIST DNS request for known malware domain d.123kuaihuo.com - Trojan.Win32.Scar.clbx</msg>
        <url>labs.snort.org/docs/16855.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|andy|02|cd&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16856</id>
        <msg>BLACKLIST DNS request for known malware domain andy.cd - Backdoor.Win32.Agent.auto</msg>
        <url>labs.snort.org/docs/16856.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|site|05|mynet|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16857</id>
        <msg>BLACKLIST DNS request for known malware domain site.mynet.com - Trojan.Win32.Buzus.dxsr</msg>
        <url>labs.snort.org/docs/16857.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|charter-x|03|biz&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16858</id>
        <msg>BLACKLIST DNS request for known malware domain charter-x.biz - Packed.Win32.Krap.ae</msg>
        <url>labs.snort.org/docs/16858.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|gerherber|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16859</id>
        <msg>BLACKLIST DNS request for known malware domain gerherber.com - Trojan-Spy.Win32.Zbot.akdw</msg>
        <url>labs.snort.org/docs/16859.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|urodinam|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16860</id>
        <msg>BLACKLIST DNS request for known malware domain urodinam.net - Trojan.Win32.TDSS.azsj</msg>
        <url>labs.snort.org/docs/16860.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0E|gite-eguisheim|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16861</id>
        <msg>BLACKLIST DNS request for known malware domain gite-eguisheim.com - Trojan-Downloader.Win32.Piker.clp</msg>
        <url>labs.snort.org/docs/16861.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|phaizeipeu|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16862</id>
        <msg>BLACKLIST DNS request for known malware domain phaizeipeu.ru - Packed.Win32.Krap.gx</msg>
        <url>labs.snort.org/docs/16862.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|teendx|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16863</id>
        <msg>BLACKLIST DNS request for known malware domain teendx.com - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16863.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|taiping2033|04|2288|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16864</id>
        <msg>BLACKLIST DNS request for known malware domain taiping2033.2288.org - Trojan-Downloader.Win32.Selvice.afy</msg>
        <url>labs.snort.org/docs/16864.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|cnfg|10|maxsitesrevenues|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16865</id>
        <msg>BLACKLIST DNS request for known malware domain cnfg.maxsitesrevenues.net - Trojan.Win32.BHO.afke</msg>
        <url>labs.snort.org/docs/16865.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|members|0A|multimania|02|co|02|uk&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16866</id>
        <msg>BLACKLIST DNS request for known malware domain members.multimania.co.uk - Trojan.Win32.Inject.ahqv</msg>
        <url>labs.snort.org/docs/16866.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|down|05|toopc|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16867</id>
        <msg>BLACKLIST DNS request for known malware domain down.toopc.com - Trojan-Dropper.Win32.Clons.hai</msg>
        <url>labs.snort.org/docs/16867.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|hostshack|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16868</id>
        <msg>BLACKLIST DNS request for known malware domain hostshack.net - Trojan.Win32.Buzus.empl</msg>
        <url>labs.snort.org/docs/16868.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|tt|04|vv49|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16869</id>
        <msg>BLACKLIST DNS request for known malware domain tt.vv49.com - Trojan-GameThief.Win32.OnLineGames.bnkb</msg>
        <url>labs.snort.org/docs/16869.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|search|09|sidegreen|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16870</id>
        <msg>BLACKLIST DNS request for known malware domain search.sidegreen.com - Backdoor.Win32.Agent.arqi</msg>
        <url>labs.snort.org/docs/16870.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0F|parfaitpournous|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16871</id>
        <msg>BLACKLIST DNS request for known malware domain parfaitpournous.com - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16871.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|postmetoday|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16872</id>
        <msg>BLACKLIST DNS request for known malware domain postmetoday.ru - Packed.Win32.Katusha.j</msg>
        <url>labs.snort.org/docs/16872.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|youword|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16873</id>
        <msg>BLACKLIST DNS request for known malware domain youword.cn - Trojan.Win32.Scar.bvgu</msg>
        <url>labs.snort.org/docs/16873.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|ophaeghaev|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16874</id>
        <msg>BLACKLIST DNS request for known malware domain ophaeghaev.ru - Trojan-Spy.Win32.Zbot.akmi</msg>
        <url>labs.snort.org/docs/16874.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|up1|08|free-sms|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16875</id>
        <msg>BLACKLIST DNS request for known malware domain up1.free-sms.co.kr - Trojan.Win32.Vilsel.akp</msg>
        <url>labs.snort.org/docs/16875.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|c|09|softdowns|04|info&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16876</id>
        <msg>BLACKLIST DNS request for known malware domain c.softdowns.info - Trojan.BAT.Agent.yn</msg>
        <url>labs.snort.org/docs/16876.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|ddkom|03|biz&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16877</id>
        <msg>BLACKLIST DNS request for known malware domain ddkom.biz - Trojan.Win32.Scar.ckhr</msg>
        <url>labs.snort.org/docs/16877.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|vopret|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16878</id>
        <msg>BLACKLIST DNS request for known malware domain vopret.ru - Trojan.Win32.FraudPack.axwn</msg>
        <url>labs.snort.org/docs/16878.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|dnfpomo|09|dnfranran|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16879</id>
        <msg>BLACKLIST DNS request for known malware domain dnfpomo.dnfranran.com - Trojan-GameThief.Win32.OnLineGames.bnkx</msg>
        <url>labs.snort.org/docs/16879.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|dnfuu|04|3322|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16880</id>
        <msg>BLACKLIST DNS request for known malware domain dnfuu.3322.org - Trojan-Downloader.Win32.Genome.asrx</msg>
        <url>labs.snort.org/docs/16880.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|sex-gifts|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16881</id>
        <msg>BLACKLIST DNS request for known malware domain sex-gifts.ru - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16881.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|111|07|168lala|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16882</id>
        <msg>BLACKLIST DNS request for known malware domain 111.168lala.com - Backdoor.Win32.Popwin.cyn</msg>
        <url>labs.snort.org/docs/16882.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0F|mcafee-registry|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16883</id>
        <msg>BLACKLIST DNS request for known malware domain mcafee-registry.ru - Trojan-Spy.Win32.Zbot.akgb</msg>
        <url>labs.snort.org/docs/16883.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|bits4ever|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16884</id>
        <msg>BLACKLIST DNS request for known malware domain bits4ever.ru - Trojan-Spy.Win32.Zbot.aknt</msg>
        <url>labs.snort.org/docs/16884.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|monicaecarlos|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16885</id>
        <msg>BLACKLIST DNS request for known malware domain monicaecarlos.com - Trojan-Downloader.Win32.Genome.awxv</msg>
        <url>labs.snort.org/docs/16885.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|d|08|trymedia|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16886</id>
        <msg>BLACKLIST DNS request for known malware domain d.trymedia.com - Trojan-Dropper.Win32.Delf.fkk</msg>
        <url>labs.snort.org/docs/16886.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|dbtte|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16888</id>
        <msg>BLACKLIST DNS request for known malware domain dbtte.com - Trojan-Banker.Win32.Banz.crk</msg>
        <url>labs.snort.org/docs/16888.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|h1|06|ripway|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16889</id>
        <msg>BLACKLIST DNS request for known malware domain h1.ripway.com - Trojan.Win32.Refroso.bcdq</msg>
        <url>labs.snort.org/docs/16889.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|in6cs|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16890</id>
        <msg>BLACKLIST DNS request for known malware domain in6cs.com - Trojan.Win32.Tdss.beea</msg>
        <url>labs.snort.org/docs/16890.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|solo1928|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16891</id>
        <msg>BLACKLIST DNS request for known malware domain solo1928.ru - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16891.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|fg545633|04|host|06|zgridc|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16892</id>
        <msg>BLACKLIST DNS request for known malware domain fg545633.host.zgridc.com - Trojan.Win32.Pincav.abub</msg>
        <url>labs.snort.org/docs/16892.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|primusdns|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16893</id>
        <msg>BLACKLIST DNS request for known malware domain primusdns.ru - Backdoor.Win32.Havar.eh</msg>
        <url>labs.snort.org/docs/16893.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|eq|06|pccppc|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16894</id>
        <msg>BLACKLIST DNS request for known malware domain eq.pccppc.com - Trojan-Downloader.Win32.Pher.fkl</msg>
        <url>labs.snort.org/docs/16894.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|alodh|02|in&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16895</id>
        <msg>BLACKLIST DNS request for known malware domain alodh.in - Backdoor.Win32.Delf.vde</msg>
        <url>labs.snort.org/docs/16895.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|reward|06|pnshop|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16896</id>
        <msg>BLACKLIST DNS request for known malware domain reward.pnshop.co.kr - Backdoor.Win32.Agent.ahra</msg>
        <url>labs.snort.org/docs/16896.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|sympathy|06|hdnews|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16897</id>
        <msg>BLACKLIST DNS request for known malware domain sympathy.hdnews.net - Trojan-Spy.Win32.Zbot.gen</msg>
        <url>labs.snort.org/docs/16897.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|sx21|05|e4578|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16898</id>
        <msg>BLACKLIST DNS request for known malware domain sx21.e4578.com - Trojan.Win32.Scar.ccqb</msg>
        <url>labs.snort.org/docs/16898.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|downloadering|04|9966|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16899</id>
        <msg>BLACKLIST DNS request for known malware domain downloadering.9966.org - Trojan.Win32.Vilsel.adxv</msg>
        <url>labs.snort.org/docs/16899.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|reportes201|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16900</id>
        <msg>BLACKLIST DNS request for known malware domain reportes201.com - Trojan-Downloader.Win32.Genome.ashe</msg>
        <url>labs.snort.org/docs/16900.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|local|04|1140|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16901</id>
        <msg>BLACKLIST DNS request for known malware domain local.1140.co.kr - Trojan-Downloader.Win32.Genome.aobm</msg>
        <url>labs.snort.org/docs/16901.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|promojoy|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16902</id>
        <msg>BLACKLIST DNS request for known malware domain promojoy.net - Packed.Win32.Krap.gx</msg>
        <url>labs.snort.org/docs/16902.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|gpwg|02|ws&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16903</id>
        <msg>BLACKLIST DNS request for known malware domain gpwg.ws - Worm.Win32.AutoRun.bjca</msg>
        <url>labs.snort.org/docs/16903.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|xoomer|05|alice|02|it&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16904</id>
        <msg>BLACKLIST DNS request for known malware domain xoomer.alice.it - Trojan-Downloader.Win32.Banload.kdu</msg>
        <url>labs.snort.org/docs/16904.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|xoomer|08|virgilio|02|it&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16905</id>
        <msg>BLACKLIST DNS request for known malware domain xoomer.virgilio.it - Backdoor.Win32.Clar.d</msg>
        <url>labs.snort.org/docs/16905.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|down|07|p2pplay|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16906</id>
        <msg>BLACKLIST DNS request for known malware domain down.p2pplay.com - Trojan-GameThief.Win32.OnLineGames.wgkv</msg>
        <url>labs.snort.org/docs/16906.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|livetrust|04|info&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16907</id>
        <msg>BLACKLIST DNS request for known malware domain livetrust.info - Trojan-Spy.Win32.Zbot.akku</msg>
        <url>labs.snort.org/docs/16907.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|ootaivilei|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16908</id>
        <msg>BLACKLIST DNS request for known malware domain ootaivilei.ru - Trojan-Spy.Win32.Zbot.akme</msg>
        <url>labs.snort.org/docs/16908.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|babah20122012|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16909</id>
        <msg>BLACKLIST DNS request for known malware domain babah20122012.com - Trojan-Spy.Win32.Zbot.akbb</msg>
        <url>labs.snort.org/docs/16909.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;0-0-0-0-0-0-0|04|info&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>16910</id>
        <msg>BLACKLIST DNS request for known malware domain pattern - 0-0-0-0-0-0-0.info</msg>
        <url>labs.snort.org/docs/16910.html</url>
      </rule>
      <rule>
        <bugtraq>23470</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1748</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [135,139,445,593,1024:]</filter1>
        <filter2>flow:established,to_server; dce_iface:50ABC2A4-574D-40B3-9D66-EE4FD5FBA076; dce_opnum:1,3; dce_stub_data; pcre:&quot;/^.*?(\x5c.){256}/sR&quot;; metadata:service netbios-ssn; classtype:attempted-admin;</filter2>
        <id>17047</id>
        <msg>NETBIOS Microsoft Windows DNS Server RPC management interface buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-029.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|ktr|04|t134|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17818</id>
        <msg>BLACKLIST DNS request for known malware domain ktr.t134.net</msg>
        <url>labs.snort.org/docs/17818.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|motuh|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17819</id>
        <msg>BLACKLIST DNS request for known malware domain motuh.com</msg>
        <url>labs.snort.org/docs/17819.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|myanimalclips|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17820</id>
        <msg>BLACKLIST DNS request for known malware domain myanimalclips.com</msg>
        <url>labs.snort.org/docs/17820.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|ketsymbol|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17821</id>
        <msg>BLACKLIST DNS request for known malware domain ketsymbol.com</msg>
        <url>labs.snort.org/docs/17821.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|ics|06|hotbar|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17822</id>
        <msg>BLACKLIST DNS request for known malware domain ics.hotbar.com</msg>
        <url>labs.snort.org/docs/17822.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0D|myroitracking|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17823</id>
        <msg>BLACKLIST DNS request for known malware domain www.myroitracking.com</msg>
        <url>labs.snort.org/docs/17823.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|teenxmovs|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17824</id>
        <msg>BLACKLIST DNS request for known malware domain teenxmovs.net</msg>
        <url>labs.snort.org/docs/17824.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|px|08|smowtion|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17825</id>
        <msg>BLACKLIST DNS request for known malware domain px.smowtion.com</msg>
        <url>labs.snort.org/docs/17825.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|cheaps1|04|info&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17826</id>
        <msg>BLACKLIST DNS request for known malware domain cheaps1.info</msg>
        <url>labs.snort.org/docs/17826.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|sexmoviesland|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17827</id>
        <msg>BLACKLIST DNS request for known malware domain sexmoviesland.net</msg>
        <url>labs.snort.org/docs/17827.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|67|03|201|02|36|02|16&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17828</id>
        <msg>BLACKLIST DNS request for known malware domain 67.201.36.16</msg>
        <url>labs.snort.org/docs/17828.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|c7|05|zxxds|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17829</id>
        <msg>BLACKLIST DNS request for known malware domain c7.zxxds.net</msg>
        <url>labs.snort.org/docs/17829.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|dickvsclit|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17830</id>
        <msg>BLACKLIST DNS request for known malware domain dickvsclit.net</msg>
        <url>labs.snort.org/docs/17830.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0E|edrichfinearts|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17831</id>
        <msg>BLACKLIST DNS request for known malware domain edrichfinearts.com</msg>
        <url>labs.snort.org/docs/17831.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|img100|07|xvideos|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17832</id>
        <msg>BLACKLIST DNS request for known malware domain img100.xvideos.com</msg>
        <url>labs.snort.org/docs/17832.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|dsnextgen|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17833</id>
        <msg>BLACKLIST DNS request for known malware domain www.dsnextgen.com</msg>
        <url>labs.snort.org/docs/17833.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|343|07|boolans|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17834</id>
        <msg>BLACKLIST DNS request for known malware domain 343.boolans.com</msg>
        <url>labs.snort.org/docs/17834.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|xpresdnet|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17835</id>
        <msg>BLACKLIST DNS request for known malware domain xpresdnet.com</msg>
        <url>labs.snort.org/docs/17835.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|gbsup|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17836</id>
        <msg>BLACKLIST DNS request for known malware domain gbsup.com</msg>
        <url>labs.snort.org/docs/17836.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|xxsmovies|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17837</id>
        <msg>BLACKLIST DNS request for known malware domain xxsmovies.com</msg>
        <url>labs.snort.org/docs/17837.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|vc|09|iwriteweb|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17838</id>
        <msg>BLACKLIST DNS request for known malware domain vc.iwriteweb.com</msg>
        <url>labs.snort.org/docs/17838.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|js|06|222233|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17839</id>
        <msg>BLACKLIST DNS request for known malware domain js.222233.com</msg>
        <url>labs.snort.org/docs/17839.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0C|grannyplanet|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17840</id>
        <msg>BLACKLIST DNS request for known malware domain www.grannyplanet.com</msg>
        <url>labs.snort.org/docs/17840.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|coop|09|crwdcntrl|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17841</id>
        <msg>BLACKLIST DNS request for known malware domain coop.crwdcntrl.net</msg>
        <url>labs.snort.org/docs/17841.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|extrahotx|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17842</id>
        <msg>BLACKLIST DNS request for known malware domain extrahotx.net</msg>
        <url>labs.snort.org/docs/17842.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|10|extralargevideos|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17843</id>
        <msg>BLACKLIST DNS request for known malware domain extralargevideos.com</msg>
        <url>labs.snort.org/docs/17843.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|derquda|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17844</id>
        <msg>BLACKLIST DNS request for known malware domain www.derquda.com</msg>
        <url>labs.snort.org/docs/17844.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|aahydrogen|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17845</id>
        <msg>BLACKLIST DNS request for known malware domain aahydrogen.com</msg>
        <url>labs.snort.org/docs/17845.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|trumpetlicks|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17846</id>
        <msg>BLACKLIST DNS request for known malware domain trumpetlicks.com</msg>
        <url>labs.snort.org/docs/17846.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|mskla|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17847</id>
        <msg>BLACKLIST DNS request for known malware domain mskla.com</msg>
        <url>labs.snort.org/docs/17847.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|play|08|unionsky|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17848</id>
        <msg>BLACKLIST DNS request for known malware domain play.unionsky.cn</msg>
        <url>labs.snort.org/docs/17848.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0C|fuckersucker|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17849</id>
        <msg>BLACKLIST DNS request for known malware domain fuckersucker.com</msg>
        <url>labs.snort.org/docs/17849.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0C|pornfucklist|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17850</id>
        <msg>BLACKLIST DNS request for known malware domain pornfucklist.com</msg>
        <url>labs.snort.org/docs/17850.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|game|0B|685faiudeme|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17851</id>
        <msg>BLACKLIST DNS request for known malware domain game.685faiudeme.com</msg>
        <url>labs.snort.org/docs/17851.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|447|02|cc&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17852</id>
        <msg>BLACKLIST DNS request for known malware domain 447.cc</msg>
        <url>labs.snort.org/docs/17852.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|dommonview|04|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17853</id>
        <msg>BLACKLIST DNS request for known malware domain dommonview.com</msg>
        <url>labs.snort.org/docs/17853.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0E|lamiaexragazza|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17854</id>
        <msg>BLACKLIST DNS request for known malware domain www.lamiaexragazza.com</msg>
        <url>labs.snort.org/docs/17854.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|acofinder|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17855</id>
        <msg>BLACKLIST DNS request for known malware domain acofinder.com</msg>
        <url>labs.snort.org/docs/17855.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0C|fuckfuckvids|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17856</id>
        <msg>BLACKLIST DNS request for known malware domain fuckfuckvids.com</msg>
        <url>labs.snort.org/docs/17856.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|cnhack|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17857</id>
        <msg>BLACKLIST DNS request for known malware domain www.cnhack.cn</msg>
        <url>labs.snort.org/docs/17857.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0F|kingsizematures|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17858</id>
        <msg>BLACKLIST DNS request for known malware domain kingsizematures.com</msg>
        <url>labs.snort.org/docs/17858.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|promotds|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17859</id>
        <msg>BLACKLIST DNS request for known malware domain promotds.com</msg>
        <url>labs.snort.org/docs/17859.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|mejac|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17860</id>
        <msg>BLACKLIST DNS request for known malware domain mejac.com</msg>
        <url>labs.snort.org/docs/17860.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|zq2|04|9wee|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17861</id>
        <msg>BLACKLIST DNS request for known malware domain zq2.9wee.com</msg>
        <url>labs.snort.org/docs/17861.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|122|09|770304123|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17862</id>
        <msg>BLACKLIST DNS request for known malware domain 122.770304123.cn</msg>
        <url>labs.snort.org/docs/17862.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|rpt2|05|21civ|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17863</id>
        <msg>BLACKLIST DNS request for known malware domain rpt2.21civ.com</msg>
        <url>labs.snort.org/docs/17863.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0E|tubexxxmatures|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17864</id>
        <msg>BLACKLIST DNS request for known malware domain tubexxxmatures.com</msg>
        <url>labs.snort.org/docs/17864.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|110|09|770304123|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17865</id>
        <msg>BLACKLIST DNS request for known malware domain 110.770304123.cn</msg>
        <url>labs.snort.org/docs/17865.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0C|aebankonline|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17866</id>
        <msg>BLACKLIST DNS request for known malware domain aebankonline.com</msg>
        <url>labs.snort.org/docs/17866.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|utm|03|trk|0A|myfuncards|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17867</id>
        <msg>BLACKLIST DNS request for known malware domain utm.trk.myfuncards.com</msg>
        <url>labs.snort.org/docs/17867.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|a|06|qq2233|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17868</id>
        <msg>BLACKLIST DNS request for known malware domain a.qq2233.com</msg>
        <url>labs.snort.org/docs/17868.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|px|0A|mgplatform|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17869</id>
        <msg>BLACKLIST DNS request for known malware domain px.mgplatform.com</msg>
        <url>labs.snort.org/docs/17869.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|trojan8|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17870</id>
        <msg>BLACKLIST DNS request for known malware domain trojan8.com</msg>
        <url>labs.snort.org/docs/17870.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|brutalxvideos|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17871</id>
        <msg>BLACKLIST DNS request for known malware domain brutalxvideos.com</msg>
        <url>labs.snort.org/docs/17871.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|www3|06|sexown|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17872</id>
        <msg>BLACKLIST DNS request for known malware domain www3.sexown.com</msg>
        <url>labs.snort.org/docs/17872.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|mummimpegs|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17873</id>
        <msg>BLACKLIST DNS request for known malware domain mummimpegs.com</msg>
        <url>labs.snort.org/docs/17873.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|10|f19dd4abb8b8bdf2|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17874</id>
        <msg>BLACKLIST DNS request for known malware domain f19dd4abb8b8bdf2.cn</msg>
        <url>labs.snort.org/docs/17874.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0F|very-young-boys|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17875</id>
        <msg>BLACKLIST DNS request for known malware domain www.very-young-boys.com</msg>
        <url>labs.snort.org/docs/17875.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|91629|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17876</id>
        <msg>BLACKLIST DNS request for known malware domain 91629.com</msg>
        <url>labs.snort.org/docs/17876.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|animal36|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17877</id>
        <msg>BLACKLIST DNS request for known malware domain animal36.com</msg>
        <url>labs.snort.org/docs/17877.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|ayb|0D|host127-0-0-1|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17878</id>
        <msg>BLACKLIST DNS request for known malware domain ayb.host127-0-0-1.com</msg>
        <url>labs.snort.org/docs/17878.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|cfg|09|353wanwan|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17879</id>
        <msg>BLACKLIST DNS request for known malware domain cfg.353wanwan.com</msg>
        <url>labs.snort.org/docs/17879.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|027dj|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17880</id>
        <msg>BLACKLIST DNS request for known malware domain www.027dj.com</msg>
        <url>labs.snort.org/docs/17880.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|fucktosky|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17881</id>
        <msg>BLACKLIST DNS request for known malware domain fucktosky.com</msg>
        <url>labs.snort.org/docs/17881.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|procca|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17882</id>
        <msg>BLACKLIST DNS request for known malware domain procca.com</msg>
        <url>labs.snort.org/docs/17882.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0D|autouploaders|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17883</id>
        <msg>BLACKLIST DNS request for known malware domain autouploaders.net</msg>
        <url>labs.snort.org/docs/17883.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|gimmemyporn|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17884</id>
        <msg>BLACKLIST DNS request for known malware domain gimmemyporn.com</msg>
        <url>labs.snort.org/docs/17884.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|waytoall|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17885</id>
        <msg>BLACKLIST DNS request for known malware domain waytoall.com</msg>
        <url>labs.snort.org/docs/17885.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|spamature|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17886</id>
        <msg>BLACKLIST DNS request for known malware domain www.spamature.com</msg>
        <url>labs.snort.org/docs/17886.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|info|15|collectionerrorreport|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17887</id>
        <msg>BLACKLIST DNS request for known malware domain info.collectionerrorreport.com</msg>
        <url>labs.snort.org/docs/17887.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|bn|03|xp1|03|ru4|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17888</id>
        <msg>BLACKLIST DNS request for known malware domain bn.xp1.ru4.com</msg>
        <url>labs.snort.org/docs/17888.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|ajie520|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17889</id>
        <msg>BLACKLIST DNS request for known malware domain www.ajie520.com</msg>
        <url>labs.snort.org/docs/17889.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0A|114search1|06|118114|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17890</id>
        <msg>BLACKLIST DNS request for known malware domain 114search1.118114.cn</msg>
        <url>labs.snort.org/docs/17890.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|08|bestkind|02|ru&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17891</id>
        <msg>BLACKLIST DNS request for known malware domain bestkind.ru</msg>
        <url>labs.snort.org/docs/17891.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|clickpotato|02|tv&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17892</id>
        <msg>BLACKLIST DNS request for known malware domain clickpotato.tv</msg>
        <url>labs.snort.org/docs/17892.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|zxc0001|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17893</id>
        <msg>BLACKLIST DNS request for known malware domain www.zxc0001.com</msg>
        <url>labs.snort.org/docs/17893.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|streq|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17894</id>
        <msg>BLACKLIST DNS request for known malware domain streq.cn</msg>
        <url>labs.snort.org/docs/17894.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|pyow|0A|prixi-soft|02|ir&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17895</id>
        <msg>BLACKLIST DNS request for known malware domain pyow.prixi-soft.ir</msg>
        <url>labs.snort.org/docs/17895.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|113552url|05|cptgt|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17896</id>
        <msg>BLACKLIST DNS request for known malware domain 113552url.cptgt.com</msg>
        <url>labs.snort.org/docs/17896.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|moneytw8|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>17897</id>
        <msg>BLACKLIST DNS request for known malware domain www.moneytw8.com</msg>
        <url>labs.snort.org/docs/17897.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|jsshmz|07|gotoip4|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18079</id>
        <msg>BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|netrand|05|house|04|sina|03|com|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18080</id>
        <msg>BLACKLIST DNS request for known malware domain netrand.house.sina.com.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|wenyixuan|04|3322|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18081</id>
        <msg>BLACKLIST DNS request for known malware domain wenyixuan.3322.org</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|3q|08|sbwanwan|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18082</id>
        <msg>BLACKLIST DNS request for known malware domain 3q.sbwanwan.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|863|06|dclsba|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18083</id>
        <msg>BLACKLIST DNS request for known malware domain 863.dclsba.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|drs317a|07|gotoip4|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18084</id>
        <msg>BLACKLIST DNS request for known malware domain drs317a.gotoip4.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|jsshmz|07|gotoip4|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18085</id>
        <msg>BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|02|qq|08|sbwanwan|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18086</id>
        <msg>BLACKLIST DNS request for known malware domain qq.sbwanwan.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0F|tiantianzaixian|07|gotoip1|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18087</id>
        <msg>BLACKLIST DNS request for known malware domain tiantianzaixian.gotoip1.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|wenyixuan|04|3322|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18088</id>
        <msg>BLACKLIST DNS request for known malware domain wenyixuan.3322.org</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|auto328|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18089</id>
        <msg>BLACKLIST DNS request for known malware domain www.auto328.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|comstelecom|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18090</id>
        <msg>BLACKLIST DNS request for known malware domain www.comstelecom.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|goodfriends|02|or|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18091</id>
        <msg>BLACKLIST DNS request for known malware domain www.goodfriends.or.kr</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|hao1345|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18092</id>
        <msg>BLACKLIST DNS request for known malware domain www.hao1345.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|opusgame|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18093</id>
        <msg>BLACKLIST DNS request for known malware domain www.opusgame.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|theoffstage|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18094</id>
        <msg>BLACKLIST DNS request for known malware domain www.theoffstage.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|wwmei|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18095</id>
        <msg>BLACKLIST DNS request for known malware domain www.wwmei.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|5yvod|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18103</id>
        <msg>BLACKLIST DNS request for known malware domain 5yvod.net</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|b|03|9s3|04|info&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18104</id>
        <msg>BLACKLIST DNS request for known malware domain b.9s3.info</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0B|baidutaobao|08|gotoip55|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18105</id>
        <msg>BLACKLIST DNS request for known malware domain baidutaobao.gotoip55.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|e|05|msssm|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18106</id>
        <msg>BLACKLIST DNS request for known malware domain e.msssm.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|06|jsshmz|07|gotoip4|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18107</id>
        <msg>BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|phoroshop|02|es&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18108</id>
        <msg>BLACKLIST DNS request for known malware domain phoroshop.es</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|04|talk|07|cetizen|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18109</id>
        <msg>BLACKLIST DNS request for known malware domain talk.cetizen.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|0F|tiantianzaixian|07|gotoip1|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18110</id>
        <msg>BLACKLIST DNS request for known malware domain tiantianzaixian.gotoip1.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|v|04|9y9c|02|co|02|cc&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18111</id>
        <msg>BLACKLIST DNS request for known malware domain v.9y9c.co.cc</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|wenyixuan|04|3322|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18112</id>
        <msg>BLACKLIST DNS request for known malware domain wenyixuan.3322.org.</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|09|wusheng03|04|3322|03|org&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18113</id>
        <msg>BLACKLIST DNS request for known malware domain wusheng03.3322.org</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|04|5fqq|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18114</id>
        <msg>BLACKLIST DNS request for known malware domain www.5fqq.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|ajs2002|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18115</id>
        <msg>BLACKLIST DNS request for known malware domain www.ajs2002.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|bnbsoft|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18116</id>
        <msg>BLACKLIST DNS request for known malware domain www.bnbsoft.co.kr</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|cineseoul|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18117</id>
        <msg>BLACKLIST DNS request for known malware domain www.cineseoul.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|hao1345|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18118</id>
        <msg>BLACKLIST DNS request for known malware domain www.hao1345.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0A|ilbondrama|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18119</id>
        <msg>BLACKLIST DNS request for known malware domain www.ilbondrama.net</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|iwebdy|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18120</id>
        <msg>BLACKLIST DNS request for known malware domain www.iwebdy.net</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0D|linzhiling123|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18121</id>
        <msg>BLACKLIST DNS request for known malware domain www.linzhiling123.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|opusgame|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18122</id>
        <msg>BLACKLIST DNS request for known malware domain www.opusgame.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|phoroshop|02|es&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18123</id>
        <msg>BLACKLIST DNS request for known malware domain www.phoroshop.es</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0A|sijianfeng|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18124</id>
        <msg>BLACKLIST DNS request for known malware domain www.sijianfeng.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|tpydb|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18125</id>
        <msg>BLACKLIST DNS request for known malware domain www.tpydb.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|tpydb|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18126</id>
        <msg>BLACKLIST DNS request for known malware domain www.tpydb.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|univus|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18127</id>
        <msg>BLACKLIST DNS request for known malware domain www.univus.co.kr</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|uwonderfull|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18128</id>
        <msg>BLACKLIST DNS request for known malware domain www.uwonderfull.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|w22rt|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18129</id>
        <msg>BLACKLIST DNS request for known malware domain www.w22rt.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|wwmei|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18130</id>
        <msg>BLACKLIST DNS request for known malware domain www.wwmei.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|ybtour|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18131</id>
        <msg>BLACKLIST DNS request for known malware domain www.ybtour.co.kr</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|001zs|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18133</id>
        <msg>BLACKLIST DNS request for known malware domain www.001zs.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|551sf|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18134</id>
        <msg>BLACKLIST DNS request for known malware domain www.551sf.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|555hd|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18135</id>
        <msg>BLACKLIST DNS request for known malware domain www.555hd.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|66xihu|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18136</id>
        <msg>BLACKLIST DNS request for known malware domain www.66xihu.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|9292cs|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18137</id>
        <msg>BLACKLIST DNS request for known malware domain www.9292cs.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0D|chateaulegend|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18138</id>
        <msg>BLACKLIST DNS request for known malware domain www.chateaulegend.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|china-aoben|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18139</id>
        <msg>BLACKLIST DNS request for known malware domain www.china-aoben.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|cqtjg|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18140</id>
        <msg>BLACKLIST DNS request for known malware domain www.cqtjg.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|dspenter|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18141</id>
        <msg>BLACKLIST DNS request for known malware domain www.dspenter.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|eastadmin|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18142</id>
        <msg>BLACKLIST DNS request for known malware domain www.eastadmin.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|fp0755|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18143</id>
        <msg>BLACKLIST DNS request for known malware domain www.fp0755.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|fp0769|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18144</id>
        <msg>BLACKLIST DNS request for known malware domain www.fp0769.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|fp360|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18145</id>
        <msg>BLACKLIST DNS request for known malware domain www.fp360.net</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|gdfp365|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18146</id>
        <msg>BLACKLIST DNS request for known malware domain www.gdfp365.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|03|gev|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18147</id>
        <msg>BLACKLIST DNS request for known malware domain www.gev.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|haoleyou|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18148</id>
        <msg>BLACKLIST DNS request for known malware domain www.haoleyou.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|haosf08|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18149</id>
        <msg>BLACKLIST DNS request for known malware domain www.haosf08.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|jxbaike|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18150</id>
        <msg>BLACKLIST DNS request for known malware domain www.jxbaike.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|10|kingsoftduba2009|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18151</id>
        <msg>BLACKLIST DNS request for known malware domain www.kingsoftduba2009.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|mainhu|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18152</id>
        <msg>BLACKLIST DNS request for known malware domain www.mainhu.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|maoyiren|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18153</id>
        <msg>BLACKLIST DNS request for known malware domain www.maoyiren.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|04|nc57|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18154</id>
        <msg>BLACKLIST DNS request for known malware domain www.nc57.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|pplog|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18155</id>
        <msg>BLACKLIST DNS request for known malware domain www.pplog.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|pxflm|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18156</id>
        <msg>BLACKLIST DNS request for known malware domain www.pxflm.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|quyou365|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18157</id>
        <msg>BLACKLIST DNS request for known malware domain www.quyou365.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0A|shzhaotian|02|cn&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18158</id>
        <msg>BLACKLIST DNS request for known malware domain www.shzhaotian.cn</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|07|soanala|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18159</id>
        <msg>BLACKLIST DNS request for known malware domain www.soanala.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|0B|stony-skunk|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18160</id>
        <msg>BLACKLIST DNS request for known malware domain www.stony-skunk.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|08|street08|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18161</id>
        <msg>BLACKLIST DNS request for known malware domain www.street08.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|09|weilingcy|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18162</id>
        <msg>BLACKLIST DNS request for known malware domain www.weilingcy.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|yisaa|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18163</id>
        <msg>BLACKLIST DNS request for known malware domain www.yisaa.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|05|yx240|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18164</id>
        <msg>BLACKLIST DNS request for known malware domain www.yx240.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|01|e|04|mssm|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18165</id>
        <msg>BLACKLIST DNS request for known malware domain e.mssm.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|05|dfgdd|04|9y6c|02|co|02|cc&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18166</id>
        <msg>BLACKLIST DNS request for known malware domain dfgdd.9y6c.co.cc</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|07|mailzou|03|com&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18183</id>
        <msg>BLACKLIST DNS request for known malware domain mailzou.com</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|dnf|08|gametime|02|co|02|kr&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18184</id>
        <msg>BLACKLIST DNS request for known malware domain dnf.gametime.co.kr</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-3962</cve>
        <filter1>udp $HOME_NET any -&gt; any 53</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,64,2; byte_test:1,!&amp;,32,2; byte_test:1,!&amp;,16,2; byte_test:1,!&amp;,8,2; content:&quot;|03|www|06|dd0415|03|net&quot;; metadata:impact_flag red, service dns; classtype:trojan-activity;</filter2>
        <id>18185</id>
        <msg>BLACKLIST DNS request for known malware domain www.dd0415.net</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;|07|authors&quot;; offset:12; nocase; content:&quot;|04|bind|00|&quot;; offset:12; nocase; metadata:service dns; classtype:attempted-recon;</filter2>
        <id>256</id>
        <msg>DNS named authors attempt</msg>
        <nessus>10728</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|07|version&quot;; offset:12; nocase; content:&quot;|04|bind|00|&quot;; offset:12; nocase; metadata:service dns; classtype:attempted-recon;</filter2>
        <id>257</id>
        <msg>DNS named version attempt</msg>
        <nessus>10028</nessus>
      </rule>
      <rule>
        <bugtraq>788</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0833</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;../../../&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>258</id>
        <msg>DNS EXPLOIT named 8.2-&gt;8.2.1</msg>
      </rule>
      <rule>
        <bugtraq>788</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0833</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;thisissometempspaceforthesockinaddrinyeahyeahiknowthisislamebutanywaywhocareshorizongotitworkingsoalliscool&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>259</id>
        <msg>DNS EXPLOIT named overflow ADM</msg>
      </rule>
      <rule>
        <bugtraq>788</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0833</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;ADMROCKS&quot;; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>260</id>
        <msg>DNS EXPLOIT named overflow ADMROCKS</msg>
        <url>www.cert.org/advisories/CA-1999-14.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|CD 80 E8 D7 FF FF FF|/bin/sh&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>261</id>
        <msg>DNS EXPLOIT named overflow attempt</msg>
        <url>www.cert.org/advisories/CA-1998-05.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;1|C0 B0|?1|DB B3 FF|1|C9 CD 80|1|C0|&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>262</id>
        <msg>DNS EXPLOIT x86 Linux overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;1|C0 B0 02 CD 80 85 C0|uL|EB|L^|B0|&quot;; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>264</id>
        <msg>DNS EXPLOIT x86 Linux overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|89 F7 29 C7 89 F3 89 F9 89 F2 AC|&lt;|FE|&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>265</id>
        <msg>DNS EXPLOIT x86 Linux overflow attempt ADMv2</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB|n^|C6 06 9A|1|C9 89|N|01 C6|F|05|&quot;; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>266</id>
        <msg>DNS EXPLOIT x86 FreeBSD overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|90 1A C0 0F 90 02| |08 92 02| |0F D0 23 BF F8|&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>267</id>
        <msg>DNS EXPLOIT sparc overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2302</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0010</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server,established; content:&quot;|AB CD 09 80 00 00 00 01 00 00 00 00 00 00 01 00 01|    |02|a&quot;; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>303</id>
        <msg>DNS EXPLOIT named tsig overflow attempt</msg>
        <nessus>10605</nessus>
      </rule>
      <rule>
        <bugtraq>2302</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0010</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; content:&quot;|80 00 07 00 00 00 00 00 01|?|00 01 02|&quot;; fast_pattern:only; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>314</id>
        <msg>DNS EXPLOIT named tsig overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>134</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0009</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>flow:to_server; isdataat:400; byte_test:1,&lt;,16,2; byte_test:1,&amp;,8,2; metadata:service dns; classtype:attempted-admin;</filter2>
        <id>3154</id>
        <msg>DNS UDP inverse query overflow</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Open Beyond Keylogger&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10089</id>
        <msg>SPYWARE-PUT Keylogger beyond Keylogger runtime detection - log sent by ftp</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453097340</url>
      </rule>
      <rule>
        <bugtraq>22079</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2007-0247</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:established,to_server; content:&quot;GET&quot;; depth:3; nocase; content:&quot;FTP|3A|//&quot;; nocase; pcre:&quot;/ftp\x3A\x2F\x2F[\w\x2E\x2F]+[^\x2F]\x3Btype=D/i&quot;; metadata:policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>10135</id>
        <msg>DOS Squid proxy FTP denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32418</filter1>
        <filter2>flow:to_server,established; content:&quot;FTP-ON&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10444</id>
        <msg>BACKDOOR acidbattery 1.0 runtime detection - open ftp serice</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=109</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Theef2&quot;; content:&quot;FTP&quot;; distance:0; content:&quot;Server&quot;; distance:0; pcre:&quot;/Theef2\s+FTP\s+Server\x3A/&quot;; flowbits:set,Theef210_TheefFTP; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12237</id>
        <msg>BACKDOOR theef 2.10 runtime detection - ftp</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-2161</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 05|&quot;; depth:2; isdataat:485; metadata:policy balanced-ips drop, policy security-ips drop, service tftp; classtype:attempted-admin;</filter2>
        <id>13927</id>
        <msg>TFTP Server log generation buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;39FDA070-61BA-11D2-AD84-00105A17B608&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*39FDA070-61BA-11D2-AD84-00105A17B608\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(SecretKey)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*39FDA070-61BA-11D2-AD84-00105A17B608\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(SecretKey))\s*=/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14778</id>
        <msg>WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|9|00|F|00|D|00|A|00|0|00|7|00|0|00|-|00|6|00|1|00|B|00|A|00|-|00|1|00|1|00|D|00|2|00|-|00|A|00|D|00|8|00|4|00|-|00|0|00|0|00|1|00|0|00|5|00|A|00|1|00|7|00|B|00|6|00|0|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x009\x00F\x00D\x00A\x000\x007\x000\x00-\x006\x001\x00B\x00A\x00-\x001\x001\x00D\x002\x00-\x00A\x00D\x008\x004\x00-\x000\x000\x001\x000\x005\x00A\x001\x007\x00B\x006\x000\x008\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14779</id>
        <msg>WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>31814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Dart.Ftp&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Dart\.Ftp\x22|\x27Dart\.Ftp\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SecretKey\s*|.*(?P=v)\s*\.\s*SecretKey\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Dart\.Ftp\x22|\x27Dart\.Ftp\x27)\s*\)(\s*\.\s*SecretKey\s*|.*(?P=n)\s*\.\s*SecretKey)\s*=/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14780</id>
        <msg>WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>31814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|a|00|r|00|t|00|.|00|F|00|t|00|p|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00a\x00r\x00t\x00.\x00F\x00t\x00p\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00a\x00r\x00t\x00.\x00F\x00t\x00p\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14781</id>
        <msg>WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7E864D3E-3E6A-48F0-88AF-CEAEE322F9FD&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7E864D3E-3E6A-48F0-88AF-CEAEE322F9FD\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*7E864D3E-3E6A-48F0-88AF-CEAEE322F9FD\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15159</id>
        <msg>WEB-ACTIVEX Evans FTP ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|E|00|8|00|6|00|4|00|D|00|3|00|E|00|-|00|3|00|E|00|6|00|A|00|-|00|4|00|8|00|F|00|0|00|-|00|8|00|8|00|A|00|F|00|-|00|C|00|E|00|A|00|E|00|E|00|3|00|2|00|2|00|F|00|9|00|F|00|D|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*7\x00E\x008\x006\x004\x00D\x003\x00E\x00-\x003\x00E\x006\x00A\x00-\x004\x008\x00F\x000\x00-\x008\x008\x00A\x00F\x00-\x00C\x00E\x00A\x00E\x00E\x003\x002\x002\x00F\x009\x00F\x00D\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15160</id>
        <msg>WEB-ACTIVEX Evans FTP ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>32814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EvansFTP.eFtpEz&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EvansFTP\.eFtpEz(\.\d)?\x22|\x27EvansFTP\.eFtpEz(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory)\s*|.*(?P=v)\s*\.\s*(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EvansFTP\.eFtpEz(\.\d)?\x22|\x27EvansFTP\.eFtpEz(\.\d)?\x27)\s*\)(\s*\.\s*(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory)\s*|.*(?P=n)\s*\.\s*(RemoteAddress|ProxyPrefix|ProxyName|Password|ProxyBypassList|LoginName|CurrentDirectory)\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15161</id>
        <msg>WEB-ACTIVEX Evans FTP ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>32814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|v|00|a|00|n|00|s|00|F|00|T|00|P|00|.|00|e|00|F|00|t|00|p|00|E|00|z|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00v\x00a\x00n\x00s\x00F\x00T\x00P\x00.\x00e\x00F\x00t\x00p\x00E\x00z\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00v\x00a\x00n\x00s\x00F\x00T\x00P\x00.\x00e\x00F\x00t\x00p\x00E\x00z\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15162</id>
        <msg>WEB-ACTIVEX Evans FTP ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33842</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;62A989CE-D39A-11D5-86F0-B9C370762176&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*62A989CE-D39A-11D5-86F0-B9C370762176\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*62A989CE-D39A-11D5-86F0-B9C370762176\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15368</id>
        <msg>WEB-ACTIVEX FathFTP ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33842</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|2|00|A|00|9|00|8|00|9|00|C|00|E|00|-|00|D|00|3|00|9|00|A|00|-|00|1|00|1|00|D|00|5|00|-|00|8|00|6|00|F|00|0|00|-|00|B|00|9|00|C|00|3|00|7|00|0|00|7|00|6|00|2|00|1|00|7|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x002\x00A\x009\x008\x009\x00C\x00E\x00-\x00D\x003\x009\x00A\x00-\x001\x001\x00D\x005\x00-\x008\x006\x00F\x000\x00-\x00B\x009\x00C\x003\x007\x000\x007\x006\x002\x001\x007\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15369</id>
        <msg>WEB-ACTIVEX FathFTP ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33842</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FathFTP.FathFTPCtrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22FathFTP\.FathFTPCtrl(\.\d)?\x22|\x27FathFTP\.FathFTPCtrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*DeleteFile\s*|.*(?P=v)\s*\.\s*DeleteFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22FathFTP\.FathFTPCtrl(\.\d)?\x22|\x27FathFTP\.FathFTPCtrl(\.\d)?\x27)\s*\)(\s*\.\s*DeleteFile\s*|.*(?P=n)\s*\.\s*DeleteFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15370</id>
        <msg>WEB-ACTIVEX FathFTP ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33842</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|a|00|t|00|h|00|F|00|T|00|P|00|.|00|F|00|a|00|t|00|h|00|F|00|T|00|P|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)F\x00a\x00t\x00h\x00F\x00T\x00P\x00.\x00F\x00a\x00t\x00h\x00F\x00T\x00P\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)F\x00a\x00t\x00h\x00F\x00T\x00P\x00.\x00F\x00a\x00t\x00h\x00F\x00T\x00P\x00C\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15371</id>
        <msg>WEB-ACTIVEX FathFTP ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-2521</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;ST -R&quot;; nocase; content:&quot;*/..&quot;; within:20; distance:1; metadata:policy security-ips alert, service ftp; classtype:attempted-dos;</filter2>
        <id>15932</id>
        <msg>FTP LIST globbing denial of service attack</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>10454</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0536</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOR asd%nmv|0D 0A|&quot;; fast_pattern:only; metadata:policy security-ips drop, service ftp; classtype:attempted-admin;</filter2>
        <id>16077</id>
        <msg>SPECIFIC-THREATS Tripwire format string vulnerability ftp exploit attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2009-4444</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:established,to_server; content:&quot;STOR&quot;; depth:4; nocase; content:&quot;.asp|3B|.&quot;; distance:0; nocase; pcre:&quot;/^STOR[^\n]+\.asp\x3B\./smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16357</id>
        <msg>FTP multiple extension code execution attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PORT&quot;; isdataat:50,relative; content:!&quot;|0A|&quot;; within:50; metadata:policy security-ips drop, service ftp; classtype:misc-attack;</filter2>
        <id>17059</id>
        <msg>FTP Vermillion 1.31 vftpd port command memory corruption</msg>
        <url>www.global-evolution.info/news/files/vftpd/vftpd.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2004-1376</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server; content:&quot;RETR|20 2F 2E 2E 2F 2E 2E 2F 2E 2E 2F 74 65 73 74 2F 70 6F 63 2E 61 61 61|&quot;; metadata:policy security-ips drop, service ftp; classtype:misc-activity;</filter2>
        <id>17446</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer FTP client directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>31879</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22</filter1>
        <filter2>flow:to_server,established; content:&quot;|C4 90 89 C8 19 AD BD 70 41 AB EF 40 55 31 B3 B8|&quot;; offset:128; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17521</id>
        <msg>SPECIFIC-THREATS GoodTech SSH Server SFTP Processing Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>5328</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2957</cve>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; isdataat:100,relative; content:!&quot;|00|&quot;; within:100; metadata:policy balanced-ips drop, policy security-ips drop, service tftp; classtype:attempted-admin;</filter2>
        <id>1941</id>
        <msg>TFTP GET filename overflow attempt</msg>
        <nessus>18264</nessus>
      </rule>
      <rule>
        <bugtraq>9675</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-0351</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;LIST&quot;; nocase; isdataat:120,relative; pcre:&quot;/^LIST(?!\n)\s[^\n]{120}/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service ftp; classtype:misc-attack;</filter2>
        <id>2338</id>
        <msg>FTP LIST buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-003.mspx</url>
      </rule>
      <rule>
        <bugtraq>7909</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-3023</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;NLST&quot;; nocase; isdataat:200,relative; pcre:&quot;/^NLST(?!\n)\s[^\n]{200}/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service ftp; classtype:attempted-admin;</filter2>
        <id>2374</id>
        <msg>FTP NLST overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-053</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOR spyagent-log&quot;; fast_pattern:only;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5881</id>
        <msg>SPYWARE-PUT Keylogger spyagent runtime detect - ftp delivery</msg>
        <url>www.spywareguide.com/product_show.php?id=22</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 21 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;220 HellzAddiction FTP server.&quot;; depth:30; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6142</id>
        <msg>BACKDOOR hellzaddiction v1.0e runtime detection - ftp open</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076338</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;_WinSession Logger.clk&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6208</id>
        <msg>SPYWARE-PUT Keylogger winsession runtime detection - ftp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097713</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 21 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;We&quot;; nocase; content:&quot;got&quot;; distance:0; nocase; content:&quot;this&quot;; distance:0; nocase; content:&quot;GREAT&quot;; distance:0; nocase; content:&quot;Daemon&quot;; distance:0; nocase; content:&quot;Fictional&quot;; nocase; content:&quot;Daemon&quot;; distance:0; nocase; pcre:&quot;/We\s+got\s+this\s+GREAT\s+Daemon.*Fictional\s+Daemon/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6288</id>
        <msg>BACKDOOR fictional daemon 4.4 runtime detection - ftp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074164</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Welcome&quot;; nocase; content:&quot;To&quot;; distance:0; nocase; content:&quot;EvilFTP&quot;; distance:0; nocase; pcre:&quot;/^\d+\x2d\s+Welcome\s+To\s+EvilFTP\s+\x3a\x29\r\n/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6319</id>
        <msg>BACKDOOR evilftp runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1929</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOR&quot;; fast_pattern:only; pcre:&quot;/^STOR\s+\x2E\x2F(kys|scr|Apps|Urls)[0-9]+\x2Etxt/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7185</id>
        <msg>SPYWARE-PUT Keylogger 007 spy software runtime detection - ftp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082794</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 20</filter1>
        <filter2>flow:from_server,established; content:&quot;&lt;title&gt;&quot;; nocase; content:&quot;Actual&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;software&quot;; distance:0; nocase; content:&quot;report&quot;; distance:0; nocase; content:&quot;&lt;/title&gt;&quot;; distance:0; nocase; pcre:&quot;/\&lt;title\&gt;Actual\s+Spy\s+software\s+report\&lt;|2F|title\&gt;/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7504</id>
        <msg>SPYWARE-PUT Keylogger actualspy runtime detection - ftp-data</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086496</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwp/msg/1,,,00.html&quot;; http_uri; content:&quot;uin=&quot;; nocase; http_uri; content:&quot;name=&quot;; nocase; http_uri; content:&quot;Anal FTP&quot;; http_uri; content:&quot;send=yes&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7762</id>
        <msg>BACKDOOR analftp 0.1 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59411</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;79EAC9E3-BAF9-11CE-8C82-00AA004BA90B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q3&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*79EAC9E3-BAF9-11CE-8C82-00AA004BA90B\s*}?\s*(?P=q3)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7934</id>
        <msg>WEB-ACTIVEX ftp Asychronous Pluggable Protocol Handler ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|9|00|E|00|A|00|C|00|9|00|E|00|3|00|-|00|B|00|A|00|F|00|9|00|-|00|1|00|1|00|C|00|E|00|-|00|8|00|C|00|8|00|2|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|4|00|B|00|A|00|9|00|0|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q4&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q4)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7935</id>
        <msg>WEB-ACTIVEX ftp Asychronous Pluggable Protocol Handler ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9996</filter1>
        <filter2>flow:established,to_server; content:&quot;cho off&quot;; depth:7; nocase; content:&quot;cmd.ftp&quot;; distance:0; nocase; content:&quot;_up.exe&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9341</id>
        <msg>SPECIFIC-THREATS sasser open ftp command shell</msg>
        <url>www.sophos.com/virusinfo/analyses/w32sassera.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 1024:</filter1>
        <filter2>flow:to_server; content:&quot;C|BB 0E|Gy3a38DM4|EC|5e|C2 0A 86 0B|Yde|02 EE|s|EB 18 0A B9|S9Cb|05|Zk|ED|F|29|cf|0D|dl|08|5u@|EB E7|8sm-95|23 AC|p+%|1D|3f|F1|s|FF 03|-|09 CD 00|q -i %s &lt;|02 03 F2|get  nSVC|80 C0 CA 96|/|29 D6|b|80 C0| |9E CF 24 BE|-|EB D6|w&amp;k |A9|8Shar|F0 D6 80 DD|+g|00|l|00 EC|DTCo|24 D0|L|07|B|FA 13|j|EF|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9402</id>
        <msg>SPECIFIC-THREATS welchia tftp propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-081815-2308-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 20</filter1>
        <filter2>flow:to_client,established; content:&quot;version&quot;; nocase; content:&quot;key&quot;; distance:0; nocase; pcre:&quot;/^version\s+\d+\x2E\d+\s+key\x3a/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>9828</id>
        <msg>SPYWARE-PUT Keylogger paq keylog runtime detection - ftp</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098520</url>
      </rule>
    </attacks>
    <groupid>242</groupid>
    <groupname>Server / Misc / FTP</groupname>
    <warnings>
      <rule>
        <bugtraq>20076</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5000</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;XMD5&quot;; nocase; isdataat:200,relative; pcre:&quot;/^XMD5(?!\n)\s[^\n]{200}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>10188</id>
        <msg>FTP Wsftp XMD5 overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;tftp.exe&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1068</id>
        <msg>WEB-MISC tftp attempt</msg>
      </rule>
      <rule>
        <bugtraq>1471</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0674</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ftp.pl&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1107</id>
        <msg>WEB-MISC ftp.pl access</msg>
        <nessus>10467</nessus>
      </rule>
      <rule>
        <bugtraq>547</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1078</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ws_ftp.ini&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1166</id>
        <msg>WEB-MISC ws_ftp.ini access</msg>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2007-3823</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5151</filter1>
        <filter2>flow:to_server; content:&quot;|AB AA|&quot;; byte_test:2,&gt;,2123,0,relative,little; classtype:denial-of-service;</filter2>
        <id>12076</id>
        <msg>DOS Ipswitch WS_FTP log server long unicode string</msg>
        <url>secunia.com/advisories/26040</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Theef210_TheefFTP; content:&quot;Theef2.10_&quot;; classtype:trojan-activity;</filter2>
        <id>12238</id>
        <msg>BACKDOOR theef 2.10 runtime detection - ftp</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-071209-4425-99</url>
      </rule>
      <rule>
        <bugtraq>9237</bugtraq>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CWD&quot;; nocase; content:&quot;...&quot;; distance:0; pcre:&quot;/^CWD\s[^\n]*?\.\.\./smi&quot;; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>1229</id>
        <msg>FTP CWD ...</msg>
      </rule>
      <rule>
        <bugtraq>2808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FtpSave.dll&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1230</id>
        <msg>WEB-MISC VirusWall FtpSave access</msg>
        <nessus>10733</nessus>
      </rule>
      <rule>
        <bugtraq>2808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FtpSaveCSP.dll&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1234</id>
        <msg>WEB-MISC VirusWall FtpSaveCSP access</msg>
        <nessus>10733</nessus>
      </rule>
      <rule>
        <bugtraq>2808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/FtpSaveCVP.dll&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1235</id>
        <msg>WEB-MISC VirusWall FtpSaveCVP access</msg>
        <nessus>10733</nessus>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 20</filter1>
        <filter2>flow:from_server,established; content:&quot;version 4.0 key|3A 0D 0A|~~~~~~~~~~~~~~~~~~~~~~~~~~&quot;; classtype:successful-recon-limited;</filter2>
        <id>12379</id>
        <msg>SPYWARE-PUT Keylogger PaqKeylogger 5.1 runtime detection - ftp</msg>
        <url>www.spywareguide.com/product_show.php?id=2709</url>
      </rule>
      <rule>
        <classtype>successful-admin</classtype>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; content:&quot;admin.dll&quot;; offset:2; nocase; metadata:service tftp; classtype:successful-admin;</filter2>
        <id>1289</id>
        <msg>TFTP GET Admin.dll</msg>
        <url>www.cert.org/advisories/CA-2001-26.html</url>
      </rule>
      <rule>
        <bugtraq>3707</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2001-0886</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;~&quot;; content:&quot;[&quot;; distance:0; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>1377</id>
        <msg>FTP wu-ftp bad file completion attempt [</msg>
        <nessus>10821</nessus>
      </rule>
      <rule>
        <bugtraq>8542</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0772</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STAT&quot;; nocase; isdataat:190,relative; pcre:&quot;/^STAT(?!\n)\s[^\n]{190}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1379</id>
        <msg>FTP STAT overflow attempt</msg>
        <url>labs.defcom.com/adv/2001/def-2001-31.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2541</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;227&quot;; depth:3; pcre:&quot;/\x28((\d{4,}|[3-9]\d\d|2[6-9]\d|25[7-9]),\d+,\d+,\d+|\d+,(\d{4,}|[3-9]\d\d|2[6-9]\d|25[7-9]),\d+,\d+|\d+,\d+,(\d{4,}|[3-9]\d\d|2[6-9]\d|25[7-9]),\d+|\d+,\d+,\d+(\d{4,}|[3-9]\d\d|2[6-9]\d|25[7-9])),\d+,\d+\x29/&quot;; classtype:attempted-user;</filter2>
        <id>13925</id>
        <msg>FTP Computer Associates eTrust Secure Content Manager PASV stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; nocase; content:&quot;w0rm&quot;; distance:1; nocase; pcre:&quot;/^USER\s+w0rm/smi&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>144</id>
        <msg>FTP ADMw0rm ftp login attempt</msg>
      </rule>
      <rule>
        <classtype>successful-admin</classtype>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; content:&quot;nc.exe&quot;; offset:2; nocase; metadata:service tftp; classtype:successful-admin;</filter2>
        <id>1441</id>
        <msg>TFTP GET nc.exe</msg>
      </rule>
      <rule>
        <classtype>successful-admin</classtype>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; content:&quot;shadow&quot;; offset:2; nocase; metadata:service tftp; classtype:successful-admin;</filter2>
        <id>1442</id>
        <msg>TFTP GET shadow</msg>
      </rule>
      <rule>
        <classtype>successful-admin</classtype>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; content:&quot;passwd&quot;; offset:2; nocase; metadata:service tftp; classtype:successful-admin;</filter2>
        <id>1443</id>
        <msg>TFTP GET passwd</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; depth:2; metadata:service tftp; classtype:bad-unknown;</filter2>
        <id>1444</id>
        <msg>TFTP Get</msg>
      </rule>
      <rule>
        <bugtraq>31563</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2008-4501</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RNTO&quot;; depth:4; nocase; pcre:&quot;/^rnto\s[^\s\x0d\x0a]*\x2e\x2e(\x2f|\x5c)/i&quot;; classtype:suspicious-filename-detect;</filter2>
        <id>14743</id>
        <msg>FTP RNTO directory traversal attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2001-0770</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; isdataat:100,relative; pcre:&quot;/^SITE(?!\n)\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1529</id>
        <msg>FTP SITE overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2120</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0065</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;CHOWN&quot;; distance:0; nocase; isdataat:100,relative; pcre:&quot;/^SITE\s+CHOWN\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1562</id>
        <msg>FTP SITE CHOWN overflow attempt</msg>
        <nessus>10579</nessus>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 666</filter1>
        <filter2>flow:to_server,established; content:&quot;FTPON&quot;; classtype:misc-activity;</filter2>
        <id>157</id>
        <msg>BACKDOOR BackConstruction 2.1 Client FTP Open Request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;FTP Port open&quot;; classtype:misc-activity;</filter2>
        <id>158</id>
        <msg>BACKDOOR BackConstruction 2.1 Server FTP Open Reply</msg>
      </rule>
      <rule>
        <bugtraq>1471</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0674</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ftp.pl?dir=../..&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1612</id>
        <msg>WEB-MISC ftp.pl attempt</msg>
        <nessus>10467</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CMD&quot;; nocase; isdataat:200,relative; pcre:&quot;/^CMD(?!\n)\s[^\n]{200}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1621</id>
        <msg>FTP CMD overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>1999-0081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RNFR &quot;; fast_pattern:only; content:&quot; ././&quot;; nocase; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>1622</id>
        <msg>FTP RNFR ././ attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;MODE&quot;; fast_pattern:only; pcre:&quot;/^MODE\s+[^ABSC]{1}/msi&quot;; metadata:service ftp; classtype:protocol-command-decode;</filter2>
        <id>1623</id>
        <msg>FTP invalid MODE</msg>
        <url>www.faqs.org/rfcs/rfc959.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PWD&quot;; nocase; isdataat:190,relative; pcre:&quot;/^PWD\s.{190}/smi&quot;; metadata:service ftp; classtype:protocol-command-decode;</filter2>
        <id>1624</id>
        <msg>FTP PWD overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SYST&quot;; nocase; isdataat:100,relative; pcre:&quot;/^SYST(?!\n)\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:protocol-command-decode;</filter2>
        <id>1625</id>
        <msg>FTP SYST overflow attempt</msg>
        <url>www.faqs.org/rfcs/rfc959.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/~ftp&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1662</id>
        <msg>WEB-MISC /~ftp access</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>tcp any any -&gt; any 21</filter1>
        <filter2>flow:established,to_server; content:&quot;USER&quot;; nocase; pcre:&quot;/USER\s{0,2}\x00/ims&quot;; classtype:attempted-dos;</filter2>
        <id>16697</id>
        <msg>FTP httpdx USER null byte denial of service</msg>
        <url>www.exploit-db.com/exploits/11734</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>tcp any any -&gt; any 21</filter1>
        <filter2>flow:established,to_server; content:&quot;PASS&quot;; nocase; pcre:&quot;/PASS\s{0,2}\x00/ims&quot;; classtype:attempted-dos;</filter2>
        <id>16698</id>
        <msg>FTP httpdx PASS null byte denial of service</msg>
        <url>www.exploit-db.com/exploits/11734</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/home/ftp&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1670</id>
        <msg>WEB-MISC /home/ftp access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>9215</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2001-0421</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CWD&quot;; fast_pattern:only; pcre:&quot;/^CWD\s+~/smi&quot;; metadata:service ftp; classtype:denial-of-service;</filter2>
        <id>1672</id>
        <msg>FTP CWD ~ attempt</msg>
      </rule>
      <rule>
        <bugtraq>39183</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET 21 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|22 22|&quot;; pcre:&quot;/^2\d{2}[^\n]*?\x22{2}/&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>16795</id>
        <msg>DOS Google Chrome FTP handling out-of-bounds array index denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;seclog&quot;; fast_pattern:only; nocase; pcre:&quot;/seclog_[a-z]{5}\d{4}_\d{10}\x2Ekcb/smi&quot;; classtype:trojan-activity;</filter2>
        <id>16806</id>
        <msg>BACKDOOR Backdoor.Win32.Qakbot.E - FTP upload seclog</msg>
        <url>www.threatexpert.com/report.aspx?md5=8171d3223f89a495f98c4e3a65537b8f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;ps_dump&quot;; fast_pattern:only; pcre:&quot;/ps_dump_[^_]+_[a-z]{5}\d{4}\x2Ekcb/smi&quot;; classtype:trojan-activity;</filter2>
        <id>16807</id>
        <msg>BACKDOOR Backdoor.Win32.Qakbot.E - FTP Upload ps_dump</msg>
        <url>www.threatexpert.com/report.aspx?md5=8171d3223f89a495f98c4e3a65537b8f</url>
      </rule>
      <rule>
        <bugtraq>15998</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-4459</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:established,to_server; content:&quot;EPRT &quot;; nocase; isdataat:128,relative; pcre:&quot;/^EPRT\x20[^\n]{128}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>17329</id>
        <msg>FTP EPRT overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8376</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3683</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; nocase; isdataat:100,relative; pcre:&quot;/^USER(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1734</id>
        <msg>FTP USER overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22489</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-0217</cve>
        <filter1>tcp $EXTERNAL_NET 21 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; isdataat:1023; pcre:&quot;/\d{3}\s+[^\n]{1019}/smi&quot;; classtype:web-application-attack;</filter2>
        <id>17367</id>
        <msg>FTP Microsoft Internet Explorer FTP Response Parsing Memory Corruption</msg>
      </rule>
      <rule>
        <bugtraq>30685</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4321</cve>
        <filter1>tcp $EXTERNAL_NET 21 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;257|20|&quot;; pcre:&quot;/^257\x20\S{257,}\x20/mi&quot;; classtype:attempted-user;</filter2>
        <id>17518</id>
        <msg>FTP FlashGet PWD command stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <cve>2006-5584</cve>
        <filter1>udp any any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 02|&quot;; depth:2; content:&quot;setup.exe|00|&quot;; distance:0; nocase; metadata:service tftp; classtype:policy-violation;</filter2>
        <id>17712</id>
        <msg>SPECIFIC-THREATS TFTP PUT Microsoft RIS filename overwrite attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-077.mspx</url>
      </rule>
      <rule>
        <bugtraq>4482</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-0073</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STAT&quot;; fast_pattern:only; pcre:&quot;/^STAT\s+[^\n]*\x2a/smi&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>1777</id>
        <msg>FTP EXPLOIT STAT * dos attempt</msg>
        <nessus>10934</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>4482</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-0073</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STAT&quot;; fast_pattern:only; pcre:&quot;/^STAT\s+[^\n]*\x3f/smi&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>1778</id>
        <msg>FTP EXPLOIT STAT ? dos attempt</msg>
        <nessus>10934</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS02-018.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; 212.26.42.47 9090</filter1>
        <filter2>flow:to_server, established; content:&quot;GET /AB HTTP/1.0&quot;; classtype:trojan-activity;</filter2>
        <id>18181</id>
        <msg>SPECIFIC-THREATS ProFTPd 1.3.3c backdoor activity</msg>
        <url>xorl.wordpress.com/2010/12/02/news-proftpd-owned-and-backdoored/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;HELP ACIDBITCHES&quot;; classtype:trojan-activity;</filter2>
        <id>18182</id>
        <msg>SPECIFIC-THREATS ProFTPd 1.3.3c backdoor help access attempt</msg>
        <url>xorl.wordpress.com/2010/12/02/news-proftpd-owned-and-backdoored/</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>1999-0880</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;NEWER&quot;; distance:1; nocase; pcre:&quot;/^SITE\s+NEWER/smi&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>1864</id>
        <msg>FTP SITE NEWER attempt</msg>
        <nessus>10319</nessus>
      </rule>
      <rule>
        <bugtraq>5427</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:established,to_server; content:&quot;SITE&quot;; nocase; content:&quot;CPWD&quot;; distance:0; nocase; isdataat:100,relative; pcre:&quot;/^SITE\s+CPWD\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>1888</id>
        <msg>FTP SITE CPWD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7950</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2002-0405</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CWD&quot;; nocase; isdataat:180,relative; pcre:&quot;/^CWD(?!\n)\s[^\n]{180}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1919</id>
        <msg>FTP CWD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>229</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0800</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;NEWER&quot;; distance:0; nocase; isdataat:100,relative; pcre:&quot;/^SITE\s+NEWER\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1920</id>
        <msg>FTP SITE NEWER overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2000-0040</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;ZIPCHK&quot;; distance:1; nocase; isdataat:100,relative; pcre:&quot;/^SITE\s+ZIPCHK\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1921</id>
        <msg>FTP SITE ZIPCHK overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;authorized_keys&quot;; metadata:service ftp; classtype:suspicious-filename-detect;</filter2>
        <id>1927</id>
        <msg>FTP authorized_keys</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RETR&quot;; nocase; content:&quot;shadow&quot;; metadata:service ftp; classtype:suspicious-filename-detect;</filter2>
        <id>1928</id>
        <msg>FTP shadow retrieval attempt</msg>
      </rule>
      <rule>
        <bugtraq>819</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RMDIR&quot;; nocase; isdataat:100,relative; pcre:&quot;/^RMDIR(?!\n)\s[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1942</id>
        <msg>FTP RMDIR overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>1505</bugtraq>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;EXEC&quot;; distance:0; nocase; pcre:&quot;/^SITE\s+EXEC\s[^\n]*?%[^\n]*?%/smi&quot;; classtype:bad-unknown;</filter2>
        <id>1971</id>
        <msg>FTP SITE EXEC format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>9285</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3683</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS&quot;; nocase; isdataat:100,relative; pcre:&quot;/^PASS(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1972</id>
        <msg>FTP PASS overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9872</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0625</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;MKD&quot;; nocase; isdataat:150,relative; pcre:&quot;/^MKD(?!\n)\s[^\n]{150}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>1973</id>
        <msg>FTP MKD overflow attempt</msg>
        <nessus>12108</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS09-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>2972</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;REST&quot;; nocase; isdataat:100,relative; pcre:&quot;/^REST(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1974</id>
        <msg>FTP REST overflow attempt</msg>
        <nessus>11755</nessus>
      </rule>
      <rule>
        <bugtraq>39041</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0625</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RMD&quot;; nocase; isdataat:100,relative; pcre:&quot;/^RMD(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1976</id>
        <msg>FTP RMD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2618</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-1054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;LIST&quot;; nocase; content:&quot;..&quot;; distance:1; content:&quot;..&quot;; distance:1; metadata:service ftp; classtype:protocol-command-decode;</filter2>
        <id>1992</id>
        <msg>FTP LIST directory traversal attempt</msg>
        <nessus>11112</nessus>
      </rule>
      <rule>
        <bugtraq>7674</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2003-0392</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CWD&quot;; nocase; content:&quot;C|3A 5C|&quot;; distance:1; metadata:service ftp; classtype:protocol-command-decode;</filter2>
        <id>2125</id>
        <msg>FTP CWD Root directory transversal attempt</msg>
        <nessus>11677</nessus>
      </rule>
      <rule>
        <bugtraq>9800</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0277</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; fast_pattern:only; pcre:&quot;/^USER\s[^\n]*?%[^\n]*?%/smi&quot;; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>2178</id>
        <msg>FTP USER format string attempt</msg>
        <nessus>11687</nessus>
      </rule>
      <rule>
        <bugtraq>9800</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2000-0699</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS&quot;; fast_pattern:only; pcre:&quot;/^PASS\s[^\n]*?%[^\n]*?%/smi&quot;; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>2179</id>
        <msg>FTP PASS format string attempt</msg>
        <nessus>10490</nessus>
      </rule>
      <rule>
        <bugtraq>8875</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0854</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;LIST&quot;; fast_pattern:only; pcre:&quot;/^LIST\s+\x22-W\s+\d+/smi&quot;; classtype:misc-attack;</filter2>
        <id>2272</id>
        <msg>FTP LIST integer overflow attempt</msg>
        <nessus>11912</nessus>
      </rule>
      <rule>
        <bugtraq>9262</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;MKD&quot;; fast_pattern:only; pcre:&quot;/^MKD\s[^\n]*?%[^\n]*?%/smi&quot;; classtype:misc-attack;</filter2>
        <id>2332</id>
        <msg>FTP MKD format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>9262</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RENAME&quot;; fast_pattern:only; pcre:&quot;/^RENAME\s[^\n]*?%[^\n]*?%/smi&quot;; classtype:misc-attack;</filter2>
        <id>2333</id>
        <msg>FTP RENAME format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>9072</bugtraq>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3535</filter1>
        <filter2>flow:to_server,established; content:&quot;USER&quot;; nocase; content:&quot;y049575046&quot;; fast_pattern:only; pcre:&quot;/^USER\s+y049575046/smi&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>2334</id>
        <msg>FTP Yak! FTP server default account login attempt</msg>
      </rule>
      <rule>
        <bugtraq>9159</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3535</filter1>
        <filter2>flow:to_server,established; content:&quot;RMD&quot;; fast_pattern:only; pcre:&quot;/^RMD\s+\x2f$/smi&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>2335</id>
        <msg>FTP RMD / attempt</msg>
      </rule>
      <rule>
        <bugtraq>8505</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0380</cve>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 02|&quot;; depth:2; isdataat:100,relative; content:!&quot;|00|&quot;; within:100; metadata:service tftp; classtype:attempted-admin;</filter2>
        <id>2337</id>
        <msg>TFTP PUT filename overflow attempt</msg>
        <nessus>18264</nessus>
      </rule>
      <rule>
        <bugtraq>7575</bugtraq>
        <classtype>bad-unknown</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 00|&quot;; depth:2; metadata:service tftp; classtype:bad-unknown;</filter2>
        <id>2339</id>
        <msg>TFTP NULL command attempt</msg>
      </rule>
      <rule>
        <bugtraq>9675</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0838</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;CHMOD&quot;; distance:0; nocase; isdataat:200,relative; pcre:&quot;/^SITE\s+CHMOD\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2340</id>
        <msg>FTP SITE CHMOD overflow attempt</msg>
        <nessus>12037</nessus>
      </rule>
      <rule>
        <bugtraq>8668</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0133</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOR&quot;; nocase; isdataat:200,relative; pcre:&quot;/^STOR(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2343</id>
        <msg>FTP STOR overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8704</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;XCWD&quot;; nocase; isdataat:100,relative; pcre:&quot;/^XCWD(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2344</id>
        <msg>FTP XCWD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7909</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-1021</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;XMKD&quot;; nocase; isdataat:200,relative; pcre:&quot;/^XMKD(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2373</id>
        <msg>FTP XMKD overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8315</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3683</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RNTO&quot;; nocase; isdataat:200,relative; pcre:&quot;/^RNTO(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2389</id>
        <msg>FTP RNTO overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8315</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0466</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOU&quot;; nocase; isdataat:200,relative; pcre:&quot;/^STOU\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2390</id>
        <msg>FTP STOU overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8542</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0772</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;APPE&quot;; nocase; isdataat:200,relative; pcre:&quot;/^APPE(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2391</id>
        <msg>FTP APPE overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8315</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3683</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RETR&quot;; nocase; isdataat:200,relative; pcre:&quot;/^RETR(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2392</id>
        <msg>FTP RETR overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9751</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0330</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;MDTM&quot;; fast_pattern:only; pcre:&quot;/^MDTM \d+[-+]\D/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2416</id>
        <msg>FTP invalid MDTM command attempt</msg>
      </rule>
      <rule>
        <bugtraq>9800</bugtraq>
        <classtype>string-detect</classtype>
        <cve>2005-2123</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;%&quot;; fast_pattern:only; pcre:&quot;/\s+.*?%.*?%/smi&quot;; metadata:service ftp; classtype:string-detect;</filter2>
        <id>2417</id>
        <msg>FTP format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>9953</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1883</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;ALLO&quot;; nocase; isdataat:200,relative; pcre:&quot;/^ALLO(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2449</id>
        <msg>FTP ALLO overflow attempt</msg>
        <nessus>14598</nessus>
      </rule>
      <rule>
        <bugtraq>9751</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0330</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;MDTM&quot;; nocase; isdataat:100,relative; pcre:&quot;/^MDTM(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>2546</id>
        <msg>FTP MDTM overflow attempt</msg>
        <nessus>12080</nessus>
      </rule>
      <rule>
        <bugtraq>9800</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1883</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RETR&quot;; fast_pattern:only; pcre:&quot;/^RETR\s[^\n]*?%[^\n]*?%/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>2574</id>
        <msg>FTP RETR format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>14339</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RNFR&quot;; nocase; isdataat:200,relative; pcre:&quot;/^RNFR\s[^\n]{200}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>3077</id>
        <msg>FTP RNFR overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>572</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-0671</cve>
        <filter1>tcp $EXTERNAL_NET 21 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|B4| |B4|!|8B CC 83 E9 04 8B 19|3|C9|f|B9 10|&quot;; classtype:attempted-user;</filter2>
        <id>308</id>
        <msg>EXPLOIT NextFTP client overflow</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;.forward&quot;; metadata:service ftp; classtype:suspicious-filename-detect;</filter2>
        <id>334</id>
        <msg>FTP .forward</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;.rhosts&quot;; metadata:service ftp; classtype:suspicious-filename-detect;</filter2>
        <id>335</id>
        <msg>FTP .rhosts</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <cve>1999-0082</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CWD&quot;; nocase; content:&quot;~root&quot;; distance:1; nocase; pcre:&quot;/^CWD\s+~root/smi&quot;; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>336</id>
        <msg>FTP CWD ~root attempt</msg>
      </rule>
      <rule>
        <bugtraq>679</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-0789</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;CEL&quot;; nocase; isdataat:100,relative; pcre:&quot;/^CEL(?!\n)\s[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>337</id>
        <msg>FTP CEL overflow attempt</msg>
        <nessus>10009</nessus>
      </rule>
      <rule>
        <bugtraq>126</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-0017</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PORT&quot;; nocase; ftpbounce; pcre:&quot;/^PORT/smi&quot;; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>3441</id>
        <msg>FTP PORT bounce attempt</msg>
        <nessus>10081</nessus>
      </rule>
      <rule>
        <bugtraq>7825</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;REST&quot;; fast_pattern:only; pcre:&quot;/REST\s+[0-9]+\n/i&quot;; metadata:service ftp; classtype:attempted-recon;</filter2>
        <id>3460</id>
        <msg>FTP REST with numeric argument</msg>
      </rule>
      <rule>
        <bugtraq>1387</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>2000-0573</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;INDEX&quot;; distance:0; nocase; pcre:&quot;/^SITE\s+INDEX\s[^\n]*?%[^\n]*?%/smi&quot;; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>3523</id>
        <msg>FTP SITE INDEX format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>8375</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS 2100</filter1>
        <filter2>flow:established,to_server; content:&quot;UNLOCK&quot;; depth:6; pcre:&quot;/^UNLOCK\s+\S+\s+\S{100}/sm&quot;; classtype:attempted-admin;</filter2>
        <id>3526</id>
        <msg>ORACLE XDB FTP UNLOCK overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS ddd@|0A|&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>353</id>
        <msg>FTP adm scan</msg>
      </rule>
      <rule>
        <bugtraq>8375</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2100</filter1>
        <filter2>flow:to_server,established; content:&quot;pass&quot;; nocase; isdataat:100,relative; pcre:&quot;/^PASS\s+[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-user;</filter2>
        <id>3532</id>
        <msg>ORACLE ftp password buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;pass -iss@iss&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>354</id>
        <msg>FTP iss scan</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;pass wh00t&quot;; fast_pattern:only; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>355</id>
        <msg>FTP pass wh00t</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RETR&quot;; nocase; content:&quot;passwd&quot;; metadata:service ftp; classtype:suspicious-filename-detect;</filter2>
        <id>356</id>
        <msg>FTP passwd retrieval attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;pass -cklaus&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>357</id>
        <msg>FTP piss scan</msg>
        <url>www.mines.edu/fs_home/dlarue/cc/baby-doe.html</url>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;pass -saint&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>358</id>
        <msg>FTP saint scan</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;pass -satan&quot;; metadata:service ftp; classtype:suspicious-login;</filter2>
        <id>359</id>
        <msg>FTP satan scan</msg>
      </rule>
      <rule>
        <bugtraq>2052</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>2001-0054</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;.%20.&quot;; fast_pattern:only; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>360</id>
        <msg>FTP serv-u directory transversal</msg>
        <nessus>10565</nessus>
      </rule>
      <rule>
        <bugtraq>2241</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>1999-0955</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SITE&quot;; nocase; content:&quot;EXEC&quot;; distance:0; nocase; pcre:&quot;/^SITE\s+EXEC/smi&quot;; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>361</id>
        <msg>FTP SITE EXEC attempt</msg>
      </rule>
      <rule>
        <bugtraq>2240</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>1999-0997</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot; --use-compress-program &quot;; fast_pattern:only; metadata:service ftp; classtype:bad-unknown;</filter2>
        <id>362</id>
        <msg>FTP tar parameters</msg>
      </rule>
      <rule>
        <bugtraq>8375</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2100</filter1>
        <filter2>flow:to_server,established; content:&quot;TEST&quot;; nocase; isdataat:100,relative; pcre:&quot;/^TEST\s+[^\n]{100}/smi&quot;; metadata:service ftp; classtype:misc-attack;</filter2>
        <id>3630</id>
        <msg>ORACLE ftp TEST command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>8375</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2100</filter1>
        <filter2>flow:to_server,established; content:&quot;user&quot;; nocase; isdataat:100,relative; pcre:&quot;/^USER\s+[^\n]{100}/smi&quot;; metadata:service ftp; classtype:attempted-user;</filter2>
        <id>3631</id>
        <msg>ORACLE ftp user name buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13821</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1812</cve>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|&quot;; content:&quot;|00|&quot;; distance:1; isdataat:100,relative; content:!&quot;|00|&quot;; within:100; metadata:service tftp; classtype:attempted-admin;</filter2>
        <id>3817</id>
        <msg>TFTP GET transfer mode overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>21301</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6183</cve>
        <filter1>udp any any -&gt; any 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 02|&quot;; content:&quot;|00|&quot;; distance:1; isdataat:100,relative; content:!&quot;|00|&quot;; within:100; metadata:service tftp; classtype:attempted-admin;</filter2>
        <id>3818</id>
        <msg>TFTP PUT transfer mode overflow attempt</msg>
      </rule>
      <rule>
        <classtype>unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:from_client,established; content:&quot;PASS&quot;; fast_pattern:only; pcre:&quot;/^PASS\s*\n/smi&quot;; classtype:unknown;</filter2>
        <id>489</id>
        <msg>FTP no password</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $HOME_NET 21 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;530 &quot;; fast_pattern:only; pcre:&quot;/^530\s+(Login|User)/smi&quot;; classtype:bad-unknown;</filter2>
        <id>491</id>
        <msg>FTP Bad login</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <cve>1999-0183</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 02|&quot;; depth:2; metadata:service tftp; classtype:bad-unknown;</filter2>
        <id>518</id>
        <msg>TFTP Put</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <cve>2002-1209</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;..&quot;; offset:2; metadata:service tftp; classtype:bad-unknown;</filter2>
        <id>519</id>
        <msg>TFTP parent directory</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <cve>1999-0183</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 01|/&quot;; depth:3; metadata:service tftp; classtype:bad-unknown;</filter2>
        <id>520</id>
        <msg>TFTP root directory</msg>
      </rule>
      <rule>
        <bugtraq>19617</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4318</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;SIZE&quot;; nocase; isdataat:524,relative; pcre:&quot;/^SIZE(?!\n)\s+[\x2F\x5C][^\x2F\x3A\x5C\n][^\n]{526}/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>8415</id>
        <msg>FTP SIZE overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2972</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;HELP&quot;; nocase; isdataat:200,relative; pcre:&quot;/^HELP(?!\n)\s[^\n]{200}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>8479</id>
        <msg>FTP HELP overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18711</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2226</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PORT &quot;; nocase; isdataat:400,relative; pcre:&quot;/^PORT\x20[^\n]{400}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>8480</id>
        <msg>FTP PORT overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2717</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2001-0334</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;NLST&quot;; fast_pattern:only; pcre:&quot;/^NLST\s+[^\n]*\x2a{10}/smi&quot;; metadata:service ftp; classtype:attempted-dos;</filter2>
        <id>8481</id>
        <msg>FTP Microsoft NLST * dos attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-026.mspx</url>
      </rule>
      <rule>
        <bugtraq>14935</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3081</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:established,to_server; content:&quot;SITE&quot;; fast_pattern:only; pcre:&quot;/^SITE\s*(\w+\s*)+\x7c/smi&quot;; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>8707</id>
        <msg>FTP WZD-FTPD SITE arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>21301</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00|&quot;; depth:1; pcre:&quot;/^(\x01|\x02)[^\x00]+\x00[^\x00]{473}/Rs&quot;; metadata:service tftp; classtype:attempted-admin;</filter2>
        <id>9621</id>
        <msg>TFTP 3COM server transport mode buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <cve>2006-5584</cve>
        <filter1>udp any any -&gt; $HOME_NET 69</filter1>
        <filter2>flow:to_server; content:&quot;|00 02|&quot;; depth:2; content:&quot;images&quot;; distance:0; nocase; content:&quot;windows&quot;; distance:0; nocase; content:&quot;|00|&quot;; distance:0; metadata:service tftp; classtype:policy-violation;</filter2>
        <id>9638</id>
        <msg>TFTP PUT Microsoft RIS filename overwrite attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-077.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;PASV&quot;; nocase; isdataat:493,relative; pcre:&quot;/^PASV(?!\n)\s[^\n]{493}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>9792</id>
        <msg>FTP PASV overflow attempt</msg>
        <url>www.milw0rm.com/exploits/2952</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>243</groupid>
    <groupname>Server / Misc / SSH</groupname>
    <warnings>
      <rule>
        <bugtraq>2347</bugtraq>
        <classtype>shellcode-detect</classtype>
        <cve>2001-0572</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22</filter1>
        <filter2>flow:to_server,established; content:&quot;|90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90|&quot;; fast_pattern:only; classtype:shellcode-detect;</filter2>
        <id>1326</id>
        <msg>EXPLOIT ssh CRC32 overflow NOOP</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;MAININFO|7C|password|7C|ENU|7C|My&quot;; depth:24; nocase; content:&quot;server&quot;; distance:0; nocase; content:&quot;|3A|D|7C|&quot;; distance:0; nocase; pcre:&quot;/^MAININFO\x7Cpassword\x7CENU\x7CMy\s+server\s+\x3AD\x7C/smi&quot;; classtype:trojan-activity;</filter2>
        <id>13814</id>
        <msg>BACKDOOR passhax runtime detection - initial connection</msg>
        <url>www.spywareguide.com/spydet_30090_passhax.html</url>
      </rule>
      <rule>
        <classtype>network-scan</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22</filter1>
        <filter2>flow:to_server,established; content:&quot;Version_Mapper&quot;; fast_pattern:only; classtype:network-scan;</filter2>
        <id>1638</id>
        <msg>SCAN SSH Version map attempt</msg>
      </rule>
      <rule>
        <bugtraq>20216</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4924</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 03|&quot;; depth:2; byte_test:4,&gt;,200000,0,relative; classtype:attempted-admin;</filter2>
        <id>17317</id>
        <msg>SPECIFIC-THREATS OpenSSH sshd Identical Blocks DOS attempt</msg>
      </rule>
      <rule>
        <bugtraq>5093</bugtraq>
        <classtype>successful-admin</classtype>
        <cve>2002-0640</cve>
        <filter1>tcp $HOME_NET 22 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;*GOBBLE*&quot;; metadata:service ssh; classtype:successful-admin;</filter2>
        <id>1810</id>
        <msg>SPECIFIC-THREATS successful gobbles ssh exploit GOBBLE</msg>
      </rule>
      <rule>
        <bugtraq>5093</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0640</cve>
        <filter1>tcp $HOME_NET 22 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;uname&quot;; metadata:service ssh; classtype:misc-attack;</filter2>
        <id>1811</id>
        <msg>SPECIFIC-THREATS successful gobbles ssh exploit uname</msg>
        <nessus>11031</nessus>
      </rule>
      <rule>
        <bugtraq>5093</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0639</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22</filter1>
        <filter2>flow:to_server,established; content:&quot;GOBBLES&quot;; classtype:misc-attack;</filter2>
        <id>1812</id>
        <msg>EXPLOIT gobbles SSH exploit attempt</msg>
        <nessus>11031</nessus>
      </rule>
      <rule>
        <bugtraq>5287</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-1059</cve>
        <filter1>tcp $EXTERNAL_NET 22 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;SSH-&quot;; nocase; isdataat:200,relative; pcre:&quot;/^SSH-\s?[^\n]{200}/ism&quot;; classtype:misc-attack;</filter2>
        <id>1838</id>
        <msg>EXPLOIT SSH server banner overflow</msg>
        <nessus>15822</nessus>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxrReceiveFileFromServer~~8~~&quot;; nocase; pcre:&quot;/^((\.\.\/|\.\.\\).*|(\.(exe|dll)))~~/Ri&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12667</id>
        <msg>EXPLOIT CA BrightStor ARCServer malicious fileupload attempt</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxsGetBackupLog~~&quot;; content:&quot;~~&quot;; distance:0; isdataat:260,relative; content:!&quot;~~&quot;; within:260; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12784</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops rsxGetBackupLog second argument overflow</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxsGetBackupComplete&quot;; content:&quot;~~&quot;; isdataat:256,relative; content:!&quot;~~&quot;; within:256; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12785</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops rsxGetBackupComplete overflow attemp</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxsSetDataGrowthScheduleAndFilter&quot;; content:&quot;~~&quot;; isdataat:256,relative; content:!&quot;~~&quot;; within:256; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12786</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops rxsSetDataGrowthScheduleAndFilter overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxsSetDefaultConfigName~~&quot;; isdataat:976,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12787</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops rxsSetDefaultConfigName overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxsSetDefaultConfigName~~&quot;; isdataat:976,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12788</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops rxsSetDefaultConfigName overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15353</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3116</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13701</filter1>
        <filter2>flow:established,to_server; dsize:4; byte_test:4,&gt;,84,0; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12904</id>
        <msg>EXPLOIT Veritas NetBackup vmd shared library buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25778</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0638</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 3207</filter1>
        <filter2>flow:to_server; content:&quot;|FE FE|&quot;; depth:2; byte_test:2,&gt;,1024,2; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13552</id>
        <msg>EXPLOIT Symantec VERITAS Storage Foundation Suite buffer overflow attempt</msg>
        <url>www.symantec.com/avcenter/security/Content/2008.02.20a.html</url>
      </rule>
      <rule>
        <bugtraq>28616</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1328</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; isdataat:90; content:&quot;  &quot;; depth:2; byte_test:10, &gt;, 80, 0, string, dec; pcre:&quot;/^.{10}[0-9a-fA-f]{80}/&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13800</id>
        <msg>EXPLOIT ARCServe LGServer service data overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 09 01|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; depth:4; offset:28; byte_test:4,&gt;,1000,32; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13846</id>
        <msg>SPECIFIC-THREATS Veritas Backup Agent password overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2279</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4888</filter1>
        <filter2>flow:to_server,established; content:&quot;NTLMSSP|00 03 00 00 00|&quot;; nocase; content:&quot;|00 00|&quot;; within:2; distance:24; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>14741</id>
        <msg>EXPLOIT Symantec Veritas Foundation Service NULL service authentication attempt</msg>
      </rule>
      <rule>
        <bugtraq>30596</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3703</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4888</filter1>
        <filter2>flow:to_server,established; content:&quot;NTLMSSP|00 03 00 00 00|&quot;; content:&quot;|00 00|&quot;; within:2; distance:34; metadata:policy balanced-ips drop, policy security-ips drop, service ident; classtype:attempted-user;</filter2>
        <id>14768</id>
        <msg>MISC Symantec Veritas Storage Scheduler Service NULL Session auth bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>30472</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3175</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:established,to_server; content:&quot;00000000&quot;; depth:8; content:&quot;AAAAAAAAAAAAAA&quot;; within:14; distance:4; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>14773</id>
        <msg>SPECIFIC-THREATS CA ARCserve LGServer handshake buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-2715</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13722</filter1>
        <filter2>flow:established,to_server; content:&quot;%n&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15931</id>
        <msg>MISC Veritas NetBackup java user interface service format string attack attempt</msg>
      </rule>
      <rule>
        <bugtraq>28927</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-1979</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:established,to_server; content:&quot;h|00 00 00|&quot;; depth:4; content:&quot;|FF FF FF|s&quot;; depth:4; offset:58; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16071</id>
        <msg>EXPLOIT CA ARCServe Backup Discovery Service denial of service attempt</msg>
        <url>www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36440</url>
      </rule>
      <rule>
        <bugtraq>31684</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2008-4399</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6504</filter1>
        <filter2>flow:established,to_server; dce_iface:506b1890-14c8-11d1-bbc3-00805fa6962e; dce_opnum:548; content:&quot;|05|&quot;; byte_test:1,&amp;,16,3,relative; content:&quot;|00|&quot;; within:1; distance:1; content:&quot;|24 02|&quot;; within:2; distance:19; metadata:policy balanced-ips drop, policy security-ips drop, service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>17520</id>
        <msg>EXPLOIT CA ARCserve Backup DB Engine Denial of Service</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-2715</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13722</filter1>
        <filter2>flow:established,to_server; content:&quot;%hn&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17706</id>
        <msg>MISC Veritas NetBackup java user interface service format string attack attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13724</filter1>
        <filter2>flow:to_server,established; content:&quot;6|00|bpspsserver|00|&quot;; flowbits:set,vnetd.bpspsserver.connection; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>6010</id>
        <msg>EXPLOIT VERITAS NetBackup vnetd connection attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13701</filter1>
        <filter2>flow:to_server,established; byte_test:1,&gt;,3,10,dec,string; byte_test:1,&lt;,11,10,dec,string; flowbits:set,veritas.vmd.connect; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>6404</id>
        <msg>EXPLOIT Veritas NetBackup Volume Manager connection attempt</msg>
      </rule>
    </attacks>
    <groupid>244</groupid>
    <groupname>Server / Misc / Backup</groupname>
    <warnings>
      <rule>
        <bugtraq>22365</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-0816</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 08|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; metadata:service sunrpc; classtype:attempted-dos;</filter2>
        <id>10132</id>
        <msg>RPC portmap BrightStor ARCserve denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>22365</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-0816</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 08|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; metadata:service sunrpc; classtype:attempted-dos;</filter2>
        <id>10133</id>
        <msg>RPC portmap BrightStor ARCserve denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 06 09|~&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10482</id>
        <msg>RPC portmap CA BrightStor ARCserve tcp request</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 06 09|~&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10483</id>
        <msg>RPC portmap CA BrightStor ARCserve udp request</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 06 09|~&quot;; depth:4; offset:16; content:&quot;|00 00 00 BF|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10484</id>
        <msg>RPC portmap CA BrightStor ARCserve tcp procedure 191 attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server; content:&quot;|00 06 09|~&quot;; depth:4; offset:12; content:&quot;|00 00 00 BF|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>10485</id>
        <msg>RPC portmap CA BrightStor ARCserve udp procedure 191 attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 06 09|~&quot;; depth:4; offset:16; content:&quot;|00 00 00 E8|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13716</id>
        <msg>RPC portmap CA BrightStor ARCserve tcp procedure 232 attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|00 06 09|~&quot;; depth:4; offset:12; content:&quot;|00 00 00 E8|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13717</id>
        <msg>RPC portmap CA BrightStor ARCserve udp procedure 232 attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 06 09|~&quot;; depth:4; offset:16; content:&quot;|00 00 00 EA|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13805</id>
        <msg>RPC portmap CA BrightStor ARCserve tcp procedure 234 attempt</msg>
      </rule>
      <rule>
        <bugtraq>23209</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-1785</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server; content:&quot;|00 06 09|~&quot;; depth:4; offset:12; content:&quot;|00 00 00 EA|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>13806</id>
        <msg>RPC portmap CA BrightStor ARCserve udp procedure 234 attempt</msg>
      </rule>
      <rule>
        <bugtraq>30472</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3175</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; byte_test:10,&gt;,18,0,dec,string; byte_jump:10,0,dec,string,post_offset -1; content:&quot;0&quot;; within:1; pcre:&quot;/^[0-9]{10}[0-9A-F]+$/i&quot;; classtype:attempted-admin;</filter2>
        <id>17045</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30472</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3175</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; byte_test:10,&gt;,86,0,dec,string; pcre:&quot;/^[0-9]{10}[0-9A-F]+$/i&quot;; classtype:attempted-admin;</filter2>
        <id>17046</id>
        <msg>EXPLOIT CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2772</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1339</filter1>
        <filter2>flow:to_server, established; content:&quot;|00 00 00 00 00 00 00 02 00 06 09 82 00 00 00 01 00 00 00 01|&quot;; content:&quot;|FF FF FF FF|&quot;; distance:8; classtype:attempted-admin;</filter2>
        <id>17643</id>
        <msg>EXPLOIT CA BrightStor ARCServe logger servie null-pointer dereference attempt</msg>
      </rule>
      <rule>
        <bugtraq>15353</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-3116</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13701</filter1>
        <filter2>flow:established,to_server; content:&quot;|64 00 00 0F 41 41 41 41|&quot;; depth:8; classtype:attempted-admin;</filter2>
        <id>17710</id>
        <msg>EXPLOIT Veritas NetBackup vmd shared library buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11974</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1172</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6101</filter1>
        <filter2>flow:established,to_server; content:&quot;|02 00|&quot;; depth:2; content:&quot;|00|&quot;; within:1; distance:1; isdataat:72; content:!&quot;|00|&quot;; depth:66; offset:6; classtype:attempted-admin;</filter2>
        <id>3084</id>
        <msg>EXPLOIT Veritas backup overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12594</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2005-0491</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 617</filter1>
        <filter2>flow:established,to_server; content:&quot;ARKADMIN_GET_&quot;; pcre:&quot;/^(CLIENT|MACHINE)_INFO/Ri&quot;; classtype:attempted-recon;</filter2>
        <id>3453</id>
        <msg>MISC Arkeia client backup system info probe</msg>
      </rule>
      <rule>
        <bugtraq>12594</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2005-0491</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 617</filter1>
        <filter2>flow:established,to_server; content:&quot;ARKFS|00|root|00|root&quot;; fast_pattern:only; classtype:attempted-recon;</filter2>
        <id>3454</id>
        <msg>MISC Arkeia client backup generic info probe</msg>
      </rule>
      <rule>
        <bugtraq>12594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0491</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 617</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|M&quot;; depth:2; byte_test:2,&gt;,23,6; classtype:attempted-user;</filter2>
        <id>3457</id>
        <msg>EXPLOIT Arkeia backup client type 77 overflow attempt</msg>
        <nessus>17158</nessus>
      </rule>
      <rule>
        <bugtraq>12594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0491</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 617</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|T&quot;; depth:2; byte_test:2,&gt;,255,6; isdataat:263; content:!&quot;|00|&quot;; depth:255; offset:8; classtype:attempted-user;</filter2>
        <id>3458</id>
        <msg>EXPLOIT Arkeia backup client type 84 overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12491</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0260</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; dsize:&gt;966; classtype:attempted-admin;</filter2>
        <id>3472</id>
        <msg>EXPLOIT ARCserve discovery service overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|98|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3474</id>
        <msg>EXPLOIT ARCserve backup TCP slot info msg client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|98|&quot;; depth:1; isdataat:40; content:!&quot;|00|&quot;; depth:16; offset:24; classtype:attempted-admin;</filter2>
        <id>3475</id>
        <msg>EXPLOIT ARCserve backup TCP slot info msg client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9B|&quot;; depth:1; isdataat:40; content:!&quot;|00|&quot;; depth:16; offset:24; classtype:attempted-admin;</filter2>
        <id>3476</id>
        <msg>EXPLOIT ARCserve backup TCP product info msg 0x9b client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9B|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3477</id>
        <msg>EXPLOIT ARCserve backup TCP product info msg 0x9b client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9C|&quot;; depth:1; isdataat:40; content:!&quot;|00|&quot;; depth:16; offset:24; classtype:attempted-admin;</filter2>
        <id>3478</id>
        <msg>EXPLOIT ARCserve backup TCP product info msg 0x9c client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 41523</filter1>
        <filter2>flow:to_server,established; content:&quot;|9C|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3479</id>
        <msg>EXPLOIT ARCserve backup TCP product info msg 0x9c client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|98|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3480</id>
        <msg>EXPLOIT ARCserve backup UDP slot info msg client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|98|&quot;; depth:1; isdataat:41; content:!&quot;|00|&quot;; depth:16; offset:25; classtype:attempted-admin;</filter2>
        <id>3481</id>
        <msg>EXPLOIT ARCserve backup UDP slot info msg client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9B|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3482</id>
        <msg>EXPLOIT ARCserve backup UDP product info msg 0x9b client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9B|&quot;; depth:1; isdataat:41; content:!&quot;|00|&quot;; depth:16; offset:25; classtype:attempted-admin;</filter2>
        <id>3483</id>
        <msg>EXPLOIT ARCserve backup UDP product info msg 0x9b client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9C|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3484</id>
        <msg>EXPLOIT ARCserve backup UDP product info msg 0x9c client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|9C|&quot;; depth:1; isdataat:41; content:!&quot;|00|&quot;; depth:16; offset:25; classtype:attempted-admin;</filter2>
        <id>3485</id>
        <msg>EXPLOIT ARCserve backup UDP product info msg 0x9c client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|99|&quot;; depth:1; isdataat:17; content:!&quot;|00|&quot;; depth:16; offset:1; classtype:attempted-admin;</filter2>
        <id>3530</id>
        <msg>EXPLOIT ARCserve backup UDP msg 0x99 client name overflow</msg>
      </rule>
      <rule>
        <bugtraq>12536</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 41524</filter1>
        <filter2>flow:to_server; content:&quot;|99|&quot;; depth:1; isdataat:41; content:!&quot;|00|&quot;; depth:16; offset:25; classtype:attempted-admin;</filter2>
        <id>3531</id>
        <msg>EXPLOIT ARCserve backup UDP msg 0x99 client domain overflow</msg>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|E8 03|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6,little; byte_test:2,&lt;,1705,6,little; classtype:attempted-admin;</filter2>
        <id>3658</id>
        <msg>EXPLOIT ARCserve universal backup agent option 1000 little endian buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|03 E8|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6; byte_test:2,&lt;,1705,6; classtype:attempted-admin;</filter2>
        <id>3659</id>
        <msg>EXPLOIT ARCserve universal backup agent option 1000 buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6,little; byte_test:2,&lt;,1705,6,little; classtype:attempted-admin;</filter2>
        <id>3660</id>
        <msg>EXPLOIT ARCserve universal backup agent option 00 little endian buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6; byte_test:2,&lt;,1705,6; classtype:attempted-admin;</filter2>
        <id>3661</id>
        <msg>EXPLOIT ARCserve universal backup agent option 00 buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|03 00|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6,little; byte_test:2,&lt;,1705,6,little; classtype:attempted-admin;</filter2>
        <id>3662</id>
        <msg>EXPLOIT ARCserve universal backup agent option 03 little endian buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <bugtraq>13102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 03|&quot;; depth:2; offset:256; isdataat:430,relative; byte_test:2,&gt;,679,6; byte_test:2,&lt;,1705,6; classtype:attempted-admin;</filter2>
        <id>3663</id>
        <msg>EXPLOIT ARCserve universal backup agent option 03 buffer overflow attempt</msg>
        <nessus>18041</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-0773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 09 01|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; depth:4; offset:28; byte_jump:4,32; byte_test:4,&gt;,1023,0,relative; classtype:attempted-admin;</filter2>
        <id>3695</id>
        <msg>EXPLOIT Veritas Backup Agent password overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14201</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0772</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:12; byte_test:4,&gt;,0,24; classtype:attempted-dos;</filter2>
        <id>3696</id>
        <msg>EXPLOIT Veritas Backup Agent DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>14020</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-0771</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6106</filter1>
        <filter2>flow:established,to_server; dce_iface:93841fd0-16ce-11ce-850d-02608c44967b; content:&quot;|05 00|&quot;; metadata:service dcerpc; classtype:protocol-command-decode;</filter2>
        <id>3697</id>
        <msg>NETBIOS DCERPC NCACN-IP-TCP veritas bind attempt</msg>
        <url>www.idefense.com/application/poi/display?id=269&amp;type=vulnerabilities</url>
      </rule>
      <rule>
        <bugtraq>14551</bugtraq>
        <classtype>suspicious-login</classtype>
        <cve>2005-2611</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 09 01|&quot;; depth:8; offset:12; content:&quot;|00 00 00 02|&quot;; depth:4; offset:28; content:&quot;root&quot;; depth:4; offset:36; nocase; content:&quot;|B4 B8 0F|&amp; |5C|B4|03 FC AE EE 8F 91|=o&quot;; distance:0; classtype:suspicious-login;</filter2>
        <id>4126</id>
        <msg>EXPLOIT Veritas Backup Exec root connection attempt using default password hash</msg>
      </rule>
      <rule>
        <bugtraq>17264</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0991</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13724</filter1>
        <filter2>flow:to_server,established; flowbits:isset,vnetd.bpspsserver.connection; byte_test:4,&gt;,1024,0; isdataat:1024; flowbits:unset,vnetd.bpspsserver.connection; classtype:attempted-admin;</filter2>
        <id>6011</id>
        <msg>EXPLOIT VERITAS NetBackup vnetd buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17264</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0989</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13701</filter1>
        <filter2>flow:to_server,established; flowbits:isset,veritas.vmd.connect; pcre:&quot;/(0x[0-9a-f]+|0[0-8]+|[1-9]\d*)\s+\S{157}|(0x[0-9a-f]+|0[0-8]+|[1-9]\d*)\s+\S+\s+\S{125}|(0x[0-9a-f]+|0[0-8]+|[1-9]\d*)\s+\S+\s+\S+\s+\S{1025}|(0x[ 0-9a-f]+|0[0-8]+|[1-9]\d*)\s+\S+\s+\S+\s+\S+\s+\S{117}|(0x[0-9a-f]+|0[0-8]+|[1-9]\d*)\s+\S+\s+\S+\s+\S+\s+\S+\s+\S{37}/i&quot;; classtype:attempted-admin;</filter2>
        <id>6405</id>
        <msg>EXPLOIT Veritas NetBackup Volume Manager overflow attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>245</groupid>
    <groupname>Server / Misc / TFTP</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>37343</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4181</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2F|OvCgi|2F|jovgraph.exe&quot;; nocase; http_uri; content:&quot;OVwSelection&quot;; nocase; http_uri; pcre:&quot;/(arg=[^\x26]*?OVwSelection[^\x26]*?\x26.*?sel=[^\s\x26]{1023}|sel=[^\x26]{1023,}\x26.*?arg=[^\s\x26]*?OVwSelection)/sU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16712</id>
        <msg>WEB-MISC HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - GET</msg>
      </rule>
      <rule>
        <bugtraq>37343</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4181</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2F|OvCgi|2F|jovgraph.exe&quot;; nocase; http_uri; content:&quot;OVwSelection&quot;; nocase; http_client_body; pcre:&quot;/(arg=[^\x26]*?OVwSelection[^\x26]*?\x26.*?sel=[^\s\x26]{1023}|sel=[^\x26]{1023,}\x26.*?arg=[^\s\x26]*?OVwSelection)/sP&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16713</id>
        <msg>WEB-MISC HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - POST</msg>
      </rule>
      <rule>
        <bugtraq>2417</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 87 99|&quot;; depth:4; offset:16; content:&quot;|00 00 01 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,20,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>569</id>
        <msg>RPC snmpXdmi overflow attempt TCP</msg>
        <nessus>10659</nessus>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
    </attacks>
    <groupid>246</groupid>
    <groupname>Server / Misc / SNMP</groupname>
    <warnings>
      <rule>
        <bugtraq>2417</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0236</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:12; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 99|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>1279</id>
        <msg>RPC portmap snmpXdmi request UDP</msg>
        <nessus>10659</nessus>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
      <rule>
        <bugtraq>18081</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-1673</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161:162</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13773;</filter2>
        <id>13773</id>
        <msg>DOS linux kernel snmp nat netfilter memory corruption attempt</msg>
        <url>kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.5</url>
      </rule>
      <rule>
        <bugtraq>2417</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0236</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 87 99|&quot;; depth:4; offset:12; content:&quot;|00 00 01 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,1024,20,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>2045</id>
        <msg>RPC snmpXdmi overflow attempt UDP</msg>
        <nessus>10659</nessus>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
      <rule>
        <bugtraq>2417</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 111</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A0|&quot;; depth:4; offset:16; content:&quot;|00 00 00 03|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:&quot;|00 01 87 99|&quot;; within:4; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>593</id>
        <msg>RPC portmap snmpXdmi request TCP</msg>
        <nessus>10659</nessus>
        <url>www.cert.org/advisories/CA-2001-05.html</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>24655</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2442</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 04 93 E1 00 00 00 00|&quot;; within:8; distance:16; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>13223</id>
        <msg>RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt</url>
      </rule>
      <rule>
        <bugtraq>24655</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2442</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 04 93 E1 00 00 00 00|&quot;; within:8; distance:16; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-admin;</filter2>
        <id>13268</id>
        <msg>RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt</url>
      </rule>
      <rule>
        <bugtraq>23285</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0957</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|90|D|FA A0 B1|^C|07|m'|1C|m|08 02 D0 C7 C0|q|EE|q|E3|R|B3 1C|}K|DE D2 C1 F8 5C|{&quot;; fast_pattern:only; metadata:policy security-ips drop, service ldap; classtype:attempted-user;</filter2>
        <id>16207</id>
        <msg>WEB-MISC MIT Kerberos V% KAdminD klog_vsyslog server overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36263</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-3111</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET [1645,1812]</filter1>
        <filter2>flow:to_server; content:&quot;|01|&quot;; depth:1; content:&quot;E|02|&quot;; within:2; distance:19; metadata:policy security-ips drop, service radius; classtype:attempted-dos;</filter2>
        <id>16209</id>
        <msg>DOS FreeRADIUS RADIUS server rad_decode remote denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1174</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>flow:established, to_server; content:&quot;|30 09 A0 03 02 01 01 A1 02 30 00 A2 0D 1B 0B 65 78 61 6D|&quot;; metadata:policy security-ips drop, service kerberos; classtype:attempted-admin;</filter2>
        <id>17273</id>
        <msg>SPECIFIC-THREATS MIT Kerberos V5 KDC krb5_unparse_name overflow attempt</msg>
        <url>secunia.com/advisories/16041/</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1175</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>flow:to_server; content:&quot;|30 09 A0 03 02 01 01 A1 02 30 00 A2 0D 1B 0B 65 78 61 6D|&quot;; metadata:policy security-ips drop, service kerberos; classtype:attempted-admin;</filter2>
        <id>17274</id>
        <msg>SPECIFIC-THREATS MIT Kerberos V5 KDC krb5_unparse_name overflow attempt</msg>
        <url>secunia.com/advisories/16041/</url>
      </rule>
      <rule>
        <bugtraq>34409</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0846</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17741, service kerberos, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17741</id>
        <msg>EXPLOIT MIT Kerberos ASN.1 asn1_decode_generaltime uninitialized pointer reference attempt</msg>
      </rule>
    </attacks>
    <groupid>247</groupid>
    <groupname>Server / Misc / Authentication</groupname>
    <warnings>
      <rule>
        <bugtraq>24657</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2443</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; byte_test:4,&gt;,0,20,relative; content:&quot;|00 00 00 01|&quot;; within:4; distance:16; byte_test:4,&gt;,2147483647,8,relative; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>12046</id>
        <msg>RPC MIT Kerberos kadmind RPC Library unix authentication buffer overflow attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt</url>
      </rule>
      <rule>
        <bugtraq>24655</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2442</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 04 93 E1 00 00 00 00|&quot;; within:8; distance:16; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>12075</id>
        <msg>RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt</msg>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt</url>
      </rule>
      <rule>
        <bugtraq>25534</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3999</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 00 00 06|&quot;; within:4; distance:16; byte_test:4,&gt;,128,0,relative; metadata:service sunrpc; classtype:attempted-admin;</filter2>
        <id>12424</id>
        <msg>RPC MIT Kerberos kadmind rpc RPCSEC_GSS buffer overflow attempt</msg>
        <url>web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt</url>
      </rule>
      <rule>
        <bugtraq>24657</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2007-2443</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 749</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; content:&quot;|00 00 00 01|&quot;; within:4; distance:16; byte_test:4,&gt;,2147483647,8,relative,big; classtype:rpc-portmap-decode;</filter2>
        <id>12708</id>
        <msg>RPC MIT Kerberos kadmind auth buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-0035</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16394, service kerberos;</filter2>
        <id>16394</id>
        <msg>DOS Active Directory Kerberos referral TGT renewal DoS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>14239</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1689</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 543</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;KRB5_SENDAUTH_&quot;; depth:14; offset:5; fast_pattern; content:!&quot;V1.0&quot;; within:4; classtype:attempted-admin;</filter2>
        <id>17243</id>
        <msg>EXPLOIT MIT Kerberos V5 krb5_recvauth double free attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2003-0072</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>flow:to_server; content:&quot;j&quot;; depth:1; content:&quot;|01 A1|&quot;; asn1:oversize_length 1024,relative_offset -1; classtype:attempted-admin;</filter2>
        <id>2578</id>
        <msg>EXPLOIT kerberos principal name overflow UDP</msg>
        <nessus>11512</nessus>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2003-0072</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 88</filter1>
        <filter2>flow:to_server,established; content:&quot;j&quot;; depth:1; offset:4; content:&quot;|01 A1|&quot;; asn1:oversize_length 1024,relative_offset -1; classtype:attempted-admin;</filter2>
        <id>2579</id>
        <msg>EXPLOIT kerberos principal name overflow TCP</msg>
        <nessus>11512</nessus>
        <url>web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</url>
      </rule>
      <rule>
        <bugtraq>12759</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0699</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 699</filter1>
        <filter2>flow:to_server; content:&quot;|01|&quot;; depth:1; content:&quot;|01 01 1F|&quot;; depth:3; offset:32; byte_test:1,&gt;,30,1,relative; isdataat:29,relative; pcre:&quot;/^\x01.{23}(\x25|\x26)/smi&quot;; classtype:attempted-admin;</filter2>
        <id>3538</id>
        <msg>EXPLOIT RADIUS registration MSID overflow attempt</msg>
        <nessus>19120</nessus>
      </rule>
      <rule>
        <bugtraq>12759</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0699</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 699</filter1>
        <filter2>flow:to_server; content:&quot;|01 01 1F|&quot;; depth:3; offset:28; byte_test:1,&gt;,30,1,relative; isdataat:29,relative; pcre:&quot;/^(\x03|[\x14-\x17]).{19}(\x25|\x26)/smi&quot;; classtype:attempted-admin;</filter2>
        <id>3539</id>
        <msg>EXPLOIT RADIUS MSID overflow attempt</msg>
        <nessus>19120</nessus>
      </rule>
      <rule>
        <bugtraq>12759</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0699</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 699</filter1>
        <filter2>flow:to_server; content:&quot;|01|&quot;; depth:1; content:&quot;|01 01 1A|&quot;; depth:3; offset:32; content:&quot;|00 00 15 9F|&quot;; depth:4; offset:36; byte_test:1,&gt;,30,1,relative; isdataat:29,relative; pcre:&quot;/^\x01.{23}(\x25|\x26).{15}(\x0A|\x34)/smi&quot;; classtype:attempted-admin;</filter2>
        <id>3540</id>
        <msg>EXPLOIT RADIUS registration vendor ATTR_TYPE_STR overflow attempt</msg>
        <nessus>19120</nessus>
      </rule>
      <rule>
        <bugtraq>12759</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0699</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 699</filter1>
        <filter2>flow:to_server; content:&quot;|01 01 1A|&quot;; depth:3; offset:28; content:&quot;|00 00 15 9F|&quot;; depth:4; offset:32; byte_test:1,&gt;,30,1,relative; isdataat:29,relative; pcre:&quot;/^(\x03|[\x14-\x17]).{19}(\x25|\x26).{15}(\x0A|\x34)/smi&quot;; classtype:attempted-admin;</filter2>
        <id>3541</id>
        <msg>EXPLOIT RADIUS ATTR_TYPE_STR overflow attempt</msg>
        <nessus>19120</nessus>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2004-0396</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;Event&quot;; nocase; content:&quot;ac1db1tch3z/blackhat4life&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13616</id>
        <msg>SPECIFIC-THREATS CVS Argument overflow</msg>
      </rule>
    </attacks>
    <groupid>248</groupid>
    <groupname>Server / Misc / CVS</groupname>
    <warnings>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2004-0396</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;Argument&quot;; nocase; isdataat:1000,relative; content:!&quot;|0A|&quot;; within:1000; classtype:attempted-admin;</filter2>
        <id>13614</id>
        <msg>EXPLOIT CVS Argument overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2004-0396</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;Event&quot;; nocase; isdataat:1000,relative; content:!&quot;|0A|&quot;; within:1000; classtype:attempted-admin;</filter2>
        <id>13615</id>
        <msg>EXPLOIT CVS Argument overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CVS/Entries&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1551</id>
        <msg>WEB-MISC /CVS/Entries access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-0670</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cvsweb/version&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1552</id>
        <msg>WEB-MISC cvsweb version access</msg>
        <nessus>10465</nessus>
      </rule>
      <rule>
        <bugtraq>10499</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0416</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [514,1999,2401]</filter1>
        <filter2>flow:to_server,established; content:&quot;Argumentx&quot;; fast_pattern:only; pcre:!&quot;/^Argument[^x\x0a]+\x0aArgumentx/mi&quot;; classtype:attempted-admin;</filter2>
        <id>15971</id>
        <msg>EXPLOIT CVS Argumentx command double free attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E Fatal error, aborting.&quot;; fast_pattern:only; content:&quot;|3A| no such user&quot;; classtype:misc-attack;</filter2>
        <id>2008</id>
        <msg>MISC CVS invalid user authentication response</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;error &quot;; content:&quot;|3A| no such repository&quot;; content:&quot;I HATE YOU&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>2009</id>
        <msg>MISC CVS invalid repository response</msg>
      </rule>
      <rule>
        <bugtraq>6650</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0015</cve>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;free|28 29 3A| warning|3A| chunk is already free&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>2010</id>
        <msg>MISC CVS double free exploit attempt response</msg>
        <nessus>11385</nessus>
      </rule>
      <rule>
        <bugtraq>6650</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0015</cve>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E protocol error|3A| invalid directory syntax in&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>2011</id>
        <msg>MISC CVS invalid directory response</msg>
        <nessus>11385</nessus>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E protocol error|3A| Root request missing&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>2012</id>
        <msg>MISC CVS missing cvsroot response</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;cvs server|3A| cannot find module&quot;; fast_pattern:only; content:&quot;error&quot;; distance:1; classtype:misc-attack;</filter2>
        <id>2013</id>
        <msg>MISC CVS invalid module response</msg>
      </rule>
      <rule>
        <bugtraq>9178</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0977</cve>
        <filter1>tcp $HOME_NET 2401 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;E cvs server|3A| warning|3A| cannot make directory CVS in /&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>2317</id>
        <msg>MISC CVS non-relative path error response</msg>
        <nessus>11947</nessus>
      </rule>
      <rule>
        <bugtraq>9178</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2003-0977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;Argument&quot;; pcre:&quot;/^Argument\s+\//smi&quot;; pcre:&quot;/^Directory/smiR&quot;; classtype:misc-attack;</filter2>
        <id>2318</id>
        <msg>MISC CVS non-relative path access attempt</msg>
        <nessus>11947</nessus>
      </rule>
      <rule>
        <bugtraq>10499</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0417</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;Max-dotdot&quot;; fast_pattern:only; pcre:&quot;/^Max-dotdot[\s\r\n]*\d{3,}/msi&quot;; classtype:misc-attack;</filter2>
        <id>2583</id>
        <msg>MISC CVS Max-dotdot integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13217</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0753</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 514</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|annotate|0A|&quot;; fast_pattern:only; pcre:&quot;/^Entry \/file\/[0-9.]{71,}\/\/.*\x0aannotate\x0a/smi&quot;; classtype:attempted-dos;</filter2>
        <id>3651</id>
        <msg>EXPLOIT CVS rsh annotate revision overflow attempt</msg>
        <nessus>18097</nessus>
        <url>ccvs.cvshome.org/servlets/NewsItemView?newsItemID=142</url>
      </rule>
      <rule>
        <bugtraq>13217</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0753</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2401</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|annotate|0A|&quot;; fast_pattern:only; pcre:&quot;/^Entry \/file\/[0-9.]{71,}\/\/.*\x0aannotate\x0a/smi&quot;; classtype:attempted-dos;</filter2>
        <id>3652</id>
        <msg>EXPLOIT CVS pserver annotate revision overflow attempt</msg>
        <nessus>18097</nessus>
        <url>ccvs.cvshome.org/servlets/NewsItemView?newsItemID=142</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>300</groupid>
    <groupname>Client</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;auth=12345678&amp;login=+++Login+++&quot;; nocase;  metadata:policy security-ips alert; classtype:attempted-admin;</filter2>
        <id>10123</id>
        <msg>SPECIFIC-THREATS PA168 chipset based IP phone default password attempt</msg>
        <url>www.procheckup.com/Vulner_PR0614.php</url>
      </rule>
      <rule>
        <bugtraq>22585</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0325</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;08D75BB0-D2B5-11D1-88FC-0080C859833B&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*08D75BB0-D2B5-11D1-88FC-0080C859833B\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10173</id>
        <msg>WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>22585</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0325</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|8|00|D|00|7|00|5|00|B|00|B|00|0|00|-|00|D|00|2|00|B|00|5|00|-|00|1|00|1|00|D|00|1|00|-|00|8|00|8|00|F|00|C|00|-|00|0|00|0|00|8|00|0|00|C|00|8|00|5|00|9|00|8|00|3|00|3|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x008\x00D\x007\x005\x00B\x00B\x000\x00-\x00D\x002\x00B\x005\x00-\x001\x001\x00D\x001\x00-\x008\x008\x00F\x00C\x00-\x000\x000\x008\x000\x00C\x008\x005\x009\x008\x003\x003\x00B\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10174</id>
        <msg>WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>22585</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0325</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SetupINICtrl&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22SetupINICtrl\x22|\x27SetupINICtrl\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22SetupINICtrl\x22|\x27SetupINICtrl\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10175</id>
        <msg>WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32418</filter1>
        <filter2>flow:to_server,established; content:&quot;PSWD/GET&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10445</id>
        <msg>BACKDOOR acidbattery 1.0 runtime detection - get password</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=109</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18A295DA-088E-42D1-BE31-5028D7F9B965&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*18A295DA-088E-42D1-BE31-5028D7F9B965\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*18A295DA-088E-42D1-BE31-5028D7F9B965\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile))/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11181</id>
        <msg>WEB-ACTIVEX Excel Viewer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-02-excelviewerocx-v-31-multiple.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|A|00|2|00|9|00|5|00|D|00|A|00|-|00|0|00|8|00|8|00|E|00|-|00|4|00|2|00|D|00|1|00|-|00|B|00|E|00|3|00|1|00|-|00|5|00|0|00|2|00|8|00|D|00|7|00|F|00|9|00|B|00|9|00|6|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x008\x00A\x002\x009\x005\x00D\x00A\x00-\x000\x008\x008\x00E\x00-\x004\x002\x00D\x001\x00-\x00B\x00E\x003\x001\x00-\x005\x000\x002\x008\x00D\x007\x00F\x009\x00B\x009\x006\x005\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11182</id>
        <msg>WEB-ACTIVEX Excel Viewer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-02-excelviewerocx-v-31-multiple.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Excel.OActrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22Excel\.OActrl(\.\d)?\x22|\x27Excel\.OActrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=v)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22Excel\.OActrl(\.\d)?\x22|\x27Excel\.OActrl(\.\d)?\x27)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=n)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|HttpDownloadFile|Save|SaveWebFile|OpenWebFile)\s*)/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11183</id>
        <msg>WEB-ACTIVEX Excel Viewer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-02-excelviewerocx-v-31-multiple.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|x|00|c|00|e|00|l|00|.|00|O|00|A|00|c|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00x\x00c\x00e\x00l\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00x\x00c\x00e\x00l\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>11184</id>
        <msg>WEB-ACTIVEX Excel Viewer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-02-excelviewerocx-v-31-multiple.html</url>
      </rule>
      <rule>
        <bugtraq>22743</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2007-1005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9191</filter1>
        <filter2>flow:established,to_server; content:&quot;|01 06 00 00 00|&quot;; depth:5; offset:2; byte_test:4,&lt;,4,128,relative, little; metadata:policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>11186</id>
        <msg>DOS CA eTrust key handling dos -- password</msg>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;97AF4A45-49BE-4485-9F55-91AB40F22BF2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F22BF2\s*}?\s*(?P=q14)(\s|&gt;).*(?P=id1)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q15&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F22BF2\s*}?\s*(?P=q15)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile))\s*\(/siO&quot;; metadata:policy balanced-ips drop, policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11187</id>
        <msg>WEB-ACTIVEX Word Viewer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|7|00|A|00|F|00|4|00|A|00|4|00|5|00|-|00|4|00|9|00|B|00|E|00|-|00|4|00|4|00|8|00|5|00|-|00|9|00|F|00|5|00|5|00|-|00|9|00|1|00|A|00|B|00|4|00|0|00|F|00|2|00|2|00|B|00|F|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q16&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x007\x00A\x00F\x004\x00A\x004\x005\x00-\x004\x009\x00B\x00E\x00-\x004\x004\x008\x005\x00-\x009\x00F\x005\x005\x00-\x009\x001\x00A\x00B\x004\x000\x00F\x002\x002\x00B\x00F\x002\x00(}\x00)?(?P=q16)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11188</id>
        <msg>WEB-ACTIVEX Word Viewer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OA.OActrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OA\.OActrl(\.\d)?\x22|\x27OA\.OActrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=v)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OA\.OActrl(\.\d)?\x22|\x27OA\.OActrl(\.\d)?\x27)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=n)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)\s*\(/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11189</id>
        <msg>WEB-ACTIVEX Word Viewer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html</url>
      </rule>
      <rule>
        <bugtraq>33243</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|A|00|.|00|O|00|A|00|c|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q17)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q18&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q18)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>11190</id>
        <msg>WEB-ACTIVEX Word Viewer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|95 00|&quot;; isdataat:55,relative; pcre:&quot;/^.{3}(\x00[^\x00]|[^\x00]\x00|[^\x00][^\x00]){25}/Rs&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11258</id>
        <msg>WEB-CLIENT Excel Malformed Named Graph Information unicode overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-023.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0215</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.xls; content:&quot;|95 00|&quot;; isdataat:133,relative; pcre:&quot;/^(.{92}[^\x00]{41}|.{148}[^\x00]{41}|.{172}[^\x00]{41}|.{212}[^\x00]{41}|.{252}[^\x00]{22}|.{272}[^\x00]{22}|.{292}[^\x00]{22}|.{312}[^\x00]{22}|.{332}[^\x00]{22})/Rs&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11290</id>
        <msg>WEB-CLIENT Excel malformed named graph information ascii overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-023.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2007-0934</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Visio |28|TM|29| Drawing|0D 0A 00 00 00 00|&quot;; fast_pattern:only; pcre:&quot;/Visio \x28TM\x29 Drawing\r\n\x00{4}([^\x00]|\x00[^\x00]|\x00\x00[^\x01-\x06\x0b]|\x00\x00[\x01-\x06\x0b][^\x00])/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>11836</id>
        <msg>MISC Visio version number anomaly</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-030.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|FA CB D9 D9 E5 E1 D6|&quot;; depth:7; flowbits:set,Theef210_Connectionwithnopassword; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12233</id>
        <msg>BACKDOOR theef 2.10 runtime detection - connect with no password</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|FA CB D9 D9 DD C5 D8 CE D6|&quot;; depth:9; flowbits:set,Theef210_Connectionwithpassword; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12235</id>
        <msg>BACKDOOR theef 2.10 runtime detection - connect with password</msg>
      </rule>
      <rule>
        <bugtraq>23826</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1747</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.xls; content:&quot;`|10|&quot;; byte_test:2,&gt;,32767,6,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12256</id>
        <msg>WEB-CLIENT Excel malformed FBI record</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-023.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.xlw&quot;; nocase; http_uri; pcre:&quot;/\x2Exlw([\?\x5c\x2f]|$)/smiU&quot;; flowbits:set,xlw.download; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>12285</id>
        <msg>WEB-CLIENT Excel Workspace file download</msg>
        <url>sc.openoffice.org/excelfileformat.pdf</url>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5660</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|W|00|U|00|S|00|W|00|e|00|b|00|A|00|g|00|e|00|n|00|t|00|.|00|W|00|e|00|b|00|A|00|g|00|e|00|n|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)D\x00W\x00U\x00S\x00W\x00e\x00b\x00A\x00g\x00e\x00n\x00t\x00.\x00W\x00e\x00b\x00A\x00g\x00e\x00n\x00t\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)D\x00W\x00U\x00S\x00W\x00e\x00b\x00A\x00g\x00e\x00n\x00t\x00.\x00W\x00e\x00b\x00A\x00g\x00e\x00n\x00t\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12703</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX function call unicode access</msg>
        <url>support.installshield.com/kb/view.asp?articleid=Q113602</url>
      </rule>
      <rule>
        <bugtraq>27279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FCED4482-7CCB-4E6F-86C9-DCB22B52843C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FCED4482-7CCB-4E6F-86C9-DCB22B52843C\s*}?\s*(?P=q5)(\s|&gt;).*(?P=id1)\s*\.\s*(AddFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FCED4482-7CCB-4E6F-86C9-DCB22B52843C\s*}?\s*(?P=q6)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(AddFile))\s*\(/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13325</id>
        <msg>WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>27279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|C|00|E|00|D|00|4|00|4|00|8|00|2|00|-|00|7|00|C|00|C|00|B|00|-|00|4|00|E|00|6|00|F|00|-|00|8|00|6|00|C|00|9|00|-|00|D|00|C|00|B|00|2|00|2|00|B|00|5|00|2|00|8|00|4|00|3|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q7&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13326</id>
        <msg>WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>27279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MVSNClientDownloadManager61Lib.DownloadManager&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22MVSNClientDownloadManager61Lib\.DownloadManager\x22|\x27MVSNClientDownloadManager61Lib\.DownloadManager\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*AddFile\s*|.*(?P=v)\s*\.\s*AddFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22MVSNClientDownloadManager61Lib\.DownloadManager\x22|\x27MVSNClientDownloadManager61Lib\.DownloadManager\x27)\s*\)(\s*\.\s*AddFile\s*|.*(?P=n)\s*\.\s*AddFile\s*)\s*\(/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13327</id>
        <msg>WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>27279</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;M|00|V|00|S|00|N|00|C|00|l|00|i|00|e|00|n|00|t|00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|6|00|1|00|L|00|i|00|b|00|.|00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00|M|00|a|00|n|00|a|00|g|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)M\x00V\x00S\x00N\x00C\x00l\x00i\x00e\x00n\x00t\x00D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x006\x001\x00L\x00i\x00b\x00.\x00D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q8)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q9&gt;\x22|\x27|)M\x00V\x00S\x00N\x00C\x00l\x00i\x00e\x00n\x00t\x00D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x006\x001\x00L\x00i\x00b\x00.\x00D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00M\x00a\x00n\x00a\x00g\x00e\x00r\x00(?P=q9)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13328</id>
        <msg>WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|13571, service http, policy security-ips drop;</filter2>
        <id>13571</id>
        <msg>WEB-CLIENT Microsoft Excel dval record arbitrary code excecution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1090</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dxf; metadata: engine shared, soid 3|13665, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>13665</id>
        <msg>WEB-CLIENT Microsoft Visio DXF file invalid memory allocation exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1434</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|13790, service http, policy security-ips drop;</filter2>
        <id>13790</id>
        <msg>WEB-CLIENT Microsoft Word malformed css remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-026.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.rtf; metadata: engine shared, soid 3|13803, service http, policy security-ips drop;</filter2>
        <id>13803</id>
        <msg>WEB-CLIENT RTF control word overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-026.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|13973, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13973</id>
        <msg>WEB-CLIENT Microsoft Excel format record code execution attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-043.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.eps&quot;; nocase; http_uri; flowbits:set,http.eps.download; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13983</id>
        <msg>WEB-CLIENT Microsoft Office eps file download</msg>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x000\x000\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14628</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Chart ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|2|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x002\x000\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14629</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components PivotTable ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|3|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x003\x000\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14630</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|14641, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14641</id>
        <msg>WEB-CLIENT Microsoft Excel invalid FRTWrapper record buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-057.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3477</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|14642, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14642</id>
        <msg>WEB-CLIENT Microsoft Excel file with embedded ActiveX control</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5b7524c8-2446-40e9-9474-94a779dba224&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14764</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service Agent ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2470</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DWUSWebAgent.WebAgent&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14765</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service Agent ActiveX function call</msg>
      </rule>
      <rule>
        <bugtraq>31987</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4A46B8CD-F7BD-11D4-B1D8-000102290E7C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4A46B8CD-F7BD-11D4-B1D8-000102290E7C\s*}?\s*(?P=q6)(\s|&gt;).*(?P=id1)\s*\.\s*(ImageURL)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*4A46B8CD-F7BD-11D4-B1D8-000102290E7C\s*}?\s*(?P=q7)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(ImageURL))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14997</id>
        <msg>WEB-ACTIVEX DjVu MSOffice Converter ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>31987</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|A|00|4|00|6|00|B|00|8|00|C|00|D|00|-|00|F|00|7|00|B|00|D|00|-|00|1|00|1|00|D|00|4|00|-|00|B|00|1|00|D|00|8|00|-|00|0|00|0|00|0|00|1|00|0|00|2|00|2|00|9|00|0|00|E|00|7|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q8&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x00A\x004\x006\x00B\x008\x00C\x00D\x00-\x00F\x007\x00B\x00D\x00-\x001\x001\x00D\x004\x00-\x00B\x001\x00D\x008\x00-\x000\x000\x000\x001\x000\x002\x002\x009\x000\x00E\x007\x00C\x00(}\x00)?(?P=q8)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14998</id>
        <msg>WEB-ACTIVEX DjVu MSOffice Converter ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4027</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15083, service http, policy security-ips drop;</filter2>
        <id>15083</id>
        <msg>EXPLOIT Microsoft Word .rtf file double free attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4256</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15088, service http, policy security-ips drop;</filter2>
        <id>15088</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4256</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15090, service http, policy security-ips drop;</filter2>
        <id>15090</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15092, service http, policy security-ips drop;</filter2>
        <id>15092</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15094, service http, policy security-ips drop;</filter2>
        <id>15094</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4253</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15096, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15096</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4253</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15098, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15098</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15100, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15100</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15102, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15102</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15104, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15104</id>
        <msg>WEB-CLIENT Visual Basic 6.0 malformed AVI buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-4025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15106, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15106</id>
        <msg>WEB-CLIENT Microsoft Word .rtf file integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.rtf; metadata: engine shared, soid 3|15107, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15107</id>
        <msg>WEB-CLIENT Microsoft Word .rtf file stylesheet buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4032</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15108, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15108</id>
        <msg>WEB-CLIENT Microsoft Office Sharepoint Server elevation of privilege exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-077.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4251</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15118, service http, policy security-ips drop;</filter2>
        <id>15118</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4251</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15120, service http, policy security-ips drop;</filter2>
        <id>15120</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1089</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|10|@|DE|naaa|87|a|17|@|DE FD F2 F1 09|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15163</id>
        <msg>SPECIFIC-THREATS Microsoft Visio Object Header Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33245</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;97AF4A45-49BE-4485-9F55-91AB40F288F2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q24&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F288F2\s*}?\s*(?P=q24)(\s|&gt;).*(?P=id1)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile|Open)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*97AF4A45-49BE-4485-9F55-91AB40F288F2\s*}?\s*(?P=q25)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\.(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile|Open))\s*\(/siO&quot;; metadata:policy balanced-ips drop, policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15230</id>
        <msg>WEB-ACTIVEX Office Viewer 2 ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>33245</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;9|00|7|00|A|00|F|00|4|00|A|00|4|00|5|00|-|00|4|00|9|00|B|00|E|00|-|00|4|00|4|00|8|00|5|00|-|00|9|00|F|00|5|00|5|00|-|00|9|00|1|00|A|00|B|00|4|00|0|00|F|00|2|00|8|00|8|00|F|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q26&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*9\x007\x00A\x00F\x004\x00A\x004\x005\x00-\x004\x009\x00B\x00E\x00-\x004\x004\x008\x005\x00-\x009\x00F\x005\x005\x00-\x009\x001\x00A\x00B\x004\x000\x00F\x002\x008\x008\x00F\x002\x00(}\x00)?(?P=q26)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15231</id>
        <msg>WEB-ACTIVEX Office Viewer 2 ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>33453</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0301</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2A7D9CCE-211A-4654-9449-718F71ED9644&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q24&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2A7D9CCE-211A-4654-9449-718F71ED9644\s*}?\s*(?P=q24)(\s|&gt;).*(?P=id1)\s*\.\s*(SaveFile|ExportToXML)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q25&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2A7D9CCE-211A-4654-9449-718F71ED9644\s*}?\s*(?P=q25)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\.(SaveFile|ExportToXML))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15282</id>
        <msg>WEB-ACTIVEX FlexCell Grid ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33453</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0301</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|A|00|7|00|D|00|9|00|C|00|C|00|E|00|-|00|2|00|1|00|1|00|A|00|-|00|4|00|6|00|5|00|4|00|-|00|9|00|4|00|4|00|9|00|-|00|7|00|1|00|8|00|F|00|7|00|1|00|E|00|D|00|9|00|6|00|4|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q26&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00A\x007\x00D\x009\x00C\x00C\x00E\x00-\x002\x001\x001\x00A\x00-\x004\x006\x005\x004\x00-\x009\x004\x004\x009\x00-\x007\x001\x008\x00F\x007\x001\x00E\x00D\x009\x006\x004\x004\x00(}\x00)?(?P=q26)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15283</id>
        <msg>WEB-ACTIVEX FlexCell Grid ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; nocase; http_method; content:&quot;.vsd&quot;; nocase; http_uri; flowbits:set, visio.request; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15294</id>
        <msg>WEB-CLIENT Microsoft Visio file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0097</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|15298, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15298</id>
        <msg>WEB-CLIENT Microsoft Visio could allow remote code execution</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-005.mspx</url>
      </rule>
      <rule>
        <bugtraq>33660</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0096</cve>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|15299, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15299</id>
        <msg>WEB-CLIENT Microsoft Office Visio invalid ho tag attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-005</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0095</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|15303, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15303</id>
        <msg>WEB-CLIENT Malformed Visio IconBitsComponent arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-005.mspx</url>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DA8484DE-52DB-4860-A986-61A8682E298A&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q7&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DA8484DE-52DB-4860-A986-61A8682E298A\s*}?\s*(?P=q7)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapShotToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*DA8484DE-52DB-4860-A986-61A8682E298A\s*}?\s*(?P=q8)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(SnapShotToFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15334</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 7000 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|A|00|8|00|4|00|8|00|4|00|D|00|E|00|-|00|5|00|2|00|D|00|B|00|-|00|4|00|8|00|6|00|0|00|-|00|A|00|9|00|8|00|6|00|-|00|6|00|1|00|A|00|8|00|6|00|8|00|2|00|E|00|2|00|9|00|8|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q9&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*D\x00A\x008\x004\x008\x004\x00D\x00E\x00-\x005\x002\x00D\x00B\x00-\x004\x008\x006\x000\x00-\x00A\x009\x008\x006\x00-\x006\x001\x00A\x008\x006\x008\x002\x00E\x002\x009\x008\x00A\x00(}\x00)?(?P=q9)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15335</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 7000 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LiveX_v7000&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LiveX_v7000(\.\d)?\x22|\x27LiveX_v7000(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=v)\s*\.\s*SnapShotToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LiveX_v7000(\.\d)?\x22|\x27LiveX_v7000(\.\d)?\x27)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=n)\s*\.\s*SnapShotToFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15336</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 7000 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|i|00|v|00|e|00|X|00|_|00|v|00|7|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q10&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x007\x000\x000\x000\x00(\.\x00\d\x00)?(?P=q10)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q11&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x007\x000\x000\x000\x00(\.\x00\d\x00)?(?P=q11)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15337</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 7000 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F4421170-DB22-4551-BBFB-FFCFFB419F6F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q12&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F4421170-DB22-4551-BBFB-FFCFFB419F6F\s*}?\s*(?P=q12)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapShotToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*F4421170-DB22-4551-BBFB-FFCFFB419F6F\s*}?\s*(?P=q13)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(SnapShotToFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15338</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8120 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|4|00|4|00|2|00|1|00|1|00|7|00|0|00|-|00|D|00|B|00|2|00|2|00|-|00|4|00|5|00|5|00|1|00|-|00|B|00|B|00|F|00|B|00|-|00|F|00|F|00|C|00|F|00|F|00|B|00|4|00|1|00|9|00|F|00|6|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q14&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x004\x004\x002\x001\x001\x007\x000\x00-\x00D\x00B\x002\x002\x00-\x004\x005\x005\x001\x00-\x00B\x00B\x00F\x00B\x00-\x00F\x00F\x00C\x00F\x00F\x00B\x004\x001\x009\x00F\x006\x00F\x00(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15339</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8120 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LiveX_v8120&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LiveX_v8120(\.\d)?\x22|\x27LiveX_v8120(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=v)\s*\.\s*SnapShotToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LiveX_v8120(\.\d)?\x22|\x27LiveX_v8120(\.\d)?\x27)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=n)\s*\.\s*SnapShotToFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15340</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8120 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|i|00|v|00|e|00|X|00|_|00|v|00|8|00|1|00|2|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x008\x001\x002\x000\x00(\.\x00\d\x00)?(?P=q15)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x008\x001\x002\x000\x00(\.\x00\d\x00)?(?P=q16)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15341</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8120 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8D58D690-6B71-4EE8-85AD-006DB0287BF1&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q17&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8D58D690-6B71-4EE8-85AD-006DB0287BF1\s*}?\s*(?P=q17)(\s|&gt;).*(?P=id1)\s*\.\s*(SnapShotToFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q18&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8D58D690-6B71-4EE8-85AD-006DB0287BF1\s*}?\s*(?P=q18)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\.(SnapShotToFile))\s*\(/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15342</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8200 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|D|00|5|00|8|00|D|00|6|00|9|00|0|00|-|00|6|00|B|00|7|00|1|00|-|00|4|00|E|00|E|00|8|00|-|00|8|00|5|00|A|00|D|00|-|00|0|00|0|00|6|00|D|00|B|00|0|00|2|00|8|00|7|00|B|00|F|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q19&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*8\x00D\x005\x008\x00D\x006\x009\x000\x00-\x006\x00B\x007\x001\x00-\x004\x00E\x00E\x008\x00-\x008\x005\x00A\x00D\x00-\x000\x000\x006\x00D\x00B\x000\x002\x008\x007\x00B\x00F\x001\x00(}\x00)?(?P=q19)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15343</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8200 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LiveX_v8200&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22LiveX_v8200(\.\d)?\x22|\x27LiveX_v8200(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=v)\s*\.\s*SnapShotToFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22LiveX_v8200(\.\d)?\x22|\x27LiveX_v8200(\.\d)?\x27)\s*\)(\s*\.\s*SnapShotToFile\s*|.*(?P=n)\s*\.\s*SnapShotToFile\s*)\s*\(/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15344</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8200 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>33782</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;L|00|i|00|v|00|e|00|X|00|_|00|v|00|8|00|2|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q20&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x008\x002\x000\x000\x00(\.\x00\d\x00)?(?P=q20)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q21&gt;\x22|\x27|)L\x00i\x00v\x00e\x00X\x00_\x00v\x008\x002\x000\x000\x00(\.\x00\d\x00)?(?P=q21)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15345</id>
        <msg>WEB-ACTIVEX GeoVision LiveX 8200 ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0238</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15365, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15365</id>
        <msg>WEB-CLIENT Microsoft Excel extrst record arbitrary code excecution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-009.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0556</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|15454, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15454</id>
        <msg>WEB-CLIENT Microsoft Office PowerPoint malformed msofbtTextbox exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4841</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15455, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15455</id>
        <msg>EXPLOIT WordPad and Office Text Converters XST parsing buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-010.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.xls&quot;; nocase; http_uri; flowbits:set,http.xls; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>15463</id>
        <msg>WEB-CLIENT Microsoft Excel file request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0100</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15465, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15465</id>
        <msg>WEB-CLIENT Microsoft Excel malformed object record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-009.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0088</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15466, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15466</id>
        <msg>EXPLOIT WordPad WordPerfect 6.x converter buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0235</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|15467, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15467</id>
        <msg>EXPLOIT WordPad and Office Text Converters PlcPcd aCP buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0087</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|15469, service http, policy security-ips drop;</filter2>
        <id>15469</id>
        <msg>WEB-CLIENT Microsoft WordPad and Office text converters integer underflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-0981</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;select%20user_name,web_password2%20from&quot;; content:&quot;WWV_FLOW_USERS&quot;; distance:1; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>15488</id>
        <msg>SPECIFIC-THREATS Oracle Database Application Express Component APEX password hash disclosure attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0549</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15519, service http, policy security-ips drop;</filter2>
        <id>15519</id>
        <msg>WEB-CLIENT Microsoft Office Excel BRAI record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0557</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15520, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15520</id>
        <msg>WEB-CLIENT Microsoft Office Excel FtCbls remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15521, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15521</id>
        <msg>WEB-CLIENT Microsoft Office Excel ExternSheet record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0563</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|15524, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15524</id>
        <msg>EXPLOIT Microsoft Word remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0565</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|15525, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15525</id>
        <msg>EXPLOIT Microsoft Word remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15537, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15537</id>
        <msg>WEB-CLIENT Microsoft Office Excel MsoDrawingGroup record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <bugtraq>36042</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3037</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15541, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15541</id>
        <msg>WEB-CLIENT Excel SST record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1134</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15542, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15542</id>
        <msg>WEB-CLIENT Microsoft Office Excel Qsir and Qsif record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.doc&quot;; nocase; http_uri; flowbits:set,http.doc; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>15587</id>
        <msg>WEB-CLIENT Word file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2496</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15685, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15685</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2496</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15687, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15687</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15689, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15689</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15691, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>15691</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0562</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E543-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E543-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15852</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components Datasource ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0562</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|4|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x004\x003\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15853</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components Datasource ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1920</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15913, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15913</id>
        <msg>WEB-CLIENT javascript arguments keyword override rce attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>25690</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2834</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15975, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15975</id>
        <msg>WEB-CLIENT OpenOffice TIFF file in little endian format parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25690</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2834</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15976, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15976</id>
        <msg>WEB-CLIENT OpenOffice TIFF file in big endian format parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.dxf&quot;; nocase; http_uri; flowbits:set,http.dxf; flowbits:noalert; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15987</id>
        <msg>WEB-MISC Microsoft Visio DXF file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2528</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|16177, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16177</id>
        <msg>EXPLOIT Microsoft GDI+ Word file Office Art Property Table remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2528</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16178, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16178</id>
        <msg>EXPLOIT Microsoft GDI+ Excel file Office Art Property Table remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3130</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16226, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16226</id>
        <msg>EXPLOIT Microsoft Office Excel integer field in row record improper validation remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3131</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16229, service http, policy security-ips drop;</filter2>
        <id>16229</id>
        <msg>WEB-CLIENT Microsoft Excel oversized ib memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3131</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16230, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16230</id>
        <msg>WEB-CLIENT Microsoft Excel oversized ib memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3132</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16233, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16233</id>
        <msg>EXPLOIT Microsoft Excel oversized ptgFuncVar cparams value buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3135</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|16234, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16234</id>
        <msg>WEB-CLIENT Microsoft Word Document remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16235, service http, policy security-ips drop;</filter2>
        <id>16235</id>
        <msg>EXPLOIT Microsoft Excel file SXDB record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3128</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16236, service http, policy security-ips drop;</filter2>
        <id>16236</id>
        <msg>EXPLOIT Microsoft Excel file SxView record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3133</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16240, service http, policy security-ips drop;</filter2>
        <id>16240</id>
        <msg>EXPLOIT Microsoft Excel file Window/Pane record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3129</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16241, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16241</id>
        <msg>WEB-CLIENT Microsoft Office Excel FeatHdr BIFF record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2506</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|16314, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16314</id>
        <msg>EXPLOIT Microsoft WordPad and Office text converter integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>33660</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0096</cve>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,visio.request; metadata: engine shared, soid 3|16318, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16318</id>
        <msg>WEB-CLIENT Microsoft Office Visio invalid ho tag attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-005</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0102</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16328, service http, policy security-ips drop;</filter2>
        <id>16328</id>
        <msg>EXPLOIT Microsoft Office Project file parsing arbitrary memory access attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-074.mspx</url>
      </rule>
      <rule>
        <bugtraq>36651</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2518</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.bmp; content:&quot;BM&quot;; fast_pattern; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; byte_test:4,&gt;,536870911,36,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16361</id>
        <msg>WEB-CLIENT Microsoft Office BMP header biClrUsed integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2010-0257</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; flowbits:isset,http.xls; metadata: engine shared, soid 3|16461, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16461</id>
        <msg>EXPLOIT Microsoft Excel write access violation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16462, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16462</id>
        <msg>EXPLOIT Microsoft Excel BIFF8 formulas from records parsing code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16463, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16463</id>
        <msg>EXPLOIT Microsoft Excel BIFF5 formulas from records parsing code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16464, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16464</id>
        <msg>WEB-CLIENT Microsoft Excel ContinueFRT12 heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0261</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16465, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16465</id>
        <msg>WEB-CLIENT Microsoft Excel ContinueFRT12 and MDXSet heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16466, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16466</id>
        <msg>EXPLOIT Microsoft Excel uninitialized stack variable code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0263</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16467, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16467</id>
        <msg>EXPLOIT Microsoft Excel 2007 invalid comments.xml uninitialized pointer access attempt 1</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0263</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16468, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16468</id>
        <msg>EXPLOIT Microsoft Excel 2007 invalid comments.xml uninitialized pointer access attempt 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0264</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16469, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16469</id>
        <msg>WEB-CLIENT Microsoft Excel DbOrParamQry.fOdbcConn parsing remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0264</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16470, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16470</id>
        <msg>WEB-CLIENT Microsoft Excel DbOrParamQry.fWeb parsing remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0264</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16471, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16471</id>
        <msg>WEB-CLIENT Microsoft Excel DbOrParamQry.fWeb parsing remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3132</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16553, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16553</id>
        <msg>EXPLOIT Microsoft Office Excel ptg index parsing code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-067.mspx</url>
      </rule>
      <rule>
        <bugtraq>30861</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3878</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;00989888-BB72-4E31-A7C6-5F819C24D2F7&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16565</id>
        <msg>WEB-ACTIVEX Ultra Shareware Office ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3135</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|16586, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16586</id>
        <msg>WEB-CLIENT Microsoft Word Document remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-068.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0822</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16638, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16638</id>
        <msg>WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0822</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16639, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16639</id>
        <msg>WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with macro</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0822</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16640, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16640</id>
        <msg>WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with linkFmla</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0822</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16641, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16641</id>
        <msg>WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with macro and linkFmla</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0823</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16643, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16643</id>
        <msg>WEB-CLIENT Microsoft Excel Chart Sheet Substream memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0824</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16644, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16644</id>
        <msg>EXPLOIT Microsoft Excel WOpt record memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16645, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16645</id>
        <msg>EXPLOIT Microsoft Excel SxView record memory pointer corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1246</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16646, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16646</id>
        <msg>EXPLOIT Microsoft Excel RealTimeData record stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1247</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16647, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16647</id>
        <msg>WEB-CLIENT Microsoft Excel RealTimeData record heap memory corruption attempt - 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1247</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16648, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16648</id>
        <msg>EXPLOIT Microsoft Excel RealTimeData record heap memory corruption attempt - 1</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16649, service http, policy security-ips drop;</filter2>
        <id>16649</id>
        <msg>WEB-CLIENT Microsoft Excel HFPicture record stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0821</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16662, service http, policy security-ips drop;</filter2>
        <id>16662</id>
        <msg>WEB-CLIENT Microsoft Excel SxView heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>35992</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1534</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;classid|3D 22|clsid|3A|0002E511-0000-0000-C000-000000000046|22|&quot;; fast_pattern:only; nocase; content:&quot;&lt;body onload&quot;; content:&quot;&lt;/html&gt;&quot;; within:200; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16786</id>
        <msg>SPECIFIC-THREATS Microsoft Office Web Components Spreadsheet ActiveX buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3471</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16800, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16800</id>
        <msg>EXPLOIT Microsoft Excel FRTWrapper record buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-057.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1900</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17119, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17119</id>
        <msg>EXPLOIT Microsoft Word sprmCMajority SPRM overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1903</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17124, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17124</id>
        <msg>WEB-CLIENT Microsoft Word malformed table record memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-056.mspx</url>
      </rule>
      <rule>
        <bugtraq>24691</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;Sheet1&quot;; content:&quot;|8C 00 04 00 56 00 56 00 C1 01 08 00 C1 01 00 00 80 38 01 00|&quot;; within:20; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17227</id>
        <msg>WEB-CLIENT Microsoft Excel sheet name memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2563</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17250, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17250</id>
        <msg>EXPLOIT Microsoft WordPad sprmTSetBrc80 SPRM overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-067.mspx</url>
      </rule>
      <rule>
        <bugtraq>17000</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0009</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;Routing|3A 20|&quot;; content:&quot;|B9 00 9B 05 56 04 3F 05 00 00 41 41 41 41|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17284</id>
        <msg>WEB-CLIENT Microsoft Office malformed routing slip code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>19414</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3649</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Attribut|00|e VB_Nam|00|e = &quot;; fast_pattern; nocase; content:&quot;|22|ThiAsDocumen|22|t&quot;; within:15; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17286</id>
        <msg>SPECIFIC-THREATS Microsoft Visual Basic for Applications document properties overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24935</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3455</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/officescan/console&quot;; fast_pattern; http_uri; content:&quot;session=&quot;; http_cookie; pcre:&quot;/session=[^\s\x3b&amp;]{520}/iC&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17295</id>
        <msg>WEB-MISC Trend Micro OfficeScan Console authentication buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23380</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1910</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|09 04 16 00 22 0C 00 00 80 57 00 00 80 57 00 00 02|&quot;; content:&quot;|00 00 00 00 00 00 00 00 FF FF 0F 00|&quot;; within:12; distance:23; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17301</id>
        <msg>WEB-CLIENT Microsoft Word TextBox sub-document memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>30124</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|13 1F 14 FF 95 80 FF FF 01 00 00 00 00 00 28 2C|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17308</id>
        <msg>WEB-CLIENT Microsoft Word SmartTag record code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>28819</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0320</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.ole; content:&quot;W|00|o|00|r|00|d|00|D|00|o|00|c|00|u|00|m|00|e|00|n|00|t|00|&quot;; nocase; content:&quot;|22 10 00 80|&quot;; within:4; distance:96; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17315</id>
        <msg>WEB-CLIENT OpenOffice OLE File Stream Buffer Overflow</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|D9 EE D9 74 24 F4|&quot;; content:&quot;|81|&quot;; distance:1; content:&quot;|13|&quot;; distance:1; content:&quot;|83|&quot;; distance:1; content:&quot;|FC E2 F4|&quot;; distance:1; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17322</id>
        <msg>SHELLCODE x86 OS agnostic fnstenv geteip dword xor decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|E8 FF FF FF FF C0 5E 81 76 0E|&quot;; content:&quot;|83 EE FC E2 F4|&quot;; distance:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17344</id>
        <msg>SHELLCODE x86 OS agnostic xor dword decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|EB 0C 5E 56 31 1E AD 01 C3 85 C0 75 F7 C3 E8 EF FF FF FF|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17345</id>
        <msg>SHELLCODE x86 OS agnostic dword additive feedback decoder</msg>
      </rule>
      <rule>
        <bugtraq>21856</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0027</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|7F 00 54 01 09 00 01 00 00 00 00 00 0C 00 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17362</id>
        <msg>WEB-CLIENT Microsoft Excel IMDATA buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25567</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0870</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|A8 00 00 00 00 00 00 00 41 41 41 41 10 00 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17368</id>
        <msg>WEB-CLIENT Microsoft Word document stream handling code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>23780</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1214</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|43 6F 6C 75 6D 6E 20 42 3F 9B 00 00 00 9D 00 02 00 02 00 9E 00 1D 00 33 00 04 2A 06 02 8C 23 01 01 04 01 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17377</id>
        <msg>SPECIFIC-THREATS Microsoft excel Malformed Filter Records Handling Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>24450</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;rtf&quot;; nocase; content:&quot;|5C|prtdata&quot;; distance:0; nocase; isdataat:200,relative; content:!&quot;|0A|&quot;; within:200; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17403</id>
        <msg>WEB-CLIENT OpenOffice RTF File parsing heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4841</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|11 84 98 FE 5E 84 68 01 60 84 98 FE 4F 4A 06 00 51 4A 06 00 6F 28 00 87 68 00 00 00 00 88 48 00 00 42 43 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17404</id>
        <msg>EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4841</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 0D 10 00 00 0F 84 D0 02 11 84 98 FE 5E 84 D0 02 60 84 98 FE 6F 28 00 87 68 00 00 00 00 88 48 00 00 1F 05|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17405</id>
        <msg>EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-010.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4841</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|5F B3 AC 33 42 1E DA DE 51 CA FA 0D 4F 71 3C 4B BE EC 72 87 2B 4D 06 22 A7 4C 49 75 6A E0 37 20 BB 29 CB A9 2E|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17406</id>
        <msg>EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>15780</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4131</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|00 18 00 1F|&quot;; byte_test:2,&amp;,1,6,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17488</id>
        <msg>SPECIFIC-THREATS Excel Malformed Range Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>18905</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.ole; content:&quot;|41 41 41 41 41 41 41 41 09 09 09 09 09 09 0D 41 41 41 41 41 41 41 41 41 41 41 41 41 41 09 0D 41|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17491</id>
        <msg>SPECIFIC-THREATS Microsoft Word mso.dll LsCreateLine Memory Corruption</msg>
      </rule>
      <rule>
        <bugtraq>18853</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1301</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|1D 00 0F 00 03 00 00 00 00 00 00 FF FF FF FF FF FF 00 00 EF|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17492</id>
        <msg>SPECIFIC-THREATS Microsoft Excel Malformed SELECTION Record Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>21589</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6561</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; content:&quot;|EC A5|&quot;; within:2; distance:504; byte_test:4,&gt;,65535,114,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17505</id>
        <msg>WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>21589</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6561</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; content:&quot;|EC A5|&quot;; within:2; distance:504; byte_test:4,&gt;,65535,126,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17506</id>
        <msg>WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>21589</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6561</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; content:&quot;|EC A5|&quot;; within:2; distance:504; byte_test:4,&gt;,65535,138,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17507</id>
        <msg>WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>16181</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0030</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|00 0D 10 38 00 00 00 18 01 61 00 61 00 61 00|&quot;; pcre:&quot;/(\x51\x10..\x01(\x02|\x00)|\x01(\x02|\x00)..\x51\x10)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17511</id>
        <msg>WEB-CLIENT Excel malformed Graphic Code Execution</msg>
      </rule>
      <rule>
        <bugtraq>17101</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|9C 00|&quot;; byte_test:2,&gt;,14,2,relative,little; byte_test:2,&gt;,20,4,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17517</id>
        <msg>WEB-CLIENT excel Malformed Record Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>15926</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|00 00 00 00 0C 00 77 30 30 74 77 30 30 74 77 30 30 74 8C 00 04 00 21 00|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17537</id>
        <msg>SPECIFIC-THREATS Microsoft Excel Unspecified Null Page Name Memory Corruption Attempt</msg>
      </rule>
      <rule>
        <bugtraq>15926</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|53 68 65 65 74 31 00 00 00 00 00 00 53 68 65 65 74 32 00 00|&quot;; depth:20; offset:688; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17538</id>
        <msg>SPECIFIC-THREATS Microsoft Excel Unspecified Page Name Memory Corruption Attempt</msg>
      </rule>
      <rule>
        <bugtraq>15926</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0030</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|00 00 00 00 00 0D 10 7E 00 00 00 3B 01 77 00 30 00 30 00 74 00 2C 00 20 00 4D 00 61 00 72 00 63 00 20 00 42 00 65 00 68 00 61 00 72 00 20 00 67 00 69 00 76 00 65 00 73 00 20 00 30 00 2E 00 30 00 31 00 24 00 20 00 62 00 6C 00 6F 00 77 00 6A 00 6F 00 62 00 20 00 61 00 74 00 20 00 65 00 62 00 61 00 79 00 2C 00 20 00 67 00 6F 00 67 00 6F 00 67 00 6F|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17539</id>
        <msg>SPECIFIC-THREATS Microsoft Excel Unspecified Grafic Pointer Memory Corruption Attempt</msg>
      </rule>
      <rule>
        <bugtraq>21922</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0031</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|00 00 80 00 FF 93 02 04 00 14 80 05 FF 92 00 E2 00 80 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17542</id>
        <msg>SPECIFIC-THREATS Excel MalformedPalete Record Memory Corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>21925</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0030</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|08 00 00 00 00 00|&quot;; byte_test:2,&gt;,255,8,relative,little; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17543</id>
        <msg>WEB-CLIENT Excel Column Record Handling Memory Corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>14216</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0564</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|04 05 02 03 04 87 7A 00 20 00 00 00 80 08 00 00 00 00 00 00 00 FF 01 00 00 00 00 00 00 44 44|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17550</id>
        <msg>SPECIFIC-THREATS Microsoft Word Font Parsing Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5660</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E9880553-B8A7-4960-A668-95C68BED571E&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 27 25 75 34|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17555</id>
        <msg>SPECIFIC-THREATS Macrovision InstallShield Update Service ActiveX exploit attempt</msg>
        <url>support.installshield.com/kb/view.asp?articleid=Q113602</url>
      </rule>
      <rule>
        <bugtraq>32583</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4026</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.doc; content:&quot;|22 B0 08 07 23 90 A0 05 24 90 A0 05 33 50 00 19 00 00 00 00 00 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17560</id>
        <msg>SPECIFIC-THREATS Microsoft Word Global Array Index Heap Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34880</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0225</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|08 00 00 00 00 00 00 00 AA FF FF 3F 00 00 00 00 FD 03 00 00 01 00 00 00 34 00 00 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17565</id>
        <msg>SPECIFIC-THREATS Microsoft Office PowerPoint PP7 File Handling Memory Corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>12480</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0848</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; http_uri; pcre:&quot;/\w{3}\x25\x30\x30[^\r\n]{2000}/Ii&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17568</id>
        <msg>WEB-MISC Microsoft Office XP URL Handling Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14362</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2768</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,visio.request; content:&quot;Visio|20 28|TM|29 20|Drawing&quot;; nocase; content:&quot;|77 77 00 80|&quot;; within:4; distance:30; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17574</id>
        <msg>SPECIFIC-THREATS Sophos Anti-Virus Visio File Parsing Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22225</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0515</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.doc; content:&quot;|24 00 61 24 03 00 00 00 00 00 00 00 D1 50 00 00 04 00 00 AC 00 00 00 00 FF FF FF FF 00 00 00 00 CE|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17578</id>
        <msg>SPECIFIC-THREATS Microsoft Word Section Table Array Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22383</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0671</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 06 00 53 68 65 65 74 33 8C 00 04 00 01 00 01|&quot;; content:&quot;|00 A0 03 41 41 41 41 81 01 09 00 00 08 C0 01 40|&quot;; within:16; distance:64; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17579</id>
        <msg>SPECIFIC-THREATS Microsoft Office Drawing Record msofbtOPT Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>32584</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4837</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|01 49 66 01 00 00 00 08 D6 FD FF 05 D6 18 04 01 00 00 04 01|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17591</id>
        <msg>WEB-CLIENT Microsoft Word Crafted Sprm memory corruption attempt </msg>
      </rule>
      <rule>
        <bugtraq>23804</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0035</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.doc; content:&quot;|01 00 00 02 01 00 00 9E 01 00 00 02 01 00 00 96 01 00 00 FF|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17649</id>
        <msg>WEB-CLIENT Microsoft Word array data handling buffer overflow attempt </msg>
      </rule>
      <rule>
        <bugtraq>28167</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0115</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17655, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17655</id>
        <msg>WEB-CLIENT Microsoft Excel malformed formula parsing code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>36200</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0201</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17665, service http, policy security-ips drop, policy balanced-ips drop;</filter2>
        <id>17665</id>
        <msg>WEB-CLIENT OpenOffice Word document table parsing multiple heap based buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>39721</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;25745F2B-2AC9-4551-948B-574C50D4EE59&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*25745F2B-2AC9-4551-948B-574C50D4EE59\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(RegisterCom)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*25745F2B-2AC9-4551-948B-574C50D4EE59\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(RegisterCom))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17670</id>
        <msg>WEB-ACTIVEX BigAnt Office Manager ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>39721</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|5|00|7|00|4|00|5|00|F|00|2|00|B|00|-|00|2|00|A|00|C|00|9|00|-|00|4|00|5|00|5|00|1|00|-|00|9|00|4|00|8|00|B|00|-|00|5|00|7|00|4|00|C|00|5|00|0|00|D|00|4|00|E|00|E|00|5|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x005\x007\x004\x005\x00F\x002\x00B\x00-\x002\x00A\x00C\x009\x00-\x004\x005\x005\x001\x00-\x009\x004\x008\x00B\x00-\x005\x007\x004\x00C\x005\x000\x00D\x004\x00E\x00E\x005\x009\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17671</id>
        <msg>WEB-ACTIVEX BigAnt Office Manager ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>39721</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AntCore.AntConsole&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22AntCore\.AntConsole(\.\d)?\x22|\x27AntCore\.AntConsole(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*RegisterCom\s*|.*(?P=v)\s*\.\s*RegisterCom\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AntCore\.AntConsole(\.\d)?\x22|\x27AntCore\.AntConsole(\.\d)?\x27)\s*\)(\s*\.\s*RegisterCom\s*|.*(?P=n)\s*\.\s*RegisterCom\s*)/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17672</id>
        <msg>WEB-ACTIVEX BigAnt Office Manager ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>39721</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|n|00|t|00|C|00|o|00|r|00|e|00|.|00|A|00|n|00|t|00|C|00|o|00|n|00|s|00|o|00|l|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)A\x00n\x00t\x00C\x00o\x00r\x00e\x00.\x00A\x00n\x00t\x00C\x00o\x00n\x00s\x00o\x00l\x00e\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)A\x00n\x00t\x00C\x00o\x00r\x00e\x00.\x00A\x00n\x00t\x00C\x00o\x00n\x00s\x00o\x00l\x00e\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17673</id>
        <msg>WEB-ACTIVEX BigAnt Office Manager ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0565</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17690, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17690</id>
        <msg>EXPLOIT Microsoft Word remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0565</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17691, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17691</id>
        <msg>EXPLOIT Microsoft Word remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>33245</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2588</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18A295DA-088E-42D1-BE31-5028D7F9B9B5&quot;; nocase; content:&quot;targetObject.OpenWebFile|28|&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>17701</id>
        <msg>SPECIFIC-THREATS Office Viewer ActiveX arbitrary command execution attempt</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>31706</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4019</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,xml.download; content:&quot;|3D|rept|28|&quot;; nocase; pcre:&quot;/\x3ccell\s+[^\x3e]*\x3aFormula\s*\x3d\s*\x22\s*\x3drept\x28/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17734</id>
        <msg>WEB-MISC Excel REPT integer underflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0563</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17742, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17742</id>
        <msg>EXPLOIT Microsoft Word remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>29104</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17743, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17743</id>
        <msg>EXPLOIT Microsoft Word RTF parsing memory corruption</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-026.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17754, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17754</id>
        <msg>EXPLOIT Microsoft Word bookmark bound check remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-079.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17755, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17755</id>
        <msg>EXPLOIT Microsoft Word unchecked index value remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-079.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3220</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|17756, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17756</id>
        <msg>WEB-CLIENT Microsoft Word XP PLFLSInTableStream heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-079.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3230</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17757, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17757</id>
        <msg>WEB-CLIENT Microsoft Excel CrErr record integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3231</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17758, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17758</id>
        <msg>EXPLOIT Microsoft Excel PtgExtraArray data parsing vulnerability exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3239</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17759, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17759</id>
        <msg>EXPLOIT Microsoft Excel invalid SerAr object exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3240</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17760, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17760</id>
        <msg>EXPLOIT Microsoft Excel RealTimeData record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3237</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17761, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17761</id>
        <msg>WEB-CLIENT Microsoft Excel malformed MergeCells record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3232</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17762, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17762</id>
        <msg>WEB-CLIENT Microsoft Excel corrupted TABLE record clean up exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3242</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17763, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17763</id>
        <msg>EXPLOIT Microsoft Excel GhostRw record exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3235</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|17764, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17764</id>
        <msg>EXPLOIT Microsoft Excel PtgName invalid index exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-080.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3334</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|18063, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18063</id>
        <msg>WEB-CLIENT Microsoft Office embedded Office Art drawings execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-087.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3333</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|18067, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18067</id>
        <msg>WEB-CLIENT Microsoft Office RTF parsing remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-087</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3335</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|18068, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18068</id>
        <msg>EXPLOIT Microsoft Excel malformed MsoDrawingObject record attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-087.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3336</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|18069, service http, policy security-ips drop;</filter2>
        <id>18069</id>
        <msg>WEB-CLIENT Microsoft Office Art drawing invalid shape identifier attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-087.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3945</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18200, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18200</id>
        <msg>EXPLOIT Microsoft Office .CGM file cell array heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3947</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.tiff; metadata: engine shared, soid 3|18201, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18201</id>
        <msg>EXPLOIT Microsoft Office TIFF filter remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3946</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pct; metadata: engine shared, soid 3|18235, service http, policy security-ips drop;</filter2>
        <id>18235</id>
        <msg>WEB-CLIENT Microsoft Office PICT graphics converter memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3949</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.tiff; metadata: engine shared, soid 3|18236, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18236</id>
        <msg>SPECIFIC-THREATS Microsoft Office TIFFIM32.FLT filter memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1201</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E530-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E530-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4170</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0002E520-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0002E520-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4175</id>
        <msg>WEB-ACTIVEX Office 2000/2002 Web Components PivotTable ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0002E500-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0002E500-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4176</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Chart ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4453</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4695</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E510-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E510-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>4177</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Spreadsheet ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0727</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0002E531-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0002E531-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4178</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Record Navigation Control ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F28D867A-DDB1-11D3-B8E8-00A0C981AEEB&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F28D867A-DDB1-11D3-B8E8-00A0C981AEEB/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4217</id>
        <msg>WEB-ACTIVEX Microsoft Office Services on the Web Free/Busy ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;6B7F1602-D44C-11D0-A7D9-AE3D17000000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6B7F1602-D44C-11D0-A7D9-AE3D17000000/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4218</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic WebClass ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| HWPE Word Filtered Echelon LOG&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5780</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwpe word filtered echelon log</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| HWAE Word Filtered Echelon LOG&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5782</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwae word filtered echelon log</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/getlinks.php&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Iterenet Explorer&quot;; nocase; http_header; content:&quot;Host|3A| www.wordiq.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5892</id>
        <msg>SPYWARE-PUT Trackware wordiq toolbar runtime detection - get link info</msg>
        <url>www.softpedia.com/progReportSpyware/12-3-196</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/search_log.php?&quot;; nocase; http_uri; content:&quot;toolbar_id=&quot;; nocase; http_uri; content:&quot;se_id=&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Iterenet Explorer&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5893</id>
        <msg>SPYWARE-PUT Trackware wordiq toolbar runtime detection - search keyword</msg>
        <url>www.softpedia.com/progReportSpyware/12-3-196</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,GhostVoice_InitConnection_withpassword; content:&quot;request|3A|&quot;; depth:8; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5958</id>
        <msg>SPYWARE-PUT Hacker-Tool ghostvoice 1.02 runtime detection - init connection with password requirement</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073224</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gettotal.m?&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;r=rxh&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5959</id>
        <msg>SPYWARE-PUT Hijacker raxsearch detection - send search keywords to raxsearch</msg>
        <url>www.spywareguide.com/product_show.php?id=2485</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/keyword.php?&quot;; nocase; http_uri; content:&quot;installID=&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;partnerID=&quot;; nocase; http_uri; content:&quot;partnerReferID=&quot;; nocase; http_uri; content:&quot;Host|3A| searchfst.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5962</id>
        <msg>SPYWARE-PUT Hijacker searchfast detection - catch search keyword</msg>
        <url>www.spywareguide.com/product_show.php?id=1694</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/delayed.cgi?&quot;; nocase; http_uri; content:&quot;g=&quot;; nocase; http_uri; content:&quot;edata=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Mirar_KeywordContent&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5992</id>
        <msg>SPYWARE-PUT Hijacker getmirar runtime detection - get keyword-related content</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077933</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/showme.aspx?keyword=&quot;; nocase; http_uri; content:&quot;Host|3A| tv.180solutions.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6185</id>
        <msg>SPYWARE-PUT Adware 180Search assistant runtime detection - reporting keyword</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/showme.aspx?keyword=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| tv.seekmo.com&quot;; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6192</id>
        <msg>SPYWARE-PUT Adware seekmo runtime detection - reporting keyword</msg>
        <url>www.spywareguide.com/product_show.php?id=2368</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| NavExcel Search Toolbar&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6278</id>
        <msg>SPYWARE-PUT Trickler navexcel search toolbar runtime detection - activate/update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074928</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;PWD|0A|&quot;; depth:4; nocase; flowbits:set,NetDemon_Init1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6309</id>
        <msg>BACKDOOR net demon runtime detection - initial connection - password request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,NetDemon_Init1; content:&quot;PWD &quot;; nocase; pcre:&quot;/^PWD\s+[^\r\n]*\n/smi&quot;; flowbits:set,NetDemon_Init2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6310</id>
        <msg>BACKDOOR net demon runtime detection - initial connection - password send</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetDemon_Init2; content:&quot;OKPWD|0A|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6311</id>
        <msg>BACKDOOR net demon runtime detection - initial connection - password accepted</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <bugtraq>18500</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|E0 C9 EA|y|F9 BA CE 11 8C 82 00 AA 00|K|A9 0B|&quot;; byte_test:4,&gt;,3628,0,relative,little; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7002</id>
        <msg>WEB-CLIENT excel url unicode overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-037.mspx</url>
      </rule>
      <rule>
        <bugtraq>18583</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3014</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;n|DB 7C D2|m|AE CF 11 96 B8|DEST|00 00|&quot;; content:&quot;FWS&quot;; within:3; distance:8; content:&quot;javascript|3A|&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7025</id>
        <msg>WEB-CLIENT excel url unicode overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1306</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;]&quot;; content:&quot;|05|&quot;; within:8; flowbits:set,excel.object; flowbits:noalert; classtype:attempted-user;</filter2>
        <id>7047</id>
        <msg>WEB-CLIENT excel object record overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1306</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,excel.object; content:&quot;]|00|&quot;; byte_test:2,&gt;,8224,1,relative; flowbits:unset,excel.object; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7048</id>
        <msg>WEB-CLIENT excel object record overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-037.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|B8 9B 93 9D 9A A2 91 86 9D 92 8D 88|&quot;; depth:12; flowbits:set,sinique_initial_crt_client-to-server; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7087</id>
        <msg>BACKDOOR sinique 1.0 runtime detection - initial connection with correct password client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|B8 9B 93 9D 9A A2 91 86 9D 92 8D 88|&quot;; depth:12; flowbits:set,sinique_initial_wrg_client-to-server; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7089</id>
        <msg>BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password -client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1480</filter1>
        <filter2>flow:to_server,established; content:&quot;catasenha|7C|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7098</id>
        <msg>BACKDOOR remote hack 1.5 runtime detection - get password</msg>
        <url>www.spywareguide.com/product_show.php?id=1523</url>
      </rule>
      <rule>
        <bugtraq>17252</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 00 00 1D 00 0F 00 03 00 00 00|&quot;; isdataat:2,relative; content:!&quot;|00|&quot;; within:1; distance:2; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7197</id>
        <msg>WEB-CLIENT excel MSO.DLL malformed string parsing single byte buffer over attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>17252</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 00 00 1D 00 0F 00 03 00 00 00|&quot;; content:&quot;|00|&quot;; within:1; distance:2; isdataat:6,relative; content:!&quot;|00 00 00 00 00|&quot;; within:5; distance:1; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7198</id>
        <msg>WEB-CLIENT excel MSO.DLL malformed string parsing multi byte buffer over attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>28166</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0114</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|02 04|&quot;; byte_test:2,&gt;,35071,2,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7199</id>
        <msg>WEB-CLIENT excel label record overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|02 D5 CD D5 9C|.|1B 10 93 97 08 00|+,|F9 AE|&quot;; content:&quot;|1E 00 00 00 00 00 00 00|&quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7200</id>
        <msg>WEB-CLIENT microsoft word document summary information null string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|E0 85 9F F2 F9|Oh|10 AB 91 08 00|+'|B3 D9|&quot;; content:&quot;|1E 00 00 00 00 00 00 00|&quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7201</id>
        <msg>WEB-CLIENT microsoft word summary information null string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|02 D5 CD D5 9C|.|1B 10 93 97 08 00|+,|F9 AE|&quot;; content:&quot;|1E 00 00 00|&quot;; distance:0; byte_test:4,&gt;,2147483646,0,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7202</id>
        <msg>WEB-CLIENT microsoft word document summary information string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1540</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|E0 85 9F F2 F9|Oh|10 AB 91 08 00|+'|B3 D9|&quot;; content:&quot;|1E 00 00 00|&quot;; distance:0; byte_test:4,&gt;,2147483646,0,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7203</id>
        <msg>WEB-CLIENT microsoft word information string overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-038.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cn.dll?pid=&quot;; nocase; http_uri; content:&quot;met=&quot;; nocase; http_uri; content:&quot;charset=&quot;; nocase; http_uri; content:&quot;name=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;name.cnnic.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*name\x2ecnnic\x2ecn/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7517</id>
        <msg>SPYWARE-PUT Hijacker chinese keywords runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074952</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|FA CB D9 D9 E5 E1 D6|&quot;; depth:7; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7616</id>
        <msg>BACKDOOR theef 2.0 runtime detection - connection without password</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083786</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|FA CB D9 D9 DD C5 D8 CE D6|&quot;; depth:9; flowbits:set,theef20.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7617</id>
        <msg>BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,theef20.1; content:&quot;|FA CB D9 D9 EB DE DE D6 9B 98 99|&quot;; depth:11; flowbits:set,theef20.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7618</id>
        <msg>BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,theef20.2; content:&quot;|FA CB D9 D9|&quot;; depth:4; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7619</id>
        <msg>BACKDOOR theef 2.0 runtime detection - connection request with password</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083786</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; dsize:5; content:&quot;PWDok&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7785</id>
        <msg>BACKDOOR forced control uploader runtime detection - connection with password</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Navhelper&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Navhelper/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7832</id>
        <msg>SPYWARE-PUT Hijacker navexcel helper runtime detection - active/update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074928</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search?&quot;; nocase; http_uri; content:&quot;p=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;ts=&quot;; nocase; http_uri; content:&quot;Host|3A| www.trustedsearch.com&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7833</id>
        <msg>SPYWARE-PUT Hijacker navexcel helper runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074928</url>
      </rule>
      <rule>
        <bugtraq>28136</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1201</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E533-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E533-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7870</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 9.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>28136</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1201</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|3|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7871</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 9.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2002-0861</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E552-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0002E552-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7874</id>
        <msg>WEB-ACTIVEX Microsoft Office PivotTable 10.0 ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2002-0861</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|5|00|2|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x005\x002\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7875</id>
        <msg>WEB-ACTIVEX Microsoft Office PivotTable 10.0 ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>35990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0562</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E553-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E553-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7876</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 10.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>35990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0562</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|5|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x005\x003\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7877</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 10.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/go3.php&quot;; nocase; http_uri; content:&quot;key=&quot;; nocase; http_uri; content:&quot;NO=&quot;; nocase; http_uri; content:&quot;PID=&quot;; nocase; http_uri; content:&quot;UN=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; content:&quot;www.yok.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eyok\x2Ecom/smi&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8358</id>
        <msg>SPYWARE-PUT Hijacker yok supersearch runtime detection - addressbar keyword search hijack</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Yok.SuperSearch&amp;threatid=44407</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;65BCBEE4-7728-41A0-97BE-14E1CAE36AAE&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*65BCBEE4-7728-41A0-97BE-14E1CAE36AAE/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8397</id>
        <msg>WEB-ACTIVEX Microsoft Office List 11.0 ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|5|00|B|00|C|00|B|00|E|00|E|00|4|00|-|00|7|00|7|00|2|00|8|00|-|00|4|00|1|00|A|00|0|00|-|00|9|00|7|00|B|00|E|00|-|00|1|00|4|00|E|00|1|00|C|00|A|00|E|00|3|00|6|00|A|00|A|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*6\x005\x00B\x00C\x00B\x00E\x00E\x004\x00-\x007\x007\x002\x008\x00-\x004\x001\x00A\x000\x00-\x009\x007\x00B\x00E\x00-\x001\x004\x00E\x001\x00C\x00A\x00E\x003\x006\x00A\x00A\x00E\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8398</id>
        <msg>WEB-ACTIVEX Microsoft Office List 11.0 ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-3875</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;}|00 0C 00 00 00|&quot;; content:!&quot;|00|&quot;; within:1; distance:1; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8448</id>
        <msg>WEB-CLIENT Excel colinfo XF record overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-059.mspx</url>
      </rule>
      <rule>
        <bugtraq>24462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3729</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E55B-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E55B-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteRecordSourceIfUnused)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E55B-0000-0000-C000-000000000046\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteRecordSourceIfUnused))\s*\(/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8723</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX clsid access</msg>
        <url>osvdb.org/27111</url>
      </rule>
      <rule>
        <bugtraq>24462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3729</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|5|00|B|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8724</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX clsid unicode access</msg>
        <url>osvdb.org/27111</url>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5660</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E9880553-B8A7-4960-A668-95C68BED571E&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E9880553-B8A7-4960-A668-95C68BED571E\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DownloadAndExecute|AddFileEx|ExecuteRemote)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*E9880553-B8A7-4960-A668-95C68BED571E\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DownloadAndExecute|AddFileEx|ExecuteRemote))\s*\(/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8738</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX clsid access</msg>
        <url>support.installshield.com/kb/view.asp?articleid=Q113602</url>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5660</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|9|00|8|00|8|00|0|00|5|00|5|00|3|00|-|00|B|00|8|00|A|00|7|00|-|00|4|00|9|00|6|00|0|00|-|00|A|00|6|00|6|00|8|00|-|00|9|00|5|00|C|00|6|00|8|00|B|00|E|00|D|00|5|00|7|00|1|00|E|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*E\x009\x008\x008\x000\x005\x005\x003\x00-\x00B\x008\x00A\x007\x00-\x004\x009\x006\x000\x00-\x00A\x006\x006\x008\x00-\x009\x005\x00C\x006\x008\x00B\x00E\x00D\x005\x007\x001\x00E\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8739</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX clsid unicode access</msg>
        <url>support.installshield.com/kb/view.asp?articleid=Q113602</url>
      </rule>
      <rule>
        <bugtraq>31235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5660</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DWUSWebAgent.WebAgent&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22DWUSWebAgent\.WebAgent\x22|\x27DWUSWebAgent\.WebAgent\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DownloadAndExecute|AddFileEx|ExecuteRemote)\s*|.*(?P=v)\s*\.\s*(DownloadAndExecute|AddFileEx|ExecuteRemote)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22DWUSWebAgent\.WebAgent\x22|\x27DWUSWebAgent\.WebAgent\x27)\s*\)(\s*\.\s*(DownloadAndExecute|AddFileEx|ExecuteRemote)\s*|.*(?P=n)\s*\.\s*(DownloadAndExecute|AddFileEx|ExecuteRemote)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8740</id>
        <msg>WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX function call access</msg>
        <url>support.installshield.com/kb/view.asp?articleid=Q113602</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/express/sq.jsp&quot;; fast_pattern; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.sogou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Esogou\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>9645</id>
        <msg>SPYWARE-PUT Hijacker sogou runtime detection - keyword hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098380</url>
      </rule>
    </attacks>
    <groupid>310</groupid>
    <groupname>Client / Office</groupname>
    <warnings>
      <rule>
        <bugtraq>2305</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2006-1652</cve>
        <filter1>tcp $EXTERNAL_NET 5900 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 00 00 04 06|&quot;; depth:8; isdataat:1029,relative; classtype:web-application-attack;</filter2>
        <id>10087</id>
        <msg>EXPLOIT VNC password request buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23068</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6026</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:established,to_server; content:&quot;LoadTestPassword|3A|&quot;; nocase; isdataat:1024,relative; pcre:&quot;/^LoadTestPassword\x3A[^\r\n]{1024,}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>10407</id>
        <msg>EXPLOIT Helix Server LoadTestPassword buffer overflow attempt</msg>
        <url>lists.helixcommunity.org/pipermail/server-cvs/2007-January/003783.html</url>
      </rule>
      <rule>
        <bugtraq>1734</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0925</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_private/shopping_cart.mdb&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1098</id>
        <msg>WEB-MISC SmartWin CyberOffice Shopping Cart access</msg>
      </rule>
      <rule>
        <bugtraq>33283</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;18A295DA-088E-42D1-BE31-5028D7F9B9B5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*18A295DA-088E-42D1-BE31-5028D7F9B9B5\s*}?\s*(?P=q9)(\s|&gt;).*(?P=id1)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q10&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*18A295DA-088E-42D1-BE31-5028D7F9B9B5\s*}?\s*(?P=q10)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\.(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile))\s*\(/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11199</id>
        <msg>WEB-ACTIVEX Office Viewer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>33283</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;1|00|8|00|A|00|2|00|9|00|5|00|D|00|A|00|-|00|0|00|8|00|8|00|E|00|-|00|4|00|2|00|D|00|1|00|-|00|B|00|E|00|3|00|1|00|-|00|5|00|0|00|2|00|8|00|D|00|7|00|F|00|9|00|B|00|9|00|B|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q11&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*1\x008\x00A\x002\x009\x005\x00D\x00A\x00-\x000\x008\x008\x00E\x00-\x004\x002\x00D\x001\x00-\x00B\x00E\x003\x001\x00-\x005\x000\x002\x008\x00D\x007\x00F\x009\x00B\x009\x00B\x005\x00(}\x00)?(?P=q11)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11200</id>
        <msg>WEB-ACTIVEX Office Viewer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>33283</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OA.OActrl&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OA\.OActrl(\.\d)?\x22|\x27OA\.OActrl(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=v)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OA\.OActrl(\.\d)?\x22|\x27OA\.OActrl(\.\d)?\x27)\s*\)(\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*|.*(?P=n)\s*\.\s*(DoOleCommand|FTPDownloadFile|FTPUploadFile|HttpUploadFile|Save|SaveWebFile|OpenWebFile)\s*)\s*\(/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11201</id>
        <msg>WEB-ACTIVEX Office Viewer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>33283</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|A|00|.|00|O|00|A|00|c|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q12)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q13&gt;\x22|\x27|)O\x00A\x00.\x00O\x00A\x00c\x00t\x00r\x00l\x00(\.\x00\d\x00)?(?P=q13)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11202</id>
        <msg>WEB-ACTIVEX Office Viewer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html</url>
      </rule>
      <rule>
        <bugtraq>24118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2903</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8936033C-4A50-11D1-98A4-00A0C90F27C6&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8936033C-4A50-11D1-98A4-00A0C90F27C6\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(HelpPopup)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8936033C-4A50-11D1-98A4-00A0C90F27C6\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(HelpPopup))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11622</id>
        <msg>WEB-ACTIVEX Microsoft Office 2000 OUACTR ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-23-microsoft-office-2000.html</url>
      </rule>
      <rule>
        <bugtraq>24118</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2903</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|9|00|3|00|6|00|0|00|3|00|3|00|C|00|-|00|4|00|A|00|5|00|0|00|-|00|1|00|1|00|D|00|1|00|-|00|9|00|8|00|A|00|4|00|-|00|0|00|0|00|A|00|0|00|C|00|9|00|0|00|F|00|2|00|7|00|C|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11623</id>
        <msg>WEB-ACTIVEX Microsoft Office 2000 OUACTR ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-23-microsoft-office-2000.html</url>
      </rule>
      <rule>
        <bugtraq>24230</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;053AFEBA-D968-435F-B557-19FF76372B1B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*053AFEBA-D968-435F-B557-19FF76372B1B\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(DeleteLocalFile|HttpDownloadFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*053AFEBA-D968-435F-B557-19FF76372B1B\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(DeleteLocalFile|HttpDownloadFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>11660</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer ActiveX clsid access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html</url>
      </rule>
      <rule>
        <bugtraq>24230</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|5|00|3|00|A|00|F|00|E|00|B|00|A|00|-|00|D|00|9|00|6|00|8|00|-|00|4|00|3|00|5|00|F|00|-|00|B|00|5|00|5|00|7|00|-|00|1|00|9|00|F|00|F|00|7|00|6|00|3|00|7|00|2|00|B|00|1|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>11661</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer ActiveX clsid unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html</url>
      </rule>
      <rule>
        <bugtraq>24230</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EDrawOfficeViewer.EDrawOfficeViewerCtrl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EDrawOfficeViewer\.EDrawOfficeViewerCtrl\x22|\x27EDrawOfficeViewer\.EDrawOfficeViewerCtrl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(DeleteLocalFile|HttpDownloadFile)\s*|.*(?P=v)\s*\.\s*(DeleteLocalFile|HttpDownloadFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EDrawOfficeViewer\.EDrawOfficeViewerCtrl\x22|\x27EDrawOfficeViewer\.EDrawOfficeViewerCtrl\x27)\s*\)(\s*\.\s*(DeleteLocalFile|HttpDownloadFile)\s*|.*(?P=n)\s*\.\s*(DeleteLocalFile|HttpDownloadFile)\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>11662</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer ActiveX function call access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html</url>
      </rule>
      <rule>
        <bugtraq>24230</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|D|00|r|00|a|00|w|00|O|00|f|00|f|00|i|00|c|00|e|00|V|00|i|00|e|00|w|00|e|00|r|00|.|00|E|00|D|00|r|00|a|00|w|00|O|00|f|00|f|00|i|00|c|00|e|00|V|00|i|00|e|00|w|00|e|00|r|00|C|00|t|00|r|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00D\x00r\x00a\x00w\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00.\x00E\x00D\x00r\x00a\x00w\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00C\x00t\x00r\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00D\x00r\x00a\x00w\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00.\x00E\x00D\x00r\x00a\x00w\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00C\x00t\x00r\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11663</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer ActiveX function call unicode access</msg>
        <url>moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html</url>
      </rule>
      <rule>
        <bugtraq>1057</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/officescan/cgi/jdkRqNotify.exe&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1192</id>
        <msg>WEB-MISC Trend Micro OfficeScan access</msg>
      </rule>
      <rule>
        <bugtraq>24462</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3729</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|W|00|C|00|1|00|1|00|.|00|D|00|a|00|t|00|a|00|S|00|o|00|u|00|r|00|c|00|e|00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)O\x00W\x00C\x001\x001\x00.\x00D\x00a\x00t\x00a\x00S\x00o\x00u\x00r\x00c\x00e\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)O\x00W\x00C\x001\x001\x00.\x00D\x00a\x00t\x00a\x00S\x00o\x00u\x00r\x00c\x00e\x00C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>11967</id>
        <msg>WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX function call unicode access</msg>
        <url>osvdb.org/27111</url>
      </rule>
      <rule>
        <bugtraq>24801</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1756</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;|09 08 10 00|&quot;; fast_pattern:only; pcre:&quot;/\x09\x08\x10\x00\x00[\x00\x01\x07-\xff]/sm&quot;; classtype:attempted-user;</filter2>
        <id>12070</id>
        <msg>EXPLOIT Microsoft Excel malformed version field</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>22555</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3029</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.xls; content:&quot;|FF FF FF FF FF FF FF FF 09 08|&quot;; content:&quot;|00 00|&quot;; within:2; distance:1; content:&quot;|05 00|&quot;; within:2; distance:1; pcre:&quot;/\x3d\x00\x12\x00..........(.[\x80-\xff]|...[\x80-\xff])/smiR&quot;; classtype:attempted-user;</filter2>
        <id>12099</id>
        <msg>MISC Microsoft Excel rtWindow1 record handling arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>24803</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3030</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.xls; content:&quot;|FF FF FF FF FF FF FF FF 09 08|&quot;; fast_pattern:only; pcre:&quot;/\xff{8}\x09\x08[\x08\x10]\x00\x00[\x05\x06]\x00\x01/sm&quot;; classtype:attempted-user;</filter2>
        <id>12184</id>
        <msg>MISC Microsoft Excel workbook workspace designation handling arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-036.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Theef210_Connectionwithnopassword; content:&quot;|FC CF D8 D6 98 84 9B 9A|&quot;; depth:8; classtype:trojan-activity;</filter2>
        <id>12234</id>
        <msg>BACKDOOR theef 2.10 runtime detection - connect with no password</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-071209-4425-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Theef210_Connectionwithpassword; content:&quot;|FA CB D9 D9 EB DE DE D6|&quot;; depth:8; classtype:trojan-activity;</filter2>
        <id>12236</id>
        <msg>BACKDOOR theef 2.10 runtime detection - connect with password</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-071209-4425-99</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0DDF3B5C-E692-11D1-AB06-00AA00BDD685&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0DDF3B5C-E692-11D1-AB06-00AA00BDD685\s*}?\s*(?P=q1)(\s|&gt;)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12261</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|D|00|D|00|F|00|3|00|B|00|5|00|C|00|-|00|E|00|6|00|9|00|2|00|-|00|1|00|1|00|D|00|1|00|-|00|A|00|B|00|0|00|6|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|D|00|D|00|6|00|8|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12262</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PDWizard.File&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22PDWizard\.File\x22|\x27PDWizard\.File\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22PDWizard\.File\x22|\x27PDWizard\.File\x27)\s*\)/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12263</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;P|00|D|00|W|00|i|00|z|00|a|00|r|00|d|00|.|00|F|00|i|00|l|00|e|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00F\x00i\x00l\x00e\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)P\x00D\x00W\x00i\x00z\x00a\x00r\x00d\x00.\x00F\x00i\x00l\x00e\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12264</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8B217752-717D-11CE-AB5B-D41203C10000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q5&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8B217752-717D-11CE-AB5B-D41203C10000\s*}?\s*(?P=q5)(\s|&gt;)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12265</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|B|00|2|00|1|00|7|00|7|00|5|00|2|00|-|00|7|00|1|00|7|00|D|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|5|00|B|00|-|00|D|00|4|00|1|00|2|00|0|00|3|00|C|00|1|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q6&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q6)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12266</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TLI.SearchHelper&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TLI\.SearchHelper\x22|\x27TLI\.SearchHelper\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TLI\.SearchHelper\x22|\x27TLI\.SearchHelper\x27)\s*\)/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12267</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|L|00|I|00|.|00|S|00|e|00|a|00|r|00|c|00|h|00|H|00|e|00|l|00|p|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q7&gt;\x22|\x27|)T\x00L\x00I\x00.\x00S\x00e\x00a\x00r\x00c\x00h\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q7)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q8&gt;\x22|\x27|)T\x00L\x00I\x00.\x00S\x00e\x00a\x00r\x00c\x00h\x00H\x00e\x00l\x00p\x00e\x00r\x00(?P=q8)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12268</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8B21775E-717D-11CE-AB5B-D41203C10000&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8B21775E-717D-11CE-AB5B-D41203C10000\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(TypeLibInfoFromFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8B21775E-717D-11CE-AB5B-D41203C10000\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(TypeLibInfoFromFile))\s*\(/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12269</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|B|00|2|00|1|00|7|00|7|00|5|00|E|00|-|00|7|00|1|00|7|00|D|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|5|00|B|00|-|00|D|00|4|00|1|00|2|00|0|00|3|00|C|00|1|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12270</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TLI.TLIApplication&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TLI\.TLIApplication\x22|\x27TLI\.TLIApplication\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*TypeLibInfoFromFile\s*|.*(?P=v)\s*\.\s*TypeLibInfoFromFile\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TLI\.TLIApplication\x22|\x27TLI\.TLIApplication\x27)\s*\)(\s*\.\s*TypeLibInfoFromFile\s*|.*(?P=n)\s*\.\s*TypeLibInfoFromFile\s*)\s*\(/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12271</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|L|00|I|00|.|00|T|00|L|00|I|00|A|00|p|00|p|00|l|00|i|00|c|00|a|00|t|00|i|00|o|00|n|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)T\x00L\x00I\x00.\x00T\x00L\x00I\x00A\x00p\x00p\x00l\x00i\x00c\x00a\x00t\x00i\x00o\x00n\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)T\x00L\x00I\x00.\x00T\x00L\x00I\x00A\x00p\x00p\x00l\x00i\x00c\x00a\x00t\x00i\x00o\x00n\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12272</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8B217746-717D-11CE-AB5B-D41203C10000&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*8B217746-717D-11CE-AB5B-D41203C10000\s*}?\s*(?P=q13)(\s|&gt;)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12273</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8|00|B|00|2|00|1|00|7|00|7|00|4|00|6|00|-|00|7|00|1|00|7|00|D|00|-|00|1|00|1|00|C|00|E|00|-|00|A|00|B|00|5|00|B|00|-|00|D|00|4|00|1|00|2|00|0|00|3|00|C|00|1|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q14&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q14)(?=\s\x00|&gt;\x00)/Osi&quot;; classtype:attempted-user;</filter2>
        <id>12274</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;TLI.TypeLibInfo&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22TLI\.TypeLibInfo\x22|\x27TLI\.TypeLibInfo\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22TLI\.TypeLibInfo\x22|\x27TLI\.TypeLibInfo\x27)\s*\)/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12275</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;T|00|L|00|I|00|.|00|T|00|y|00|p|00|e|00|L|00|i|00|b|00|I|00|n|00|f|00|o|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q15&gt;\x22|\x27|)T\x00L\x00I\x00.\x00T\x00y\x00p\x00e\x00L\x00i\x00b\x00I\x00n\x00f\x00o\x00(?P=q15)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)T\x00L\x00I\x00.\x00T\x00y\x00p\x00e\x00L\x00i\x00b\x00I\x00n\x00f\x00o\x00(?P=q16)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12276</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3890</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;8|00 04 00|&quot;; byte_test:2,&gt;,32767,0,relative,little; flowbits:isset,xlw.download; classtype:attempted-user;</filter2>
        <id>12284</id>
        <msg>WEB-CLIENT Excel rtWnDesk record memory corruption exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/ms07-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>25892</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4821</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6BA21C22-53A5-463F-BBE8-5CF7FFA0132B&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6BA21C22-53A5-463F-BBE8-5CF7FFA0132B\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6BA21C22-53A5-463F-BBE8-5CF7FFA0132B\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile))\s*\(/si&quot;; classtype:attempted-user;</filter2>
        <id>12430</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer Component ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25892</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4821</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|B|00|A|00|2|00|1|00|C|00|2|00|2|00|-|00|5|00|3|00|A|00|5|00|-|00|4|00|6|00|3|00|F|00|-|00|B|00|B|00|E|00|8|00|-|00|5|00|C|00|F|00|7|00|F|00|F|00|A|00|0|00|1|00|3|00|2|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>12431</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer Component ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25892</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4821</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;EDraw.OfficeViewer&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22EDraw\.OfficeViewer\x22|\x27EDraw\.OfficeViewer\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile)\s*|.*(?P=v)\s*\.\s*(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22EDraw\.OfficeViewer\x22|\x27EDraw\.OfficeViewer\x27)\s*\)(\s*\.\s*(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile)\s*|.*(?P=n)\s*\.\s*(HttpDownloadFile|HttpDownloadFileToTempDir|FtpDownloadFile)\s*)\s*\(/smi&quot;; classtype:attempted-user;</filter2>
        <id>12432</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer Component ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25892</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4821</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;E|00|D|00|r|00|a|00|w|00|.|00|O|00|f|00|f|00|i|00|c|00|e|00|V|00|i|00|e|00|w|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)E\x00D\x00r\x00a\x00w\x00.\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)E\x00D\x00r\x00a\x00w\x00.\x00O\x00f\x00f\x00i\x00c\x00e\x00V\x00i\x00e\x00w\x00e\x00r\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; classtype:attempted-user;</filter2>
        <id>12433</id>
        <msg>WEB-ACTIVEX EDraw Office Viewer Component ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25629</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4776</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;Reference&quot;; nocase; pcre:&quot;/^Reference\s*=\s*\*\x5CG\{[A-Z\d-]{36}\}\x23\d+\.\d+\x23\d+\x23[^\r\n]{474}/smi&quot;; classtype:attempted-user;</filter2>
        <id>12618</id>
        <msg>WEB-CLIENT Microsoft Visual Basic VBP file reference overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/q/qry.phtml?&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;cx=&quot;; nocase; http_uri; content:&quot;cxv=&quot;; nocase; http_uri; content:&quot;qs=&quot;; nocase; http_uri; content:&quot;get=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13277</id>
        <msg>SPYWARE-PUT Adware netword agent runtime detection</msg>
        <url>www.symantec.com/fr/fr/security_response/writeup.jsp?docid=2006-042614-1031-99</url>
      </rule>
      <rule>
        <bugtraq>4453</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4695</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|1|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>13467</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Spreadsheet ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>4449</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1201</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|3|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; classtype:attempted-user;</filter2>
        <id>13468</id>
        <msg>WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS02-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0109</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.doc; metadata: engine shared, soid 3|13469;</filter2>
        <id>13469</id>
        <msg>WEB-CLIENT Microsoft Word ole stream memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-009.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/kwordenter.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;ver=KW&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;vb&quot;; nocase; http_header; content:&quot;wininet&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*vb\s+wininet/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13556</id>
        <msg>SPYWARE-PUT Hijacker kword interkey runtime detection - search traffic 1</msg>
        <url>www.noadware.net/research/index2.php?item_id=2656&amp;item_name=Kword.InterKey</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.asp?&quot;; nocase; http_uri; content:&quot;fcode=&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; content:&quot;part=&quot;; nocase; http_uri; content:&quot;Host|3A| search.kword.co.kr&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13557</id>
        <msg>SPYWARE-PUT Hijacker kword interkey runtime detection - search traffic 2</msg>
        <url>www.noadware.net/research/index2.php?item_id=2656&amp;item_name=Kword.InterKey</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dwi_log/catch?&quot;; fast_pattern; nocase; http_uri; content:&quot;C=&quot;; nocase; http_uri; content:&quot;V=&quot;; nocase; http_uri; content:&quot;E=&quot;; nocase; http_uri; content:&quot;R=&quot;; nocase; http_uri; content:&quot;www.kword.co.kr&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>13558</id>
        <msg>SPYWARE-PUT Hijacker kword interkey runtime detection - log user info</msg>
        <url>www.noadware.net/research/index2.php?item_id=2656&amp;item_name=Kword.InterKey</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0081</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13569;</filter2>
        <id>13569</id>
        <msg>WEB-CLIENT Microsoft Excel macro validation arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4695</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13580;</filter2>
        <id>13580</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components remote code execution attempt ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4695</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13581;</filter2>
        <id>13581</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components remote code execution attempt ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-017.mspx</url>
      </rule>
      <rule>
        <bugtraq>1057</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/officescan/cgi/jdkRqNotify.exe?&quot;; nocase; http_uri; content:&quot;domain=&quot;; nocase; http_uri; content:&quot;event=&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1381</id>
        <msg>WEB-MISC Trend Micro OfficeScan attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3460</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13958;</filter2>
        <id>13958</id>
        <msg>WEB-CLIENT WordPerfect Graphics file invalid RLE buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4256</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15089;</filter2>
        <id>15089</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4256</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15091;</filter2>
        <id>15091</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15093;</filter2>
        <id>15093</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15095;</filter2>
        <id>15095</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4253</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15097;</filter2>
        <id>15097</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4253</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15099;</filter2>
        <id>15099</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15101;</filter2>
        <id>15101</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15103;</filter2>
        <id>15103</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4251</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15119;</filter2>
        <id>15119</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4251</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15121;</filter2>
        <id>15121</id>
        <msg>WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-070.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0560</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|15539, service http;</filter2>
        <id>15539</id>
        <msg>WEB-CLIENT Microsoft Office Excel Formula record remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-021.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|0A FF|WPC&quot;; content:&quot;|01 0A 02 01|&quot;; within:4; distance:4; metadata:service http; classtype:misc-activity;</filter2>
        <id>15575</id>
        <msg>WEB-CLIENT WordPerfect file download</msg>
        <url>www.corelconnected.com/html/files/WPFF_%21DocumentStructure.htm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2496</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15686;</filter2>
        <id>15686</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2496</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15688;</filter2>
        <id>15688</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15690;</filter2>
        <id>15690</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15692;</filter2>
        <id>15692</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OWC10.Spreadsheet&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OWC10\.Spreadsheet(\.\d)?\x22|\x27OWC10\.Spreadsheet(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OWC10\.Spreadsheet(\.\d)?\x22|\x27OWC10\.Spreadsheet(\.\d)?\x27)\s*\)/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15855</id>
        <msg>WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|W|00|C|00|1|00|0|00|.|00|S|00|p|00|r|00|e|00|a|00|d|00|s|00|h|00|e|00|e|00|t|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)O\x00W\x00C\x001\x000\x00.\x00S\x00p\x00r\x00e\x00a\x00d\x00s\x00h\x00e\x00e\x00t\x00(\.\x00\d\x00)?(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)O\x00W\x00C\x001\x000\x00.\x00S\x00p\x00r\x00e\x00a\x00d\x00s\x00h\x00e\x00e\x00t\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15856</id>
        <msg>WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1534</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E512-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E512-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(htmlurl)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E512-0000-0000-C000-000000000046\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(htmlurl))\s*=/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15858</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components Spreadsheet ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1534</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|1|00|2|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x001\x002\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15859</id>
        <msg>WEB-ACTIVEX Microsoft Office Web Components Spreadsheet ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-0028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|02 00 09 00 00 00 02 00|@|00 00 03 00 05 00 09 00 FF FF FF FF|A|15 00 01 00 05 00 09 00 01 00|&quot;; classtype:attempted-user;</filter2>
        <id>16059</id>
        <msg>EXPLOIT Microsoft Excel malformed file format parsing code execution attempt </msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-012.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-3134</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.xls; metadata: engine shared, soid 3|16228;</filter2>
        <id>16228</id>
        <msg>WEB-CLIENT Microsoft Excel malformed StartObject record arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-067.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16650;</filter2>
        <id>16650</id>
        <msg>WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 1</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16651;</filter2>
        <id>16651</id>
        <msg>WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16652;</filter2>
        <id>16652</id>
        <msg>WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 3</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16653;</filter2>
        <id>16653</id>
        <msg>WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 4</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1250</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16654;</filter2>
        <id>16654</id>
        <msg>WEB-CLIENT Microsoft Excel undocumented Publisher record heap buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1251</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16655;</filter2>
        <id>16655</id>
        <msg>WEB-CLIENT Microsoft Excel Lbl record stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1252</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16656;</filter2>
        <id>16656</id>
        <msg>WEB-CLIENT Microsoft Excel BIFF5 ExternSheet record stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1253</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16657;</filter2>
        <id>16657</id>
        <msg>WEB-CLIENT Microsoft Excel DBQueryExt record memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2562</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17134;</filter2>
        <id>17134</id>
        <msg>WEB-CLIENT Microsoft Excel out-of-bounds structure read memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-057.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2238</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.emf; content:&quot;|00 00 00 54|&quot;; byte_test:4,&gt;,2147483647,43,relative,little; classtype:attempted-user;</filter2>
        <id>17388</id>
        <msg>WEB-CLIENT OpenOffice EMF file EMR record parsing integer overflow attempt</msg>
        <url>www.openoffice.org/security/cves/CVE-2008-2238.html</url>
      </rule>
      <rule>
        <bugtraq>32618</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4265</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;]|00|&quot;; content:&quot;|15|&quot;; distance:0; byte_test:2,&gt;,30,2,relative; content:&quot;|04 01 BF 00 08 00 08 00 81 01 09 00 00 08 83 01|&quot;; content:&quot;|4D 00 00 08 BF 01 10 00 10 00 C0 01 17 00 00 08|&quot;; within:16; classtype:attempted-user;</filter2>
        <id>17532</id>
        <msg>SPECIFIC-THREATS Microsoft Excel TXO and OBJ Records Parsing Stack Memory Corruption</msg>
      </rule>
      <rule>
        <bugtraq>17378</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2006-1652</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5800</filter1>
        <filter2>flow:to_server,established; content:&quot;GET &quot;; depth:4; isdataat:1029,relative; content:!&quot;|0A|&quot;; within:1024; classtype:web-application-attack;</filter2>
        <id>17708</id>
        <msg>EXPLOIT VNC password request URL buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;word.onlinephilbert42f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18049</id>
        <msg>PHISHING-SPAM word.onlinephilbert42f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>default-login-attempt</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9090</filter1>
        <filter2>flow:to_server,established; content:&quot;/servlet/admin&quot;; content:&quot;ae9f86d6beaa3f9ecb9a5b7e072a4138&quot;; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>1859</id>
        <msg>WEB-MISC Sun JavaServer default password login attempt</msg>
        <nessus>10995</nessus>
      </rule>
      <rule>
        <classtype>default-login-attempt</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A|&quot;; nocase; http_header; pcre:&quot;/^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s+OmFkbWlu/smiH&quot;; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>1860</id>
        <msg>WEB-MISC Linksys router default password login attempt</msg>
        <nessus>10999</nessus>
      </rule>
      <rule>
        <classtype>default-login-attempt</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;YWRtaW46YWRtaW4&quot;; pcre:&quot;/^Authorization\x3a\s*Basic\s+(?-i)YWRtaW46YWRtaW4[=\s]/smi&quot;; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>1861</id>
        <msg>WEB-MISC Linksys router default username and password login attempt</msg>
        <nessus>10999</nessus>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2027</id>
        <msg>RPC yppasswd old password overflow attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2028</id>
        <msg>RPC yppasswd old password overflow attempt TCP</msg>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:12; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2029</id>
        <msg>RPC yppasswd new password overflow attempt UDP</msg>
      </rule>
      <rule>
        <bugtraq>2763</bugtraq>
        <classtype>rpc-portmap-decode</classtype>
        <cve>2001-0779</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 86 A9|&quot;; depth:4; offset:16; content:&quot;|00 00 00 01|&quot;; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_jump:4,0,relative,align; byte_jump:4,0,relative,align; byte_test:4,&gt;,64,0,relative; content:&quot;|00 00 00 00|&quot;; depth:4; offset:8; metadata:service sunrpc; classtype:rpc-portmap-decode;</filter2>
        <id>2030</id>
        <msg>RPC yppasswd new password overflow attempt TCP</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 512</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; content:&quot;|00|&quot;; distance:33; content:&quot;|00|&quot;; distance:0; classtype:attempted-admin;</filter2>
        <id>2114</id>
        <msg>RSERVICES rexec password overflow attempt</msg>
      </rule>
      <rule>
        <classtype>default-login-attempt</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A|&quot;; nocase; http_header; content:&quot;YWRtaW46cGFzc3dvcmQ&quot;; nocase; http_header; pcre:&quot;/^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s+YWRtaW46cGFzc3dvcmQ/smiH&quot;; metadata:service http; classtype:default-login-attempt;</filter2>
        <id>2230</id>
        <msg>WEB-MISC NetGear router default password login attempt admin/password</msg>
        <nessus>11737</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2000-0138</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 27665</filter1>
        <filter2>flow:established,to_server; content:&quot;betaalmostdone&quot;; classtype:attempted-dos;</filter2>
        <id>233</id>
        <msg>DDOS Trin00 Attacker to Master default startup password</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2000-0138</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 27665</filter1>
        <filter2>flow:established,to_server; content:&quot;gOrave&quot;; classtype:attempted-dos;</filter2>
        <id>234</id>
        <msg>DDOS Trin00 Attacker to Master default password</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <cve>2000-0138</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 27665</filter1>
        <filter2>flow:established,to_server; content:&quot;killme&quot;; classtype:bad-unknown;</filter2>
        <id>235</id>
        <msg>DDOS Trin00 Attacker to Master default mdie password</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2000-0138</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27444</filter1>
        <filter2>flow:to_server; content:&quot;l44adsl&quot;; classtype:attempted-dos;</filter2>
        <id>237</id>
        <msg>DDOS Trin00 Master to Daemon default password attempt</msg>
      </rule>
      <rule>
        <bugtraq>9766</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.pl&quot;; http_uri; content:&quot;st=&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>2408</id>
        <msg>WEB-MISC Invision Power Board search.pl access</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1417</filter1>
        <filter2>flow:to_server,established; content:&quot;|05 00|&gt;&quot;; depth:16; classtype:bad-unknown;</filter2>
        <id>505</id>
        <msg>MISC Insecure TIMBUKTU Password</msg>
      </rule>
      <rule>
        <bugtraq>17978</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-2369</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [5800,5900:5999]</filter1>
        <filter2>flow:to_server,established; flowbits:isset,vnc.server.auth.types; flowbits:unset,vnc.server.auth.types; dsize:1; byte_test:1,=,1,0; classtype:attempted-admin;</filter2>
        <id>6471</id>
        <msg>EXPLOIT RealVNC password authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>18872</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3431</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|93 02|&quot;; byte_test:2,&gt;,733,4,relative,little; classtype:attempted-user;</filter2>
        <id>7024</id>
        <msg>WEB-CLIENT excel style handling overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-059.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sinique_initial_crt_client-to-server; content:&quot;|B8 9B 93 9D 9A A2 91 86 9D 92 9D 91 90|&quot;; depth:13; classtype:trojan-activity;</filter2>
        <id>7088</id>
        <msg>BACKDOOR sinique 1.0 runtime detection - initial connection with correct password server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sinique_initial_wrg_client-to-server; content:&quot;|B8 9B 93 9D 9A B2 95 9D 98 91 90|&quot;; depth:11; classtype:trojan-activity;</filter2>
        <id>7090</id>
        <msg>BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077730</url>
      </rule>
      <rule>
        <bugtraq>18886</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1306</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;]|00|&quot;; content:&quot;|15|&quot;; distance:0; byte_test:2,&gt;,30,2,relative; classtype:attempted-user;</filter2>
        <id>7204</id>
        <msg>WEB-CLIENT excel object ftCmo overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18890</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1308</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xls; content:&quot;|9C 00|&quot;; byte_test:2,&gt;,14,2,relative; classtype:attempted-user;</filter2>
        <id>7205</id>
        <msg>WEB-CLIENT excel FngGroupCount record overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0002E551-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0002E551-0000-0000-C000-000000000046\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>7872</id>
        <msg>WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1136</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|2|00|E|00|5|00|5|00|1|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x002\x00E\x005\x005\x001\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>7873</id>
        <msg>WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-043.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>22085</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.gif; content:&quot;GIF&quot;; byte_test:1,!&amp;,128,7,relative; content:&quot;,&quot;; within:1; distance:10; content:&quot;|00 00|&quot;; within:2; distance:4; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10062</id>
        <msg>WEB-CLIENT Java Virtual Machine malformed GIF buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14242</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2265</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;InstallVersion&quot;; nocase; content:&quot;compareTo&quot;; distance:0; nocase; pcre:&quot;/InstallVersion\s*\x29?\s*\.\s*compareTo/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10131</id>
        <msg>WEB-CLIENT mozilla compareTo arbitrary code execution attempt</msg>
        <url>www.mozilla.org/security/announce/2005/mfsa2005-50.html</url>
      </rule>
      <rule>
        <bugtraq>23771</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0944</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;colgroup&quot;; nocase; content:&quot;delete&quot;; distance:0; nocase; pcre:&quot;/&lt;colgroup\s+[^&gt;]*id\s*=\s*(?P&lt;q1&gt;\x22|\x27|)(?P&lt;q2&gt;\w+)(?P=q1)[^&gt;]*&gt;.*\s+(?P=q2)\.delete/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11257</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer colgroup tag uninitialized memory corruption vulnerability</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <bugtraq>24165</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2881</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1080</filter1>
        <filter2>flow:to_server,established; content:&quot;|05 01|&quot;; depth:2; content:&quot;|03|&quot;; within:1; distance:1; byte_test:1,&gt;,136,0,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>11680</id>
        <msg>MISC Sun Java web proxy sockd buffer overflow attempt</msg>
        <url>sunsolve.sun.com/search/document.do?assetkey=1-26-102927-1</url>
      </rule>
      <rule>
        <bugtraq>22966</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2007-1752</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ieframe.dll/navcancl.htm|23|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>11834</id>
        <msg>WEB-MISC Internet Explorer navcancl.htm url spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>25734</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5019</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5852F5ED-8BF4-11D4-A245-0080C6F74284&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5852F5ED-8BF4-11D4-A245-0080C6F74284\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(dnsResolve)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*5852F5ED-8BF4-11D4-A245-0080C6F74284\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(dnsResolve))\s*\(/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12472</id>
        <msg>WEB-ACTIVEX Sun Java Web Start ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>25734</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5019</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;5|00|8|00|5|00|2|00|F|00|5|00|E|00|D|00|-|00|8|00|B|00|F|00|4|00|-|00|1|00|1|00|D|00|4|00|-|00|A|00|2|00|4|00|5|00|-|00|0|00|0|00|8|00|0|00|C|00|6|00|F|00|7|00|4|00|2|00|8|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12473</id>
        <msg>WEB-ACTIVEX Sun Java Web Start ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>25734</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5019</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;JavaWebStart.isInstalled&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22JavaWebStart\.isInstalled\x22|\x27JavaWebStart\.isInstalled\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*dnsResolve\s*|.*(?P=v)\s*\.\s*dnsResolve\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22JavaWebStart\.isInstalled\x22|\x27JavaWebStart\.isInstalled\x27)\s*\)(\s*\.\s*dnsResolve\s*|.*(?P=n)\s*\.\s*dnsResolve\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12474</id>
        <msg>WEB-ACTIVEX Sun Java Web Start ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>25734</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5019</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;J|00|a|00|v|00|a|00|W|00|e|00|b|00|S|00|t|00|a|00|r|00|t|00|.|00|i|00|s|00|I|00|n|00|s|00|t|00|a|00|l|00|l|00|e|00|d|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)J\x00a\x00v\x00a\x00W\x00e\x00b\x00S\x00t\x00a\x00r\x00t\x00.\x00i\x00s\x00I\x00n\x00s\x00t\x00a\x00l\x00l\x00e\x00d\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)J\x00a\x00v\x00a\x00W\x00e\x00b\x00S\x00t\x00a\x00r\x00t\x00.\x00i\x00s\x00I\x00n\x00s\x00t\x00a\x00l\x00l\x00e\x00d\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12475</id>
        <msg>WEB-ACTIVEX Sun Java Web Start ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-1544</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|13834, service http, policy security-ips drop;</filter2>
        <id>13834</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer request header overwrite</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-031.mspx</url>
      </rule>
      <rule>
        <bugtraq>28448</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;iframe&quot;; nocase; content:&quot;iframe.contentDocument.designMode&quot;; nocase; content:&quot;addEventListener&quot;; nocase; pcre:&quot;/addEventListener\s*\(\s*(?P&lt;q&gt;\x22|\x27|)(mouse(move|down)|keydown)(?P=q)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13838</id>
        <msg>WEB-CLIENT Mozilla Firefox IFRAME style change handling code execution</msg>
        <url>www.mozilla.org/security/announce/2008/mfsa2008-15.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13960, service http, policy security-ips drop;</filter2>
        <id>13960</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer static text range overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-045.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-2258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|13961, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13961</id>
        <msg>WEB-CLIENT Internet Explorer table layout access violation vulnerability</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2259</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13963, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13963</id>
        <msg>WEB-CLIENT Internet Explorer argument validation in print preview handling vulnerability</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-045.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1681</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 898</filter1>
        <filter2>flow:to_server,established; content:&quot;com.sun.management.viperimpl.services.authentication.AuthenticationPrincipal&quot;; fast_pattern:only; content:&quot;UserDesc&quot;; nocase; content:&quot;t|00|&quot;; distance:0; isdataat:100,relative; content:&quot;%&quot;; within:50; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>14615</id>
        <msg>EXPLOIT Sun Java web console format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>28083</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;?xml&quot;; nocase; content:&quot;encoding&quot;; distance:0; nocase; pcre:&quot;/^&lt;\x3Fxml[^&gt;]+?encoding\s*=\s*(\x22[^\x22]{28}|\x27[^\x27]{28})/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15081</id>
        <msg>WEB-CLIENT Sun Java Web Start xml encoding buffer overflow attempt</msg>
        <url>sunsolve.sun.com/search/document.do?assetkey=1-66-233323-1</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4261</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15114, policy security-ips drop;</filter2>
        <id>15114</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer embed src buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <bugtraq>32721</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4844</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;datasrc&quot;; distance:0; nocase; content:&quot;datafld&quot;; nocase; pcre:&quot;/&lt;(?P&lt;t1&gt;button|div|input[^&gt;]+?type\s*=\s*(\x22|\x27)button(\x22|\x27)|label|legend|marquee|param|span)\s+[^&gt;]*(datasrc\s*=\s*(?P&lt;q1&gt;\x22|\x27|)(?P&lt;d1&gt;\S+)(?P=q1)\s+[^&gt;]*datafld\s*=\s*(?P&lt;q2&gt;\x22|\x27|)(?P&lt;d2&gt;\S+)(?P=q2)|datafld\s*=\s*(?P&lt;q3&gt;\x22|\x27|)(?P&lt;d3&gt;\S+)(?P=q3)\s+[^&gt;]*datasrc\s*=\s*(?P&lt;q4&gt;\x22|\x27|)(?P&lt;d4&gt;\S+)(?P=q4))[^&gt;]*&gt;(?!.*?&lt;\/\s*(?P=t1)\s*&gt;.*?&lt;(?P=t1)).*?&lt;(?P=t1)\s+[^&gt;]*(datasrc\s*=\s*(?P&lt;q5&gt;\x22|\x27|)((?P=d1)|(?P=d3))(?P=q5)\s+datafld\s*=\s*(?P&lt;q6&gt;\x22|\x27|)((?P=d2)|(?P=d4))(?P=q6)|(datafld\s*=\s*(?P&lt;q7&gt;\x22|\x27|)(?P=d1)(?P=q7)\s+datasrc\s*=\s*(?P&lt;q8&gt;\x22|\x27|)(?P=d2)(?P=q8)))/Osi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15126</id>
        <msg>WEB-CLIENT Internet Explorer nested tag memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-078.mspx</url>
      </rule>
      <rule>
        <bugtraq>24242</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2867</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document.getElementById|28 22|path|22 29|.pathSegList.getItem|28|-1|29|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15164</id>
        <msg>SPECIFIC-THREATS Mozilla Products SVG Layout Engine Index Parameter memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|89|PNG|0D 0A 1A 0A 00 00 00 0D|IHDR|00 00 80 00 00 00 80 00 08 06 00 00 01 B3|{|93|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15191</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox animated PNG processing integer overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.class&quot;; nocase; http_uri; flowbits:set,java_class_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15237</id>
        <msg>WEB-MISC Java .class file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>23608</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2175</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,java_class_file.request; content:&quot;toQTPointer&quot;; content:&quot;quicktime/util/QTPointerRef&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15238</id>
        <msg>SPECIFIC-THREATS Apple QuickTime for Java toQTPointer function memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0081</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,emf.request; metadata: engine shared, soid 3|15300, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15300</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer EMF polyline overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-006.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0075</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15304, service http, policy balanced-ips alert, policy security-ips alert;</filter2>
        <id>15304</id>
        <msg>WEB-CLIENT Internet Explorer object clone deletion memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-002.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0076</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15305, service http, policy security-ips alert;</filter2>
        <id>15305</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer dynamic style update memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-002.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;String.fromCharCode|28|&quot;; nocase; content:&quot;String.fromCharCode|28|&quot;; within:100; nocase; content:&quot;String.fromCharCode|28|&quot;; within:100; nocase; content:&quot;String.fromCharCode|28|&quot;; within:100; nocase; content:&quot;String.fromCharCode|28|&quot;; within:100; nocase; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15362</id>
        <msg>WEB-CLIENT obfuscated javascript excessive fromCharCode - potential attack</msg>
        <url>www.cs.ucsb.edu/~marco/blog/2008/10/dom-based-obfuscation-in-malicious-javascript.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;eval|28|&quot;; nocase; content:&quot;unescape|28|&quot;; within:15; nocase; content:!&quot;|29|&quot;; within:250; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15363</id>
        <msg>WEB-CLIENT Potential obfuscated javascript eval unescape attack attempt</msg>
        <url>www.cs.ucsb.edu/~marco/blog/2008/10/dom-based-obfuscation-in-malicious-javascript.html</url>
      </rule>
      <rule>
        <bugtraq>26132</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5339</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;XUL_NS&quot;; content:&quot;child.parentNode.removeChild&quot;; distance:0; content:&quot;onselect=|22|deleteChild|28|event.originalTarget|29|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15383</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox XBL Event Handler Tags Removal memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>33990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0771</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,svg_file.request; content:&quot;getElementsByTagName&quot;; content:&quot;pathSegList&quot;; content:&quot;createSVGPathSegMoveto&quot;; fast_pattern; nocase; content:&quot;appendItem&quot;; distance:1; content:&quot;replaceItem&quot;; distance:1; pcre:&quot;/(?P&lt;N1&gt;[a-zA-Z\x5f][a-zA-Z\x5f0-9]*\x2e)appendItem(?!.+?(?P=N1)appendItem).+?(?P=N1)replaceItem/s&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15428</id>
        <msg>WEB-CLIENT Mozilla Firefox SVG data processing memory corruption attempt</msg>
        <url>www.mozilla.org/security/announce/2009/mfsa2009-07.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0551</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15458, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15458</id>
        <msg>EXPLOIT Internet Explorer navigating between pages race condition attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0552</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15459, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15459</id>
        <msg>EXPLOIT Internet Explorer deleted/unitialized object memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0553</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15460, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15460</id>
        <msg>EXPLOIT Internet Explorer ActiveX load/unload race condition attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0554</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15461, service http, policy balanced-ips alert, policy security-ips drop;</filter2>
        <id>15461</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer marquee tag onstart memory corruption</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2881</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1080</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|&quot;; depth:1; byte_jump:1, 0, relative; content:&quot;|FF|&quot;; within:1; isdataat:300,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15482</id>
        <msg>EXPLOIT Sun Java System sockd authentication buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2007-3091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15529, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15529</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer cross-domain navigation cookie stealing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.classid='clsid|3A|0955AC62-BF2E-4CBA-A2B9-A63F772D46CF'|3B|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15678</id>
        <msg>SPECIFIC-THREATS Microsoft DirectShow ActiveX exploit via JavaScript</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-032.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.|00 00 00|c|00 00 00|l|00 00 00|a|00 00 00|s|00 00 00|s|00 00 00|i|00 00 00|d|00 00 00|=|00 00 00|'|00 00 00|c|00 00 00|l|00 00 00|s|00 00 00|i|00 00 00|d|00 00 00 3A 00 00 00|0|00 00 00|9|00 00 00|5|00 00 00|5|00 00 00|A|00 00 00|C|00 00 00|6|00 00 00|2|00 00 00|-|00 00 00|B|00 00 00|F|00 00 00|2|00 00 00|E|00 00 00|-|00 00 00|4|00 00 00|C|00 00 00|B|00 00 00|A|00 00 00|-|00 00 00|A|00 00 00|2|00 00 00|B|00 00 00|9|00 00 00|-|00 00 00|A|00 00 00|6|00 00 00|3|00 00 00|F|00 00 00|7|00 00 00|7|00 00 00|2|00 00 00|D|00 00 00|4|00 00 00|6|00 00 00|C|00 00 00|F|00 00 00|'|00 00 00 3B|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15679</id>
        <msg>SPECIFIC-THREATS Microsoft DirectShow ActiveX exploit via JavaScript - unicode encoding</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-032.mspx</url>
      </rule>
      <rule>
        <bugtraq>35660</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;unescape&quot;; nocase; pcre:&quot;/var[^=]+=\s*unescape\s*\x3b/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15697</id>
        <msg>WEB-CLIENT Generic javascript obfuscation attempt</msg>
      </rule>
      <rule>
        <bugtraq>35660</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;%u0c0c%u0c0c&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15698</id>
        <msg>WEB-CLIENT Possible generic javascript heap spray attempt</msg>
      </rule>
      <rule>
        <bugtraq>35707</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2479</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Math.ceil|28|Math.log|28|&quot;; nocase; content:&quot;Math.LN2|29|&quot;; distance:0; nocase; pcre:&quot;/\x29\s*\x2f\s*Math.LN2\x29/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15699</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox 3.5 unicode stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1917</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15731, service http, policy security-ips drop;</filter2>
        <id>15731</id>
        <msg>EXPLOIT javascript deleted reference arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1919</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15732, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15732</id>
        <msg>EXPLOIT Microsoft Internet Explorer CSS handling memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1918</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15733, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15733</id>
        <msg>EXPLOIT Microsoft Internet Explorer empty table tag memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2003-0838</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;window.createPopup|28 29|&quot;; content:&quot;oPopup.document.body.innerHTML&quot;; distance:0; content:&quot;&lt;object data=ouch.php&gt;&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15880</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer popup window object tag code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>30614</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2254</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;getElementById&quot;; nocase; content:&quot;innerHTML&quot;; distance:0; nocase; pcre:&quot;/id=\s*([^&gt;]+)&gt;.*?&lt;script&gt;.*?getElementByID\s*\x28[^\x29]*?\1\s*(\x22|\x27)\x29\x2EinnerHTML/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15910</id>
        <msg>EXPLOIT Microsoft Internet Explorer getElementById object corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>35660</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2477</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;function&quot;; nocase; content:&quot;|28|data|29|&quot;; within:20; nocase; pcre:&quot;/if\x28\s*(?P&lt;var&gt;[^\s]*)\s*\x3D\x3D\s*\x27(\x26|\x3f|\x3d|\x25|\s)\x27.*?(?P=var)\s*\x3d\s*escape\x28\s*(?P=var)\s*\x29\x3b/smiR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15997</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox JIT escape function memory corruption attempt</msg>
        <url>www.kb.cert.org/vuls/id/443060</url>
      </rule>
      <rule>
        <bugtraq>21668</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6504</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;bb.appendChild|28|fr.childNodes[4]|29 3B|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15999</id>
        <msg>SPECIFIC-THREATS Mozilla products frame comment objects manipulation memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>22085</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|F9 04 01 00 00 10 00|,|00 00 00 00 00 00 90 01|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16000</id>
        <msg>WEB-CLIENT Sun Microsystems Java gif handling memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>22694</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0777</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;arguments=function |28 29|{}|3B|&quot;; content:&quot;arguments|28 29 3B|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16005</id>
        <msg>SPECIFIC-THREATS Mozilla browsers JavaScript argument passing code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>23771</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0944</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;COLGROUP id=|22|colgroupid|22| span=2&gt;&quot;; content:&quot;colgroupid.test = 'something'|3B|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16007</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer colgroup tag uninitialized memory exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-027.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2007-0947</cve>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client, established, only_stream; content:&quot;HTTP/1.1 304 Not Modified&quot;; content:&quot;HTTP/1.1 304 Not Modified&quot;; distance:0; detection_filter:track by_src, count 20, seconds 1; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>16008</id>
        <msg>WEB-MISC Microsoft Internet Explorer 7 html object memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>24376</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2876</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;charset=utf-8,%3Chtml%3E&quot;; content:&quot;overflow%28%29%22%3ECrashIt&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16009</id>
        <msg>SPECIFIC-THREATS Mozilla products overflow event handling memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17671</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1993</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;id=|22|x_OtherInfo|22| name=|22|x_OtherInfo|22|&gt;&quot;; content:&quot;iframe.contentWindow.focus|28 29|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16024</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox Javascript Function focus overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17658</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1992</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;STYLE&gt;&lt;/STYLE&gt;|0A|&lt;OBJECT&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16031</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer nested object tag memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>18309</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2382</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;charset=UTF-8&quot;; nocase; file_data; content:&quot;|F8|AAA|F8|AA|C8|&quot;; within:8; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16032</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer HTML Decoding memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>19987</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3873</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Location|3A| /ABCDEFGHIJ&quot;; http_header; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16033</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer compressed content attempt</msg>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;.createTextRange|28 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;&lt;input type|3D 22|image|22|&quot;; nocase; pcre:&quot;/\x3Cinput\s+type\x3D\x22image\x22\s+id\x3D(?P&lt;q1&gt;(\x22|\x27|))(?P&lt;t&gt;\S+)(?P=q1).*?document\x2EgetElementById\x28(?P&lt;q2&gt;(\x22|\x27|))(?P=t)(?P=q2)\x29\x2EcreateTextRange/isO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16035</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>16476</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0295</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;Components.interfaces.&quot;; content:&quot;|2E|QueryInterface&quot;; distance:0; pcre:&quot;/(?P&lt;var&gt;\S+)\s*\x3D\s*eval\x28\s*(\x22|\x27|)Components\x2Einterfaces\x2E.*?\x2EQueryInterface\x28\s*(?P=var)\s*\x29.*?(location|navigator)/s&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16036</id>
        <msg>WEB-CLIENT Mozilla Products QueryInterface method memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>16476</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;?xml&quot;; content:&quot;&lt;svg&quot;; distance:0; content:&quot;&lt;filter&quot;; distance:0; pcre:&quot;/^[^\x3E]*(width|height)\s*\x3D\s*(\x22|\x27)([3-9]\d{4}|\d{6})/R&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16037</id>
        <msg>WEB-CLIENT Mozilla products graphics and XML features integer overflows attempt</msg>
      </rule>
      <rule>
        <bugtraq>16770</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0884</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;iframe&quot;; nocase; pcre:&quot;/^\s*[^\x3e]*src\s*\x3d\s*[\x22\x27][^\x22\x27]*javascript\x3a/iR&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>16038</id>
        <msg>MISC Mozilla Thunderbird WYSIWIG engine filtering IFRAME JavaScript execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>16427</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0496</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;P style=|22|-moz-binding|3A| url|28|http|3A|//gsx2/~rzhan/poc.xml|23|exploit|29 3B 22|&gt;&lt;/P&gt;&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16042</id>
        <msg>SPECIFIC-THREATS Mozilla browsers CSS moz-binding cross domain scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>17468</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-1188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|09 09|pre {|0A 09 09 09|white-space|3A|normal|3B 0A|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>16043</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer html tag memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17516</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1730</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;style=|22|letter-spacing|3A| -2147483648&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16044</id>
        <msg>WEB-CLIENT Mozilla Firefox CSS Letter-Spacing overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18682</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3280</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document.getElementById|28|'testdiv'|29|.innerHTML='&lt;object data=|22|/~&quot;; content:&quot;/poc.php|22| type=text/html id=|22|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16045</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-5959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;div|3A 3A|first-letter&quot;; nocase; content:&quot;position|3A| fixed&quot;; nocase; content:&quot;&lt;q&gt;&quot;; nocase; content:&quot;display|3A| -moz-box&quot;; nocase; content:&quot;binding.xml&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16047</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox layout frame constructor memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17516</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0749</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;BGCOLOR=|22|http|3A 22|-|9D 22 22| DP=-|B3| UNITS=|22 E2 E2 E2 E2|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16050</id>
        <msg>WEB-CLIENT Mozilla Firefox tag order memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>27668</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0076</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;style&gt;&quot;; nocase; content:&quot;&lt;isindex&gt;&quot;; distance:0; fast_pattern; nocase; content:&quot;&lt;style&gt;&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16063</id>
        <msg>WEB-CLIENT Internet Explorer isindex buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>24911</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2007-3826</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;opener.document.body.onbeforeunload=|22 22|&quot;; nocase; content:&quot;&lt;body onBeforeUnload='spoofed=1'&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>16064</id>
        <msg>SPECIFIC-THREATS internet explorer onBeforeUnload address bar spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>26427</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5347</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;execScript|28|'function f|28 29|{location.replace|28 22|about|3A|blank|22 29 3B|}|3B|setTimeout|28 22|f|28 29 22|,5|29 3B|&quot;; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16065</id>
        <msg>SPECIFIC-THREATS internet explorer location.replace memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-069.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-5344</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;removeNode&quot;; nocase; pcre:&quot;/(\w+)\x2EremoveNode\s*\x28true\x29.*\1\x2EremoveNode\s*\x28\x29.*\1\x2E[^r]+/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16067</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer DOM object cache management memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>36343</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3076</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;window.pkcs11.addmodule|28|&quot;; pcre:&quot;/(caption,\x22\x5c\x5c\x5c|\x22\x5cn\x5cn\x5cn\x22\x20\x2b\x20str)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16142</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox PKCS11 module installation code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>36023</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2195</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;var pi=3+0.14159265358979323846264338327950288419716939937510582097494459230781640628620899862803482534211706798214808651328230664709384460955058223172535940812848111745028410270193852&quot;; content:&quot;document.write|28 22|Area = pi*|28|r^2|29 22|+pi*|28|radius*radius|29 29 3B|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16145</id>
        <msg>SPECIFIC-THREATS Apple Safari Webkit floating point buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1547</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16149, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16149</id>
        <msg>EXPLOIT Microsoft Internet Explorer data stream header remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-054.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-2529</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16150, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16150</id>
        <msg>EXPLOIT Internet Explorer variant argument validation remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-054.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-2530</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16151, service http, policy security-ips drop;</filter2>
        <id>16151</id>
        <msg>WEB-CLIENT Internet Explorer unitialized or deleted object access attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-054.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-2531</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16152, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16152</id>
        <msg>EXPLOIT Internet Explorer table layout unitialized or deleted object access attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0076</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16169, service http, policy security-ips alert;</filter2>
        <id>16169</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer dynamic style update memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-002.mspx</url>
      </rule>
      <rule>
        <bugtraq>34743</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1313</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;white-space|3A| pre&quot;; content:&quot;&lt;script&gt;|0A|function doe|28 29|&quot;; content:&quot;getElementById|28|'a'|29|.childNodes[0].splitText|28|1|29|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16284</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox ClearTextRun exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>36881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 0B 28|II[B[B[B|29|V|01 00 0A|setDiffICM|01 00|S|28|II&quot;; content:&quot;|0A|,|10 0A 11 01 90 BB 00 17|Y|10 10 08 08 BC|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16288</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime AWT setDiffICM stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35891</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2404</cve>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|16|&quot;; content:&quot;|0B|&quot;; within:1; distance:4; byte_test:3,&gt;,0,3,relative,big; content:&quot;|06 03|U|04 03|&quot;; distance:0; pcre:&quot;/^[\x0c\x13]([\x00-\x7f]|\x81.|\x82.{2})\x28(?=[^\x29]*\x7e)[^\x29]*\x7c/sR&quot;; metadata:policy security-ips drop, service ssl; classtype:attempted-user;</filter2>
        <id>16291</id>
        <msg>WEB-CLIENT Mozilla Network Security Services regexp heap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3673</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16317, service http, policy security-ips drop;</filter2>
        <id>16317</id>
        <msg>EXPLOIT Internet Explorer mouse move during refresh memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2540</cve>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,safari.dll; metadata: engine shared, soid 3|16319, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16319</id>
        <msg>WEB-CLIENT Safari-IE SearchPath blended threat attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-015.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0246</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16326, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16326</id>
        <msg>EXPLOIT Microsoft Internet Explorer 8 DOM memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0075</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16339, service http, policy balanced-ips alert, policy security-ips alert;</filter2>
        <id>16339</id>
        <msg>WEB-CLIENT Internet Explorer object clone deletion memory corruption attempt - obfuscated</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-002.mspx</url>
      </rule>
      <rule>
        <bugtraq>36343</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3073</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.push&quot;; content:&quot;new&quot;; within:10; pcre:&quot;/^\s*function\s*(\S+)\s*\x28\s*\S+\s*\x29.+for\s*\x28[^\x29]+\x29\s*\x7B?\s*\S+\x2Epush\s*\x28\s*new\s+\1/sm&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16344</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox top-level script object offset calculation memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>36866</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3382</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3A|first-letter {float|3A| &quot;; fast_pattern; content:&quot;.setAttribute|28|'style', 'display|3A| -moz-box|3B| '|29 3B|&quot;; content:&quot;.style.display= 'none'|3B|&quot;; within:60; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16347</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox browser engine memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16367, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16367</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer invalid object access memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-002.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16369, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16369</id>
        <msg>EXPLOIT Microsoft Internet Explorer deleted object access memory corruption attempt - public exploit</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-002.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2010-0244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16376, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16376</id>
        <msg>EXPLOIT Internet Explorer onPropertyChange deleteTable memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2010-0247</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16377, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16377</id>
        <msg>EXPLOIT Internet Explorer DOM mergeAttributes memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>37896</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0387</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:!&quot;GET&quot;; nocase; http_method; content:!&quot;POST&quot;; nocase; http_method; content:&quot;Authorization&quot;; nocase; content:&quot;Digest&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/^Authorization\s*\x3A\s*Digest\s+([^\n\x2C]*\x2C){15}/im&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16392</id>
        <msg>WEB-MISC Sun Java System Web Server 7.0u7 authorization digest heap overflow</msg>
      </rule>
      <rule>
        <bugtraq>37910</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0388</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;PROPFIND&quot;; nocase; http_method; content:&quot;encoding&quot;; pcre:&quot;/\&lt;\?xml[^\&gt;]+encoding\s*\=\s*(\'|\&quot;)[^\'\&quot;\&gt;\%]*\%/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16426</id>
        <msg>WEB-MISC Sun Java System Web Server 7.0 WebDAV format string exploit attempt - PROPFIND method</msg>
      </rule>
      <rule>
        <bugtraq>37910</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0388</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;LOCK&quot;; fast_pattern; nocase; http_method; content:&quot;encoding&quot;; pcre:&quot;/\&lt;\?xml[^\&gt;]+encoding\s*\=\s*(\'|\&quot;)[^\'\&quot;\&gt;\%]*\%/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16427</id>
        <msg>WEB-MISC Sun Java System Web Server 7.0 WebDAV format string exploit attempt - LOCK method</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| Mozilla|0D 0A|&quot;; http_header; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16442</id>
        <msg>BOTNET-CNC Possible Zeus User-Agent - Mozilla</msg>
        <url>en.wikipedia.org/wiki/Zeus_(trojan_horse)</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16482, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16482</id>
        <msg>WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt</msg>
        <url>support.microsoft.com/kb/980182</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0049</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.innerHTML&quot;; nocase; content:&quot;rtl&quot;; nocase; content:&quot;&lt;NOBR&quot;; fast_pattern; nocase; pcre:&quot;/&lt;(body|html)[^&gt;]+dir\s*=\s*(?P&lt;q1&gt;\x22|\x27|)rtl(?P=q1)/smi&quot;; pcre:&quot;/(?P&lt;obj&gt;[A-Z\d_]+)\s*=\s*document\.getElementsByTagName\((?P&lt;q2&gt;\x22|\x27|)NOBR(?P=q2)\).*?(?P=obj)\.innerHTML\s*=\s*(\x22\x22|\x27\x27)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16492</id>
        <msg>WEB-CLIENT Safari inline text box use after free attempt</msg>
      </rule>
      <rule>
        <bugtraq>38298</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;wOFF|00 01 00 00|&quot;; content:&quot;|00 00|&quot;; within:2; distance:6; pcre:&quot;/^.{28}([0-9A-Z\x20\x2F]{4}.{8}[^\xFF].{7})*([0-9A-Z\x20\x2F]{4}.{8}\xFF{3})/isR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16501</id>
        <msg>WEB-CLIENT Mozilla Firefox WOFF font processing integer overflow attempt - TrueType</msg>
        <url>www.kb.cert.org/vuls/id/964549</url>
      </rule>
      <rule>
        <bugtraq>38298</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;wOFFOTTO&quot;; content:&quot;|00 00|&quot;; within:2; distance:6; pcre:&quot;/^.{28}([0-9A-Z\x20\x2F]{4}.{8}[^\xFF].{7})*([0-9A-Z\x20\x2F]{4}.{8}\xFF{3})/isR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16502</id>
        <msg>WEB-CLIENT Mozilla Firefox WOFF font processing integer overflow attempt - CFF-based</msg>
        <url>www.kb.cert.org/vuls/id/964549</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0267</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16503, service http, policy security-ips drop;</filter2>
        <id>16503</id>
        <msg>EXPLOIT Microsoft Internet Explorer event handling remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2010-0488</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|16504, service http, policy security-ips drop;</filter2>
        <id>16504</id>
        <msg>EXPLOIT Microsoft Internet Explorer 7 encoded content handling exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2010-0494</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|16509, service http, policy security-ips drop;</filter2>
        <id>16509</id>
        <msg>EXPLOIT Microsoft Internet Explorer designMode-enabled information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA&quot;; fast_pattern:only; nocase; content:&quot;Launch&quot;; nocase; pcre:&quot;/&lt;object[^&gt;]+classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)clsid\s*\x3A\s*{?\s*CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA\s*}?(?P=q1)/smi&quot;; pcre:&quot;/([A-Z\d_]+)\.Launch\(/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16547</id>
        <msg>WEB-ACTIVEX Java Web Start ActiveX launch command by CLSID</msg>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA&quot;; fast_pattern:only; nocase; content:&quot;createElement&quot;; nocase; content:&quot;Launch&quot;; nocase; pcre:&quot;/(?P&lt;obj&gt;[A-Z\d_]+)\s*=\s*document\.createElement\((?P&lt;q1&gt;\x22|\x27|)OBJECT(?P=q1)\).*?(?P=obj)\.classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)clsid\x3ACAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA(?P=q2).*?(?P=obj)\.launch\(/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16548</id>
        <msg>WEB-ACTIVEX Java Web Start ActiveX launch command by JavaScript CLSID</msg>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/npruntime-scriptable-plugin|3B|deploymenttoolkit&quot;; nocase; content:&quot;-J-jar&quot;; pcre:&quot;/http\x3A\s+-J-jar\s+-J[^\s]+\x2Ejar/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16549</id>
        <msg>WEB-CLIENT Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - npruntime-scriptable-plugin</msg>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/java-deployment-toolkit&quot;; nocase; content:&quot;-J-jar&quot;; pcre:&quot;/http\x3A\s+-J-jar\s+-J[^\s]+\x2Ejar/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16550</id>
        <msg>WEB-CLIENT Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - java-deployment-toolkit</msg>
      </rule>
      <rule>
        <bugtraq>34169</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0927</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;app.doc.Collab.getIcon&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16554</id>
        <msg>WEB-CLIENT Adobe Acrobat JavaScript getIcon method buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;8AD9C840-044E-11D1-B3E9-00805F499D93&quot;; fast_pattern:only; nocase; content:&quot;-XXaltjvm&quot;; content:&quot;launchjnlp&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16584</id>
        <msg>WEB-CLIENT Java Web Start arbitrary command execution attempt - Internet Explorer</msg>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-java-applet&quot;; nocase; content:&quot;-XXaltjvm&quot;; fast_pattern:only; content:&quot;launchjnlp&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16585</id>
        <msg>WEB-CLIENT Java Web Start arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;function loop|28 29|&quot;; content:&quot;setInterval|28|doit,0|29|&quot;; distance:0; content:&quot;function doit|28 29|&quot;; distance:0; content:&quot;document.write&quot;; distance:0; content:&quot;setInterval|28|loop,0|29|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16592</id>
        <msg>SPECIFIC-THREATS Opera asynchronous document modifications attempted memory corruption</msg>
        <url>www.opera.com/support/kb/view/953/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.classid='clsid|3A|0369B4E5-45B6-11D3-B650-00C04F79498E'|3B|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16602</id>
        <msg>SPECIFIC-THREATS Microsoft DirectShow 3 ActiveX exploit via JavaScript</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-032.mspx</url>
      </rule>
      <rule>
        <bugtraq>32721</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4844</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;%3c%53%50%41%4e%20%44%41%54%41%53%52%43%3d%23%49%20%44%41%54%41%46%4c%44%3d%43%20%44%41%54%41%46%4f%52%4d%41%54%41%53%3d%48%54%4d%4c%3e&quot;; fast_pattern:only; nocase; content:&quot;%3c%53%50%41%4e%20%44%41%54%41%53%52%43%3d%23%49%20%44%41%54%41%46%4c%44%3d%43%20%44%41%54%41%46%4f%52%4d%41%54%41%53%3d%54%45%58%54%3e&quot;; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16605</id>
        <msg>SPECIFIC-THREATS Internet Explorer nested SPAN tag memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0811</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;8fe85d00-4647-40b9-87e4-5eb8a52f4759&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16635</id>
        <msg>WEB-ACTIVEX Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16637, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16637</id>
        <msg>EXPLOIT Microsoft Internet Explorer security zone restriction bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-035.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1257</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16658, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16658</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer 8 cross-site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-035.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1262</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16659, service http, policy security-ips drop;</filter2>
        <id>16659</id>
        <msg>EXPLOIT Microsoft Internet Explorer style sheet array memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-035.mspx</url>
      </rule>
      <rule>
        <bugtraq>39990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1939</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;for|28|var i = 0|3B| i |3C| 2|3B| i|2B 2B 29|&quot;; content:&quot;parent.alert|28 22|&quot;; within:50; content:&quot;self.close|28 29 3B|&quot;; within:50; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16666</id>
        <msg>SPECIFIC-THREATS Apple Safari window.parent.close unspecified remote code execution vulnerability</msg>
        <url>secunia.com/advisories/39670</url>
      </rule>
      <rule>
        <bugtraq>39813</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1663</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;src=|22|https|3A 2F 2F|www.google.com|2F|accounts|2F|ManageAccount?hl=fr|22|&quot;; content:&quot;javascr|5C|u0009ipt|3A|alert|28|document.cookie&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16667</id>
        <msg>SPECIFIC-THREATS Google Chrome GURL cross origin bypass attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>39813</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1663</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;src=|22|http|3A 2F 2F|www.google.ca|2F|language_tools?hl=en|22|&quot;; content:&quot;window.open|28 27|j|5C|navascript|3A|alert|28|document.cookie|29 27|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16668</id>
        <msg>SPECIFIC-THREATS Google Chrome GURL cross origin bypass attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;innerHTML&quot;; content:&quot;Math.round|28|&quot;; within:100; content:&quot;.createTextRange|28 29|&quot;; distance:0; fast_pattern; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16690</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>34240</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1097</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|89|PNG|0D 0A 1A 0A 00 00 00 0D|IHDR&quot;; fast_pattern:only; pcre:&quot;/^\x89PNG\x0d\x0a\x1a\x0a\x00{3}\x0dIHDR([^\x00]|\x00[^\x00]|.{4}[^\x00]|.{4}\x00[^\x00]|.{8}[\x11-\xff])/ms&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16716</id>
        <msg>WEB-CLIENT Sun Java Web Start Splashscreen PNG processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;document|2E|createElement&quot;; pcre:&quot;/\x2Ereplace\x28\x2F(\x23\x7C?|\x5C\x24\x7C?|\x5C\x28\x7C?|\x26\x7C?|\x5C\x5E\x7C?|\x40\x7C?|\x5C\x21\x7C?|\x5C\x29\x7C?){8}\x2F\x69\x67\x2C\x20\x27\x27\x29/&quot;; metadata:policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17058</id>
        <msg>SPECIFIC-THREATS Trojan-Downloader.JS.Agent.ewh Javascript download attempt</msg>
        <url>www.virustotal.com/analisis/68b650e4f6c6e13c335a270ba5c3db3dc84012ec18c71841fcbbcb421000dec5-1262969947</url>
      </rule>
      <rule>
        <bugtraq>23539</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1681</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [898,1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;Lcom.sun.management.viperimpl.services.authentication.AuthenticationPrincipal&quot;; content:&quot;roleDescq|00|&quot;; distance:0; content:&quot;userDescq|00|&quot;; distance:0; content:&quot;3|25|065478x|25|6|24|n|25|065539x|25|6|24|hn|25|30|24|08189x|25|n|25|30|24|059148x|25|hn&quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17109</id>
        <msg>SPECIFIC-THREATS Sun Java Web Console logging functionality format string exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2560</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17132, service http, policy security-ips drop;</filter2>
        <id>17132</id>
        <msg>EXPLOIT Microsoft Internet Explorer invalid object access attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17136, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17136</id>
        <msg>EXPLOIT Microsoft Internet Explorer 6 race condition exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>42154</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-2709</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/OVCgi/webappmon.exe&quot;; nocase; http_uri; content:&quot;OvJavaLocale&quot;; nocase; http_header; pcre:&quot;/^Cookie\s*\x3A\s*OvJavaLocale\s*\x3D\s*.{1024}/imH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17140</id>
        <msg>WEB-MISC OpenView Network Node Manager OvJavaLocale buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>39855</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1728</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;document.write&quot;; content:&quot;setInterval&quot;; fast_pattern:only; nocase; pcre:&quot;/function\s+(?P&lt;func&gt;[a-z\x5F]+).+?\x7B[^\x7D]+?document\x2Ewrite[^\x7D]+?setInterval\x28(?P=func)/is&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17165</id>
        <msg>WEB-CLIENT Opera browser document writing uninitialized memory access attempt</msg>
      </rule>
      <rule>
        <bugtraq>36343</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3075</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;.replace|28|&quot;; pcre:&quot;/(?P&lt;var&gt;\w+)\x2Ereplace\x28\s*(?P=var)\s*\x2C\s*(?P=var)\s*\x29/&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17166</id>
        <msg>WEB-CLIENT Mozilla multiple products JavaScript string replace buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-1532</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, from_server; content:&quot;arguments|2E|callee|2E|&quot;; nocase; content:&quot;|5F 5F|parent|5F 5F 2E|eval&quot;; distance:0; fast_pattern; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17212</id>
        <msg>WEB-CLIENT Mozilla Firefox JavaScript eval arbitrary code execution attempt</msg>
        <url>secunia.com/advisories/15528/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2706</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; content:&quot;window|2E|open&quot;; nocase; content:&quot;about|3A|mozilla&quot;; within:50; nocase; content:&quot;document|2E|write&quot;; distance:0; nocase; content:&quot;about|3A|config&quot;; within:50; fast_pattern; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17213</id>
        <msg>WEB-CLIENT Mozilla Firefox Chrome Page Loading Restriction Bypass attempt</msg>
        <url>secunia.com/advisories/16911/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3070</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; content:&quot;-moz-column-&quot;; fast_pattern:only; content:&quot;documentElement.style.height&quot;; pcre:&quot;/&lt;html[^&gt;]*?height[^&gt;]*?&gt;/smi&quot;; pcre:&quot;/&lt;body[^&gt;]*?position[^&gt;]*?inherit[^&gt;]*?-moz-column-(count|width)[^&gt;]*?documentElement\.style\.height[^&gt;]*?/smiR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17236</id>
        <msg>WEB-CLIENT Mozilla Firefox nsPropertyTable PropertyList memory corruption attempt</msg>
        <url>secunia.com/advisories/36671/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-0230</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|img|20|&quot;; content:&quot;|2E|bat&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/\x3cimg\s[^\x3e]*\x2ebat/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17245</id>
        <msg>WEB-CLIENT Mozilla Firefox image dragging exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>34181</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1044</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;selection|2E|timedSelect|28|1|2C|8000|29 3B|&quot;; content:&quot;tree|2E|view|2E|selection|3D|null|3B|&quot;; distance:0; content:&quot;delete|20|tree&quot;; distance:0; content:&quot;delete|20|selection&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17258</id>
        <msg>WEB-CLIENT Mozilla Firefox XUL tree element code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17671</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1993</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;contentWindow.document.designMode = |22|on|22|&quot;; content:&quot;contentWindow.document.write&quot;; within:100; content:&quot;contentWindow.document.close&quot;; within:100; content:&quot;&lt;iframe&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17260</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox Javascript contentWindow in an iframe exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;.createTextRange|28 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;&lt;input type|3D 22|checkbox|22|&quot;; nocase; pcre:&quot;/\x3Cinput\s+type\x3D\x22checkbox\x22\s+id\x3D(?P&lt;q1&gt;(\x22|\x27|))(?P&lt;t&gt;\S+)(?P=q1).*?document\x2EgetElementById\x28(?P&lt;q2&gt;(\x22|\x27|))(?P=t)(?P=q2)\x29\x2EcreateTextRange/isO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17261</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;.createTextRange|28 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;&lt;input type|3D 22|radio|22|&quot;; nocase; pcre:&quot;/\x3Cinput\s+type\x3D\x22radio\x22\s+id\x3D(?P&lt;q1&gt;(\x22|\x27|))(?P&lt;t&gt;\S+)(?P=q1).*?document\x2EgetElementById\x28(?P&lt;q2&gt;(\x22|\x27|))(?P=t)(?P=q2)\x29\x2EcreateTextRange/isO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17262</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.createTextRange|28 29 09 0A 0D 09 20 0A 20 0A 20 0D|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17263</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>12655</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0527</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;file|2E|initWithPath|28 22|c|3A 5C 5C 5C 5C|booom|2E|bat&quot;; content:&quot;xpcom|20 2B 3D 20 27|file|2E|createUnique&quot;; content:&quot;outputStream|2E|init|28|file|2C|0x04|7C|0x08|7C|0x20|2C|420&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17265</id>
        <msg>WEB-CLIENT Mozilla Firefox plugin access control bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>12884</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0402</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;onclick|3D 22|window|2E|sidebar|2E|addPanel|28 27|FSC|20|sidebar&quot;; content:&quot;http|3A 2F 2F|gsx3|2F 7E|swarelis|2F|CAN|2D|2005|2D|0402|2F|poc|2E|html&quot;; distance:4; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17268</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox sidebar panel arbitrary code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14282</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2308</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; file_data; content:&quot;|FF D8 FF|&quot;; content:&quot;|FF DA|&quot;; distance:0; content:&quot;|03|&quot;; within:1; distance:2; content:&quot;|01 00 02 11 01|&quot;; within:5; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17355</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer JPEG Decoder Vulnerabilities attempt</msg>
      </rule>
      <rule>
        <bugtraq>14916</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2701</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xbm; content:&quot;static|20|char|20|gopher|5F|binary|5F|bits|5B 5D|&quot;; content:&quot;0x71|2C 20|0x26|2C 20|0x01|20 20 20 20 20 20|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17360</id>
        <msg>WEB-CLIENT Mozilla Firefox XBM image processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.png; content:&quot;IHDR&quot;; byte_test:4,&gt;,32767,4,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17378</id>
        <msg>WEB-CLIENT Mozilla Firefox Animated PNG Processing integer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.png; content:&quot;IHDR&quot;; byte_test:8,&gt;,32767,4,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17379</id>
        <msg>WEB-CLIENT Mozilla Firefox Animated PNG Processing integer overflow</msg>
      </rule>
      <rule>
        <bugtraq>18228</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2779</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document|2E|addEventListener|28 22|DOMNodeRemoved|22|&quot;; nocase; content:&quot;document|2E|body|2E|appendChild|28|document|2E|getElementById|28|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17389</id>
        <msg>SPECIFIC-THREATS mozilla firefox DOMNodeRemoved attack attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot; shellcode&quot;; fast_pattern:only; nocase; pcre:&quot;/var\s+shellcode\s*=/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:shellcode-detect;</filter2>
        <id>17392</id>
        <msg>SHELLCODE JavaScript var shellcode</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot; heapspray&quot;; fast_pattern:only; nocase; pcre:&quot;/var\s+heapspray[A-Z\d_\s]*=/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:shellcode-detect;</filter2>
        <id>17393</id>
        <msg>SHELLCODE JavaScript var heapspray</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2086</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.gif; content:&quot;|46 38 39 61 FF FF FF FF B3 FF 00 FF FF FF CD CD CD A6 A6 A3 0E 0D 0D 05 05 83 ED EC EC AB AB B4|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17395</id>
        <msg>SPECIFIC-THREATS Sun Java Web Start Splashscreen GIF decoding buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0773</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;a|5B|10|5D 20 3D 20 22|AAAAAAAAAA|22 3B|&quot;; content:&quot;a|2E|splice|28|10|2C 20|1|29 3B|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17398</id>
        <msg>WEB-CLIENT Mozilla Firefox Javascript array.splice memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>33990</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0773</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;a|5B|6|5D 20 3D 20 22|toto|22 3B|&quot;; content:&quot;a|2E|splice|28|6|2C 20|1|29 3B|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17399</id>
        <msg>WEB-CLIENT Mozilla Firefox Javascript array.splice memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;var &quot;; nocase; content:&quot;unescape&quot;; within:100; distance:5; nocase; pcre:&quot;/var\s+[A-Z][A-Z\d\x5F]{5,}\s*=\s*unescape[\s\x3b]/smi&quot;; flowbits:set,js.rename.unescape; flowbits:noalert;  metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17400</id>
        <msg>WEB-CLIENT rename of JavaScript unescape function - likely malware obfuscation</msg>
      </rule>
      <rule>
        <bugtraq>32721</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4844</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,js.rename.unescape; content:&quot;|25|53|25|52|25|43|25|3d|25|5c|25|5c|25|26|25|23&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17401</id>
        <msg>SPECIFIC-THREATS Internet Explorer nested tag memory corruption attempt - unescaped</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-078.mspx</url>
      </rule>
      <rule>
        <bugtraq>32721</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4844</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;adong7&quot;; nocase; content:&quot;adong7&quot;; distance:0; nocase; content:&quot;datasrc&quot;; distance:0; nocase; content:&quot;datafld&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17402</id>
        <msg>SPECIFIC-THREATS Internet Explorer nested tag memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-078.mspx</url>
      </rule>
      <rule>
        <bugtraq>12427</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0056</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|channel|20 0D 0A 20 20|href|3D 22|file|3A 2F 2F|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17411</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CDF cross-domain scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>12998</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0989</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;x|20 3D 20|x|2E|replace|28 2F|end|2F|i|2C 20|function|28 24|1|29 7B 20|var|20|y|20 3D 20 22|any|22 3B 20|y|2E|match|28 2F|any|2F|i|29|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17414</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox Javascript Engine Information Disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>12998</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0989</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;var|20|mem|20 3D 20|genGluck|28 20 22|XXX&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17415</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox Javascript Engine Information Disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>13544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1477</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;IconURL|3A 20 22|javascript|3A|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17424</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox IconURL Arbitrary Javascript Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>14918</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2702</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content|2D|Type|3A 20|text|2F|html&quot;; http_header; content:&quot;|3B 26 23|8204|3B 26 23|8204&quot;; fast_pattern; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17434</id>
        <msg>WEB-CLIENT Mozilla Firefox Unicode sequence handling stack corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0554</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17462, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17462</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer marquee object handling memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>15823</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2829</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;spoffset()|20|{|0A 20 20 20 20 20 20|&quot;; nocase; content:&quot;var|20|mv|20|=|20|window|2E|navi&quot;; within:20; nocase; content:&quot;var|20|sp2&quot;; within:7; distance:29; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17463</id>
        <msg>SPECIFIC-THREATS Internet Explorer File Download Dialog Box Manipulation</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>34169</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0927</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;|55 1E 42 91 74 A1 4A FA 21 C7 DB 53 14 DE DE 9E A4 6A CD ED 29 C7 4E DE 9E BC ED 49 B3 35 11 D6|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17471</id>
        <msg>SPECIFIC-THREATS Adobe Acrobat JavaScript getIcon method buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34169</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0927</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;|B3 2E 86 F7 BA C8 F4 4A 2B C7 AB 99 E8 6B 72 99 39 40 C7 59 B1 2E C9 D1 AE 0C 6E 39 A8 E5 DC 60|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17472</id>
        <msg>SPECIFIC-THREATS Adobe Acrobat JavaScript getIcon method buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1316</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;news|3A 2F 2F|&quot;; pcre:&quot;/news\x3a\x2f\x2f.*?\x2f?(profile|search).*?\x2f.*?\x5c[^\s\x22\x27]{0,1}/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17482</id>
        <msg>WEB-CLIENT Mozilla NNTP URL Handling Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>16687</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-0753</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;script&quot;; nocase; content:&quot;javascript&quot;; distance:0; nocase; content:&quot;location=&quot;; distance:0; nocase; pcre:&quot;/javascript.+function\s+(\w+)\s*\(\w*\)\s*\{.+location=[^}]+\1.+\}/sim&quot;; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>17487</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Engine Stack Exhaustion Denial of Service attempt</msg>
      </rule>
      <rule>
        <bugtraq>31346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;a href=|22 01 78 78|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17519</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox UTF-8 URL Handling Stack Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>31879</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Encoding: pack200-gz&quot;; nocase; content:&quot;|9A 10 3A C7 39 E2 E6 DE BE F7 71 BA 7C 22 5E D7|&quot;; content:&quot;|49 F4 EF C7 73 9F 9B 9C 8B 32 A7 88 58 FF 13 31|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17522</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime Environment Pack200 Decompression Integer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>25916</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3892</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;for|20 28|i=0|3B 20|i&lt;20|3B 20|i++|29 7B|&quot;; nocase; content:&quot;document|2E|location|2E|href|3D|fileURL|3B|&quot;; within:32; distance:11; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17549</id>
        <msg>SPECIFIC-THREATS Internet Explorer Error Handling Code Execution</msg>
      </rule>
      <rule>
        <bugtraq>26817</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5344</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;getElementsByTagName&quot;; nocase; content:&quot;removeNode|28|true|29|&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/\x2EgetElementsByTagName\x28[^\x29]+?\x2EremoveNode\x28true\x29/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17554</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer DOM object cache management memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>30986</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;36723f97-7aa0-11d4-8919-ff2d71d0d32c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*36723f97-7aa0-11d4-8919-ff2d71d0d32c\s*}?\s*(?P=q1)(\s|&gt;).*?&lt;param\s*name\s*=\s*operation[^&gt;]+?value\s*=\s*[^\s][^\x22\x27\s]{512}/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17557</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX operation parameter overflow</msg>
        <url>support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html</url>
      </rule>
      <rule>
        <bugtraq>32608</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2008-5352</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Content-Encoding|3A 20|pack200-gzip&quot;; nocase; content:&quot;|C3 B5 17 B7 9E B8 31 F3 30 32 33 31 31 32 32 30|&quot;; distance:0; content:&quot;|7D FF A4 AC D4 E4 92 E0 92 A2 CC BC F4 82 FC 64|&quot;; within:16; distance:64; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>17562</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime Environment Pack200 Decompression Integer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>32608</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5354</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|1D 79 05 13 28 88 55 51 C2 A4 84 29 05 12 0C 19|&quot;; content:&quot;|F1 2B C6 40 A1 3D C6 60 81 A8 5D 28 34 30 44 06|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17563</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime Environment JAR File Processing Stack Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>35224</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1530</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;activate|20|=|20|function|20|()&quot;; nocase; pcre:&quot;/on(before|de)activate\s*\x3d\s*function\s*\x28\x29\s*\x7b\s*call(back|malFunc)\x28\x29/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17566</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer 7 Event Handler Memory Corruption</msg>
      </rule>
      <rule>
        <bugtraq>28448</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1236</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;contentDocument.designMode&quot;; nocase; content:&quot;addEvenListener|28|&quot;; distance:0; nocase; content:&quot;iframe.style.position&quot;; within:100; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17570</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox IFRAME style change handling code execution</msg>
        <url>www.mozilla.org/security/announce/2008/mfsa2008-15.html</url>
      </rule>
      <rule>
        <bugtraq>17468</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;&lt;pre&gt;|0A 09 09|&lt;span style=|22|white-space|3A|normal|3B 22 2F|&gt;&lt;span&gt;&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17580</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer span tag memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17516</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0749</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;table&gt;|0A|&lt;html&gt;|0A|&lt;frameset&gt;&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17581</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox tag order memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>22678</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1094</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;document.write(&quot;; content:&quot;body|20|onunload=|22|exploit&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17585</id>
        <msg>SPECIFIC-THREATS Internet Explorer possible javascript onunload event memory corruption</msg>
      </rule>
      <rule>
        <bugtraq>11726</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1029</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;jnlp &quot;; nocase; content:&quot;&lt;resources&gt;&quot;; distance:0; nocase; content:&quot; -classpath&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/&lt;property[^&gt;]*?value\s*=\s*(?P&lt;q1&gt;\x22|\x27).*? -classpath.*?(?P=q1)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17586</id>
        <msg>WEB-CLIENT Sun Java Web Start malicious parameter value</msg>
      </rule>
      <rule>
        <bugtraq>11366</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6E449683-C509-11CF-AAFA-00AA00B6015C&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E449683-C509-11CF-AAFA-00AA00B6015C\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(BaseUrl|SetCifFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*6E449683-C509-11CF-AAFA-00AA00B6015C\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(BaseUrl|SetCifFile))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17588</id>
        <msg>WEB-ACTIVEX Microsoft Internet Explorer Install Engine ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS04-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>11366</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6|00|E|00|4|00|4|00|9|00|6|00|8|00|3|00|-|00|C|00|5|00|0|00|9|00|-|00|1|00|1|00|C|00|F|00|-|00|A|00|A|00|F|00|A|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|B|00|6|00|0|00|1|00|5|00|C|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*6\x00E\x004\x004\x009\x006\x008\x003\x00-\x00C\x005\x000\x009\x00-\x001\x001\x00C\x00F\x00-\x00A\x00A\x00F\x00A\x00-\x000\x000\x00A\x00A\x000\x000\x00B\x006\x000\x001\x005\x00C\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17589</id>
        <msg>WEB-ACTIVEX Microsoft Internet Explorer Install Engine ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS04-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>32281</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5016</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset, xul.download; content:&quot;style=&quot;; content:&quot;&lt;treechildren&quot;; nocase; content:&quot;&lt;treechildren&quot;; distance:0; nocase; content:&quot;ordinal&quot;; content:&quot;event.target.parentNode.removeChild&quot;; fast_pattern:only; nocase; pcre:&quot;/onoverflow\s*=\s*(\x22|\x27)\s*event.target.parentNode.removeChild/smi&quot;; pcre:&quot;/&lt;treechildren.*ordinal=.*&lt;treechildren/smi&quot;; pcre:&quot;/&lt;tree .*tree(?!children).*&lt;treechildren.*&lt;treechildren/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17601</id>
        <msg>WEB-CLIENT Mozilla Firefox file type memory corruption attempt</msg>
        <url>www.mozilla.org/security/announce/2008/mfsa2008-52.html</url>
      </rule>
      <rule>
        <bugtraq>32281</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5021</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;type=&quot;; nocase; content:&quot;file&quot;; within:7; distance:1; nocase; content:&quot;getElement&quot;; nocase; pcre:&quot;/var\s*(?P&lt;varname&gt;[^\s]*)\s*\x3d\s*[^\x2E]*\x2EgetElement[^\x28]*\x28(\x22|\x27)(?P&lt;elementid&gt;[^\x22\x27]*)(\x22|\x27)\x29.*(?P=varname)\x2etype\s*\x3D\s*(\x22|\x27)(?!file).*id\s*\x3d\s*(\x22|\x27)(?P=elementid)[^&gt;]*type\s*=\s*(\x22|\x27)file/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17603</id>
        <msg>WEB-CLIENT Mozilla Firefox file type memory corruption attempt</msg>
        <url>www.mozilla.org/security/announce/2008/mfsa2008-55.html</url>
      </rule>
      <rule>
        <bugtraq>21675</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;java/awt/image/ConvolveOp|0C 00 0E 00 23 01 00|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17604</id>
        <msg>SPECIFIC-THREATS Java AWT ConvolveOp memory corruption attempt</msg>
        <url>sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1</url>
      </rule>
      <rule>
        <bugtraq>37874</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0361</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;COPY&quot;; depth:4; nocase; isdataat:200,relative; pcre:&quot;/^COPY(?!\n)\s[^\n]{200}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17609</id>
        <msg>WEB-MISC Sun Java Web Server Webdav Stack Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35326</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1392</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;first-letter&quot;; nocase; content:&quot;direction&quot;; distance:0; nocase; content:&quot;rtl&quot;; within:8; content:&quot;whitespace |3D| &quot;; distance:0; nocase; content:&quot;pre&quot;; within:10; nocase; content:&quot;|3C|span&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17613</id>
        <msg>WEB-MISC Mozilla Firefox browser engine  memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3902</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; content:&quot;obj|2E|setExpression|28 22|width&quot;; fast_pattern; nocase; content:&quot;|22 2C 22|document|2E|body|2E|offsetWidth|22 29|&quot;; within:30; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17622</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer object reference memory corruption attempt</msg>
        <url>www.securityfocus.com/bid/26506</url>
      </rule>
      <rule>
        <bugtraq>34240</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1099</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|63 3B 84 6A B2 84 BC F8 B0 41 1B 77 2D E5 CE 32 34 0D C6 F2 8A F4 08 57 E4 45 19 76 E7 51 82 43 3C F9 F3 33 A3 8B D8 41 C0 D4 E6 8B F9 E0 12 EB|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17623</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime Environment Type1 Font parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34240</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1099</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|1F 8B 08 08 D4 73 61 49 00 03 65 2E 70 61 63 6B 00 ED CE 3B 4B 03 41 10 00 E0 D9 7B C7 3B 15 63 63 2D 16 8A 8F D3 68 17 11 22 E4 34 21 31 82 31|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17624</id>
        <msg>SPECIFIC-THREATS Sun Java Runtime Environment Type1 Font parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>22085</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|52 4B 55 F6 EF DF 63 70 A3 6C 5C 5B 48 71 BB 7A 70 77 3B 44 69 5B|&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17628</id>
        <msg>SPECIFIC-THREATS Sun Microsystems Java gif handling memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>14920</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2706</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; content:&quot;window|2E|open&quot;; nocase; content:&quot;about:&quot;; within:10; nocase; content:&quot;document|2E|write&quot;; distance:0; nocase; content:&quot;about:&quot;; within:30; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17629</id>
        <msg>WEB-CLIENT Mozilla Firefox Chrome Page Loading Restriction Bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>29802</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;counter|2D|reset|3A|&quot;; content:&quot;counter|2D|increment|3A|&quot;; distance:0; content:&quot;|3C|ol|20|id|3D 22|id1|22 3E 0A|&quot;; distance:0; content:&quot;|3C|li|3E 3C 2F|li|3E 0A 3C|li|3E 3C 2F|li|3E 0A 3C|li|3E 3C 2F|li|3E 0A|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17630</id>
        <msg>WEB-CLIENT Mozilla multiple products CSSValue array memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>30148</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3111</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|j2se&quot;; content:&quot;java|2D|vm|2D|args&quot;; pcre:&quot;/\x3cj2se[^\x3e]*java\x2dvm\x2dargs\s*\x3d\s*\x22[^\x22]*\x2dea\x3a[^\s\x22\x3e]{100}/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17631</id>
        <msg>WEB-CLIENT Sun Java Web Start JNLP java-vm-args buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35765</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2462</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;first-letter&quot;; nocase; content:&quot;float: right&quot;; distance:0; nocase; content:&quot;parentNode.removeAttribute(|22|class|22|)&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17642</id>
        <msg>WEB-CLIENT Mozilla Firefox ConstructFrame with floating first-letter memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0075</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;var nopsled&quot;; nocase; content:&quot;cloneNode|28 29|&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17644</id>
        <msg>SPECIFIC-THREATS Internet Explorer object clone deletion memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-002.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0943</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;text-decoration&quot;; nocase; pcre:&quot;/\x2E[A-Z\d_]+\s*\x7b\s*text-decoration[^\x3A]*?\x7d/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17645</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer CSS strings parsing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>39346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1423</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;8AD9C840-044E-11D1-B3E9-00805F499D93&quot;; nocase; content:&quot;jnlpDocbase=|22|ABBA|3A|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17660</id>
        <msg>SPECIFIC-THREATS Java Web Start arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17685, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17685</id>
        <msg>EXPLOITS Internet Explorer invalid pointer memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17686, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17686</id>
        <msg>EXPLOITS Internet Explorer invalid pointer memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17687, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17687</id>
        <msg>EXPLOITS Internet Explorer invalid pointer memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17688, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17688</id>
        <msg>WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt</msg>
        <url>support.microsoft.com/kb/980182</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0806</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17689, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17689</id>
        <msg>WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt</msg>
        <url>support.microsoft.com/kb/980182</url>
      </rule>
      <rule>
        <bugtraq>30612</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2259</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17692, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17692</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer ExecWB security zone bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>12602</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2005-0500</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;window.open|28|&quot;; nocase; content:&quot;authentication.trusted.com&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>17703</id>
        <msg>SPECIFIC-THREATS Internet Explorer popup title bar spoofing attempt</msg>
      </rule>
      <rule>
        <bugtraq>34424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0553</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17709, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17709</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer EMBED element memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <bugtraq>34743</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1313</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;white-space|3A| pre&quot;; content:&quot;getElementById|28|'para'|29|.childNodes[0].splitText|28|11|29|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17719</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox ClearTextRun exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2255</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17720, service http, policy security-ips drop;</filter2>
        <id>17720</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer static text range overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>17404</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2006-1626</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;win = window.open|28 27|test.swf|27|&quot;; nocase; content:&quot;win = window.open|28 27|http|3A 2F 2F|&quot;; within:100; nocase; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>17726</id>
        <msg>SPECIFIC-THREATS Internet Explorer address bar spoofing attempt</msg>
      </rule>
      <rule>
        <bugtraq>34424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0553</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;embed type=|27 22| + asMimeTypes.shift&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17729</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer EMBED element memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-014.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-1883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,eot.download; metadata: engine shared, soid 3|17747, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17747</id>
        <msg>EXPLOIT Microsoft Internet Explorer compressed HDMX font processing integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-076.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3330</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17771, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17771</id>
        <msg>EXPLOIT Microsoft Internet Explorer cross-domain information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-071.mspx</url>
      </rule>
      <rule>
        <bugtraq>17196</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1359</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.createTextRange|28 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;&lt;input type|3D 22|image|22|&quot;; nocase; pcre:&quot;/\x3Cinput\s+type\x3D\x22image\x22\s+id\x3D(?P&lt;q1&gt;(\x22|\x27|))(?P&lt;t&gt;\S+)(?P=q1).*?document\x2EgetElementById\x28(?P&lt;q2&gt;(\x22|\x27|))(?P=t)(?P=q2)\x29\x2EcreateTextRange/isO&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17781</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3765</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;var tags = new Array|28 22|audio|22|, |22|a|22|, |22|base|22 29|&quot;; nocase; content:&quot;var html = |22|&lt;|22| + tags[i] + |22| |22| + atts[j]&quot;; distance:0; fast_pattern; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17804</id>
        <msg>WEB-CLIENT Mozilla Firefox html tag attributes memory corruption</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3962</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18062, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18062</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer CSS style memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/2458511.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1739</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|25 6E 25 6E 25 6E 25 6E 25 6E 25 6E 22 45 57 49 44 54 48 3D 6C 65 66 74 20 53 49 5A 45 3D 8B 8B 8B 8B 8B|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18077</id>
        <msg>SPECIFIC-THREATS Mozilla products CSS rendering out-of-bounds array write attempt</msg>
        <url>osvdb.org/show/osvdb/24660</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1739</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|HR WIDTH|3D|4444444 COLOR|3D 22 23|000000|22 3E|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18078</id>
        <msg>SPECIFIC-THREATS Mozilla products CSS rendering out-of-bounds array write attempt</msg>
        <url>osvdb.org/show/osvdb/24660</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-4091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.pdf; metadata: engine shared, soid 3|18102, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18102</id>
        <msg>WEB-CLIENT Adobe Reader invalid PDF JavaScript extension call</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-28.html</url>
      </rule>
      <rule>
        <bugtraq>35660</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;%u9090%u9090&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18167</id>
        <msg>WEB-CLIENT Possible generic javascript heap spray attempt</msg>
      </rule>
      <rule>
        <bugtraq>35660</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;%u4141%u4141&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18168</id>
        <msg>WEB-CLIENT Possible generic javascript heap spray attempt</msg>
      </rule>
      <rule>
        <bugtraq>10816</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0842</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C 73 74 79 6C 65 3E 3B 40 2F 2A|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18174</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CSS memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>10816</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0842</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C 73 74 79 6C 65 3E 40 3B 2F 2A|&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18175</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CSS memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17516</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1738</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|button onclick|3D 22|document|2E|getElementsByTagName|28 27|row|27 29 5B|0|5D 2E|style|2E|display|3D 27 2D|moz|2D|grid|2D|group|27 22|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18186</id>
        <msg>SPECIFIC-THREATS Mozilla products -moz-grid and -moz-grid-group display styles code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17516</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1790</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;InstallTrigger.install.call|28|document|2C 22|a|22 2C 22|a|22 29 3B|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18187</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox InstallTrigger.install memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3971</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;@import &quot;; content:&quot;@import &quot;; distance:0; content:&quot;@import &quot;; distance:0; pcre:&quot;/\x40import (url\x28)?\x22([^\x22]+)\x22.*\x40import (url\x28)?\x22\2\x22.*\x40import (url\x28)?\x22\2\x22/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18196</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer CSS importer use-after-free attempt</msg>
        <url>www.vupen.com/english/advisories/2010/3156</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3343</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18216, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18216</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer 6 #default#anim attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3345</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18217, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18217</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer 8 select element execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3346</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18218, service http, policy security-ips alert;</filter2>
        <id>18218</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer html time manipulation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;location.search.substring|28|1|29|&quot;; nocase; content:&quot;.charCodeAt|28|&quot;; within:200; pcre:&quot;/var\s+(\w+)\s*=\s*location\.search\.substring\(1\).{1,200}\1\.charCodeAt\(i\x25\1\.length\)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18239</id>
        <msg>WEB-CLIENT known malicious JavaScript decryption routine</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3971</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;@|00|i|00|m|00|p|00|o|00|r|00|t|00| |00|&quot;; content:&quot;@|00|i|00|m|00|p|00|o|00|r|00|t|00| |00|&quot;; distance:0; content:&quot;@|00|i|00|m|00|p|00|o|00|r|00|t|00| |00|&quot;; distance:0; pcre:&quot;/\x40\x00i\x00m\x00p\x00o\x00r\x00t\x00 \x00(u\x00r\x00l\x00\x28\x00)?\x22\x00([^\x22]+)\x22\x00.*\x40\x00i\x00m\x00p\x00o\x00r\x00t\x00 \x00(u\x00r\x00l\x00\x28\x00)?\x22\x00\2\x22.*\x40\x00i\x00m\x00p\x00o\x00r\x00t\x00 \x00(u\x00r\x00l\x00\x28\x00)?\x22\x00\2\x22/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18240</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer CSS importer use-after-free attempt</msg>
        <url>www.vupen.com/english/advisories/2010/3156</url>
      </rule>
      <rule>
        <bugtraq>44023</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-3552</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;launchjnlp&quot;; fast_pattern; nocase; content:&quot;docbase&quot;; within:100; nocase; pcre:&quot;/name\s*=\s*[\x22\x27]docbase[\x22\x27]\s+value\s*=\s*[\x22\x27][^\x22\x27]{200}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18244</id>
        <msg>WEB-CLIENT Sun Java browswer plugin docbase overflow attempt</msg>
        <url>osvdb.org/show/osvdb/69054</url>
      </rule>
      <rule>
        <bugtraq>44023</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-3552</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;name=|22|docbase|22| value=|22 27| + &quot;; nocase; content:&quot;sBoF&quot;; within:20; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18245</id>
        <msg>SPECIFIC-THREATS Sun Java browswer plugin docbase overflow attempt</msg>
        <url>osvdb.org/show/osvdb/69054</url>
      </rule>
      <rule>
        <bugtraq>16476</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;alert|28|xx.toXMLString&quot;; fast_pattern:only; content:&quot;for|28|i=0|3B|i&lt;|28|1024*1024|29|/2|3B|i++|29| m += |22 5C|n|22 3B|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>18250</id>
        <msg>SPECIFIC-THREATS Mozilla products EscapeAttributeValue integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-0555</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.rat; file_data; content:&quot;name&quot;; nocase; pcre:&quot;/rating\x2Dservice.{0,300}\x28\s*name\s*\x22[^\x22]{261}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>3686</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Content Advisor memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>14087</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2087</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;03D9F3F2-B0E3-11D2-B081-006008039BF0&quot;; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*03D9F3F2-B0E3-11D2-B081-006008039BF0/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3814</id>
        <msg>WEB-CLIENT IE javaprxy.dll COM access</msg>
        <url>www.osvdb.org/displayvuln.php?osvdb_id=17680</url>
      </rule>
      <rule>
        <bugtraq>667</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F72A7B0E-0DD8-11D1-BD6E-00AA00B92AF1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F72A7B0E-0DD8-11D1-BD6E-00AA00B92AF1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4169</id>
        <msg>WEB-ACTIVEX Internet Explorer Active Setup ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-037.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;BC5F1E51-5110-11D1-AFF5-006097C9A284&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*BC5F1E51-5110-11D1-AFF5-006097C9A284/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4198</id>
        <msg>WEB-ACTIVEX Internet Explorer Blnmgrps.dll ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;F27CE930-4CA3-11D1-AFF2-006097C9A284&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*F27CE930-4CA3-11D1-AFF2-006097C9A284/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4199</id>
        <msg>WEB-ACTIVEX Internet Explorer Blnmgrps.dll ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;208DD6A3-E12B-4755-9607-2E39EF84CFC5&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*208DD6A3-E12B-4755-9607-2E39EF84CFC5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4210</id>
        <msg>WEB-ACTIVEX Internet Explorer Msb1geen.dll ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0006F02A-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0006F02A-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4222</id>
        <msg>WEB-ACTIVEX Internet Explorer Outllib.dll ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;8E26BFC1-AFD6-11CF-BFFC-00AA003CFDFC&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*8E26BFC1-AFD6-11CF-BFFC-00AA003CFDFC/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4235</id>
        <msg>WEB-ACTIVEX Helper Object for Java ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>13799</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1790</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;body&quot;; nocase; content:&quot;onLoad&quot;; distance:0; nocase; content:&quot;window&quot;; distance:0; nocase; pcre:&quot;/&lt;body\s+[^&gt;]*onLoad\s*=\s*[\x22\x27]?window\(\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4647</id>
        <msg>WEB-CLIENT internet explorer javascript onload overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>13799</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1790</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;prompt&quot;; nocase; content:&quot;fillmem&quot;; distance:0; nocase; content:&quot;body&quot;; nocase; content:&quot;onLoad&quot;; distance:0; nocase; content:&quot;setTimeout&quot;; distance:0; nocase; pcre:&quot;/prompt\(fillmem[^\)]*\).*?&lt;body\s+[^&gt;]*onLoad\s*=\s*[\x22\x27]?setTimeout\(/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4917</id>
        <msg>WEB-CLIENT internet explorer javascript onload prompt obfuscation overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>18198</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2766</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mhtml|3A|//&quot;; nocase; pcre:&quot;/href\s*=\s*(\x22mhtml\x3A\x2F\x2F[A-Z\x2D]{2,31}\x3A[^\x22]{1253}|\x27mhtml\x3A\x2F\x2F[A-Z\x2D]{2,31}\x3A[^\x27]{1253}|mhtml\x3A\x2F\x2F[A-Z\x2D]{2,31}\x3A[^\x09\r\n\x20]{1253})/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6509</id>
        <msg>WEB-CLIENT Internet Explorer mhtml uri href buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>18198</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2766</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;URL&quot;; nocase; content:&quot;mhtml|3A|//&quot;; distance:0; nocase; pcre:&quot;/^\s*URL\s*=\s*mhtml\x3A\x2F\x2F[A-Z\x2D]{2,31}\x3A[^\r\n]{1253}/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6510</id>
        <msg>WEB-CLIENT Internet Explorer mhtml uri shortcut buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-043.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;01E04581-4EEE-11D0-BFE9-00AA005B4383&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*01E04581-4EEE-11D0-BFE9-00AA005B4383/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8019</id>
        <msg>WEB-ACTIVEX Internet Explorer Address Bar ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|1|00|E|00|0|00|4|00|5|00|8|00|1|00|-|00|4|00|E|00|E|00|E|00|-|00|1|00|1|00|D|00|0|00|-|00|B|00|F|00|E|00|9|00|-|00|0|00|0|00|A|00|A|00|0|00|0|00|5|00|B|00|4|00|3|00|8|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x001\x00E\x000\x004\x005\x008\x001\x00-\x004\x00E\x00E\x00E\x00-\x001\x001\x00D\x000\x00-\x00B\x00F\x00E\x009\x00-\x000\x000\x00A\x00A\x000\x000\x005\x00B\x004\x003\x008\x003\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8020</id>
        <msg>WEB-ACTIVEX Internet Explorer Address Bar ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>19181</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3677</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;window.navigator&quot;; nocase; content:&quot;=&quot;; within:2; content:&quot;java.&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8058</id>
        <msg>WEB-CLIENT Mozilla javascript navigator object access</msg>
        <url>www.mozilla.org/security/announce/2006/mfsa2006-45.html</url>
      </rule>
      <rule>
        <bugtraq>20042</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4566</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;new RegExp|28|&quot;; nocase; pcre:&quot;/^(?=[^\x29]*\x5c{2}[\x22\x27])[^\x29]*\x5b[^\x5d]*\x5c{2}[\x22\x27]/R&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>8443</id>
        <msg>WEB-CLIENT Mozilla regular expression heap corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>14087</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2087</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|3|00|D|00|9|00|F|00|3|00|F|00|2|00|-|00|B|00|0|00|E|00|3|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|0|00|8|00|1|00|-|00|0|00|0|00|6|00|0|00|0|00|8|00|0|00|3|00|9|00|B|00|F|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x003\x00D\x009\x00F\x003\x00F\x002\x00-\x00B\x000\x00E\x003\x00-\x001\x001\x00D\x002\x00-\x00B\x000\x008\x001\x00-\x000\x000\x006\x000\x000\x008\x000\x003\x009\x00B\x00F\x000\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9628</id>
        <msg>WEB-ACTIVEX javaprxy.dll ActiveX clsid unicode access</msg>
        <url>www.osvdb.org/displayvuln.php?osvdb_id=17680</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0046</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.pdf|23|&quot;; nocase; content:&quot;document.&quot;; distance:0; nocase; pcre:&quot;/\x2Epdf\x23[^\r\n]+\x3Djavascript\x3A[^\r\n]*document\x2E\w+/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9843</id>
        <msg>WEB-CLIENT Adobe Acrobat Plugin JavaScript parameter double free attempt</msg>
        <url>www.adobe.com/support/security/advisories/apsa07-01.html</url>
      </rule>
    </attacks>
    <groupid>320</groupid>
    <groupname>Client / Browser</groupname>
    <warnings>
      <rule>
        <bugtraq>23532</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2126</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dbms_snap_internal.delete_refresh_operations&quot;; nocase; pcre:&quot;/((\w+)[\r\n\s]*\x3a=[\r\n\s]*(\x27[^\x27]{46,}\x27|\x22[^\x22]{46,}\x22)[\r\n\s]*\x3b.*snap_name[\r\n\s]*=&gt;[\r\n\s]*\2|snap_name\s*=&gt;\s*(\x27[^\x27]{46}|\x22[^\x22]{46})|\(\s*(\x27[^\x27]*\x27|\x22[^\x22]*\x22)\s*,\s*(\x27[^\x27]{46}|\x22[^\x22]{46}))/si&quot;; classtype:attempted-user;</filter2>
        <id>11000</id>
        <msg>ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html</url>
      </rule>
      <rule>
        <bugtraq>23532</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2126</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dbms_snap_internal.delete_refresh_operations&quot;; nocase; pcre:&quot;/((\w+)[\r\n\s]*\x3a=[\r\n\s]*(\x27[^\x27]{32,}\x27|\x22[^\x22]{32,}\x22)[\r\n\s]*\x3b.*snap_owner[\r\n\s]*=&gt;[\r\n\s]*\2|snap_owner\s*=&gt;\s*(\x27[^\x27]{32,}|\x22[^\x22]{32,})|\(\s*(\x27[^\x27]{32,}|\x22[^\x22]{32,}))/si&quot;; classtype:attempted-user;</filter2>
        <id>11001</id>
        <msg>ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html</url>
      </rule>
      <rule>
        <bugtraq>23532</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2126</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dbms_snap_internal.generate_refresh_operations&quot;; nocase; pcre:&quot;/((\w+)[\r\n\s]*\x3a=[\r\n\s]*(\x27[^\x27]{46,}\x27|\x22[^\x22]{46,}\x22)[\r\n\s]*\x3b.*snap_name[\r\n\s]*=&gt;[\r\n\s]*\2|snap_name\s*=&gt;\s*(\x27[^\x27]{46,}|\x22[^\x22]{46,})|\(\s*(\x27[^\x27]*\x27|\x22[^\x22]*\x22)\s*,\s*(\x27[^\x27]{46,}|\x22[^\x22]{46,}))/si&quot;; classtype:attempted-user;</filter2>
        <id>11002</id>
        <msg>ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html</url>
      </rule>
      <rule>
        <bugtraq>23532</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2126</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dbms_snap_internal.generate_refresh_operations&quot;; nocase; pcre:&quot;/((\w+)[\r\n\s]*\x3a=[\r\n\s]*(\x27[^\x27]{32,}\x27|\x22[^\x22]{32,}\x22)[\r\n\s]*\x3b.*snap_owner[\r\n\s]*=&gt;[\r\n\s]*\2|snap_owner\s*=&gt;\s*(\x27[^\x27]{32,}|\x22[^\x22]{32,})|\(\s*(\x27[^\x27]{32,}|\x22[^\x22]{32,}))/si&quot;; classtype:attempted-user;</filter2>
        <id>11003</id>
        <msg>ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html</url>
      </rule>
      <rule>
        <bugtraq>24423</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1750</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;style&quot;; nocase; content:&quot;csstext&quot;; distance:0; nocase; pcre:&quot;/\x3c[^\x3e]*style\s*=[^\x3e]*?csstext\x3a/smi&quot;; classtype:attempted-user;</filter2>
        <id>11966</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer CSS tag memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>22966</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2007-1499</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;about|3A|cancel|23|&quot;; nocase; metadata:service http; classtype:misc-attack;</filter2>
        <id>12014</id>
        <msg>WEB-MISC Internet Explorer navcancl.htm url spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-033.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-5045</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;-chrome&quot;; pcre:&quot;/-chrome\s*javascript/&quot;; classtype:attempted-user;</filter2>
        <id>12593</id>
        <msg>EXPLOIT Firefox Quicktime chrome exploit</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-5243</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00|R&quot;; depth:4; byte_test:4, &gt;, 152, 4, relative; classtype:attempted-admin;</filter2>
        <id>13840</id>
        <msg>EXPLOIT Borland Interbase service attach operation buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-5243</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 14|&quot;; depth:4; byte_test:4, &gt;, 540, 4, relative; classtype:attempted-admin;</filter2>
        <id>13841</id>
        <msg>EXPLOIT Borland Interbase create operation buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-5243</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 13|&quot;; depth:4; byte_test:4, &gt;, 1024, 4, relative; classtype:attempted-admin;</filter2>
        <id>13842</id>
        <msg>EXPLOIT Borland Interbase operation buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2257</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13974;</filter2>
        <id>13974</id>
        <msg>WEB-CLIENT Internet Explorer XHTML element memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-045.mspx</url>
      </rule>
      <rule>
        <bugtraq>29736</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2908</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;36723f97-7aa0-11d4-8919-ff2d71d0d32c&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*36723f97-7aa0-11d4-8919-ff2d71d0d32c\s*}?\s*(?P=q1)[^&gt;]*&gt;.*&lt;param\s*[^&gt;]*\s*name\s*=\s*(operation|printer-url)[^&gt;]*\s*value\s*=\s*(\x22[^&gt;\s\x22]{256}|\x27[^&gt;\s\x27]{256}|[^&gt;\s]{256})/Osmi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14037</id>
        <msg>WEB-ACTIVEX Novell iPrint ActiveX operation or printer-url parameter overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1141</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15531;</filter2>
        <id>15531</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Unexpected method call remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-1531</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15538;</filter2>
        <id>15538</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer onreadystatechange memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2003-1025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;%01@&quot;; pcre:&quot;/http\x3A\x2f\x2f[^\r\n]+\x2501\x40/smi&quot;; metadata:service http; classtype:misc-activity;</filter2>
        <id>15933</id>
        <msg>WEB-CLIENT Internet Explorer URL canonicalization address bar spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms04-004.mspx</url>
      </rule>
      <rule>
        <bugtraq>24283</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2007-3091</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;win = open|28 22|poc_dummy.html|22|,|22|victim|22 29 3B|&quot;; metadata:service http; classtype:misc-activity;</filter2>
        <id>16010</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer Javascript Page update race condition attempt</msg>
      </rule>
      <rule>
        <bugtraq>23769</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0945</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;oa.cols=0x41414141|3B|&quot;; content:&quot;ob.mergeAttributes|28|oa,1|29 3B|&quot;; distance:0; metadata:service http; classtype:attempted-user;</filter2>
        <id>16011</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CSS property method handling memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2507</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16155;</filter2>
        <id>16155</id>
        <msg>WEB-CLIENT Internet Explorer indexing service malformed parameters</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>29802</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2785</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;counter-reset|3A| section&quot;; nocase; content:&quot;&lt;li&gt;&lt;/li&gt;|0A|&lt;li&gt;&lt;/li&gt;|0A|&lt;li&gt;&lt;/li&gt;|0A|&lt;li&gt;&lt;/li&gt;|0A|&lt;li&gt;&lt;/li&gt;|0A|&quot;; distance:0; nocase; classtype:attempted-user;</filter2>
        <id>16292</id>
        <msg>SPECIFIC-THREATS Mozilla CSS value counter overflow attempt</msg>
        <url>www.mozilla.org/security/announce/2008/mfsa2008-34.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3674</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16330;</filter2>
        <id>16330</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer orphan DOM objects memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0248</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16378;</filter2>
        <id>16378</id>
        <msg>WEB-CLIENT Internet Explorer deleted object cells reference memory corruption vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>38519</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Length&quot;; nocase; http_header; pcre:&quot;/^Content-Length\s*\x3A\s*[^\n]{20}/miH&quot;; classtype:attempted-user;</filter2>
        <id>16481</id>
        <msg>WEB-CLIENT Opera Content-Length header integer overflow attempt</msg>
        <url>www.hack0wn.com/view.php?xroot=672.0&amp;cat=exploits</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0491</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16507;</filter2>
        <id>16507</id>
        <msg>WEB-CLIENT Internet Explorer onreadystatechange memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1939</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;parent&quot;; content:&quot;.prompt&quot;; distance:0; pcre:&quot;/var\s+(\w+)\s*\x3D\s*parent\s*\x3b.*\1\x2Eprompt.*\1\x2Eclose/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16596</id>
        <msg>WEB-CLIENT Apple Safari information disclosure and remote code execution attempt</msg>
        <url>secunia.com/advisories/39670</url>
      </rule>
      <rule>
        <bugtraq>38691</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0054</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;removeChild(document.getElementsByTagName(|22|img|22|)[0])&quot;; classtype:attempted-user;</filter2>
        <id>16631</id>
        <msg>SPECIFIC-THREATS Safari image use after remove attempt</msg>
        <url>&quot;support.apple.com/kb/HT4070&quot;</url>
      </rule>
      <rule>
        <bugtraq>38691</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0054</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;imgBar = document.body.getElementsByTagName(|22|img|22|)[0]&quot;; classtype:attempted-user;</filter2>
        <id>16632</id>
        <msg>SPECIFIC-THREATS Safari image use after reparent attempt</msg>
        <url>&quot;support.apple.com/kb/HT4070&quot;</url>
      </rule>
      <rule>
        <bugtraq>4858</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0902</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;img src=javascript&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1667</id>
        <msg>WEB-MISC cross site scripting HTML Image tag set to javascript attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1258</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17115;</filter2>
        <id>17115</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer cross domain information disclosure attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-2556</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|17129;</filter2>
        <id>17129</id>
        <msg>WEB-CLIENT Internet Explorer use-after-free memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>41933</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-2755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;object&quot;; nocase; content:&quot;|22 22|&quot;; within:200; fast_pattern; pcre:&quot;/\x3Cobject(?![^\x3E]+?src)[^\x3E]+?data\s*\x3D\s*\x22\x22/i&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17153</id>
        <msg>WEB-CLIENT Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>41933</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-2755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;object&quot;; nocase; content:&quot;|27 27|&quot;; within:200; fast_pattern; pcre:&quot;/\x3Cobject(?![^\x3E]+?src)[^\x3E]+?data\s*\x3D\s*\x27\x27/i&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17154</id>
        <msg>WEB-CLIENT Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>17634</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1986</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;cellspacing&quot;; nocase; pcre:&quot;/^\s*\x3D\s*\d{10}/R&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17216</id>
        <msg>WEB-CLIENT Apple Safari TABLE tag with large CELLSPACING attribute exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>17634</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1987</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;&lt;frame&quot;; nocase; content:&quot;scrolling&quot;; within:100; nocase; isdataat:10,relative; content:!&quot;auto&quot;; within:10; nocase; content:!&quot;yes&quot;; within:10; nocase; content:!&quot;no&quot;; within:10; nocase; pcre:&quot;/\x3Cframe([^\x3E]+scrolling\s*\x3D(?!\s*(\x22|\x27)?\s*(yes|no|auto))){2}/i&quot;; classtype:attempted-user;</filter2>
        <id>17217</id>
        <msg>WEB-CLIENT Apple Safari invalid FRAME tag remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>17634</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1988</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;&lt;li&quot;; nocase; pcre:&quot;/^[^\x3E]+?value\s*\x3D\s*\d{10}/iR&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17218</id>
        <msg>WEB-CLIENT Apple Safari LI tag with large VALUE attribute exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26816</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3903</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; content:&quot;document|2E|createElement&quot;; nocase; content:&quot;|2E|cloneNode()&quot;; distance:0; fast_pattern; nocase; content:&quot;|2E|cloneNode()&quot;; distance:0; nocase; classtype:attempted-user;</filter2>
        <id>17303</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer clone object memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>15660</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4089</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|style&quot;; nocase; content:&quot;@import url|28 22|http|3A 2F 2F|news|2E|google|2E|com|2F|news|3F|hl|3D|en|26|ned|3D|us|26|q|3D 25|7D|25|7B|22 29|&quot;; distance:0; nocase; classtype:attempted-user;</filter2>
        <id>17311</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>15660</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4089</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|3C|style&quot;; nocase; content:&quot;@import url|28 22|http|3A 2F 2F|search|2E|msn|2E|com|2F|results|2E|aspx|3F|q|3D 25|7D|25|7B|22 29|&quot;; distance:0; nocase; classtype:attempted-user;</filter2>
        <id>17312</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>28379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1544</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;XMLHttpRequest&quot;; nocase; content:&quot;setRequestHeader&quot;; distance:0; nocase; pcre:&quot;/setRequestHeader\x28[^\x29]*(Host|Referer|Content-Length)[\x22\x27][^\x2c]*[\xA0-\xFF]/smi&quot;; classtype:attempted-user;</filter2>
        <id>17384</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer setRequestHeader overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1544</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;XMLHttpRequest&quot;; nocase; content:&quot;setRequestHeader&quot;; distance:0; nocase; pcre:&quot;/setRequestHeader\x28[^\x29]*(Host|Referer|Content-Length).*?String.fromCharCode\x28/smi&quot;; byte_test:3,&gt;,160,0,relative,string; classtype:attempted-user;</filter2>
        <id>17385</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer setRequestHeader overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2005-2830</cve>
        <filter1>tcp $HOME_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; flowbits:isset,http.stat_code_407; content:&quot;|2F|accounts|2F|ServiceLogin|3F|service|3D|mail|26|passive|3D|true|26|rm|3D|false|26|continue|3D|http&quot;; nocase; http_uri; metadata:service http; classtype:misc-attack;</filter2>
        <id>17448</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer HTTPS proxy information disclosure vulnerability</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>19667</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Location|3A|&quot;; nocase; http_header; isdataat:600,relative; pcre:&quot;/Location\x3A\s+[^\r\n]{600}/Hi&quot;; classtype:attempted-user;</filter2>
        <id>17494</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Long URL Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;&quot;; content:&quot;onmouseover&quot;; within:24; nocase; pcre:&quot;/[^&gt;]\w*\s*(on(mouse(over|up|down)|load|click)=([^(\n|\s|&gt;)]|\(|\))*\s*){21}/Rmi&quot;; classtype:attempted-user;</filter2>
        <id>17512</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;&quot;; content:&quot;onclick&quot;; within:20; nocase; pcre:&quot;/[^&gt;]\w*\s*(on(mouse(over|up|down)|load|click)=([^(\n|\s|&gt;)]|\(|\))*\s*){21}/Rmi&quot;; classtype:attempted-user;</filter2>
        <id>17513</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;&quot;; content:&quot;onmouseup&quot;; within:22; nocase; pcre:&quot;/[^&gt;]\w*\s*(on(mouse(over|up|down)|load|click)=([^(\n|\s|&gt;)]|\(|\))*\s*){21}/Rmi&quot;; classtype:attempted-user;</filter2>
        <id>17514</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;&quot;; content:&quot;onload&quot;; within:19; nocase; pcre:&quot;/[^&gt;]\w*\s*(on(mouse(over|up|down)|load|click)=([^(\n|\s|&gt;)]|\(|\))*\s*){21}/Rmi&quot;; classtype:attempted-user;</filter2>
        <id>17515</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17131</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1245</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;&quot;; content:&quot;onmousedown&quot;; within:24; nocase; pcre:&quot;/[^&gt;]\w*\s*(on(mouse(over|up|down)|load|click)=([^(\n|\s|&gt;)]|\(|\))*\s*){21}/Rmi&quot;; classtype:attempted-user;</filter2>
        <id>17516</id>
        <msg>WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>32323</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5178</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;file|3A 2F 2F|&quot;; fast_pattern:only; nocase; pcre:&quot;/(src|href)\s*=\s*(\x22|\x27|)file\x3a\x2f\x2f[^\s\x22\x27]{900}/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17725</id>
        <msg>WEB-CLIENT Opera file URI handling buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>36881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3867</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,java_class_file.request; file_data; content:&quot;|01 00 2C 28|Ljava|2F|net|2F|URL|3B 29|Ljavax|2F|sound|2F|midi|2F|Soundbank&quot;; content:&quot;|01 00 0C|getSoundbank&quot;; content:&quot;file|3A 2F 2F|&quot;; byte_test:2,&gt;,312,-9,relative,big; content:&quot;|01|&quot;; within:1; distance:-10; pcre:&quot;/^.{2}file|3A 2F 2F|[\x21-\x7E]{305}/R&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17776</id>
        <msg>WEB-CLIENT Sun Java HsbParser.getSoundBank stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;function re|28|s,n,r,b,e|29|{if|28|s&lt;b|7C 7C|s&gt;e|29|return s|3B|&quot;; fast_pattern:only; classtype:trojan-activity;</filter2>
        <id>18132</id>
        <msg>SPECIFIC-THREATS malware-associated JavaScript obfuscation function</msg>
        <url>labs.snort.org/docs/18132.html</url>
      </rule>
      <rule>
        <bugtraq>22679</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|64 6F 63 75 6D 65 6E 74 2E 77 72 69 74 65 28 27 3C 68 74 6D 6C 3E 3C 62 6F 64 79 20 6F 6E 75 6E 6C 6F 61 64 3D 22|&quot;; content:&quot;|66 6F 72 20 28 69 3D 30 3B 69 3C 32 35 30 3B 69 2B 2B 29|&quot;; distance:0; content:&quot;|64 6F 63 75 6D 65 6E 74 2E 77 72 69 74 65 28 27 3C 73 63 72 69 70 74 3E 64 6F 63 75 6D 65 6E 74 2E 77 72 69 74 65 28 22|&quot;; distance:0; classtype:attempted-user;</filter2>
        <id>18170</id>
        <msg>SPECIFIC-THREATS Mozilla Firefox and SeaMonkey onUnload event handler memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>19197</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3113</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|73 72 63 3D 22 64 61 74 61 3A 74 65 78 74 2F 68 74 6D 6C 3B 63 68 61 72 73 65 74 3D 75 74 66 2D 38 2C 25 33 43 68 74 6D 6C 25 33 45 25 30 44 25 30 41|&quot;; content:&quot;|25|3Cscript|25|3E&quot;; within:300; content:&quot;window|2E|removeEventListener|28|&quot;; within:500; classtype:attempted-user;</filter2>
        <id>18176</id>
        <msg>SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>19197</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3113</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|73 72 63 3D 22 64 61 74 61 3A 74 65 78 74 2F 68 74 6D 6C 3B 63 68 61 72 73 65 74 3D 75 74 66 2D 38 2C 25 33 43 68 74 6D 6C 25 33 45 25 30 44 25 30 41|&quot;; content:&quot;|25|3Cscript|25|3E&quot;; within:300; content:&quot;window|2E|addEventListener|28|&quot;; within:500; classtype:attempted-user;</filter2>
        <id>18177</id>
        <msg>SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>19197</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3113</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|63 6C 61 73 73 3D 22 6D 65 6E 75 22 3E 3C 61 20 68 72 65 66 3D 22 22 20 74 61 72 67 65 74 3D 22 5F 74 6F 70 22 3E 51 51 51 51 51 51 51 51 51 51 3C 2F 61 3E|&quot;; content:&quot;|63 6C 61 73 73 3D 22 6D 65 6E 75 22 3E 3C 61 20 68 72 65 66 3D 22 22 20 74 61 72 67 65 74 3D 22 5F 74 6F 70 22 3E 51 51 51 51 51 51 51 51 51 51 3C 2F 61 3E|&quot;; distance:0; classtype:attempted-user;</filter2>
        <id>18178</id>
        <msg>SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>18682</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3280</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|6F 6E 6C 6F 61 64 3D 22 73 65 74 54 69 6D 65 6F 75 74 28 27 61 6C 65 72 74 28 6F 2E 6F 62 6A 65 63 74 2E 64 6F 63 75 6D 65 6E 74 45 6C 65 6D 65 6E 74 2E 6F 75 74 65 72 48 54 4D 4C 29 27 2C 31 30 30 30 29|&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>18193</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>18682</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3280</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|72 65 74 72 20 3D 20 6F 2E 6F 62 6A 65 63 74 2E 64 6F 63 75 6D 65 6E 74 45 6C 65 6D 65 6E 74 2E 69 6E 6E 65 72 48 54 4D 4C|&quot;; content:&quot;|73 65 74 54 69 6D 65 6F 75 74 28 27 72 65 74 72 69 65 76 65 28 29 27 2C 31 29|&quot;; distance:0; metadata:service http; classtype:attempted-user;</filter2>
        <id>18194</id>
        <msg>SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3962</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18221;</filter2>
        <id>18221</id>
        <msg>WEB-CLIENT Internet Explorer malformed table remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-090.mspx</url>
      </rule>
      <rule>
        <bugtraq>5346</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-0815</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document.domain|28|&quot;; nocase; classtype:attempted-user;</filter2>
        <id>1840</id>
        <msg>WEB-CLIENT Javascript document.domain attempt</msg>
      </rule>
      <rule>
        <bugtraq>5293</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;javascript|3A|//&quot;; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>1841</id>
        <msg>WEB-CLIENT Javascript URL host spoofing attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/oprocmgr-status&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1874</id>
        <msg>WEB-MISC Oracle Java Process Manager access</msg>
        <nessus>10851</nessus>
      </rule>
      <rule>
        <bugtraq>12881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;image/&quot;; http_header; pcre:&quot;/^Content-Type\s*\x3a(\s*|\s*\r?\n\s+)image\x2fgif/smiH&quot;; content:&quot;GIF&quot;; content:&quot;!|FF 0B|NETSCAPE2.0&quot;; distance:0; nocase; content:&quot;|02|&quot;; within:1; distance:1; byte_test:4,&gt;,0x7f,3,relative; classtype:attempted-user;</filter2>
        <id>3534</id>
        <msg>WEB-CLIENT Mozilla GIF single packet heap overflow - NETSCAPE2.0</msg>
        <nessus>17605</nessus>
      </rule>
      <rule>
        <bugtraq>12881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.gif; content:&quot;GIF&quot;; content:&quot;!|FF 0B|NETSCAPE2.0&quot;; distance:0; nocase; content:&quot;|02|&quot;; within:1; distance:1; byte_test:4,&gt;,0x7f,3,relative; classtype:attempted-user;</filter2>
        <id>3536</id>
        <msg>WEB-CLIENT Mozilla GIF multipacket heap overflow - NETSCAPE2.0</msg>
        <nessus>17605</nessus>
      </rule>
      <rule>
        <bugtraq>30560</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2939</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;IFRAME&quot;; nocase; pcre:&quot;/\x3c\s*IFRAME\s*[^\x3e]*src=\x22javascript\x3a/smi&quot;; classtype:attempted-user;</filter2>
        <id>3679</id>
        <msg>WEB-CLIENT Web-client IFRAME src javascript code execution</msg>
        <nessus>18243</nessus>
      </rule>
      <rule>
        <bugtraq>13941</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1211</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; content:&quot;IHDR&quot;; within:4; distance:4; content:&quot;tRNS&quot;; distance:0; byte_test:4,&gt;,256,-8,relative,big; classtype:attempted-user;</filter2>
        <id>3689</id>
        <msg>WEB-CLIENT Internet Explorer tRNS overflow attempt</msg>
        <nessus>18490</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-025.mspx</url>
      </rule>
      <rule>
        <bugtraq>13799</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1790</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;document.write&quot;; nocase; pcre:&quot;/document\.write\(([^\x22\x27\x29\x3B]*([\x22\x27]))((?(?=\2)\2(?1)))\x3C(?3)b(?3)o(?3)d(?3)y(?3)\s*(?3)o(?3)n(?3)l(?3)o(?3)a(?3)d(?3)\s*(?3)=(?3)\s*(?3)w(?3)i(?3)n(?3)d(?3)o(?3)w(?3)\x28(?3)\x29/smi&quot;; classtype:attempted-user;</filter2>
        <id>4916</id>
        <msg>WEB-CLIENT internet explorer javascript onload document.write obfuscation overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <bugtraq>12881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;image/&quot;; pcre:&quot;/^Content-Type\s*\x3a(\s*|\s*\r?\n\s+)image\x2fgif/smi&quot;; content:&quot;GIF&quot;; distance:0; content:&quot;!|FF 0B|ANIMEXTS1.0&quot;; distance:0; nocase; content:&quot;|02|&quot;; within:1; distance:1; byte_test:4,&gt;,0x7f,3,relative; classtype:attempted-user;</filter2>
        <id>6502</id>
        <msg>WEB-CLIENT Mozilla GIF single packet heap overflow - ANIMEXTS1.0</msg>
        <nessus>17605</nessus>
      </rule>
      <rule>
        <bugtraq>12881</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0399</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.gif; content:&quot;GIF&quot;; content:&quot;!|FF 0B|ANIMEXTS1.0&quot;; distance:0; nocase; content:&quot;|02|&quot;; within:1; distance:1; byte_test:4,&gt;,0x7f,3,relative; classtype:attempted-user;</filter2>
        <id>6503</id>
        <msg>WEB-CLIENT Mozilla GIF multipacket heap overflow - ANIMEXTS1.0</msg>
        <nessus>17605</nessus>
      </rule>
      <rule>
        <bugtraq>4858</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0902</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;img src=javascript&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>7071</id>
        <msg>WEB-MISC encoded cross site scripting HTML Image tag set to javascript attempt</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;233A9694-667E-11d1-9DFB-006097D50408&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*233A9694-667E-11d1-9DFB-006097D50408\s*}?\s*(?P=q1)(\s|&gt;)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11236</id>
        <msg>WEB-ACTIVEX OutlookExpress.AddressBook ActiveX clsid access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|3|00|3|00|A|00|9|00|6|00|9|00|4|00|-|00|6|00|6|00|7|00|E|00|-|00|1|00|1|00|d|00|1|00|-|00|9|00|D|00|F|00|B|00|-|00|0|00|0|00|6|00|0|00|9|00|7|00|D|00|5|00|0|00|4|00|0|00|8|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q2&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11237</id>
        <msg>WEB-ACTIVEX OutlookExpress.AddressBook ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;O|00|u|00|t|00|l|00|o|00|o|00|k|00|E|00|x|00|p|00|r|00|e|00|s|00|s|00|.|00|A|00|d|00|d|00|r|00|e|00|s|00|s|00|B|00|o|00|o|00|k|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q3&gt;\x22|\x27|)O\x00u\x00t\x00l\x00o\x00o\x00k\x00E\x00x\x00p\x00r\x00e\x00s\x00s\x00.\x00A\x00d\x00d\x00r\x00e\x00s\x00s\x00B\x00o\x00o\x00k\x00(?P=q3)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)O\x00u\x00t\x00l\x00o\x00o\x00k\x00E\x00x\x00p\x00r\x00e\x00s\x00s\x00.\x00A\x00d\x00d\x00r\x00e\x00s\x00s\x00B\x00o\x00o\x00k\x00(?P=q4)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11238</id>
        <msg>WEB-ACTIVEX OutlookExpress.AddressBook ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3213</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; http_method; content:&quot;/owa/ev.owa&quot;; http_uri; content:&quot;ns=Rule&quot;; http_uri; content:&quot;ev=Save&quot;; http_uri; content:&quot;&amp;#60params&amp;#62&amp;#60Id&amp;#62&amp;#60/Id&amp;#62&amp;#60Name&amp;#62Test&amp;#60/Name&amp;#62&amp;#60RecpA4&amp;#62&amp;#60item&amp;#62&amp;#60Rcp&quot;; http_client_body; content:&quot;AO=|22|3|22|&amp;#62&amp;#60/Rcp&amp;#62&amp;#60/item&amp;#62&amp;#60/RecpA4&amp;#62&amp;#60Actions&amp;#62&amp;#60item&amp;#62&amp;#60rca&quot;; http_client_body; content:&quot; t=|22|4|22|&amp;#62&amp;#60/rca&amp;#62&amp;#60/item&amp;#62&amp;#60/Actions&amp;#62&amp;#60/params&amp;#62&quot;; http_client_body; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17296</id>
        <msg>WEB-MISC Outlook Web Access XSRF attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/2401593.mspx</url>
      </rule>
      <rule>
        <bugtraq>3026</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0538</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OVCtl.OVCtl.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22OVCtl.OVCtl.1\x22|\x27OVCtl.OVCtl.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OVCtl.OVCtl.1\x22|\x27OVCtl.OVCtl.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4150</id>
        <msg>WEB-ACTIVEX Outlook View OVCtl ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0006F071-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0006F071-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4900</id>
        <msg>WEB-ACTIVEX Outlook Progress Ctl ActiveX Object Access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-054.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;OutlookExpress.AddressBook&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22OutlookExpress\.AddressBook\x22|\x27OutlookExpress\.AddressBook\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22OutlookExpress\.AddressBook\x22|\x27OutlookExpress\.AddressBook\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7005</id>
        <msg>WEB-ACTIVEX OutlookExpress.AddressBook ActiveX function call access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0006F03A-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0006F03A-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8371</id>
        <msg>WEB-ACTIVEX Outlook.Application ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|6|00|F|00|0|00|3|00|A|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x000\x000\x006\x00F\x000\x003\x00A\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8372</id>
        <msg>WEB-ACTIVEX Outlook.Application ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <bugtraq>3026</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0538</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0006F063-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0006F063-0000-0000-C000-000000000046\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8422</id>
        <msg>WEB-ACTIVEX Outlook View OVCtl ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0006F033-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*0006F033-0000-0000-C000-000000000046/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8721</id>
        <msg>WEB-ACTIVEX Outlook Data Object ActiveX CLSID access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|6|00|F|00|0|00|3|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x000\x000\x006\x00F\x000\x003\x003\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8722</id>
        <msg>WEB-ACTIVEX Outlook Data Object ActiveX CLSID unicode access</msg>
        <url>metasploit.com/projects/Framework/modules/exploits/ie_createobject.pm</url>
      </rule>
      <rule>
        <bugtraq>21649</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0006F023-0000-0000-C000-000000000046&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0006F023-0000-0000-C000-000000000046\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9668</id>
        <msg>WEB-ACTIVEX Outlook Recipient Control ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21649</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|6|00|F|00|0|00|2|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x006\x00F\x000\x002\x003\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9669</id>
        <msg>WEB-ACTIVEX Outlook Recipient Control ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21649</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;RECIP.RecipCtl.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22RECIP.RecipCtl.1\x22|\x27RECIP.RecipCtl.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22RECIP.RecipCtl.1\x22|\x27RECIP.RecipCtl.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9670</id>
        <msg>WEB-ACTIVEX Outlook Recipient Control ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>3026</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0538</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|0|00|0|00|6|00|F|00|0|00|6|00|3|00|-|00|0|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|-|00|C|00|0|00|0|00|0|00|-|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|0|00|4|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x000\x000\x006\x00F\x000\x006\x003\x00-\x000\x000\x000\x000\x00-\x000\x000\x000\x000\x00-\x00C\x000\x000\x000\x00-\x000\x000\x000\x000\x000\x000\x000\x000\x000\x000\x004\x006\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9819</id>
        <msg>WEB-ACTIVEX Outlook View OVCtl ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-038.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0034</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.xls; content:&quot;S|00|a|00|v|00|e|00|d|00|S|00|e|00|a|00|r|00|c|00|h|00|&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9847</id>
        <msg>WEB-CLIENT Outlook Saved Search download attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-003.mspx</url>
      </rule>
    </attacks>
    <groupid>330</groupid>
    <groupname>Client / Email</groupname>
    <warnings>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-0110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|13573;</filter2>
        <id>13573</id>
        <msg>WEB-CLIENT Microsoft Outlook arbitrary command line attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-015.mspx</url>
      </rule>
      <rule>
        <bugtraq>13952</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0563</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;javascript|3A|alert|28|'Attacker supplied script&quot;; metadata:service smtp; classtype:attempted-user;</filter2>
        <id>15947</id>
        <msg>SPECIFIC-THREATS Microsoft Outlook Web Access Cross-Site Scripting attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3897</cve>
        <filter1>tcp $EXTERNAL_NET 119 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;1094795585 |0D 0A|1094795585 |0D 0A|&quot;; classtype:attempted-user;</filter2>
        <id>16428</id>
        <msg>EXPLOIT Microsoft Outlook Express and Windows Mail NNTP handling buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-056.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>26586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3066</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FDC7A535-4070-4B92-A0EA-D9994BCC0DC5&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FDC7A535-4070-4B92-A0EA-D9994BCC0DC5\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FDC7A535-4070-4B92-A0EA-D9994BCC0DC5\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import))\s*\(/Osi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10192</id>
        <msg>WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>26586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3066</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|D|00|C|00|7|00|A|00|5|00|3|00|5|00|-|00|4|00|0|00|7|00|0|00|-|00|4|00|B|00|9|00|2|00|-|00|A|00|0|00|E|00|A|00|-|00|D|00|9|00|9|00|9|00|4|00|B|00|C|00|C|00|0|00|D|00|C|00|5|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/Osi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10193</id>
        <msg>WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3066</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;IERPCtl.IERPCtl&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22IERPCtl\.IERPCtl\x22|\x27IERPCtl\.IERPCtl\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import)\s*|.*(?P=v)\s*\.\s*(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22IERPCtl\.IERPCtl\x22|\x27IERPCtl\.IERPCtl\x27)\s*\)(\s*\.\s*(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import)\s*|.*(?P=n)\s*\.\s*(GetComponentVersion|HandleAction|DoAutoUpdateRequest|Quoting|PlayerProperty|Import)\s*)\s*\(/Osmi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>10194</id>
        <msg>WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>23652</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;|00 00 00 01|ftyp&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11180</id>
        <msg>WEB-CLIENT quicktime movie ftyp buffer underflow</msg>
      </rule>
      <rule>
        <bugtraq>23698</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2365</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; content:&quot;PLTE&quot;; byte_test:4,&gt;,768,-8,relative,big; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>11267</id>
        <msg>WEB-CLIENT Adobe Photoshop PNG file handling stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>24856</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3456</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,flv.xfer; content:&quot;|12|&quot;; content:&quot;|02|&quot;; within:1; distance:10; byte_jump:2,0,relative,big; content:&quot;|0C|&quot;; within:1; byte_test:4, &gt;, 2147483647, 0, relative, big; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12183</id>
        <msg>EXPLOIT Adobe FLV long string script data buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>24658</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3410</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;smil &quot;; nocase; content:&quot;wallclock|28|&quot;; distance:0; nocase; pcre:&quot;/wallclock\x28((\d{2}\x3A){2}\d{2}\.[^\x2b\x2d\x5a]{11}|\d{4}-\d{2}-\d{2}T(\d{2}\x3A){2}\d{2}\.[^\x2b\x2d\x5a]{11})/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12219</id>
        <msg>WEB-CLIENT SMIL RealPlayer wallclock parsing buffer overflow</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</url>
      </rule>
      <rule>
        <bugtraq>26549</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6166</cve>
        <filter1>udp $EXTERNAL_NET 554 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; content:&quot;RTSP&quot;; depth:4; fast_pattern; content:&quot;Content-Type&quot;; nocase; isdataat:257,relative; content:!&quot;|0A|&quot;; within:257; pcre:&quot;/Content-Type\s*\x3A[^\n\x3A]{256}/smi&quot;; metadata:policy security-ips drop, service rtsp; classtype:attempted-user;</filter2>
        <id>12742</id>
        <msg>EXPLOIT Apple Quicktime UDP RTSP sdp type buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26341</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3750</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.quicktime; content:&quot;stsd&quot;; byte_test:4,&gt;,0,4,relative,big; byte_test:4,&lt;,12,8,relative,big; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12746</id>
        <msg>EXPLOIT Apple QuickTime STSD atom overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26344</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4672</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 00 00 00 00 00 00|&quot;; content:&quot;|00 11 02 FF|&quot;; distance:0; fast_pattern; content:&quot;|82 01|&quot;; distance:0; byte_test:4,&lt;,50,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12757</id>
        <msg>WEB-CLIENT Apple Quicktime uncompressed PICT stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m7&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m7)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q18&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA\s*}?\s*(?P=q18)(\s|&gt;).*(?P=id1)\s*\.\s*(ParseWallClock|GetSourceTransport)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q19&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA\s*}?\s*(?P=q19)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m8&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m8)(\s|&gt;).*(?P=id2)\.(ParseWallClock|GetSourceTransport))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12766</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX clsid access</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|C|00|D|00|A|00|A|00|0|00|3|00|-|00|8|00|B|00|E|00|4|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|8|00|4|00|B|00|-|00|0|00|0|00|2|00|0|00|A|00|F|00|B|00|B|00|C|00|C|00|F|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q20&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00F\x00C\x00D\x00A\x00A\x000\x003\x00-\x008\x00B\x00E\x004\x00-\x001\x001\x00C\x00F\x00-\x00B\x008\x004\x00B\x00-\x000\x000\x002\x000\x00A\x00F\x00B\x00B\x00C\x00C\x00F\x00A\x00(}\x00)?(?P=q20)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12767</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX clsid unicode access</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer G2 Control&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*G2\s*Control\x22|\x27rmocx\.RealPlayer\s*G2\s*Control\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(ParseWallClock|GetSourceTransport)\s*|.*(?P=v)\s*\.\s*(ParseWallClock|GetSourceTransport)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*G2\s*Control\x22|\x27rmocx\.RealPlayer\s*G2\s*Control\x27)\s*\)(\s*\.\s*(ParseWallClock|GetSourceTransport)\s*|.*(?P=n)\s*\.\s*(ParseWallClock|GetSourceTransport)\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12768</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX function call access</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|G|00|2|00| |00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q21&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*G\x002\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q21)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q22&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*G\x002\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q22)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>12769</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX function call unicode access</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</url>
      </rule>
      <rule>
        <bugtraq>26586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5601</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;VulObject = |22|IER|22| + |22|PCtl.I|22| + |22|ERP|22| + |22|Ctl.1|22 3B|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12775</id>
        <msg>SPECIFIC-THREATS obfuscated RealPlayer Ierpplug.dll ActiveX exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-6244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ShockwaveFlash.ShockwaveFlash&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ShockwaveFlash\.ShockwaveFlash\x22|\x27ShockwaveFlash\.ShockwaveFlash\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*navigateToURL\s*|.*?(?P=v)\s*\.\s*navigateToURL\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ShockwaveFlash\.ShockwaveFlash\x22|\x27ShockwaveFlash\.ShockwaveFlash\x27)\s*\)(\s*\.\s*navigateToURL\s*|.*?(?P=n)\s*\.\s*navigateToURL\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13216</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX function call access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb07-20.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-6244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|h|00|o|00|c|00|k|00|w|00|a|00|v|00|e|00|F|00|l|00|a|00|s|00|h|00|.|00|S|00|h|00|o|00|c|00|k|00|w|00|a|00|v|00|e|00|F|00|l|00|a|00|s|00|h|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x00S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x00S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13217</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX function call unicode access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb07-20.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;S|00|h|00|o|00|c|00|k|00|w|00|a|00|v|00|e|00|F|00|l|00|a|00|s|00|h|00|.|00|S|00|h|00|o|00|c|00|k|00|w|00|a|00|v|00|e|00|F|00|l|00|a|00|s|00|h|00|.|00|9|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q1&gt;\x22|\x27|)S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x00S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x009\x00(?P=q1)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q2&gt;\x22|\x27|)S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x00S\x00h\x00o\x00c\x00k\x00w\x00a\x00v\x00e\x00F\x00l\x00a\x00s\x00h\x00.\x009\x00(?P=q2)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13218</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash.9 ActiveX function call unicode access</msg>
        <url>www.securityfocus.com/archive/1/443383/30/150/threaded</url>
      </rule>
      <rule>
        <bugtraq>26342</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;video/quicktime&quot;; nocase; content:&quot;pdat&quot;; byte_test:2,=,0,6,relative; byte_test:4,&gt;,104,-8,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13293</id>
        <msg>WEB-CLIENT QuickTime panorama atoms buffer overflow attempt</msg>
        <url>docs.info.apple.com/article.html?artnum=306896</url>
      </rule>
      <rule>
        <bugtraq>26951</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6242</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;FWS&quot;; content:&quot;|FF D8|&quot;; distance:0; content:&quot;JFIF&quot;; distance:0; content:&quot;|FF C0|&quot;; distance:0; byte_test:2, &gt;, 32767, 3, relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13300</id>
        <msg>WEB-CLIENT Adobe Flash Player embedded JPG image height overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26951</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6242</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;FWS&quot;; content:&quot;|FF D8|&quot;; distance:0; content:&quot;JFIF&quot;; distance:0; content:&quot;|FF C0|&quot;; distance:0; byte_test:2, &gt;, 32767, 5, relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13301</id>
        <msg>WEB-CLIENT Adobe Flash Player embedded JPG image width overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27641</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0655</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|F7 C5|d|F2 F8 F9|e|B7 EF 8B E9 AF BF F2|@|F1 FB FB A2 9C D9 B3 FB F7 05 CE|&gt;|1E FB F3 E5|x|28|&gt;=~-|B6|Y|DA E9 BC|9|9E A7|&amp;|E6 F4|l2|8A CB|&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>13477</id>
        <msg>SPECIFIC-THREATS Adobe PDF collab.collectEmailInfo exploit attempt - compressed</msg>
      </rule>
      <rule>
        <bugtraq>27641</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0655</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;collab.collectEmailInfo&quot;; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>13478</id>
        <msg>SPECIFIC-THREATS Adobe PDF collab.collectEmailInfo exploit attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| QuickTime&quot;; http_header; flowbits:set,quicktime_agent; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13515</id>
        <msg>WEB-CLIENT Quicktime user agent</msg>
      </rule>
      <rule>
        <bugtraq>27225</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0234</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset, quicktime_agent; content:&quot;HTTP/1.1 404&quot;; isdataat:256,relative; content:!&quot;|0A|&quot;; within:256; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13516</id>
        <msg>WEB-CLIENT Quicktime HTTP error response buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0065</cve>
        <filter1>tcp $EXTERNAL_NET [80,8090] -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;misc/ultravox&quot;; content:&quot;&lt;artist&gt;&quot;; distance:0; nocase; isdataat:266,relative; content:!&quot;&lt;/artist&gt;&quot;; within:256; pcre:&quot;/Content-Type\x3A\s*misc/ultravox.+?(\r?\n){2}\x5A.9\x01/is&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13520</id>
        <msg>EXPLOIT Winamp Ultravox streaming malicious metadata</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0065</cve>
        <filter1>tcp $EXTERNAL_NET [80,8090] -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;misc/ultravox&quot;; content:&quot;&lt;name&gt;&quot;; distance:0; nocase; isdataat:266,relative; content:!&quot;&lt;/name&gt;&quot;; within:256; pcre:&quot;/Content-Type\x3A\s*misc/ultravox.+?(\r?\n){2}\x5A.9\x01/is&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13521</id>
        <msg>EXPLOIT Winamp Ultravox streaming malicious metadata</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer Download Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*Download\s*Handler(\.\d)?\x22|\x27rmocx\.RealPlayer\s*Download\s*Handler(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*Download\s*Handler(\.\d)?\x22|\x27rmocx\.RealPlayer\s*Download\s*Handler(\.\d)?\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13603</id>
        <msg>WEB-ACTIVEX RealPlayer Download Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13604</id>
        <msg>WEB-ACTIVEX RealPlayer Download Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer RAM Download Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*RAM\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RAM\s*Download\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*RAM\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RAM\s*Download\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13605</id>
        <msg>WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|R|00|A|00|M|00| |00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q16&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00A\x00M\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q16)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q17&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00A\x00M\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q17)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13606</id>
        <msg>WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Console)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Console))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13607</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|C|00|D|00|A|00|A|00|0|00|3|00|-|00|8|00|B|00|E|00|4|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|8|00|4|00|B|00|-|00|0|00|0|00|2|00|0|00|A|00|F|00|B|00|B|00|C|00|C|00|F|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13608</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer G2 Control&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*G2\s*Control\x22|\x27rmocx\.RealPlayer\s*G2\s*Control\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*Console\s*|.*(?P=v)\s*\.\s*Console\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*G2\s*Control\x22|\x27rmocx\.RealPlayer\s*G2\s*Control\x27)\s*\)(\s*\.\s*Console\s*|.*(?P=n)\s*\.\s*Console)\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13609</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|G|00|2|00| |00|C|00|o|00|n|00|t|00|r|00|o|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*G\x002\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*G\x002\x00(\s\x00)*C\x00o\x00n\x00t\x00r\x00o\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>13610</id>
        <msg>WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>29386</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|A8 15|&quot;; content:&quot;|BF 15 0C 00 00 00|&quot;; within:6; distance:45; content:&quot;|BF 14 7F 01 00 00|&quot;; within:6; distance:12; content:&quot;?|13 19 00 00 00|&quot;; within:6; distance:383; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13820</id>
        <msg>WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb08-11.html</url>
      </rule>
      <rule>
        <bugtraq>29386</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|BF 15 84 03 00 00|&quot;; content:&quot;|BF 14|D|02 00 00|&quot;; within:6; distance:900; content:&quot;?|13 1F 00 00 00|&quot;; within:6; distance:640; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13821</id>
        <msg>WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb08-11.html</url>
      </rule>
      <rule>
        <bugtraq>29386</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|A8 15|&quot;; content:&quot;|8C 15|&quot;; within:2; distance:40; content:&quot;|BF 14 7F 01 00 00|&quot;; within:6; distance:12; content:&quot;|19 13|&quot;; within:2; distance:383; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13822</id>
        <msg>WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb08-11.html</url>
      </rule>
      <rule>
        <bugtraq>28583</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.quicktime; metadata: engine shared, soid 3|13897, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13897</id>
        <msg>EXPLOIT Apple Quicktime crgn atom parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15306</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2753</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;hdlr&quot;; byte_test:1,&gt;=,251,24,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13917</id>
        <msg>WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15306</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2753</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;tmci&quot;; byte_test:1,&gt;=,251,24,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13918</id>
        <msg>WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28583</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1022</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;obji&quot;; nocase; byte_test:4,&lt;,20,-8,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13920</id>
        <msg>WEB-CLIENT Apple Quicktime Obji Atom parsing stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CFCDA953-8BE4-11CF-B84B-0020AFBBCCFA&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q6&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CFCDA953-8BE4-11CF-B84B-0020AFBBCCFA\s*}?\s*(?P=q6)(\s|&gt;)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14042</id>
        <msg>WEB-ACTIVEX RealPlayer General Property Page ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|C|00|D|00|A|00|9|00|5|00|3|00|-|00|8|00|B|00|E|00|4|00|-|00|1|00|1|00|C|00|F|00|-|00|B|00|8|00|4|00|B|00|-|00|0|00|0|00|2|00|0|00|A|00|F|00|B|00|B|00|C|00|C|00|F|00|A|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q7&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00F\x00C\x00D\x00A\x009\x005\x003\x00-\x008\x00B\x00E\x004\x00-\x001\x001\x00C\x00F\x00-\x00B\x008\x004\x00B\x00-\x000\x000\x002\x000\x00A\x00F\x00B\x00B\x00C\x00C\x00F\x00A\x00(}\x00)?(?P=q7)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14043</id>
        <msg>WEB-ACTIVEX RealPlayer General Property Page ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer Playback Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*Playback\s*Handler\x22|\x27rmocx\.RealPlayer\s*Playback\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*Playback\s*Handler\x22|\x27rmocx\.RealPlayer\s*Playback\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14044</id>
        <msg>WEB-ACTIVEX RealPlayer Playback Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|P|00|l|00|a|00|y|00|b|00|a|00|c|00|k|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q11&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*P\x00l\x00a\x00y\x00b\x00a\x00c\x00k\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q11)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q12&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*P\x00l\x00a\x00y\x00b\x00a\x00c\x00k\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q12)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14045</id>
        <msg>WEB-ACTIVEX RealPlayer Playback Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer RMP Download Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*RMP\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RMP\s*Download\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*RMP\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RMP\s*Download\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14046</id>
        <msg>WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|R|00|M|00|P|00| |00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q26&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00M\x00P\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q26)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q27&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00M\x00P\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q27)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14047</id>
        <msg>WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer RNX Download Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*RNX\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RNX\s*Download\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*RNX\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*RNX\s*Download\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14048</id>
        <msg>WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|R|00|N|00|X|00| |00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q31&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00N\x00X\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q31)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q32&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*R\x00N\x00X\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q32)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14049</id>
        <msg>WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer SMIL Download Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*SMIL\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*SMIL\s*Download\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*SMIL\s*Download\s*Handler\x22|\x27rmocx\.RealPlayer\s*SMIL\s*Download\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14050</id>
        <msg>WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|S|00|M|00|I|00|L|00| |00|D|00|o|00|w|00|n|00|l|00|o|00|a|00|d|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q36&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*S\x00M\x00I\x00L\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q36)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q37&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*S\x00M\x00I\x00L\x00(\s\x00)*D\x00o\x00w\x00n\x00l\x00o\x00a\x00d\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q37)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14051</id>
        <msg>WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;rmocx.RealPlayer Stream Handler&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22rmocx\.RealPlayer\s*Stream\s*Handler\x22|\x27rmocx\.RealPlayer\s*Stream\s*Handler\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=v)\s*\.\s*(Console|Controls)\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22rmocx\.RealPlayer\s*Stream\s*Handler\x22|\x27rmocx\.RealPlayer\s*Stream\s*Handler\x27)\s*\)(\s*\.\s*(Console|Controls)\s*|.*(?P=n)\s*\.\s*(Console|Controls))\s*=/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14052</id>
        <msg>WEB-ACTIVEX RealPlayer Stream Handler ActiveX function call access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;r|00|m|00|o|00|c|00|x|00|.|00|R|00|e|00|a|00|l|00|P|00|l|00|a|00|y|00|e|00|r|00| |00|S|00|t|00|r|00|e|00|a|00|m|00| |00|H|00|a|00|n|00|d|00|l|00|e|00|r|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q41&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*S\x00t\x00r\x00e\x00a\x00m\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q41)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q42&gt;\x22|\x27|)r\x00m\x00o\x00c\x00x\x00.\x00R\x00e\x00a\x00l\x00P\x00l\x00a\x00y\x00e\x00r\x00(\s\x00)*S\x00t\x00r\x00e\x00a\x00m\x00(\s\x00)*H\x00a\x00n\x00d\x00l\x00e\x00r\x00(?P=q42)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14053</id>
        <msg>WEB-ACTIVEX RealPlayer Stream Handler ActiveX function call unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>30814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2646205B-878C-11D1-B07C-0000C040BCDB&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2646205B-878C-11D1-B07C-0000C040BCDB\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(CallHTMLHelp)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2646205B-878C-11D1-B07C-0000C040BCDB\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(CallHTMLHelp))\s*\(/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14235</id>
        <msg>WEB-ACTIVEX Microsoft Windows Media Services ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>30814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|6|00|4|00|6|00|2|00|0|00|5|00|B|00|-|00|8|00|7|00|8|00|C|00|-|00|1|00|1|00|D|00|1|00|-|00|B|00|0|00|7|00|C|00|-|00|0|00|0|00|0|00|0|00|C|00|0|00|4|00|0|00|B|00|C|00|D|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x006\x004\x006\x002\x000\x005\x00B\x00-\x008\x007\x008\x00C\x00-\x001\x001\x00D\x001\x00-\x00B\x000\x007\x00C\x00-\x000\x000\x000\x000\x00C\x000\x004\x000\x00B\x00C\x00D\x00B\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14236</id>
        <msg>WEB-ACTIVEX Microsoft Windows Media Services ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>30814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;NSIEMisc.NSIEMisc&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22NSIEMisc\.NSIEMisc\x22|\x27NSIEMisc\.NSIEMisc\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*CallHTMLHelp\s*|.*(?P=v)\s*\.\s*CallHTMLHelp\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22NSIEMisc\.NSIEMisc\x22|\x27NSIEMisc\.NSIEMisc\x27)\s*\)(\s*\.\s*CallHTMLHelp\s*|.*(?P=n)\s*\.\s*CallHTMLHelp\s*)\s*\(/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14237</id>
        <msg>WEB-ACTIVEX Microsoft Windows Media Services ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>30814</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;N|00|S|00|I|00|E|00|M|00|i|00|s|00|c|00|.|00|N|00|S|00|I|00|E|00|M|00|i|00|s|00|c|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)N\x00S\x00I\x00E\x00M\x00i\x00s\x00c\x00.\x00N\x00S\x00I\x00E\x00M\x00i\x00s\x00c\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)N\x00S\x00I\x00E\x00M\x00i\x00s\x00c\x00.\x00N\x00S\x00I\x00E\x00M\x00i\x00s\x00c\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smi&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>14238</id>
        <msg>WEB-ACTIVEX Microsoft Windows Media Services ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3008</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14255, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14255</id>
        <msg>WEB-ACTIVEX Windows Media Encoder 9 ActiveX clsid access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3008</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14257, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14257</id>
        <msg>WEB-ACTIVEX Windows Media Encoder 9 ActiveX function call access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>32105</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4817</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7\s*}?\s*(?P=q1)(\s|&gt;)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15007</id>
        <msg>WEB-ACTIVEX NOS Microsystems / Adobe getPlus Download Manager ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>32105</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4817</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|F|00|4|00|0|00|A|00|C|00|C|00|5|00|-|00|E|00|1|00|B|00|B|00|-|00|4|00|a|00|f|00|f|00|-|00|A|00|C|00|7|00|2|00|-|00|0|00|4|00|C|00|2|00|F|00|6|00|1|00|6|00|B|00|C|00|A|00|7|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q2&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*C\x00F\x004\x000\x00A\x00C\x00C\x005\x00-\x00E\x001\x00B\x00B\x00-\x004\x00a\x00f\x00f\x00-\x00A\x00C\x007\x002\x00-\x000\x004\x00C\x002\x00F\x006\x001\x006\x00B\x00C\x00A\x007\x00(}\x00)?(?P=q2)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>15008</id>
        <msg>WEB-ACTIVEX NOS Microsystems / Adobe getPlus Download Manager ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pdf&quot;; nocase; http_uri; flowbits:set,http.pdf; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15013</id>
        <msg>WEB-MISC Adobe Portable Document Format file download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-2992</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;/S/JavaScript/JS&quot;; nocase; content:&quot;util.printf&quot;; pcre:&quot;/\x28\s*\x22\s*\x25([2-9][6-9][5-9]|[1-9][0-9]{3,})f/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15014</id>
        <msg>WEB-CLIENT Adobe Reader and Acrobat util.printf buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33751</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0658</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;JBIG2Decode&quot;; nocase; content:&quot;stream&quot;; distance:0; pcre:&quot;/JBIG2Decode.*?stream(\x0d\x0a|\x0a|\x0d)/smi&quot;; byte_test:1, &amp;, 64, 4, relative; byte_test:1, &lt;, 160, 5, relative; byte_test:4, &gt;, 35256, 6, relative,little; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15357</id>
        <msg>WEB-CLIENT Adobe PDF JBIG2 remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>34938</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0010</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|00 11 02 FF 0C 00|&quot;; pcre:&quot;/\x00[\x70-\x74]\x00[\x00-\x09]/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15384</id>
        <msg>WEB-CLIENT Apple QuickTime pict image poly structure memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>35052</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1831</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,maki_file.request; metadata: engine shared, soid 3|15433, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15433</id>
        <msg>WEB-CLIENT Winamp MAKI parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>16410</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0476</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;[playlist]&quot;; nocase; content:&quot;File&quot;; distance:0; nocase; content:&quot;=&quot;; within:5; distance:1; isdataat:500,relative; content:!&quot;|0A|&quot;; within:500; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15472</id>
        <msg>WEB-CLIENT Nullsoft Winamp pls file player name handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33880</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0520</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|43 57 53 06 40 F3 14 00 78 DA 44 7C 05 58 54 DB F7 F6 1A 66 80 A1 87 54 86 EE EE A1 86 9A A1 41 10 10 A4 2C 44 3A 2C 10 0B 61 08 15 41 10 15 95 52 4A 01 11 15 05 F4 9A A0 A2 5E 95 10 30 08 03|&quot;; within:64; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15478</id>
        <msg>SPECIFIC-THREATS Adobe Flash Player invalid object reference code execution attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.swf&quot;; nocase; http_uri; flowbits:set,http.swf; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15483</id>
        <msg>WEB-MISC Adobe Shockwave Flash file request</msg>
      </rule>
      <rule>
        <bugtraq>34740</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1493</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.pdf; content:&quot;spell.customDictionaryOpen&quot;; nocase; pcre:&quot;/spell\.customDictionaryOpen\x5C\((\s*\d|[^\x2C]+\x2C\s*[A-Z\d_])/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15492</id>
        <msg>SPECIFIC-THREATS Adobe PDF spell.customDictionaryOpen exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>34736</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.pdf; content:&quot;getAnnots&quot;; nocase; pcre:&quot;/getAnnots\x5C?\([^\x29\x2C]+\x2C\s*[^\x29\x2C]+\x2C\s*[^\x29\x2C]+\x2C\s*-\d/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15493</id>
        <msg>SPECIFIC-THREATS Adobe PDF getAnnots exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>35139</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1537</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15517, service http, policy balanced-ips alert, policy security-ips alert;</filter2>
        <id>15517</id>
        <msg>WEB-CLIENT AVI DirectShow quicktime parsing overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>35167</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0954</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;crgn&quot;; byte_jump:2,-6,relative,big; content:!&quot;|7F FF 7F FF|&quot;; within:4; distance:-8; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15559</id>
        <msg>WEB-CLIENT Apple QuickTime Movie File Clipping Region handling heap buffer overflow attempt</msg>
        <url>support.apple.com/kb/HT3591</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1859</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;jP  &quot;; content:&quot;|FF|O|FF|Q&quot;; distance:0; byte_jump:2,36,relative,multiplier 3,big; content:&quot;|FF|R&quot;; within:2; byte_test:1,&gt;,16,7,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15562</id>
        <msg>WEB-CLIENT Adobe Reader JPX malformed code-block width attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1539</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15680, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15680</id>
        <msg>EXPLOIT Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-028.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1538</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15682, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15682</id>
        <msg>WEB-CLIENT Microsoft DirectShow QuickTime file stsc atom parsing heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-028.mspx</url>
      </rule>
      <rule>
        <bugtraq>35157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0950</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;itms|3A|//&quot;; nocase; isdataat:256,relative; pcre:&quot;/(\x22|\x27)itms\x3a\x2f\x2f[^\x22\x27]*\x3a[^\x22\x27\x2f]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15703</id>
        <msg>WEB-CLIENT Apple iTunes ITMS protocol handler stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0950</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;itmss|3A|//&quot;; nocase; isdataat:256,relative; pcre:&quot;/(\x22|\x27)itmss\x3a\x2f\x2f[^\x22\x27]*\x3a[^\x22\x27\x2f]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15704</id>
        <msg>WEB-CLIENT Apple iTunes ITMSS protocol handler stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0950</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;pcast|3A|//&quot;; nocase; pcre:&quot;/(\x22|\x27)pcast\x3a\x2f\x2f[^\x22\x27]*\x3a[^\x22\x27\x2f]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15705</id>
        <msg>WEB-CLIENT Apple iTunes PCAST protocol handler stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0950</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;daap|3A|//&quot;; nocase; isdataat:256,relative; pcre:&quot;/(\x22|\x27)daap\x3a\x2f\x2f[^\x22\x27]*\x3a[^\x22\x27\x2f]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15706</id>
        <msg>WEB-CLIENT Apple iTunes DAAP protocol handler stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0950</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;itpc|3A|//&quot;; nocase; isdataat:256,relative; pcre:&quot;/(\x22|\x27)itpc\x3a\x2f\x2f[^\x22\x27]*\x3a[^\x22\x27\x2f]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15707</id>
        <msg>WEB-CLIENT Apple iTunes ITPC protocol handler stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36600</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3459</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;/DecodeParms&quot;; content:&quot;/Predictor&quot;; distance:0; byte_test:8,&gt;,1,0,relative,string,dec; pcre:&quot;/\x2fDecodeParms\s*\x3c{2}\s*(?=[^\x3e]*\/Predictor\s+0*(1\d{1}|[2-9]))([^\x3e]*\x2fBitsPerComponent\s+\d{3}|[^\x3e]*\x2fColumns\s+(\d{5}|[6-9]\d{3})|[^\x3e]*\x2fColors\s+(\d{5}|[6-9]\d{3}))/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15709</id>
        <msg>WEB-CLIENT Adobe Acrobat and Adobe Reader FlateDecode integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35759</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1862</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;ByteArray&quot;; nocase; content:&quot;|04 0C 0C 0C 0C|&quot;; within:100; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15728</id>
        <msg>EXPLOIT Possible Adobe PDF ActionScript byte_array heap spray attempt</msg>
        <url>blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html</url>
      </rule>
      <rule>
        <bugtraq>35759</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1862</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.swf; content:&quot;ByteArray&quot;; nocase; content:&quot;|04 0C 0C 0C 0C|&quot;; within:100; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15729</id>
        <msg>EXPLOIT Possible Adobe Flash ActionScript byte_array heap spray attempt</msg>
        <url>blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html</url>
      </rule>
      <rule>
        <bugtraq>32100</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4813</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;obj&lt;&lt;&quot;; content:&quot;/BaseFont&quot;; distance:0; content:&quot;endobj&quot;; distance:0; pcre:&quot;/obj\x3c\x3c.*?\x2fBaseFont\x2f[^\x80-\xff\x2f]*[\x80-\xff].*?endobj/s&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15867</id>
        <msg>WEB-CLIENT Adobe Acrobat PDF font processing memory corruption attempt</msg>
        <url>vallejo.cc/proyectos/adobereader812.html</url>
      </rule>
      <rule>
        <bugtraq>32896</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5499</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00|airappinstaller|00|ASnative|00|&quot;; pcre:&quot;/\x00[\x3b\x7c\x26\x60][^\x00]+\x00airappinstaller\x00ASnative\x00/smi&quot;; content:&quot;|99 08|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15869</id>
        <msg>WEB-CLIENT Adobe Flash Player ASnative command execution attempet</msg>
      </rule>
      <rule>
        <bugtraq>33384</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0002</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;trak&quot;; content:&quot;tkhd&quot;; within:4; distance:4; fast_pattern; pcre:&quot;/trak.{4}tkhd.{40}(?!\x00\x01\x00\x00.{12}\x00\x01\x00\x00)/s&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15909</id>
        <msg>WEB-CLIENT Apple QuickTime VR Track Header Atom heap corruption attempt</msg>
        <url>support.apple.com/kb/HT3403</url>
      </rule>
      <rule>
        <bugtraq>26214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2264</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.ra|FD 00 04 00 00|.ra4|00 00 00 89 00 04 0F FF FF FF|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15940</id>
        <msg>SPECIFIC-THREATS RealNetworks RealPlayer Multiple Products RA file processing overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35907</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.swf; content:&quot;|01 01 02 09 03 80 80 80 80 01 01 02 01 01 04 01 00 03 00 01 01 09|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15993</id>
        <msg>SPECIFIC-THREATS Adobe Flash Player ActionScript intrf_count integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>18507</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3228</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;MThd|00 00 00 06 00 00 00 01 00|`MTrk&quot;; byte_test:4,&gt;,2147483648,8,relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16027</id>
        <msg>WEB-CLIENT winamp midi file header overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>19976</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4384</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|FA F1 02 00 00 00 00 00 00 00 00 00 0A 03 00 00 0B 00 01 00 FF|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16041</id>
        <msg>SPECIFIC-THREATS Apple QuickTime FLIC animation file buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5081</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;DATA|00 00|A'|00 00 00 00 00|'|00 00 00 00 00 00 01|&lt;|FF FF|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16046</id>
        <msg>SPECIFIC-THREATS RealNetworks RealPlayer RealMedia file format processing heap corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17953</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2238</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.bmp; content:&quot;BM&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; byte_test:4,&gt;,65535,4,relative,little; byte_test:4,&gt;,3,12,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16054</id>
        <msg>WEB-CLIENT Quicktime bitmap multiple header overflow</msg>
      </rule>
      <rule>
        <bugtraq>18730</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1467</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mp4a&quot;; content:&quot;stsc&quot;; distance:0; byte_jump:4,-8,relative,big; content:&quot;stsz&quot;; within:4; byte_test:4,&lt;,257,-8,relative,big; byte_test:4,&gt;,60,8,relative,big; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16055</id>
        <msg>WEB-CLIENT Apple iTunes AAC file handling integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15822</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-4216</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1111</filter1>
        <filter2>flow:to_server,established; dsize:3; content:&quot;a|0D 0A|&quot;; depth:3; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>16091</id>
        <msg>SPECIFIC-THREATS Macromedia Flash Media Server administration service denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>15732</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4092</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;dinf|00 00 00 1C|dref|00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0F|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16148</id>
        <msg>SPECIFIC-THREATS Apple QuickTime and iTunes heap memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2527</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16156, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16156</id>
        <msg>WEB-CLIENT Windows Media Player 6.4 marker object memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-052.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2997</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16172, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16172</id>
        <msg>EXPLOIT Adobe Acrobat Reader U3D line set heap corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2998</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16173, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16173</id>
        <msg>EXPLOIT Adobe Acrobat Reader U3D progressive mesh continuation pointer overwrite attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3458</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16174, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16174</id>
        <msg>EXPLOIT Adobe Acrobat Reader U3D progressive mesh continuation off by one index attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2988</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16175, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16175</id>
        <msg>EXPLOIT Adobe collab.removeStateModel denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2996</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16176, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16176</id>
        <msg>EXPLOIT Adobe collab.addStateModel remote corruption attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.dir&quot;; nocase; http_uri; flowbits:set,http.dir; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>16219</id>
        <msg>WEB-CLIENT Adobe Director file format transfer</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3466</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|16220, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16220</id>
        <msg>WEB-CLIENT Adobe Shockwave director file malformed lcsr block memory corruption attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb09-16.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3464</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|16223, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16223</id>
        <msg>WEB-CLIENT Adobe Shockwave tSAC pointer overwrite attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb09-16.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3465</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|16225, service http, policy security-ips drop;</filter2>
        <id>16225</id>
        <msg>EXPLOIT Adobe Shockwave arbitrary memory access attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb09-16.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3463</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.dir; content:&quot;|FF FF FF FF 01 1F 02|H|00 00 00|6|00 00 FF FF 01 1F 1F EE|&quot;; content:!&quot;|FF FF FF FF|&quot;; within:4; distance:-24; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16293</id>
        <msg>WEB-CLIENT Adobe Shockwave Flash memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3797</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.swf; metadata: engine shared, soid 3|16316, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16316</id>
        <msg>WEB-CLIENT Adobe Flash Player malformed getPropertyLate actioncode attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2984</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16320, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16320</id>
        <msg>WEB-CLIENT Adobe PNG empty sPLT exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2995</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16321, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16321</id>
        <msg>WEB-CLIENT Adobe tiff oversized image length attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2980</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16322, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16322</id>
        <msg>WEB-CLIENT Adobe Reader oversized object width attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2995</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16323, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16323</id>
        <msg>EXPLOIT Adobe JPEG2k uninitialized QCC memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2993</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16324, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16324</id>
        <msg>WEB-CLIENT Adobe doc.export arbitrary file write attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2995</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16325, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16325</id>
        <msg>EXPLOIT Adobe JPEG2k uninitialized QCC memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>37331</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4324</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;/S/JavaScript&quot;; content:&quot;this.media.newPlayer&quot;; pcre:&quot;/^\x5C?\x28null\x5C?\x29/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16333</id>
        <msg>WEB-CLIENT Adobe Reader media.newPlayer memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4324</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;&amp;|EA A7 7C 9A 1D C4 1C FE|&amp;|7F|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16334</id>
        <msg>SPECIFIC-THREATS Adobe Reader compressed media.newPlayer memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>37420</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-3792</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16337, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16337</id>
        <msg>EXPLOIT Adobe Flash directory traversal attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb09-18.html</url>
      </rule>
      <rule>
        <bugtraq>37192</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4195</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;%!PS-Adobe-&quot;; nocase; content:&quot;EPSF-&quot;; within:10; pcre:&quot;/%[^\x0d\x0a]{1000}/smiR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16359</id>
        <msg>WEB-CLIENT Adobe Illustrator DSC comment overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35166</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;stsd&quot;; content:&quot;rpza&quot;; distance:12; fast_pattern; content:&quot;|00 00 00 00 00 00|&quot;; within:6; byte_test:2,&gt;,0x1FFC,18,relative,big; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16360</id>
        <msg>WEB-CLIENT Apple QuickTime Image Description Atom sign extension memory corruption attempt</msg>
        <url>support.apple.com/kb/HT3591</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3955</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16370, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16370</id>
        <msg>WEB-CLIENT Adobe Reader JP2C Region Atom CompNum memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>37759</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16371, service http, policy security-ips drop;</filter2>
        <id>16371</id>
        <msg>WEB-ACTIVEX NOS Microsystems Adobe atl_getcom ActiveX clsid access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-02.html</url>
      </rule>
      <rule>
        <bugtraq>36665</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16373, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16373</id>
        <msg>WEB-CLIENT Adobe Acrobat Reader U3D CLODMeshContinuation code execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb09-15.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; flowbits:isset,http.pdf; content:&quot;|EB|/|ED|Z|B9|qX|F4 D8|C|F5|a|BF|+|0D 8C D2 F3 DD|*|EE 09|W|B1 B3 9B|P|EB AD D1 B3 07 A0|4|D8|m|7C 7F EB B5 EF|j|E8 F5|m[+t|8F 7C BC|f|BB 86|ql|F7 C0 C3 E8|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16490</id>
        <msg>SPECIFIC-THREATS Adobe Reader malformed TIFF remote code execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-07.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0268</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16537, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16537</id>
        <msg>EXPLOIT Windows Media Player ActiveX unknow compression algorithm use arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-027.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0478</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1755</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16541, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16541</id>
        <msg>EXPLOIT Microsoft Windows Media Service stack overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-025.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0480</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.avi; metadata: engine shared, soid 3|16543, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16543</id>
        <msg>WEB-CLIENT Microsoft Windows Media Player codec code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-026.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1241</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16546, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16546</id>
        <msg>EXPLOIT Adobe Reader/Acrobat Pro CFF font parsing heap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1279</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16561, service http, policy security-ips drop;</filter2>
        <id>16561</id>
        <msg>EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 1</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-10.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1279</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16562, service http, policy security-ips drop;</filter2>
        <id>16562</id>
        <msg>EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 2</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-10.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1279</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16563, service http, policy security-ips drop;</filter2>
        <id>16563</id>
        <msg>EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 3</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-10.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1279</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16564, service http, policy security-ips drop;</filter2>
        <id>16564</id>
        <msg>EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 4</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-10.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3008</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;unescape|28|'&quot;; content:&quot;GetDetailsString|28|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16578</id>
        <msg>EXPLOIT Microsoft Windows Media Encoder 9 ActiveX buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0196</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.pdf; content:&quot;stream|0A|U3D&quot;; content:&quot;1|FF FF FF|&quot;; distance:1; byte_jump:2,8,relative,little,post_offset 32; byte_test:4,&gt;=,97612894,0,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16603</id>
        <msg>WEB-CLIENT Adobe Reader U3D CLOD integer overflow</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-09.html</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid=|27|clsid|3A|2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93|27|&quot;; content:&quot;unescape|28 27 25|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16607</id>
        <msg>SPECIFIC-THREATS RealPlayer RAM Download Handler ActiveX exploit attempt</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>26130</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5601</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid|3D 27|clsid|3A|FDC7A535-4070-4B92-A0EA-D9994BCC0DC5|27|&quot;; fast_pattern:only; nocase; content:&quot;document.getElementById|28 27|&quot;; distance:0; content:&quot;new String|28 27|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16609</id>
        <msg>SPECIFIC-THREATS RealPlayer ActiveX Import playlist name buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16633, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16633</id>
        <msg>WEB-CLIENT Adobe PDF File containing Flash use-after-free attack</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16634, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16634</id>
        <msg>WEB-CLIENT Adobe Flash use-after-free attack</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1880</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16663, service http, policy security-ips drop;</filter2>
        <id>16663</id>
        <msg>WEB-CLIENT Windows Media Player JPG header record mismatch memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>40586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1297</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|43 57 53 09 A2 D2 00 00 78 9C EC BD 79 7C 54 C5 D2 37 DE 7D|&quot;; content:&quot;|CF E7 77 BC EB 19 53 BF 99 F7 7C FB B8 D4 4B FA 7C EE E7 AC C7 83 AD 58 D8 F3 35 8B A5 1E B4 67 4D EA 3F EE 9E 3F 79 C9 AB ED 63 B6 F4 58 7A 57|&quot;; within:48; distance:316; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16664</id>
        <msg>SPECIFIC-THREATS Adobe Reader and Acrobat authplay.dll vulnerability exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1292</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; flowbits:isset,http.dir; content:&quot;XFIR&quot;; depth:4; content:&quot;pami&quot;; distance:0; byte_test:4,&gt;,0x7FFFFFFF,4,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16673</id>
        <msg>WEB-CLIENT Adobe Shockwave DIR file PAMI chunk code execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-12.html</url>
      </rule>
      <rule>
        <bugtraq>36600</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3459</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;1073741838&quot;; pcre:&quot;/(C|#43)(o|#6F)(l|#6C)(o|#6F)(r|#72)(s|#73)\s*1073741838/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16676</id>
        <msg>SPECIFIC-THREATS Adobe Reader malformed FlateDecode colors declaration</msg>
      </rule>
      <rule>
        <bugtraq>36600</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3459</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;FlateDecode&quot;; content:&quot;DecodeParms&quot;; pcre:&quot;/DecodeParms\s*\[[^\]]*Colors\s*\d\d\d\d/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16677</id>
        <msg>WEB-CLIENT Adobe Reader malformed FlateDecode colors declaration</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0186</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,caff_request; content:&quot;CAFF|00 01 00 00|desc&quot;; depth:12; nocase; byte_test:4,&gt;,268435455,32,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16683</id>
        <msg>WEB-MISC Nullsoft Winamp CAF file processing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>41130</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2010-2204</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16801, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16801</id>
        <msg>EXPLOIT Adobe Reader CoolType.dll remote memory corruption denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>35028</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(ConvertFile)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.(ConvertFile))/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17096</id>
        <msg>WEB-ACTIVEX AOL WinAmpX ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>35028</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;F|00|E|00|0|00|B|00|D|00|7|00|7|00|9|00|-|00|4|00|4|00|E|00|E|00|-|00|4|00|A|00|4|00|B|00|-|00|A|00|A|00|2|00|E|00|-|00|7|00|4|00|3|00|C|00|6|00|3|00|F|00|2|00|E|00|5|00|E|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*F\x00E\x000\x00B\x00D\x007\x007\x009\x00-\x004\x004\x00E\x00E\x00-\x004\x00A\x004\x00B\x00-\x00A\x00A\x002\x00E\x00-\x007\x004\x003\x00C\x006\x003\x00F\x002\x00E\x005\x00E\x006\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17097</id>
        <msg>WEB-ACTIVEX AOL WinAmpX ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>35028</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;classid|3D 27|clsid|3A|FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6|27|&quot;; content:&quot;unescape|28|&quot;; within:300; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17098</id>
        <msg>SPECIFIC-THREATS AOL IWinAmpActiveX class ConvertFile buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2216</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17141, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17141</id>
        <msg>EXPLOIT Adobe Flash invalid data precision arbitrary code execution exploit attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-16.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0209</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17142, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17142</id>
        <msg>EXPLOIT Adobe Flash Player SWF ActionScript exploit attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-16.html</url>
      </rule>
      <rule>
        <bugtraq>40389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;AnglUntF&quot;; nocase; byte_test:4,&gt;,1020,12,relative,big; content:&quot;8BIM&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17143</id>
        <msg>WEB-CLIENT Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>40389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;AnglUntF&quot;; nocase; byte_test:4,&gt;,1020,12,relative,big; content:&quot;8BBR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17144</id>
        <msg>WEB-CLIENT Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>40389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Stylenum&quot;; nocase; byte_test:4,&gt;,1020,8,relative,big; content:&quot;8BSL&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17145</id>
        <msg>WEB-CLIENT Adobe Photoshop CS4 ASL file processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>40389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00|G|00|r|00|a|00|d|00|i|00|e|00|n|00|t&quot;; nocase; byte_test:4,&gt;,1020,13,relative,big; content:&quot;8BGR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17146</id>
        <msg>WEB-CLIENT Adobe Photoshop CS4 GRD file processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>40389</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-1296</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;AnglUntF|23|Ang&quot;; byte_test:4,&gt;,1020,8,relative,big; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17147</id>
        <msg>SPECIFIC-THREATS Adobe Photoshop CS4 ABR file processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17179, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17179</id>
        <msg>WEB-CLIENT Adobe Director file pamm record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2864</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17180, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17180</id>
        <msg>WEB-CLIENT Adobe Director file LsCM record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2864</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17181, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17181</id>
        <msg>WEB-CLIENT Adobe Director file LsCM record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17182, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17182</id>
        <msg>WEB-CLIENT Adobe Director file tSAC record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17183, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17183</id>
        <msg>WEB-CLIENT Adobe Director file tSAC record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17184, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17184</id>
        <msg>WEB-CLIENT Adobe Director file tSAC record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17185, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17185</id>
        <msg>WEB-CLIENT Adobe Director file rcsL record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17186, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17186</id>
        <msg>WEB-CLIENT Adobe Director file rcsL record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17187, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17187</id>
        <msg>WEB-CLIENT Adobe Director file rcsL record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17188, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17188</id>
        <msg>WEB-CLIENT Adobe Director file rcsL record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2869</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17189, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17189</id>
        <msg>WEB-CLIENT Adobe Director file rcsL record exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2871</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17190, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17190</id>
        <msg>EXPLOIT Adobe Director remote code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2872</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17191, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17191</id>
        <msg>EXPLOIT Adobe Director remote code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2873</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17192, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17192</id>
        <msg>EXPLOIT Adobe Director remote code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2874</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17193, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17193</id>
        <msg>EXPLOIT Adobe Director remote code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2875</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17194, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17194</id>
        <msg>EXPLOIT Adobe Director file tSAC tag exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2876</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17195, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17195</id>
        <msg>EXPLOIT Adobe Director file exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2877</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17196, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17196</id>
        <msg>EXPLOIT Adobe Director file exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2879</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17197, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17197</id>
        <msg>EXPLOIT Adobe Director file exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2878</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17198, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17198</id>
        <msg>EXPLOIT Adobe Director file exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2863</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17199, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17199</id>
        <msg>WEB-CLIENT Adobe Director file file lRTX overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2864</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17200, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17200</id>
        <msg>WEB-CLIENT Adobe Director file LsCM overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2865</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17201, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17201</id>
        <msg>WEB-CLIENT Adobe Director file file LsCM overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2866</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17202, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17202</id>
        <msg>WEB-CLIENT Adobe Director file file Shockwave 3D overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2867</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17203, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17203</id>
        <msg>WEB-CLIENT Adobe Director file file rcsL overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2870</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.dir; metadata: engine shared, soid 3|17204, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17204</id>
        <msg>WEB-CLIENT Adobe Director file file mmap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1818</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;_Marshaled_pUnk&quot;; nocase; pcre:&quot;/name\s*=\s*(?P&lt;q1&gt;\x22|\x27|)_Marshaled_pUnk(?P=q1)/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17211</id>
        <msg>WEB-CLIENT Quicktime marshaled punk remote code execution</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; file_data; content:&quot;stream|0A 78 9C ED 5B 5B 6F E2 38 14 7E EF AF 88 B2 6F CB 0E E6 0E AD 0A 23 73 5B 68 9B 02 E5 DA BE 8C 4C E2 04 97 24 0E B1 D3 00 BF 7E ED 24 B4 94 99 DD 19 69 1F 56 5A 39 D2 07 E7 F6 1D 1F DB 71 9E 7C|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17214</id>
        <msg>SPECIFIC-THREATS Adobe Reader and Acrobat libtiff TIFFFetchShortPair stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0188</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; file_data; content:&quot;stream|0A 78 9C ED 5B 49 73 E2 38 14 BE F7 AF 70 79 6E C3 34 62 87 A4 42 BA C4 36 90 C4 01 C2 9A 5C BA 84 2D 1B 07 DB 32 96 1C 03 BF 7E 24 2F 6C D3 3D 9D C3 54 4D 4D 95 5C F5 81 DE|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17215</id>
        <msg>SPECIFIC-THREATS Adobe Reader and Acrobat libtiff TIFFFetchShortPair stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25307</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3035</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|5B B7 D6 CA 91 94 5C C8 DB B1 29 8F FA A4 39 A6 9B B3 65 AD 6D CE EC 2C DB 28 0F FB FD E1 F9 F5 F9 E1 F9 7C 9E 83 C1 41 7B F6 26 93 40 0A B0 0C|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17228</id>
        <msg>SPECIFIC-THREATS Microsoft Windows Media Player skin decompression code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2883</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|35 3E 5D 0A 3E 3E 0A 73 74 61 72 74 78 72 65 66 0A 32 34 36 31 32 35 0A 25 25 45 4F 46 0A 0D 0A 25 53 49 47 4E 41 54 55 52 45 3A 20 E2 DA 47 7E AC 80 D7 7E AB 80|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17233</id>
        <msg>SPECIFIC-THREATS Adobe Reader and Acrobat TTF SING table parsing remote code execution attempt</msg>
        <url>www.adobe.com/support/security/advisories/apsa10-02.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0818</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.wmv; flowbits:isset,http.wma; flowbits:isset,http.asf; metadata: engine shared, soid 3|17242, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17242</id>
        <msg>WEB-CLIENT Windows Media Player ASF file arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2884</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.swf; content:&quot;|6C 23 B1 63 9A 87 31 36 CC 6F DD BA 75 7F C7 D0|&quot;; depth:160; offset:144; content:&quot;|9F 4E AA 98 1C 24 BF 33 AE 78 A5 58 32 B3 DE 54|&quot;; within:16; distance:352; content:&quot;|05 7D 9F EA A8 E5 CA A6 73 4A CE BC 5C 72 65 63|&quot;; within:16; distance:240; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17257</id>
        <msg>SPECIFIC-THREATS Adobe Flash Player and Reader remote code execution attempt</msg>
        <url>www.adobe.com/support/security/advisories/apsa10-03.html</url>
      </rule>
      <rule>
        <bugtraq>13530</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2052</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.avi; content:&quot;strf&quot;; content:&quot;|08 00|&quot;; within:2; distance:18; byte_test:4,&gt;,0x100,16,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17272</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer AVI parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>44203</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-2862</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|01|pmaxp|02 ED 0A 7B 00 00|p|0E 00 00 00 20|name|EA 2E F3 EE 00 00|p.|00 00 04|aposts|F1|o|84 00 00|t|8F 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17288</id>
        <msg>SPECIFIC-THREATS Adobe Acrobat font parsing integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>20138</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4965</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;quicktime|20|type|3D 22|application&quot;; nocase; content:&quot;qtnext|3D 22|file|3A 2F 2F|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17290</id>
        <msg>WEB-CLIENT Quicktime Plug-In Security Bypass</msg>
      </rule>
      <rule>
        <bugtraq>17202</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0323</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.swf; content:&quot;application/x-shockwave-flash&quot;; nocase; http_header; file_data; content:&quot;|46 57 53 05 CF 00 00 00 60 90 90 90 90 90 90 90 90 90 90|&quot;; within:19; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17334</id>
        <msg>SPECIFIC-THREATS RealPlayer SWF Flash File buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14276</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2310</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; file_data; content:&quot;ID3&quot;; within:3; pcre:&quot;/T(PE(1|2)|IT2)/iR&quot;; byte_test:4,&gt;,0x190,0,relative,big; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17351</id>
        <msg>WEB-CLIENT Winamp ID3v2 Tag Handling Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>21910</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0104</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; flowbits:isset,http.pdf; content:&quot;3 0 obj|0D 3C 3C 20 0D|/Type /Pages|20 0D|&quot;; fast_pattern; nocase; content:&quot;/Kids|20 5B 20|3 0 R |5D|&quot;; within:15; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17361</id>
        <msg>SPECIFIC-THREATS Adobe Acrobat Reader PDF Catalog Handling denial of service attempt</msg>
        <url>projects.info-pull.com/moab/MOAB-06-01-2007.html</url>
      </rule>
      <rule>
        <bugtraq>22844</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0714</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;udta&quot;; content:&quot;|A9|nam|FF|&quot;; distance:0; byte_test:2,&gt;,251,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17372</id>
        <msg>WEB-CLIENT Apple QuickTime udta atom parsing heap overflow vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>26342</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4675</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 00 00 00 01 A6 73 65 61 6E 00 00 00 01 00 00 00 04 00 00 00 00 00 00 41 41 70 64 61 74 00 00 00 01 00 00 00 00 00 00 00 00 00 02 00 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17373</id>
        <msg>SPECIFIC-THREATS QuickTime panorama atoms buffer overflow attempt</msg>
        <url>docs.info.apple.com/article.html?artnum=306896</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3625</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;|00 00 00 01 0F 00 00 00 FE B4 00 00 FE 01 1A C4 42 01 1A C4 41 1A EC EC 42 81 1A C4 43 81 00 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17381</id>
        <msg>SPECIFIC-THREATS Apple QuickTime PDAT Atom parsing buffer overflow attempt</msg>
        <url>support.apple.com/kb/HT3027</url>
      </rule>
      <rule>
        <bugtraq>26130</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5601</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FDC7A535-4070-4B92-A0EA-D9994BCC0DC5&quot;; fast_pattern:only; nocase; content:&quot;aaaaaaaaaaaaaaaaaa&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17425</id>
        <msg>SPECIFIC-THREATS RealPlayer ActiveX Import playlist name buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15382</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2630</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|50 4B 03 04 14 00 00 00 08 00 91 98 6E 33 EB 71 F9 B3 1D 00 00 00 00 01 00 00 0B 00 00 00 53 68 75 66 66 6C 65 2E 62 6D 70 73 F2 DD C1 E5 08 04|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17461</id>
        <msg>SPECIFIC-THREATS RealNetworks RealPlayer zipped skin file buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33390</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0007</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 56 6A 70 65 67 00 00 00 00 00 00 00 01 00 00 00 00 61 70 70 6C 00 00 00 00 00 00 02 00 00 02 00 03 00 48 00 00 00 48 00 00 00 00 00 00 00 01 0C 50 68 6F 74 6F 20 2D 20 4A 50 45 47 00 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17470</id>
        <msg>SPECIFIC-THREATS Apple QuickTime STSD JPEG atom heap corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>36328</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2799</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;|81 F6 3B 80 00 00 40 80 FF FF FF 87 25 B8 20 00|&quot;; content:&quot;|F9 31 40 00 52 EA FB EF BE FB EF BE FB EF BE FB|&quot;; within:16; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17523</id>
        <msg>SPECIFIC-THREATS Apple QuickTime H.264 Movie File Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>35282</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1855</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|3C 3C 2F|Subtype|2F|U3D|2F|Length&quot;; nocase; content:&quot;|48 89 EC 55 7B 4C 53 69 16 BF 3C 2C F4 21 A0 C2|&quot;; content:&quot;|95 96 0B 5C 0A 22 BD 76 78 8A D8 5A 40 1E 22 2D|&quot;; within:16; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17526</id>
        <msg>SPECIFIC-THREATS Adobe Acrobat and Adobe Reader U3D RHAdobeMeta Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>23650</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2295</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;|4E E7 32 C0 0E 18 54 0B C4 5A CD 49 9F 51 2F D4 BE 30 24 B6 BC 7D 7A|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17531</id>
        <msg>SPECIFIC-THREATS Apple Quicktime MOV File JVTCompEncodeFrame Heap Overflow</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;application/smil&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3A\s*application\x2Fsmil/smiH&quot;; flowbits:set,quicktime.smil; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>17547</id>
        <msg>WEB-CLIENT Apple Quicktime SMIL transfer</msg>
      </rule>
      <rule>
        <bugtraq>24873</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2394</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,quicktime.smil; content:&quot;&lt;smil&gt;&quot;; pcre:&quot;/(author|copyright|information)/smiR&quot;; content:&quot;content|3D|&quot;; distance:1; nocase; isdataat:1024,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17548</id>
        <msg>WEB-CLIENT Apple Quicktime SMIL File Handling Integer Overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pmd&quot;; nocase; http_uri; flowbits:set,http.pmd; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>17552</id>
        <msg>WEB-CLIENT Adobe Pagemaker file request</msg>
      </rule>
      <rule>
        <bugtraq>25989</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5169</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.pmd; content:&quot;Courier|20|New|61 61 61 61 61 61 61 61 61|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17553</id>
        <msg>SPECIFIC-THREATS Adobe Pagemaker Font Name Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33652</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0375</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|1F 5C 80 00 00 08 72 61 6D 34 2E 72 65 63 00 00 00 00 00 00 01 79|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17561</id>
        <msg>SPECIFIC-THREATS RealNetworks RealPlayer IVR Overly Long Filename Code Execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>32896</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5499</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;|43 57 53 07 C5 01 00 00 78 DA 74 50 B1 4E C3 30 14 BC 38 A1 71 11 2A 52 55 29 0C FD 81 2E 2C B0 A2 B6 54 42 62 68 1A B5 1D BA 45 A6 44 25 22 89 A3 C4 20 F8 02 3A 75 8C D4 81 FF E1 9B 58 CA B3 9D 15 0F A7 77 E7 F7 CE E7 F7 01 FC 02 6C 03 0C 1C CC D8 89 4E B7 03 3A 91 43 30 EE 0D 08 A9 8A E2 38 12 DB 57 B1 4B EA EB F5 9B 92 38 F5 6E 74 43 B4 DF E0 1C 46 89 77 99 7C 12 19 44 5A 89 B2 4C 8B 5A 89 2C 4B 2A 4C 57 85 50 E9 7B 82 B8 92 52 61 2B F3 5C 14 CF 28 2B A9 A4 FA 2C 13 E4 22 2D 40 23 D4 B9 4A 54 54 C9 F2 21 13 BB 1A 0D 03 C7 B0 DF FF 66 F8 31 C4 19 1A E9 C0 75 3E 36 82 40 73 05 CE 7C 1D C4 C2 91 AE 7C 46 55 DB EB 2E 1B 07 EE 52 5B DC 1A 0B CF C8 67 A1 1D D4 9D 16 FE 19 0C BE C8 76 D1 78 F0 C0 3B 21 11 27 B0 C4 3F 5C E8 BD B8 23 B0 7C 8B 41 9B B5 E9 82 73 5F A7 E3 98 2C 16 CD A5 8D C5 3C C7 77 B5 D8 BD 0B 30 76 EF A9 DC 0F C9 65 BE 9E AE 66 F1 7C FA 18 42 BD A4 B5 5D A3 D9 86 B1 D3 6F 07 ED BF 7D EB C4 59 9B 2E C0 84 E8 1F 00 00 00 FF FF 03 00 89 17 52 74|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17606</id>
        <msg>SPECIFIC-THREATS Adobe Flash ASnative command execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb08-24.html</url>
      </rule>
      <rule>
        <bugtraq>26338</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4677</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.quicktime; metadata: engine shared, soid 3|17608, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17608</id>
        <msg>WEB-CLIENT Apple QuickTime color table atom movie file handling heap corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>33405</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0398</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; flowbits:isset,http.quicktime; content:&quot;ctts&quot;; content:&quot;|00 00 00 00 00 00 00 8F 00 00 00 01 00 00 00 14 00 FF FF FF|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17610</id>
        <msg>WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33405</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0398</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; flowbits:isset,http.quicktime; content:&quot;stss&quot;; content:&quot;|00 00 00 00 00 00 00 03 00 00 00 01 00 FF FF FF|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17611</id>
        <msg>WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33405</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0398</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; flowbits:isset,http.quicktime; content:&quot;stts&quot;; content:&quot;|00 00 00 00 00 00 00 01 EE 00 00 26 00 00 04 00 00|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17612</id>
        <msg>WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30370</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5400</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.swf; content:&quot;|78 00 05 5F 00 00 0F A0 00 00 0C 01 00 43 02 FF FF FF BF 00 39|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17633</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer SWF frame handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28695</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.swf; metadata: engine shared, soid 3|17647, service http, policy security-ips drop;</filter2>
        <id>17647</id>
        <msg>WEB-CLIENT Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb08-11.html</url>
      </rule>
      <rule>
        <bugtraq>31999</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6432</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.pmd; content:&quot;Magenta&quot;; nocase; content:&quot;|41 41 41 41 41|&quot;; within:5; distance:241; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17650</id>
        <msg>SPECIFIC-THREATS Adobe Pagemaker Key Strings Stack Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15332</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2628</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.swf; content:&quot;|0B 25 C9 92 0D 21 ED 48 87 65 30 3B 6D E1 D8 B4|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17658</id>
        <msg>SPECIFIC-THREATS Adobe Flash frame type identifier memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>17202</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Transfer-Encoding&quot;; nocase; http_header; content:&quot;chunked&quot;; fast_pattern; nocase; http_header; content:&quot;Content-Type|3A|&quot;; nocase; http_header; pcre:&quot;/Content-Type\x3a[^\x10\x13]*real(audio|video)/smiH&quot;; file_data; isdataat:1024,relative; content:!&quot;|0A|&quot;; within:1024; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17666</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer invalid chunk size heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28874</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1765</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.bmp; content:&quot;Content-Type: text/plain|0D 0A 0D 0A|BM&quot;; fast_pattern:only; content:&quot;BM&quot;; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; byte_test:4, &gt;, 256, 36, relative, little; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17678</id>
        <msg>WEB-CLIENT Adobe BMP image handler buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0611</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;LIST|3D|1C|3D|&quot;; content:&quot;INFOINAM|3D|10|3D|00|3D|00|3D|00AAAAAAAAAAAA&quot;; within:32; distance:8; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17698</id>
        <msg>SPECIFIC-THREATS RealNetworks RealPlayer wav chunk string overflow attempt in email</msg>
      </rule>
      <rule>
        <bugtraq>12697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0611</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,wav_file.request; metadata: engine shared, soid 3|17700, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17700</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer wav chunk string overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25989</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5169</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,http.pmd; content:&quot;|61 61 61 61 61 61 61 61 61 61 61 61 0F 42 01 05 41 41 41 41 41 41 41 41|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17735</id>
        <msg>SPECIFIC-THREATS Adobe Pagemaker Font Name Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2745</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.wmv; metadata: engine shared, soid 3|17773, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17773</id>
        <msg>EXPLOIT Microsoft Windows Media Player Firefox plugin memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-083.mspx</url>
      </rule>
      <rule>
        <bugtraq>42682</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-2873</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.dir; content:&quot;rcsL&quot;; content:&quot;|FF F0 02 67|&quot;; within:4; distance:203; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17803</id>
        <msg>WEB-CLIENT Adobe Shockwave Director rcsL chunk memory corruption attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-20.html</url>
      </rule>
      <rule>
        <bugtraq>44291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-3653</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.dir; content:&quot;rcsL&quot;; content:&quot;|01 02 4C 00 00 00 00 80 00 00 F0 FF F0 02 67 25 A2 01 33 41|&quot;; within:20; distance:192; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17806</id>
        <msg>SPECIFIC-THREATS Adobe Shockwave Director rcsL chunk remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>44291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-3653</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.dir; content:&quot;rcsL&quot;; content:&quot;|00 00 00 80 00 00 F0 41 41 41 41 41 41 AB 41 05 43 01 57 17|&quot;; within:20; distance:484; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17807</id>
        <msg>SPECIFIC-THREATS Adobe Shockwave Director rcsL chunk remote code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3654</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|94 C5 F6 3F 3E E5 D9 7D 76 53 37 D9 10 62 28 06 8D 44 71|&quot;; content:&quot;|CC F3 6C A1 DC 0F DF DF EB F5 FD E7 8B 99 E7 99 39 73 E6 CC 99|&quot;; distance:0; content:&quot;|EE 7E F1 F1 1E E9 C8 72 36 A9 3A 54 1F 2A 1A C4 58 B7 DB|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17808</id>
        <msg>SPECIFIC-THREATS Adobe Flash authplay.dll memory corruption attempt</msg>
        <url>www.adobe.com/support/security/advisories/apsa10-05.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;video/x-quicktime&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3A\s*video\x2Fx-quicktime/smiH&quot;; flowbits:set,http.quicktime; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>17809</id>
        <msg>WEB-CLIENT quicktime movie file transfer</msg>
      </rule>
      <rule>
        <bugtraq>44684</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-3648</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18180, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18180</id>
        <msg>EXPLOIT Adobe Flash Player ActionScript remote code execution attempt</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-26.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18222, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18222</id>
        <msg>WEB-CLIENT Microsoft Windows Media Encoder wmerrorenu.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18223, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18223</id>
        <msg>WEB-CLIENT Microsoft Windows Media Encoder winietenu.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18224, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18224</id>
        <msg>WEB-CLIENT Microsoft Windows Media Encoder asferrorenu.dll dll-load attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18225, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18225</id>
        <msg>NETBIOS Microsoft Windows Media Encoder wmerrorenu.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18226, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18226</id>
        <msg>NETBIOS Microsoft Windows Media Encoder swinietenu.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3965</cve>
        <filter1>tcp $HOME_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18227, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18227</id>
        <msg>NETBIOS Microsoft Windows Media Encoder asferrorenu.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-094.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3952</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.fpx; metadata: engine shared, soid 3|18229, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18229</id>
        <msg>SPECIFIC-THREAT Microsoft FlashPix tile length overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3956</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.otf; metadata: engine shared, soid 3|18233, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18233</id>
        <msg>WEB-CLIENT Microsoft Publisher Adobe Font Driver code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-091.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3951</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18237, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18237</id>
        <msg>WEB-CLIENT Flashpix graphics filter fpx32.flt remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-105.mspx</url>
      </rule>
      <rule>
        <bugtraq>12238</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0043</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;[playlist]&quot;; pcre:&quot;/^File[0-9]+=http\x3a\x2f\x2f[^\n]{150}/Rsmi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3471</id>
        <msg>WEB-CLIENT iTunes playlist URL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12698</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0455</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;smil&gt;&quot;; nocase; content:&quot;system-screen-size=|22|&quot;; distance:0; nocase; isdataat:256; content:!&quot;|22|&quot;; within:256; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>3473</id>
        <msg>WEB-CLIENT RealPlayer SMIL file overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>793</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>1999-1110</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;22D6F312-B0F6-11D0-94AB-0080C74C7E95&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*22D6F312-B0F6-11D0-94AB-0080C74C7E95/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4152</id>
        <msg>WEB-ACTIVEX Windows Media Player 6.4 ActiveX Object Access</msg>
      </rule>
      <rule>
        <bugtraq>1221</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2000-0400</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;05589FA1-C356-11CE-BF01-00AA0055595A&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*05589FA1-C356-11CE-BF01-00AA0055595A/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4158</id>
        <msg>WEB-ACTIVEX Windows Media Player Active Movie ActiveX Object Access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;video/quicktime&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3A\s*video\x2Fquicktime/smiH&quot;; flowbits:set,http.quicktime; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>4678</id>
        <msg>WEB-CLIENT quicktime movie file transfer</msg>
      </rule>
      <rule>
        <bugtraq>15308</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2754</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;hdlr&quot;; nocase; byte_test:1,&gt;,250,24,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4679</id>
        <msg>WEB-CLIENT quicktime movie file component name integer overflow multipacket attempt</msg>
        <url>docs.info.apple.com/article.html?artnum=302772</url>
      </rule>
      <rule>
        <bugtraq>16644</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0005</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;EMBED&quot;; nocase; content:&quot;src&quot;; distance:0; nocase; pcre:&quot;/&lt;EMBED(\s+|\s+[^&gt;]*?\s+)src\s*=\s*(\x22[^\x22]{2082}|\x27[^\x27]{2082}|[^\r\n\s]{2082})/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>5710</id>
        <msg>WEB-CLIENT Windows Media Player Plugin for Non-IE browsers buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-006.mspx</url>
      </rule>
      <rule>
        <bugtraq>16633</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0006</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BM|00 00 00 00|&quot;; pcre:&quot;/^BM\x00\x00\x00\x00/sm&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>5711</id>
        <msg>WEB-CLIENT Windows Media Player zero length bitmap heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-005.mspx</url>
      </rule>
      <rule>
        <bugtraq>16633</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0006</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BM&quot;; byte_test:4,&lt;,14,8,little,relative; pcre:&quot;/^BM/sm&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>5712</id>
        <msg>WEB-CLIENT Windows Media Player invalid data offset bitmap heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-005.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?c=&quot;; nocase; http_uri; content:&quot;&amp;g=&quot;; nocase; http_uri; content:&quot;&amp;i=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Daemon&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>6368</id>
        <msg>SPYWARE-PUT Adware flashtrack media/spoton runtime detection - update request</msg>
        <url>www.spywareguide.com/product_show.php?id=477</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/js/jsnew2.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;grp=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;ft_id=&quot;; nocase; http_uri; content:&quot;c=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;k=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6371</id>
        <msg>SPYWARE-PUT Adware flashtrack media/spoton runtime detection - pop up ads</msg>
        <url>www.spywareguide.com/product_show.php?id=477</url>
      </rule>
      <rule>
        <bugtraq>17074</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1249</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; depth:8; byte_test:4,&gt;,8388606,56,little,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6505</id>
        <msg>WEB-CLIENT quicktime fpx file SectNumMiniFAT overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17953</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1460</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;udta&quot;; byte_test:4,&gt;,4294967291,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6506</id>
        <msg>WEB-CLIENT quicktime udta atom overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B|00|4|00|D|00|C|00|8|00|D|00|D|00|9|00|-|00|2|00|C|00|C|00|1|00|-|00|4|00|0|00|8|00|1|00|-|00|9|00|B|00|2|00|B|00|-|00|2|00|0|00|D|00|7|00|0|00|3|00|0|00|2|00|3|00|4|00|E|00|F|00|&quot;; fast_pattern:only; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*B\x004\x00D\x00C\x008\x00D\x00D\x009\x00-\x002\x00C\x00C\x001\x00-\x004\x000\x008\x001\x00-\x009\x00B\x002\x00B\x00-\x002\x000\x00D\x007\x000\x003\x000\x002\x003\x004\x00E\x00F\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6680</id>
        <msg>WEB-ACTIVEX Windows Media Transform Effects ActiveX CLSID unicode access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-1303</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;B4DC8DD9-2CC1-4081-9B2B-20D7030234EF&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B4DC8DD9-2CC1-4081-9B2B-20D7030234EF/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6681</id>
        <msg>WEB-ACTIVEX Windows Media Transform Effects ActiveX CLSID access</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-021.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/lordofsearchD_468X60.html&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;aresflashdownloader.com&quot;; nocase; http_header; pcre:&quot;/^Host|3A|[^\r\n]*aresflashdownloader\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7142</id>
        <msg>SPYWARE-PUT Adware ares flash downloader 2.04 runtime detection</msg>
        <url>www.download2you.com/details_page.asp?titleID=12388</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Flashbar&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; content:&quot;X&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Flashbar[^\r\n]*Toolbar[^\r\n]*X/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7581</id>
        <msg>SPYWARE-PUT Hijacker flashbar runtime detection - user-agent</msg>
        <url>data.icxo.com/htmlnews/2006/07/10/875297.htm</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C1145550-A454-11D4-9020-00D0B7239081&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C1145550-A454-11D4-9020-00D0B7239081/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7888</id>
        <msg>WEB-ACTIVEX AOLFlash.AOLFlash ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;C|00|1|00|1|00|4|00|5|00|5|00|5|00|0|00|-|00|A|00|4|00|5|00|4|00|-|00|1|00|1|00|D|00|4|00|-|00|9|00|0|00|2|00|0|00|-|00|0|00|0|00|D|00|0|00|B|00|7|00|2|00|3|00|9|00|0|00|8|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*C\x001\x001\x004\x005\x005\x005\x000\x00-\x00A\x004\x005\x004\x00-\x001\x001\x00D\x004\x00-\x009\x000\x002\x000\x00-\x000\x000\x00D\x000\x00B\x007\x002\x003\x009\x000\x008\x001\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>7889</id>
        <msg>WEB-ACTIVEX AOLFlash.AOLFlash ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-6244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D27CDB6E-AE6D-11CF-96B8-444553540000&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D27CDB6E-AE6D-11CF-96B8-444553540000\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*navigateToURL|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*D27CDB6E-AE6D-11CF-96B8-444553540000\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\.navigateToURL)\s*\(/si&quot;; metadata:policy security-ips alert, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7978</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX clsid access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb07-20.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-6244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;D|00|2|00|7|00|C|00|D|00|B|00|6|00|E|00|-|00|A|00|E|00|6|00|D|00|-|00|1|00|1|00|C|00|F|00|-|00|9|00|6|00|B|00|8|00|-|00|4|00|4|00|4|00|5|00|5|00|3|00|5|00|4|00|0|00|0|00|0|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/1([^&gt;]\x00)*1(?P&lt;q3&gt;\x22\x00|\x27\x00|)1({\x00)?1(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7979</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX clsid unicode access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb07-20.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ShockwaveFlash.ShockwaveFlash.9&quot;; fast_pattern:only; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ShockwaveFlash\.ShockwaveFlash\.9\x22|\x27ShockwaveFlash\.ShockwaveFlash\.9\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ShockwaveFlash\.ShockwaveFlash\.9\x22|\x27ShockwaveFlash\.ShockwaveFlash\.9\x27)\s*\)/smi&quot;; metadata:policy security-ips alert, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>7980</id>
        <msg>WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash.9 ActiveX function call access</msg>
        <url>www.securityfocus.com/archive/1/443383/30/150/threaded</url>
      </rule>
      <rule>
        <bugtraq>14945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2710</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;imfl&gt;&quot;; nocase; pcre:&quot;/&lt;[^&gt;]*?\x25/ROsmi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8091</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer error message format string vulnerability attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|2|00|B|00|F|00|2|00|5|00|D|00|5|00|-|00|8|00|C|00|1|00|7|00|-|00|4|00|B|00|2|00|3|00|-|00|B|00|C|00|8|00|0|00|-|00|D|00|3|00|4|00|8|00|8|00|A|00|B|00|D|00|D|00|C|00|6|00|B|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*0\x002\x00B\x00F\x002\x005\x00D\x005\x00-\x008\x00C\x001\x007\x00-\x004\x00B\x002\x003\x00-\x00B\x00C\x008\x000\x00-\x00D\x003\x004\x008\x008\x00A\x00B\x00D\x00D\x00C\x006\x00B\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8376</id>
        <msg>WEB-ACTIVEX QuickTime Object ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0FDF6D6B-D672-463B-846E-C6FF49109662&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0FDF6D6B-D672-463B-846E-C6FF49109662\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*0FDF6D6B-D672-463B-846E-C6FF49109662\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8377</id>
        <msg>WEB-ACTIVEX RealPlayer Download Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;0|00|F|00|D|00|F|00|6|00|D|00|6|00|B|00|-|00|D|00|6|00|7|00|2|00|-|00|4|00|6|00|3|00|B|00|-|00|8|00|4|00|6|00|E|00|-|00|C|00|6|00|F|00|F|00|4|00|9|00|1|00|0|00|9|00|6|00|6|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*0\x00F\x00D\x00F\x006\x00D\x006\x00B\x00-\x00D\x006\x007\x002\x00-\x004\x006\x003\x00B\x00-\x008\x004\x006\x00E\x00-\x00C\x006\x00F\x00F\x004\x009\x001\x000\x009\x006\x006\x002\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8378</id>
        <msg>WEB-ACTIVEX RealPlayer Download Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;224E833B-2CC6-42D9-AE39-90B6A38A4FA2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m13&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m13)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q33&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*224E833B-2CC6-42D9-AE39-90B6A38A4FA2\s*}?\s*(?P=q33)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q34&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*224E833B-2CC6-42D9-AE39-90B6A38A4FA2\s*}?\s*(?P=q34)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m14&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m14)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8381</id>
        <msg>WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|2|00|4|00|E|00|8|00|3|00|3|00|B|00|-|00|2|00|C|00|C|00|6|00|-|00|4|00|2|00|D|00|9|00|-|00|A|00|E|00|3|00|9|00|-|00|9|00|0|00|B|00|6|00|A|00|3|00|8|00|A|00|4|00|F|00|A|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q35&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x002\x004\x00E\x008\x003\x003\x00B\x00-\x002\x00C\x00C\x006\x00-\x004\x002\x00D\x009\x00-\x00A\x00E\x003\x009\x00-\x009\x000\x00B\x006\x00A\x003\x008\x00A\x004\x00F\x00A\x002\x00(}\x00)?(?P=q35)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8382</id>
        <msg>WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m5&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m5)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q13&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93\s*}?\s*(?P=q13)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q14&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93\s*}?\s*(?P=q14)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m6&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m6)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8383</id>
        <msg>WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;2|00|F|00|5|00|4|00|2|00|A|00|2|00|E|00|-|00|E|00|D|00|C|00|9|00|-|00|4|00|B|00|F|00|7|00|-|00|8|00|C|00|B|00|1|00|-|00|8|00|7|00|C|00|9|00|9|00|1|00|9|00|F|00|7|00|F|00|9|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q15&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*2\x00F\x005\x004\x002\x00A\x002\x00E\x00-\x00E\x00D\x00C\x009\x00-\x004\x00B\x00F\x007\x00-\x008\x00C\x00B\x001\x00-\x008\x007\x00C\x009\x009\x001\x009\x00F\x007\x00F\x009\x003\x00(}\x00)?(?P=q15)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8384</id>
        <msg>WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3B46067C-FD87-49B6-8DDD-12F0D687035F&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m3&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m3)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q8&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B46067C-FD87-49B6-8DDD-12F0D687035F\s*}?\s*(?P=q8)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q9&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B46067C-FD87-49B6-8DDD-12F0D687035F\s*}?\s*(?P=q9)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m4&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m4)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8385</id>
        <msg>WEB-ACTIVEX RealPlayer Playback Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|B|00|4|00|6|00|0|00|6|00|7|00|C|00|-|00|F|00|D|00|8|00|7|00|-|00|4|00|9|00|B|00|6|00|-|00|8|00|D|00|D|00|D|00|-|00|1|00|2|00|F|00|0|00|D|00|6|00|8|00|7|00|0|00|3|00|5|00|F|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q10&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00B\x004\x006\x000\x006\x007\x00C\x00-\x00F\x00D\x008\x007\x00-\x004\x009\x00B\x006\x00-\x008\x00D\x00D\x00D\x00-\x001\x002\x00F\x000\x00D\x006\x008\x007\x000\x003\x005\x00F\x00(}\x00)?(?P=q10)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8386</id>
        <msg>WEB-ACTIVEX RealPlayer Playback Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3B5E0503-DE28-4BE8-919C-76E0E894A3C2&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m11&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m11)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q28&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B5E0503-DE28-4BE8-919C-76E0E894A3C2\s*}?\s*(?P=q28)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q29&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*3B5E0503-DE28-4BE8-919C-76E0E894A3C2\s*}?\s*(?P=q29)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m12&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m12)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8387</id>
        <msg>WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;3|00|B|00|5|00|E|00|0|00|5|00|0|00|3|00|-|00|D|00|E|00|2|00|8|00|-|00|4|00|B|00|E|00|8|00|-|00|9|00|1|00|9|00|C|00|-|00|7|00|6|00|E|00|0|00|E|00|8|00|9|00|4|00|A|00|3|00|C|00|2|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q30&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*3\x00B\x005\x00E\x000\x005\x000\x003\x00-\x00D\x00E\x002\x008\x00-\x004\x00B\x00E\x008\x00-\x009\x001\x009\x00C\x00-\x007\x006\x00E\x000\x00E\x008\x009\x004\x00A\x003\x00C\x002\x00(}\x00)?(?P=q30)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8388</id>
        <msg>WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;44CCBCEB-BA7E-4C99-A078-9F683832D493&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m9&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m9)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q23&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*44CCBCEB-BA7E-4C99-A078-9F683832D493\s*}?\s*(?P=q23)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q24&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*44CCBCEB-BA7E-4C99-A078-9F683832D493\s*}?\s*(?P=q24)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m10&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m10)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8389</id>
        <msg>WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|4|00|C|00|C|00|B|00|C|00|E|00|B|00|-|00|B|00|A|00|7|00|E|00|-|00|4|00|C|00|9|00|9|00|-|00|A|00|0|00|7|00|8|00|-|00|9|00|F|00|6|00|8|00|3|00|8|00|3|00|2|00|D|00|4|00|9|00|3|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q25&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x004\x00C\x00C\x00B\x00C\x00E\x00B\x00-\x00B\x00A\x007\x00E\x00-\x004\x00C\x009\x009\x00-\x00A\x000\x007\x008\x00-\x009\x00F\x006\x008\x003\x008\x003\x002\x00D\x004\x009\x003\x00(}\x00)?(?P=q25)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8390</id>
        <msg>WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;760C4B83-E211-11D2-BF3E-00805FBE84A6&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*760C4B83-E211-11D2-BF3E-00805FBE84A6/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8401</id>
        <msg>WEB-ACTIVEX Windows Media Services DRM Storage ActiveX CLSID access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;7|00|6|00|0|00|C|00|4|00|B|00|8|00|3|00|-|00|E|00|2|00|1|00|1|00|-|00|1|00|1|00|D|00|2|00|-|00|B|00|F|00|3|00|E|00|-|00|0|00|0|00|8|00|0|00|5|00|F|00|B|00|E|00|8|00|4|00|A|00|6|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00O\x00B\x00J\x00E\x00C\x00T\x00(\s\x00)+([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*([\x22\x27]\x00)?(\s\x00)*c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*(\x7B\x00)?(\s\x00)*7\x006\x000\x00C\x004\x00B\x008\x003\x00-\x00E\x002\x001\x001\x00-\x001\x001\x00D\x002\x00-\x00B\x00F\x003\x00E\x00-\x000\x000\x008\x000\x005\x00F\x00B\x00E\x008\x004\x00A\x006\x00/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8402</id>
        <msg>WEB-ACTIVEX Windows Media Services DRM Storage ActiveX CLSID unicode access</msg>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A1A41E11-91DB-4461-95CD-0C02327FD934&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m15&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m15)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q38&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A1A41E11-91DB-4461-95CD-0C02327FD934\s*}?\s*(?P=q38)(\s|&gt;).*(?P=id1)\s*\.\s*(Console|Controls)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q39&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*A1A41E11-91DB-4461-95CD-0C02327FD934\s*}?\s*(?P=q39)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m16&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m16)(\s|&gt;).*(?P=id2)\s*\.\s*(Console|Controls))\s*=/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8409</id>
        <msg>WEB-ACTIVEX RealPlayer Stream Handler ActiveX clsid access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <bugtraq>28157</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1309</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;A|00|1|00|A|00|4|00|1|00|E|00|1|00|1|00|-|00|9|00|1|00|D|00|B|00|-|00|4|00|4|00|6|00|1|00|-|00|9|00|5|00|C|00|D|00|-|00|0|00|C|00|0|00|2|00|3|00|2|00|7|00|F|00|D|00|9|00|3|00|4|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q40&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*A\x001\x00A\x004\x001\x00E\x001\x001\x00-\x009\x001\x00D\x00B\x00-\x004\x004\x006\x001\x00-\x009\x005\x00C\x00D\x00-\x000\x00C\x000\x002\x003\x002\x007\x00F\x00D\x009\x003\x004\x00(}\x00)?(?P=q40)(?=\s\x00|&gt;\x00)/si&quot;; metadata:policy security-ips alert, service http; classtype:attempted-user;</filter2>
        <id>8410</id>
        <msg>WEB-ACTIVEX RealPlayer Stream Handler ActiveX clsid unicode access</msg>
        <url>www.kb.cert.org/vuls/id/831457</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;FLV|01|&quot;; content:&quot;|00 00 00 09|&quot;; within:4; distance:1; flowbits:set,flv.xfer; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>912182</id>
        <msg>POLICY Adobe FLV file transfer</msg>
      </rule>
      <rule>
        <bugtraq>20138</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4965</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;?xml version&quot;; nocase; content:&quot;&lt;?quicktime type=|22|application/x-quicktime-media-link&quot;; distance:0; nocase; pcre:&quot;/&lt;embed[^&gt;]*javascript/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9429</id>
        <msg>WEB-CLIENT Quicktime Movie link scripting security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>20138</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4965</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;?xml version&quot;; nocase; content:&quot;&lt;?quicktime type=|22|application/x-quicktime-media-link&quot;; distance:0; nocase; content:&quot;qtnext=|22|file&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9430</id>
        <msg>WEB-CLIENT Quicktime Movie link file URI security bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>21247</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6134</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;ref&quot;; nocase; content:&quot;href&quot;; distance:0; nocase; pcre:&quot;/&lt;ref\s+href\s*=\s*\x22([^\x22]{2}|(\x25[0-9A-Z]{2}){1,2})\x3A\x2F[^\x22]{100}/smi&quot;; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9625</id>
        <msg>WEB-CLIENT Windows Media Player ASX file ref href buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-078.mspx</url>
      </rule>
      <rule>
        <bugtraq>21453</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5856</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;?aom&quot;; nocase; content:&quot;&lt;url&gt;&quot;; isdataat:271; content:!&quot;&lt;/url&gt;&quot;; within:271; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9637</id>
        <msg>WEB-CLIENT Adobe Download Manger dm.ini stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4702</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|90 08 00|3|B1 E5 CF 11 89 F4 00 A0 C9 03|I|CB|&quot;; byte_test:4,&gt;,715827882,36,relative,little; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9641</id>
        <msg>WEB-CLIENT Windows Media Player ASF simple index object parsing buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-078.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4702</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;@R|D1 86 1D|1|D0 11 A3 A4 00 A0 C9 03|H|F6|&quot;; byte_test:4,&gt;,134217727,24,relative,little; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9642</id>
        <msg>WEB-CLIENT Windows Media Player ASF codec list object parsing buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-078.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4702</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|01 CD 87 F4|Q|A9 CF 11 8E E6 00 C0 0C| Se&quot;; byte_test:4,&gt;,134217727,24,relative,little; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9643</id>
        <msg>WEB-CLIENT Windows Media Player ASF marker object parsing buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS06-078.mspx</url>
      </rule>
      <rule>
        <bugtraq>21802</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6847</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;405DE7C0-E7DD-11D2-92C5-00C0F01F77C1&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;OBJECT\s*[^&gt;]*\s*classid\s*=\s*(\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*405DE7C0-E7DD-11D2-92C5-00C0F01F77C1\s*}?\s*\1/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9671</id>
        <msg>WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>21802</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6847</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|0|00|5|00|D|00|E|00|7|00|C|00|0|00|-|00|E|00|7|00|D|00|D|00|-|00|1|00|1|00|D|00|2|00|-|00|9|00|2|00|C|00|5|00|-|00|0|00|0|00|C|00|0|00|F|00|0|00|1|00|F|00|7|00|7|00|C|00|1|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x000\x005\x00D\x00E\x007\x00C\x000\x00-\x00E\x007\x00D\x00D\x00-\x001\x001\x00D\x002\x00-\x009\x002\x00C\x005\x00-\x000\x000\x00C\x000\x00F\x000\x001\x00F\x007\x007\x00C\x001\x00(}\x00)?\5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9672</id>
        <msg>WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>21802</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6847</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;AutoStream.AutoStream.1&quot;; fast_pattern:only; pcre:&quot;/(\w+)\s*=\s*(\x22AutoStream.AutoStream.1\x22|\x27AutoStream.AutoStream.1\x27)\s*\x3b.*\w+\s*=\s*new\s*ActiveXObject\s*\(\s*\1\s*\)|\w+\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22AutoStream.AutoStream.1\x22|\x27AutoStream.AutoStream.1\x27)\s*\)/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9673</id>
        <msg>WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>21612</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-6601</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MThd&quot;; content:&quot;|00 00 00 00 00 00|&quot;; within:6; distance:4; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>9801</id>
        <msg>WEB-CLIENT Windows Media Player or Explorer Malformed RIFF File denial of service attempt</msg>
        <url>www.milw0rm.com/exploits/3190</url>
      </rule>
      <rule>
        <bugtraq>21829</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;rtsp|3A|//&quot;; nocase; pcre:&quot;/(=\s*(('|\x22)rtsp\x3A[^\3]{200}|rstp\x3A[^\s\x3E]{200})|\x3Csrc\x3Ertsp\x3A[^\x3C]{200})/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9823</id>
        <msg>WEB-CLIENT QuickTime RTSP URI overflow attempt</msg>
        <url>applefun.blogspot.com/2007/01/moab-01-01-2007-apple-quicktime-rtsp.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2007-0059</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.quicktime; content:&quot;&gt; T&lt;&quot;; fast_pattern:only; pcre:&quot;/A?&lt;\s*([A-Za-z]{3,5}\x3A\x2F\x2F|javascript\x3a)[^&gt;]+&gt; T&lt;/sm&quot;; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>9840</id>
        <msg>WEB-CLIENT QuickTime HREF Track Detected</msg>
        <url>www.apple.com/quicktime/tutorials/hreftracks.html</url>
      </rule>
    </attacks>
    <groupid>340</groupid>
    <groupname>Client / Multimedia</groupname>
    <warnings>
      <rule>
        <bugtraq>26586</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3066</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;I|00|E|00|R|00|P|00|C|00|t|00|l|00|.|00|I|00|E|00|R|00|P|00|C|00|t|00|l|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)I\x00E\x00R\x00P\x00C\x00t\x00l\x00.\x00I\x00E\x00R\x00P\x00C\x00t\x00l\x00(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*1\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*1\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)I\x00E\x00R\x00P\x00C\x00t\x00l\x00.\x00I\x00E\x00R\x00P\x00C\x00t\x00l\x00(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/Osmi&quot;; classtype:attempted-user;</filter2>
        <id>12663</id>
        <msg>WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <bugtraq>26214</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5080</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;LYRICSBEGIN&quot;; nocase; pcre:&quot;/(EAL|EAR|ETT)\s*-0{0,4}1/i&quot;; classtype:attempted-user;</filter2>
        <id>12707</id>
        <msg>WEB-CLIENT RealNetworks RealPlayer lyrics heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26549</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6166</cve>
        <filter1>tcp $EXTERNAL_NET 554 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;RTSP&quot;; depth:4; fast_pattern; content:&quot;Content-Type&quot;; nocase; isdataat:257,relative; content:!&quot;|0A|&quot;; within:257; pcre:&quot;/Content-Type\s*\x3A[^\n\x3A]{256}/smi&quot;; metadata:service rtsp; classtype:attempted-user;</filter2>
        <id>12741</id>
        <msg>EXPLOIT Apple Quicktime TCP RTSP sdp type buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15306</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2753</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.quicktime; content:&quot;text&quot;; byte_test:1,&gt;=,251,49,relative; metadata:service http; classtype:attempted-user;</filter2>
        <id>13919</id>
        <msg>WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3008</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14256;</filter2>
        <id>14256</id>
        <msg>WEB-ACTIVEX Windows Media Encoder 9 ActiveX clsid unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3008</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14258;</filter2>
        <id>14258</id>
        <msg>WEB-ACTIVEX Windows Media Encoder 9 ActiveX function call unicode access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15914, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15914</id>
        <msg>WEB-CLIENT Microsoft Windows Media sample duration header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15915, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15915</id>
        <msg>WEB-CLIENT Microsoft Windows Media Timecode header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15916, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15916</id>
        <msg>WEB-CLIENT Microsoft Windows Media file name header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15917, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15917</id>
        <msg>WEB-CLIENT Microsoft Windows Media content type header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15918, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15918</id>
        <msg>WEB-CLIENT Microsoft Windows Media pixel aspect ratio header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|15919, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>15919</id>
        <msg>WEB-CLIENT Microsoft Windows Media encryption sample ID header RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2009-3951</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; metadata: engine shared, soid 3|16315, service http;</filter2>
        <id>16315</id>
        <msg>WEB-MISC Adobe Flash PlugIn check if file exists attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3794</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.swf; metadata: engine shared, soid 3|16331;</filter2>
        <id>16331</id>
        <msg>WEB-CLIENT Adobe Flash Player JPEG parsing heap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2498</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.asf; metadata: engine shared, soid 3|16338, service http, policy balanced-ips drop, policy connectivity-ips drop;</filter2>
        <id>16338</id>
        <msg>WEB-CLIENT Microsoft Windows Media extended stream properties object RCE attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms09-047.mspx</url>
      </rule>
      <rule>
        <bugtraq>37759</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3958</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16372;</filter2>
        <id>16372</id>
        <msg>WEB-ACTIVEX NOS Microsystems Adobe atl_getcom ActiveX clsid unicode access</msg>
        <url>www.adobe.com/support/security/bulletins/apsb10-02.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0196</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16544;</filter2>
        <id>16544</id>
        <msg>WEB-CLIENT Adobe Reader Linux malformed U3D mesh deceleration block exploit attempt </msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0197</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16545;</filter2>
        <id>16545</id>
        <msg>WEB-CLIENT Adobe Reader malformed Richmedia annotation exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>26960</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2007-6244</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|11 BA EE 66 DA B8 6C D6 A9 D7 D9 C2 DB F0 26 7D|&quot;; fast_pattern:only; metadata:service http; classtype:misc-activity;</filter2>
        <id>17223</id>
        <msg>SPECIFIC-THREATS Adobe Flash Player navigateToURL cross-site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>15334</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2628</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;FWS|06|&quot;; within:4; content:&quot;|43 02|&quot;; within:27; byte_test:1,&lt;,64,3,relative; content:&quot;|03|&quot;; within:1; distance:4; pcre:&quot;/^(\x9B|\x8E)/R&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17457</id>
        <msg>WEB-CLIENT Macromedia Flash ActionDefineFunction memory access vulnerability exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>35282</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1855</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/robohelp/robo/reserved/web/&quot;; nocase; http_uri; content:&quot;.jsp&quot;; nocase; http_uri; pcre:&quot;/\x2frobohelp\x2frobo\x2freserved\x2fweb\x2f[^\r\n]{0,60}\x2Ejsp/Ui&quot;; classtype:attempted-user;</filter2>
        <id>17529</id>
        <msg>SPECIFIC-THREATS Adobe RoboHelp Server Arbitrary File Upload and Execute</msg>
      </rule>
      <rule>
        <bugtraq>9579</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,realplayer.playlist; content:&quot;file|3A|//&quot;; nocase; pcre:&quot;/^file\x3a\x2f\x2f[^\n]{400}/smi&quot;; classtype:attempted-user;</filter2>
        <id>2438</id>
        <msg>WEB-CLIENT RealPlayer playlist file URL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9579</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,realplayer.playlist; content:&quot;http|3A|//&quot;; nocase; pcre:&quot;/^http\x3a\x2f\x2f[^\n]{400}/smi&quot;; classtype:attempted-user;</filter2>
        <id>2439</id>
        <msg>WEB-CLIENT RealPlayer playlist http URL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9579</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0755</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,realplayer.playlist; content:&quot;rtsp|3A|//&quot;; nocase; pcre:&quot;/^http\x3a\x2f\x2f[^\n]{400}/smi&quot;; classtype:attempted-user;</filter2>
        <id>2440</id>
        <msg>WEB-CLIENT RealPlayer playlist rtsp URL overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9735</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 8000:8001</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; pcre:&quot;/^User-Agent\x3a[^\n]{244,255}/smi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>2442</id>
        <msg>WEB-MISC Quicktime User-Agent buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;Extended module|3A|&quot;; nocase; isdataat:20,relative; content:!&quot;|1A|&quot;; within:21; classtype:attempted-user;</filter2>
        <id>2550</id>
        <msg>EXPLOIT winamp XM module name overflow</msg>
        <url>www.nextgenss.com/advisories/winampheap.txt</url>
      </rule>
      <rule>
        <bugtraq>11730</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1119</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;.cda&quot;; nocase; pcre:&quot;/(\x5c[^\x5c]{16,}|\x2f[^\x2f]{16,})\.cda$/smi&quot;; classtype:attempted-user;</filter2>
        <id>3088</id>
        <msg>WEB-CLIENT winamp .cda file name overflow attempt</msg>
        <nessus>15817</nessus>
      </rule>
      <rule>
        <bugtraq>11309</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1481</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;.RMF&quot;; nocase; content:&quot;VIDORV30&quot;; distance:0; byte_test:4,&gt;,1000000,-16,relative; classtype:attempted-admin;</filter2>
        <id>3470</id>
        <msg>WEB-CLIENT RealPlayer VIDORV30 header length buffer overflow</msg>
        <url>www.eeye.com/html/research/advisories/AD20041001.html</url>
      </rule>
      <rule>
        <bugtraq>12096</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2004-1373</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8000</filter1>
        <filter2>flow:established,to_server; content:&quot;/content/&quot;; fast_pattern:only; pcre:&quot;/\/content\/[^\r\n\x20]*\x2emp3/smi&quot;; classtype:web-application-attack;</filter2>
        <id>4131</id>
        <msg>EXPLOIT SHOUTcast URI format string attempt</msg>
      </rule>
      <rule>
        <bugtraq>15308</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2754</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;video/quicktime&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3A\s*video\x2Fquicktime/smiH&quot;; content:&quot;hdlr&quot;; nocase; byte_test:1,&gt;,250,24,relative; classtype:attempted-user;</filter2>
        <id>4680</id>
        <msg>WEB-CLIENT quicktime movie file component name integer overflow attempt</msg>
        <url>docs.info.apple.com/article.html?artnum=302772</url>
      </rule>
      <rule>
        <bugtraq>11271</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8000</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP/1.&quot;; nocase; pcre:&quot;/HTTP\/1\.[01].*?\n([^\r\n]+?\r?\n){32}/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>8701</id>
        <msg>WEB-MISC IceCast header buffer overflow attempt</msg>
        <url>archives.neohapsis.com/archives/bugtraq/2004-09/0366.html</url>
      </rule>
      <rule>
        <bugtraq>11271</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8000</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB 0C| / HTTP/1.1 &quot;; nocase; pcre:&quot;/\xeb\x0c \/ HTTP\/1\.1\s+\S+/smi&quot;; classtype:attempted-admin;</filter2>
        <id>8702</id>
        <msg>EXPLOIT IceCast header buffer overflow attempt</msg>
        <url>archives.neohapsis.com/archives/bugtraq/2004-09/0366.html</url>
      </rule>
      <rule>
        <bugtraq>11271</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-1561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8000</filter1>
        <filter2>flow:to_server,established; content:&quot;GET / HTTP/1.0|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|a|0D 0A|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>8703</id>
        <msg>EXPLOIT IceCast header buffer overflow attempt</msg>
        <url>archives.neohapsis.com/archives/bugtraq/2004-09/0366.html</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2007-0045</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.pdf|23|&quot;; nocase; pcre:&quot;/\x2Epdf\x23[^\r\n]+\x3Djavascript\x3A/smi&quot;; classtype:misc-attack;</filter2>
        <id>9842</id>
        <msg>WEB-CLIENT Adobe Acrobat Plugin Universal cross-site scripting attempt</msg>
        <url>isc.sans.org/diary.php?storyid=1999</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>350</groupid>
    <groupname>Client / Peer to Peer</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>26748</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5989</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;skype4com|3A|&quot;; fast_pattern:only; pcre:&quot;/skype4com\x3A[A-Z\d]{0,6}[^A-Z\d]/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13292</id>
        <msg>EXPLOIT Skype skype4com URI handler memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 4244</filter1>
        <filter2>flow:to_server,established; content:&quot;PASS gooback&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>15939</id>
        <msg>SPECIFIC-THREATS MSN Messenger IRC bot calling home attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=19bffa751aafa9e63420203938a0d8a9</url>
      </rule>
      <rule>
        <bugtraq>38699</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;skype|3A|&quot;; nocase; pcre:&quot;/\x3Ca\s+[^\x3E]*href\s*\x3D\s*(\x22|\x27)?skype\x3A[^\s\x3E]*[\x01-\x07]/i&quot;; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>16718</id>
        <msg>EXPLOIT Skype URI handler input validation exploit attempt</msg>
        <url>security-assessment.com/files/advisories/Skype_URI_Handling_Vulnerability.pdf</url>
      </rule>
      <rule>
        <bugtraq>36459</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4741</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;42481700-CF3C-4D05-8EC6-F9A1C57E8DC0&quot;; fast_pattern:only; nocase; pcre:&quot;/(&lt;object\s*[^&gt;]*\s*id\s*=\s*(?P&lt;m1&gt;\x22|\x27|)(?P&lt;id1&gt;.+?)(?P=m1)(\s|&gt;)[^&gt;]*\s*classid\s*=\s*(?P&lt;q1&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42481700-CF3C-4D05-8EC6-F9A1C57E8DC0\s*}?\s*(?P=q1)(\s|&gt;).*(?P=id1)\s*\.\s*(RegisterWindow)|&lt;object\s*[^&gt;]*\s*classid\s*=\s*(?P&lt;q2&gt;\x22|\x27|)\s*clsid\s*\x3a\s*{?\s*42481700-CF3C-4D05-8EC6-F9A1C57E8DC0\s*}?\s*(?P=q2)(\s|&gt;)[^&gt;]*\s*id\s*=\s*(?P&lt;m2&gt;\x22|\x27|)(?P&lt;id2&gt;.+?)(?P=m2)(\s|&gt;).*(?P=id2)\s*\.\s*(RegisterWindow))\s*=/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17674</id>
        <msg>WEB-ACTIVEX Skype Extras Manager ActiveX clsid access</msg>
      </rule>
      <rule>
        <bugtraq>36459</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4741</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;4|00|2|00|4|00|8|00|1|00|7|00|0|00|0|00|-|00|C|00|F|00|3|00|C|00|-|00|4|00|D|00|0|00|5|00|-|00|8|00|E|00|C|00|6|00|-|00|F|00|9|00|A|00|1|00|C|00|5|00|7|00|E|00|8|00|D|00|C|00|0|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/&lt;\x00o\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*([^&gt;]\x00)*c\x00l\x00a\x00s\x00s\x00i\x00d\x00(\s\x00)*=\x00(\s\x00)*(?P&lt;q3&gt;\x22\x00|\x27\x00|)c\x00l\x00s\x00i\x00d\x00(\s\x00)*\x3a\x00(\s\x00)*({\x00)?(\s\x00)*4\x002\x004\x008\x001\x007\x000\x000\x00-\x00C\x00F\x003\x00C\x00-\x004\x00D\x000\x005\x00-\x008\x00E\x00C\x006\x00-\x00F\x009\x00A\x001\x00C\x005\x007\x00E\x008\x00D\x00C\x000\x00(}\x00)?(?P=q3)(?=\s\x00|&gt;\x00)/siO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17675</id>
        <msg>WEB-ACTIVEX Skype Extras Manager ActiveX clsid unicode access</msg>
      </rule>
      <rule>
        <bugtraq>36459</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4741</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ezPMUtils.WindowGroup&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)\s*=\s*(\x22ezPMUtils\.WindowGroup(\.\d)?\x22|\x27ezPMUtils\.WindowGroup(\.\d)?\x27)\s*\x3b.*(?P&lt;v&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(?P=c)\s*\)(\s*\.\s*RegisterWindow\s*|.*(?P=v)\s*\.\s*RegisterWindow\s*)|(?P&lt;n&gt;\w+)\s*=\s*new\s*ActiveXObject\s*\(\s*(\x22ezPMUtils\.WindowGroup(\.\d)?\x22|\x27ezPMUtils\.WindowGroup(\.\d)?\x27)\s*\)(\s*\.\s*RegisterWindow\s*|.*(?P=n)\s*\.\s*RegisterWindow)\s*=/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17676</id>
        <msg>WEB-ACTIVEX Skype Extras Manager ActiveX function call access</msg>
      </rule>
      <rule>
        <bugtraq>36459</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4741</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;e|00|z|00|P|00|M|00|U|00|t|00|i|00|l|00|s|00|.|00|W|00|i|00|n|00|d|00|o|00|w|00|G|00|r|00|o|00|u|00|p|00|&quot;; fast_pattern:only; nocase; pcre:&quot;/(?P&lt;c&gt;\w+)(\s\x00)*=(\s\x00)*(?P&lt;q4&gt;\x22|\x27|)e\x00z\x00P\x00M\x00U\x00t\x00i\x00l\x00s\x00.\x00W\x00i\x00n\x00d\x00o\x00w\x00G\x00r\x00o\x00u\x00p\x00(\.\x00\d\x00)?(?P=q4)(\s|&gt;)(\s\x00)*\x3b\x00.*(?P&lt;v&gt;(\w\x00)+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P=c)(\s\x00)*\)\x00|(?P&lt;n&gt;\w+)(\s\x00)*=\x00(\s\x00)*n\x00e\x00w\x00(\s\x00)*A\x00c\x00t\x00i\x00v\x00e\x00X\x00O\x00b\x00j\x00e\x00c\x00t\x00(\s\x00)*\(\x00(\s\x00)*(?P&lt;q5&gt;\x22|\x27|)e\x00z\x00P\x00M\x00U\x00t\x00i\x00l\x00s\x00.\x00W\x00i\x00n\x00d\x00o\x00w\x00G\x00r\x00o\x00u\x00p\x00(\.\x00\d\x00)?(?P=q5)(\s|&gt;)(\s\x00)*\)\x00/smiO&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17677</id>
        <msg>WEB-ACTIVEX Skype Extras Manager ActiveX function call unicode access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1863</filter1>
        <filter2>flow:to_server,established; content:&quot;http|3A|//www.home.no/&quot;; nocase; content:&quot;/jituxramon.exe&quot;; distance:0; nocase;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9380</id>
        <msg>SPECIFIC-THREATS jitux msn messenger propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-123116-3525-99&amp;tabid=2</url>
      </rule>
    </attacks>
    <groupid>360</groupid>
    <groupname>Client / Instant Messenger</groupname>
    <warnings>
      <rule>
        <bugtraq>10889</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0636</cve>
        <filter1>tcp $EXTERNAL_NET [80,8080] -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;aim|3A|goaway?message=&quot;; nocase; isdataat:500,relative; pcre:&quot;/\x22aim\x3Agoaway\x3Fmessage\x3D[^\x22]{500}|\x27aim\x3Agoaway\x3Fmessage\x3D[^\x27]{500}|aim\x3Agoaway\x3Fmessage\x3D[^\s]{500}/i&quot;; classtype:misc-attack;</filter2>
        <id>3085</id>
        <msg>EXPLOIT AIM goaway message buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10872</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0957</cve>
        <filter1>tcp $EXTERNAL_NET 1863 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-msnmsgrp2p&quot;; nocase; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; distance:0; content:&quot;IHDR&quot;; within:4; distance:4; content:&quot;|03|&quot;; within:1; distance:9; content:&quot;tRNS&quot;; distance:0; byte_test:4,&gt;,256,-8,relative,big; classtype:attempted-user;</filter2>
        <id>3130</id>
        <msg>EXPLOIT MSN Messenger png overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-009.mspx</url>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>400</groupid>
    <groupname>Protocol Anomaly</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:0; content:&quot;pslist&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10107</id>
        <msg>BACKDOOR icmp cmd 1.0 runtime detection - pslist</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077250</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:0; content:&quot;pskill&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10108</id>
        <msg>BACKDOOR icmp cmd 1.0 runtime detection - pskill</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077250</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;Pinging from Delphi code written by F. Piette&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10452</id>
        <msg>BACKDOOR only 1 rat runtime detection - icmp request</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Only%201%20RAT&amp;threatid=40632</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-0066</cve>
        <filter1>icmp $HOME_NET any -&gt; 224.0.0.1 any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13288, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13288</id>
        <msg>BAD-TRAFFIC Windows remote kernel tcp/ip icmp vulnerability exploit attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-001.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0239</cve>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16405, policy security-ips drop;</filter2>
        <id>16405</id>
        <msg>ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Prefix Information stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-009.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0241</cve>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|18249, policy security-ips drop;</filter2>
        <id>18249</id>
        <msg>ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Route Information stack buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-009.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>icmp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>itype:0; content:&quot;This is made by yyt_hac!&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6128</id>
        <msg>BACKDOOR dkangel runtime detection - icmp echo reply client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076278</url>
      </rule>
    </attacks>
    <groupid>410</groupid>
    <groupname>Protocol Anomaly / Invalid Traffic</groupname>
    <warnings>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;mailto|3A|ops@digisle.com&quot;; depth:22; classtype:misc-activity;</filter2>
        <id>1813</id>
        <msg>ICMP digital island bandwidth query</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2000-0138</cve>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>icmp_id:0; itype:0; content:&quot;AAAAAAAAAA&quot;; fast_pattern:only; classtype:attempted-dos;</filter2>
        <id>222</id>
        <msg>DDOS tfn2k icmp possible communication</msg>
      </rule>
      <rule>
        <bugtraq>9952</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0367</cve>
        <filter1>ip any any -&gt; any any</filter1>
        <filter2>ip_proto:2; byte_test:1,&gt;,63,0; byte_test:1,&lt;,67,0; byte_test:1,&gt;,16,12; classtype:attempted-admin;</filter2>
        <id>2462</id>
        <msg>EXPLOIT IGMP IGAP account overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>9952</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0367</cve>
        <filter1>ip any any -&gt; any any</filter1>
        <filter2>ip_proto:2; byte_test:1,&gt;,63,0; byte_test:1,&lt;,67,0; byte_test:1,&gt;,64,13; classtype:attempted-admin;</filter2>
        <id>2463</id>
        <msg>EXPLOIT IGMP IGAP message overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>514</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>1999-0918</cve>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>fragbits:M+; ip_proto:2; classtype:attempted-dos;</filter2>
        <id>272</id>
        <msg>DOS IGMP dos attack</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS99-034.mspx</url>
      </rule>
      <rule>
        <bugtraq>13124</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-1060</cve>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:3; icode:4; byte_test:2,&lt;,576,2; classtype:attempted-dos;</filter2>
        <id>3626</id>
        <msg>ICMP PATH MTU denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;ISSPNGRQ&quot;; depth:32; classtype:attempted-recon;</filter2>
        <id>465</id>
        <msg>ICMP ISS Pinger</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>dsize:20; icmp_id:0; icmp_seq:0; itype:8; content:&quot;|00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; fast_pattern:only; classtype:attempted-recon;</filter2>
        <id>467</id>
        <msg>ICMP Nemesis v1.1 Echo</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>icode:0; itype:8; content:&quot;|00 00 00 00|EEEEEEEEEEEE&quot;; fast_pattern:only; classtype:attempted-recon;</filter2>
        <id>476</id>
        <msg>ICMP webtrends scanner</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;89|3A 3B|&lt;=&gt;?&quot;; depth:100; classtype:misc-activity;</filter2>
        <id>480</id>
        <msg>ICMP PING speedera</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;TJPingPro by Jim&quot;; depth:32; classtype:misc-activity;</filter2>
        <id>481</id>
        <msg>ICMP TJPingPro1.1Build 2 Windows</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;WhatsUp - A Netw&quot;; depth:32; classtype:misc-activity;</filter2>
        <id>482</id>
        <msg>ICMP PING WhatsupGold Windows</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>itype:8; content:&quot;Cinco Network, Inc.&quot;; depth:32; classtype:misc-activity;</filter2>
        <id>484</id>
        <msg>ICMP PING Sniffer Pro/NetXRay network scan</msg>
      </rule>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>420</groupid>
    <groupname>Protocol Anomaly / ICMP</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>430</groupid>
    <groupname>Protocol Anomaly / IGMP</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>440</groupid>
    <groupname>Protocol Anomaly / RPC</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
    </attacks>
    <groupid>450</groupid>
    <groupname>Protocol Anomaly / Misc</groupname>
    <warnings>
    </warnings>
  </group>
  <group>
    <attacks>
      <rule>
        <bugtraq>2126</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1069</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/carbo.dll&quot;; http_uri; content:&quot;icatcommand=&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>1001</id>
        <msg>WEB-MISC carbo.dll access</msg>
      </rule>
      <rule>
        <bugtraq>16476</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0295</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;location.QueryInterface&quot;; nocase; content:&quot;Components.interfaces.nsIClassInfo&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>10063</id>
        <msg>WEB-CLIENT Firefox query interface suspicious function call access attempt</msg>
        <url>www.mozilla.org/security/announce/2006/mfsa2006-04.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/connect.php&quot;; nocase; http_uri; content:&quot;N=&quot;; nocase; http_uri; content:&quot;Zango&quot;; nocase; http_uri; content:&quot;Messenger&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.easymessage.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eeasymessage\x2Enet/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>10090</id>
        <msg>SPYWARE-PUT Trickler zango easymessenger runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2182</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;|B0 AE B6 F9 CD F8 B5 C1|&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a\s+\xb0\xae\xb6\xf9\xcd\xf8\xb5\xc1/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10091</id>
        <msg>SPYWARE-PUT Hacker-Tool spylply.a runtime detection</msg>
        <url>db.kingsoft.com/virus/forecast/2005/06/08/43198.shtml</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;referer=&quot;; nocase; http_uri; content:&quot;show=&quot;; nocase; http_uri; content:&quot;Host|3A| bar-navig.yandex.ru&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10092</id>
        <msg>SPYWARE-PUT Trackware russian searchbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079056</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/gd_ad.html&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;toolsbar.kuaiso.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*toolsbar\x2Ekuaiso\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>10093</id>
        <msg>SPYWARE-PUT Hijacker kuaiso toolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098930</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/send&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;pop_rule_id=&quot;; nocase; http_uri; content:&quot;n=&quot;; nocase; http_uri; content:&quot;Host|3A| www.borlander.com.cn&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10094</id>
        <msg>SPYWARE-PUT Adware borlan runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097501</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/pra.php?&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.bydou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Ebydou\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10095</id>
        <msg>SPYWARE-PUT Trackware bydou runtime detection</msg>
        <url>bbs.360safe.com/viewthread.php?tid=58707</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;KEY&quot;; depth:3; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10096</id>
        <msg>SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - keylog</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075959</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 456</filter1>
        <filter2>flow:to_server,established; content:&quot;info&quot;; depth:4; nocase; flowbits:set,Win32.RemoteKeylog.b.info; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10097</id>
        <msg>SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Win32.RemoteKeylog.b.info; content:&quot;Product&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10098</id>
        <msg>SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - get system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075959</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 456</filter1>
        <filter2>flow:to_server,established; content:&quot;url&quot;; depth:3; nocase; flowbits:set,Win32.RemoteKeylog.b.website; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10099</id>
        <msg>SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Win32.RemoteKeylog.b.website; content:&quot;WNDMicrosoft&quot;; depth:12; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10100</id>
        <msg>SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - open website</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075959</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;delete|7C|&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10101</id>
        <msg>BACKDOOR crossfires trojan 3.0 runtime detection - delete file</msg>
        <url>www.megasecurity.org/trojans/c/crossfires/Crossfires.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;chat|7C|&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10102</id>
        <msg>BACKDOOR crossfires trojan 3.0 runtime detection - chat with victim</msg>
        <url>www.megasecurity.org/trojans/c/crossfires/Crossfires.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;getinfo&quot;; depth:7; nocase; flowbits:set,HavRat_pcinfo1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10103</id>
        <msg>BACKDOOR hav-rat 1.1 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,HavRat_pcinfo1; content:&quot;User|3A|&quot;; depth:5; nocase; flowbits:set,HavRat_pcinfo2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10104</id>
        <msg>BACKDOOR hav-rat 1.1 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,HavRat_pcinfo2; content:&quot;StartPage|3A|&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10105</id>
        <msg>BACKDOOR hav-rat 1.1 runtime detection - retrieve pc info</msg>
        <url>www.megasecurity.org/trojans/h/hav/Havrat1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;SndInfo&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10109</id>
        <msg>BACKDOOR k-msnrat 1.0.0 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/k/kmsnrat/Kmsnrat1.0.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|F6 13 00 00|&quot;; depth:4; flowbits:set,PoisonIvy_init; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10110</id>
        <msg>BACKDOOR poison ivy 2.1.2 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,PoisonIvy_init; content:&quot;U|8B EC|P|B8 02 00 00 00 81 C4 04 F0 FF FF|&quot;; depth:15; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10111</id>
        <msg>BACKDOOR poison ivy 2.1.2 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/p/poisonivy/Poisonivy2.1.2.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8812 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;connected&quot;; depth:9; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10112</id>
        <msg>BACKDOOR rix3 1.0 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/r/rix3/Rix3_1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 4000 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|E3 0C|&quot;; depth:2; content:&quot;|00 00 00 00 A0 0F 00|&quot;; depth:7; offset:18;  metadata:impact_flag red, policy balanced-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10113</id>
        <msg>BOTNET-CNC Trojan Peacomm command and control propagation detected</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 7871 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server; content:&quot;|E3 0C|&quot;; depth:2; content:&quot;|00 00 00 00 A0 0F 00|&quot;; depth:7; offset:18;  metadata:impact_flag red, policy balanced-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10114</id>
        <msg>BOTNET-CNC Trojan Peacomm command and control propagation detected</msg>
      </rule>
      <rule>
        <bugtraq>22146</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2007-0021</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;aim|3A|GoChat?&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>10116</id>
        <msg>WEB-CLIENT AIM GoChat URL access attempt</msg>
        <url>projects.info-pull.com/moab/MOAB-20-01-2007.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SetIE/SetIE.txt&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10164</id>
        <msg>SPYWARE-PUT Adware adclicker-ej runtime detection</msg>
        <url>vil.nai.com/vil/content/v_139523.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A D0 C5 CF A2|&quot;; fast_pattern:only; content:&quot;Subject|3A|&quot;; nocase; pcre:&quot;/^From\x3a\xd0\xc5\xcf\xa2.*Subject\x3a[^\r\n]*\d+\x2d\d+\x2d\d+\x2d\d+\x3a\d+\x3a\d+/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10165</id>
        <msg>SPYWARE-PUT Keylogger mybr Keylogger runtime detection</msg>
        <url>www.hack77.com/Soft/hkgj/jpjl/200701/2844.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sszsex.html&quot;; nocase; http_uri; content:&quot;src=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;dm=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;client.baigoo.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*client\x2Ebaigoo\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10166</id>
        <msg>SPYWARE-PUT Trackware baigoo runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098801</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 201 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;OK              &quot;; depth:16; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10168</id>
        <msg>BACKDOOR one runtime detection</msg>
        <url>www.megasecurity.org/trojans/o/one/One0.12b.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET 1275 -&gt; $HOME_NET 1276</filter1>
        <filter2>content:&quot;RequestConnect&quot;; depth:14;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10169</id>
        <msg>BACKDOOR matrix 1.03 by mtronic runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/m/matrix/Matrix1.03.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;BysooTB&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*BysooTB/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10179</id>
        <msg>SPYWARE-PUT Trackware bysoo runtime detection</msg>
        <url>www.360safe.com/elist.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cm&quot;; http_uri; content:&quot;toolbar.eqiso.com&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10180</id>
        <msg>SPYWARE-PUT Adware eqiso runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Eqiso&amp;threatid=88999</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;SystemSleuth&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*SystemSleuth/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10181</id>
        <msg>SPYWARE-PUT Keylogger systemsleuth runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097306</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cliententry/&quot;; fast_pattern; nocase; http_uri; content:&quot;X-TITLE|3A|&quot;; nocase; http_header; content:&quot;X-KEYWORD|3A|&quot;; nocase; http_header; content:&quot;X-ADLIST|3A|&quot;; nocase; http_header; content:&quot;X-COMMAND|3A|&quot;; nocase; http_header; content:&quot;X-CLIENTID|3A|&quot;; nocase; http_header; content:&quot;X-TARGETURL|3A|&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10182</id>
        <msg>SPYWARE-PUT Adware newweb runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097957</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Activity&quot;; distance:0; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; content:&quot;Logs&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*Activity[^\r\n]*Keylogger[^\r\n]*Logs/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10183</id>
        <msg>SPYWARE-PUT Keylogger activity Keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097325</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;R|00|23&quot;; depth:4;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10184</id>
        <msg>BACKDOOR wow 23 runtime detection</msg>
        <url>www.megasecurity.org/trojans/0_9/23/23_0.3.html</url>
      </rule>
      <rule>
        <bugtraq>22487</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 54345</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 05 00 00 00 01|&quot;; byte_jump:4, -12, relative; byte_jump:4, 4, relative, align; byte_test:4, &gt;, 1132, 0, relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>10187</id>
        <msg>EXPLOIT HP Mercury Loadrunner command line buffer overflow</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; 85.17.3.250 80</filter1>
        <filter2>flow:established,to_server; content:&quot;cmp=dun_tek&quot;; nocase; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10403</id>
        <msg>BOTNET-CNC Trojan.Duntek Checkin GET Request</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2006-102514-0554-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hzyt/client/procpost.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.ccnnlc.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eccnnlc\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10435</id>
        <msg>SPYWARE-PUT Trackware admedia runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098012</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;mail&quot;; distance:0; nocase; content:&quot;function&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*mail\s+function/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>10436</id>
        <msg>SPYWARE-PUT Keylogger keyspy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3266</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates/checkversion.php&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.myarmory.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Emyarmory\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>10437</id>
        <msg>SPYWARE-PUT Hijacker bazookabar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073886</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates/checkversion.php&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.myarmory.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Emyarmory\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10438</id>
        <msg>SPYWARE-PUT Hijacker bazookabar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073886</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/starts.asp&quot;; nocase; http_uri; content:&quot;ids=&quot;; nocase; http_uri; content:&quot;webid=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ad.mokead.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ad\x2Emokead\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>10439</id>
        <msg>SPYWARE-PUT Adware mokead runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453101519</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;PC&quot;; distance:0; nocase; content:&quot;Black&quot;; distance:0; nocase; content:&quot;Box&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*PC[^\r\n]*Black[^\r\n]*Box/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>10440</id>
        <msg>SPYWARE-PUT Keylogger pc black box runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=PC%20Black%20Box&amp;threatid=117239</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 4973</filter1>
        <filter2>flow:to_server,established; content:&quot;|F9 14|&quot;; depth:2; content:&quot;|B3 B3 84 86 83 83 F5 B3 B3 B3|&quot;; within:10; distance:110;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>10441</id>
        <msg>SPYWARE-PUT Hacker-Tool statwin runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098082</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; dsize:&lt;20; content:&quot;|AC|kC|3A 5C|&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10442</id>
        <msg>BACKDOOR nirvana 2.0 runtime detection - explore c drive</msg>
        <url>www.megasecurity.org/trojans/n/nirvana/Nirvana2.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32418</filter1>
        <filter2>flow:to_server,established; content:&quot;SNIFF/&quot;; depth:6; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10443</id>
        <msg>BACKDOOR acidbattery 1.0 runtime detection - sniff info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=109</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32418</filter1>
        <filter2>flow:to_server,established; content:&quot;SERVER/NFO&quot;; depth:10; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10446</id>
        <msg>BACKDOOR acidbattery 1.0 runtime detection - get server info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=109</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwp/msg/1,,,00.html&quot;; nocase; http_uri; content:&quot;Uin=223220036&quot;; nocase; http_uri; content:&quot;Name=51D&quot;; nocase; http_uri; content:&quot;Send=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10447</id>
        <msg>BACKDOOR 51d 1b runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084229</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2612 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;connect_&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10448</id>
        <msg>BACKDOOR acessor 2.0 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/a/acessor/Acessor2.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|1B|[2J|1B|[40m|1B|[37mAcid&quot;; depth:18; nocase; content:&quot;Shiver&quot;; distance:0; nocase; content:&quot;System&quot;; distance:0; nocase; content:&quot;Release&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10449</id>
        <msg>BACKDOOR acid shivers runtime detection - init telnet connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=112</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;D41D8CD98F00B204E9800998ECF8427E&quot;; depth:34; flowbits:set,Only1RAT_Control; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10450</id>
        <msg>BACKDOOR only 1 rat runtime detection - control command</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Only1RAT_Control; content:&quot;|7C FF 00 FF 00 FF 00 FF 00 FF 00 FF 0D 0A|&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>10451</id>
        <msg>BACKDOOR only 1 rat runtime detection - control command</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Only%201%20RAT&amp;threatid=40632</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5600 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected&quot;; depth:9; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10454</id>
        <msg>BACKDOOR [x]-ztoo 1.0 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084134</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5600</filter1>
        <filter2>flow:to_server,established; content:&quot;GetInfo&quot;; depth:7; nocase; flowbits:set,XZTOO_Getinfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10455</id>
        <msg>BACKDOOR [x]-ztoo 1.0 runtime detection - get system info</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5600 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,XZTOO_Getinfo; content:&quot;Info|3B|&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10456</id>
        <msg>BACKDOOR [x]-ztoo 1.0 runtime detection - get system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084134</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5600 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;LogStarted&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10457</id>
        <msg>BACKDOOR [x]-ztoo 1.0 runtime detection - start keylogger</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084134</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5024</filter1>
        <filter2>flow:to_server,established; content:&quot;[LOAD DRIVE DATA]&quot;; depth:17; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10458</id>
        <msg>BACKDOOR [x]-ztoo 1.0 or illusion runtime detection - open file manager</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084134</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;WinEggDropShell&quot;; depth:15; offset:28; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10459</id>
        <msg>BACKDOOR wineggdrop shell pro runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077750</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3132</filter1>
        <filter2>flow:to_server,established; content:&quot;000&quot;; depth:3; flowbits:set,Winicabras_getinfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10460</id>
        <msg>BACKDOOR winicabras 1.1 runtime detection - get system info</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3132 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Winicabras_getinfo; content:&quot;|0D 0A|==INFORMACION&quot;; depth:15; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10461</id>
        <msg>BACKDOOR winicabras 1.1 runtime detection - get system info</msg>
        <url>www.megasecurity.org/trojans/w/winicabras/Winicabras1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12667</filter1>
        <filter2>flow:to_server,established; content:&quot;DRIVE&quot;; depth:5; nocase; flowbits:set,Winicabras_explorer; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10462</id>
        <msg>BACKDOOR winicabras 1.1 runtime detection - explorer</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 12667 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Winicabras_explorer; content:&quot;DRIVE&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>10463</id>
        <msg>BACKDOOR winicabras 1.1 runtime detection - explorer</msg>
        <url>www.megasecurity.org/trojans/w/winicabras/Winicabras1.1.html</url>
      </rule>
      <rule>
        <bugtraq>23371</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1204</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2869</filter1>
        <filter2>flow:to_server,established; content:&quot;SUBSCRIBE&quot;; fast_pattern:only; pcre:&quot;/^(UN)?SUBSCRIBE\s/smi&quot;; pcre:&quot;/^(NT|CallBack|SID|TimeOut)\s*\x3a\s*[^\n]{512}/Rsmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>10475</id>
        <msg>MISC UPNP notification type overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-019.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 03 00|&quot;; depth:3; offset:2; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>10996</id>
        <msg>WEB-MISC SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <bugtraq>22743</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2007-1005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9191</filter1>
        <filter2>flow:established,to_server; content:&quot;|01 06 00 00 00|&quot;; depth:5; offset:2; byte_test:4,&lt;,4,0,relative, little; metadata:policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>11185</id>
        <msg>DOS CA eTrust key handling dos -- username</msg>
      </rule>
      <rule>
        <bugtraq>13368</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0684</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; isdataat:500,relative; content:!&quot;|0A|&quot;; within:500; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>11196</id>
        <msg>EXPLOIT MaxDB WebDBM get buffer overflow</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $HOME_NET 8765 -&gt; 255.255.255.255 8765</filter1>
        <filter2>flow:to_server; content:&quot;ChildWebGuardian|3A|&quot;; depth:17; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>11306</id>
        <msg>SPYWARE-PUT Snoopware childwebguardian runtime detection - udp broadcast</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453099134</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Computer&quot;; distance:0; nocase; content:&quot;Monitor&quot;; distance:0; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*Computer[^\r\n]*Monitor[^\r\n]*Keylogger/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>11307</id>
        <msg>SPYWARE-PUT Keylogger computer monitor Keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097349</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db/db.php&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SpyDawn&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*SpyDawn/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>11308</id>
        <msg>SPYWARE-PUT Other-Technologies spydawn runtime detection - update checking</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453109604</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;SSKC&quot;; nocase; content:&quot;v2.0&quot;; distance:0; nocase; content:&quot;Startup&quot;; distance:0; nocase; content:&quot;at&quot;; distance:0; nocase; pcre:&quot;/^SSKC[^\r\n]*v2\x2E0[^\r\n]*Startup[^\r\n]*at/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>11309</id>
        <msg>SPYWARE-PUT Keylogger sskc v2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076545</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwp/msg/1,,,00.html&quot;; fast_pattern; nocase; http_uri; content:&quot;Uin=&quot;; nocase; http_uri; content:&quot;Name=&quot;; nocase; http_uri; content:&quot;iowA&quot;; nocase; http_uri; content:&quot;WebDloader&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>11310</id>
        <msg>SPYWARE-PUT Trickler iowa webdownloader - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59689</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upload.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.pcsentinelsoftware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Epcsentinelsoftware\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>11311</id>
        <msg>SPYWARE-PUT Keylogger pcsentinelsoftware Keylogger runtime detection - upload infor</msg>
        <url>www.pcsentinelsoftware.com</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Response2.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; content:&quot;myadid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;uplink.co.kr&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*uplink\x2Eco\x2Ekr/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>11312</id>
        <msg>SPYWARE-PUT Trackware uplink runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-031317-1701-99&amp;tabid=1</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db/db.php&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Spy-Locked&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Spy\-Locked/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>11313</id>
        <msg>SPYWARE-PUT Other-Technologies spywarelocker 3.3 runtime detection - update checking</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=SpyLocked&amp;threatid=129037</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ShadowNet&quot;; nocase; content:&quot;Remote&quot;; distance:0; nocase; content:&quot;Web&quot;; distance:0; nocase; content:&quot;Based&quot;; distance:0; nocase; content:&quot;Spyware&quot;; distance:0; nocase; pcre:&quot;/ShadowNet\s+Remote\s+Web\s+Based\s+Spyware/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11314</id>
        <msg>BACKDOOR shadownet remote spy 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453081042</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1115 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|0D|Lurker&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11316</id>
        <msg>BACKDOOR lurker 1.1 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077370</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;&amp;&amp;**&quot;; depth:4;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>11317</id>
        <msg>BACKDOOR abremote pro 3.1 runtime detection - init connection</msg>
        <url>www.heibai.net/download/Soft/Soft_6836.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 19820 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;EMSG0006&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11318</id>
        <msg>BACKDOOR boer runtime detection - init connection</msg>
        <url>soft.myboer.cn</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5050 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|1B 00 00 00|&quot;; depth:4; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11319</id>
        <msg>BACKDOOR netwindow runtime detection - init connection request</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=NetWindow&amp;threatid=43584</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 5051</filter1>
        <filter2>flow:to_server,established; content:&quot;NWHOST&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11320</id>
        <msg>BACKDOOR netwindow runtime detection - reverse mode init connection request</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=NetWindow&amp;threatid=43584</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; 255.255.255.255 5053</filter1>
        <filter2>flow:to_server; content:&quot;NWHOST&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11321</id>
        <msg>BACKDOOR netwindow runtime detection - udp broadcast</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=NetWindow&amp;threatid=43584</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5712 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;RFB 003.003|0A|&quot;; depth:12; nocase; flowbits:set,Sohoanywhere_Init; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11322</id>
        <msg>BACKDOOR sohoanywhere runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5712</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Sohoanywhere_Init; content:&quot;RFB 003.004|0A|&quot;; depth:12; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>11323</id>
        <msg>BACKDOOR sohoanywhere runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060132</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HTTP_SERVERS 443 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv3.client_hello.request; flowbits:isnotset,sslv3.server_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>11671</id>
        <msg>WEB-MISC SSLv2 Server_Hello request from SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2003-0109</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SEARCH &quot;; depth:7; nocase; isdataat:1000,relative; content:!&quot;|0A|&quot;; within:1000; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>11686</id>
        <msg>SPECIFIC-THREATS WebDAV search overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms03-007.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 610</filter1>
        <filter2>flow:to_server,established; content:&quot;L&quot;; depth:1; nocase; content:&quot;|00|&quot;; depth:1; offset:3; pcre:&quot;/^L\d\d\x00/smi&quot;; flowbits:set,SupervisorPlus_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>11953</id>
        <msg>BACKDOOR supervisor plus runtime detection</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HTTP_SERVERS 443 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,tlsv1.client_hello.request; flowbits:isnotset,sslv2.server_hello.request; flowbits:isnotset,sslv3.server_hello.request; flowbits:isnotset,tlsv1.server_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>11965</id>
        <msg>WEB-MISC SSLv2 Server_Hello request from TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 58008</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;SYSTMTIME&gt;&quot;; depth:11; nocase; flowbits:set,Tron_Initconnection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12054</id>
        <msg>BACKDOOR tron runtime detection - init connection - flowbit set</msg>
      </rule>
      <rule>
        <bugtraq>22340</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0449</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2200</filter1>
        <filter2>flow:to_server,established; content:&quot;N=,|1B|&quot;; depth:4; isdataat:1000; content:!&quot;N=,|1B|&quot;; within:996; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>12078</id>
        <msg>EXPLOIT CA BrightStor LGServer Heap buffer overflow</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 456</filter1>
        <filter2>flow:to_server,established; content:&quot;info&quot;; depth:4; flowbits:set,RemoteKeyLog.b.Info_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12129</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - get sys info</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;WND&quot;; depth:3; flowbits:set,RemoteKeyLog.b.Keylogging_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12131</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - keylogging</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 456</filter1>
        <filter2>flow:to_server,established; content:&quot;url&quot;; depth:3; flowbits:set,RemoteKeyLog.b.Url_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12133</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - open url</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 456</filter1>
        <filter2>flow:to_server,established; content:&quot;fun&quot;; depth:3; flowbits:set,RemoteKeyLog.b.Fun_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12135</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - fun</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|99 F3 00 00 00 00 00 00 FF FF FF FF|&quot;; depth:12; flowbits:set,AccessRemotePC_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12142</id>
        <msg>BACKDOOR access remote pc runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;AUTH&quot;; depth:4; flowbits:set,BlueEye1.0b_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12146</id>
        <msg>BACKDOOR blue eye 1.0b runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 54320</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00|&quot;; depth:3; content:&quot;|CD C3 13|7&quot;; within:4; distance:1; flowbits:set,BackOrifice2006_1.1.5_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12148</id>
        <msg>BACKDOOR back orifice 2006 - v1.1.5 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|FF FD 03 FF FD 18 FF FD 1F|&quot;; depth:9; flowbits:set,CAFEiNi_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12150</id>
        <msg>BACKDOOR cafeini 1.0 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 500 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot; |0D 0A|&quot;; depth:3; flowbits:set,OptixPROv1.32Download_detection1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12153</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - download file</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 500 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Download_detection1; content:&quot;+OK REDY|0D 0A|&quot;; depth:10; flowbits:set,OptixPROv1.32Download_detection2; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12154</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - download file</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 501</filter1>
        <filter2>flow:to_server,established; content:&quot;InfoOn|AC|&quot;; depth:7; flowbits:set,OptixPROv1.32Upload_detection1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12156</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - upload file</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 501 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Upload_detection1; content:&quot; |0D 0A|&quot;; depth:3; flowbits:set,OptixPROv1.32Upload_detection2; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12157</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - upload file</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 503</filter1>
        <filter2>flow:to_server,established; content:&quot;SendACap|AC|&quot;; depth:9; flowbits:set,OptixPROv1.32Screencapture_detection1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12160</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - screen capturing</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 503 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Screencapture_detection1; content:&quot; |0D 0A|&quot;; depth:3; flowbits:set,OptixPROv1.32Screencapture_detection2; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12161</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - screen capturing</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1357</filter1>
        <filter2>flow:to_server,established; content:&quot;DIR&quot;; depth:3; offset:3; pcre:&quot;/^(SYS|WIN)DIR$/sm&quot;; flowbits:set,CobraUploader1.0_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12163</id>
        <msg>BACKDOOR cobra uploader 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [37,31415,31416]</filter1>
        <filter2>flow:to_server,established; content:&quot;|24 00 00 00 00 00 03 00 0D 00 00 00|&quot;; depth:12; flowbits:set,Lithium1.02_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12165</id>
        <msg>BACKDOOR lithium 1.02 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET [37,31415,31416] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,Lithium1.02_detection; content:&quot;|00 00 00 00 00 04 00|&quot;; offset:1; metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>12166</id>
        <msg>BACKDOOR lithium 1.02 runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-061113-2401-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|1B|[2J|0D 0A| &quot;; depth:7; content:&quot;Hello&quot;; nocase; content:&quot;my&quot;; distance:0; nocase; content:&quot;master&quot;; distance:0; nocase; content:&quot;waiting&quot;; distance:0; nocase; content:&quot;for&quot;; distance:0; nocase; content:&quot;your&quot;; distance:0; nocase; content:&quot;commands&quot;; distance:0; nocase; flowbits:set,Genie1.7_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12240</id>
        <msg>BACKDOOR genie 1.7 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Start&quot;; depth:5; nocase; pcre:&quot;/^Start$/smi&quot;; flowbits:set,HotmailHackerLogEdition5.0_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12242</id>
        <msg>BACKDOOR hotmail hacker log edition 5.0 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|09 08 10 00 00 06 00 01|&quot;; flowbits:set,xlw.download; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>12283</id>
        <msg>WEB-CLIENT xlw file download</msg>
        <url>sc.openoffice.org/excelfileformat.pdf</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ms162cfg.jsp?&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2fms162cfg\x2ejsp\x3f([sverlcfan]\x3d[^\x26\s]*\x26){8}/iU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>12293</id>
        <msg>SPYWARE-PUT Hijacker morpheus toolbar runtime detection - get cfg info</msg>
        <url>www.sophos.com/security/analyses/morpheustoolbar.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|05 00 00 00 BC|&quot;; depth:5; content:&quot;|CC|&quot;; within:1; distance:3; flowbits:set,Bifrost_v1.2.1_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12297</id>
        <msg>BACKDOOR bifrost v1.2.1 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 00 00 00 01 00 00 00 08 08|&quot;; depth:10; flowbits:set,Radmin3.0_conn_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12373</id>
        <msg>BACKDOOR radmin 3.0 runtime detection - initial connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 00 00 00 05 00 00 02|''|02 00 00 00|&quot;; depth:14; flowbits:set,Radmin3.0_login_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12375</id>
        <msg>BACKDOOR radmin 3.0 runtime detection - login &amp; remote control</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;F|15 1D|&quot;; depth:3; flowbits:set,sharK_2.3.2_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12377</id>
        <msg>BACKDOOR shark 2.3.2 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Email Reports from Inside Website Logger&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:successful-recon-limited;</filter2>
        <id>12480</id>
        <msg>SPYWARE-PUT Keylogger inside website logger 2.4 runtime detection</msg>
        <url>www.programurl.com/inside-website-logger.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/&quot;; nocase; http_uri; content:&quot;.php?&quot;; nocase; http_uri; content:&quot;acc=&quot;; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;city=&quot;; nocase; http_uri; content:&quot;state=&quot;; nocase; http_uri; content:&quot;uninstalled=&quot;; nocase; http_uri; content:&quot;User-Agent&quot;; nocase; http_header; content:&quot;iebar&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\s*\x3A[^\r\n]*iebar/miH&quot;; metadata:policy security-ips alert, service http; classtype:successful-recon-limited;</filter2>
        <id>12672</id>
        <msg>SPYWARE-PUT Trackware searchmiracle elitebar runtime detection - get ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|B9 E1 A5|~|C7 B7 82|n|22|n|0B CB FD|w|ED|I&quot;; depth:16; flowbits:set,PoisonIvy2.3.0_initDetection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12699</id>
        <msg>BACKDOOR poison ivy 2.3.0 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;1DbsLbE3i/MBQu9Z&quot;; depth:16; flowbits:set,DarkMoon411_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12724</id>
        <msg>BACKDOOR dark moon 4.11 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|CF 8F 80 9B 9A 9D CF C9 CA C9 D9 8D C9|&quot;; depth:13; flowbits:set,Bandook135_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>12726</id>
        <msg>BACKDOOR bandook 1.35 runtime detection</msg>
      </rule>
      <rule>
        <bugtraq>24658</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3410</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;smi&quot;; nocase; content:&quot;wallclock|28|&quot;; pcre:&quot;/^[^\x29]*\x2E[0-9]{11}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service sunrpc; classtype:attempted-user;</filter2>
        <id>12728</id>
        <msg>WEB-CLIENT RealNetworks SMIL wallclock stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26042</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4619</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;fLaC&quot;; content:&quot;|06|&quot;; byte_jump:4,7,relative; content:&quot;|FF FF FF FF|&quot;; within:4; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12743</id>
        <msg>WEB-CLIENT FLAC libFLAC picture description metadata buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26042</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4619</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;fLaC&quot;; content:&quot;|04|&quot;; content:&quot;|FF FF FF FF|&quot;; within:4; distance:3; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12744</id>
        <msg>WEB-CLIENT FLAC libFLAC VORBIS string buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26042</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4619</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;fLaC&quot;; content:&quot;|06|&quot;; content:&quot;|FF FF FF FF|&quot;; within:4; distance:7; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>12745</id>
        <msg>WEB-CLIENT FLAC libFLAC picture metadata buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;Digi-Watcher.com&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*Digi\x2DWatcher\x2Ecom/smi&quot;; flowbits:set,DigiWatcher232_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12758</id>
        <msg>SPYWARE-PUT Keylogger/RAT digi watcher 2.32 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Powered&quot;; distance:0; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; content:&quot;Logs&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3A[^\r\n]*Powered\s+Keylogger\s+Logs/smi&quot;; flowbits:set,PoweredKeylogger22_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12760</id>
        <msg>SPYWARE-PUT Keylogger powered Keylogger 2.2 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Attachment&quot;; nocase; content:&quot;contains&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;Lantern&quot;; distance:0; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; content:&quot;log&quot;; distance:0; nocase; content:&quot;file&quot;; distance:0; nocase; pcre:&quot;/Attachment\s+contains\s+Spy\s+Lantern\s+Keylogger.*log\s+file\x2E/smi&quot;; flowbits:set,SpyLanternKeylogger6_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>12792</id>
        <msg>SPYWARE-PUT Keylogger spy lantern Keylogger pro 6.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0064</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;BFC3CD50-618F-11CF-8BB2-00AA00B4E220&quot;; byte_test:4, &gt;, 65522, 12, relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13160</id>
        <msg>WEB-CLIENT Microsft Media Player asf streaming audio spread error correction data length integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-068.mspx</url>
      </rule>
      <rule>
        <bugtraq>25454</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4221</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 407</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; content:&quot;|00 23 07|&quot;; depth:3; offset:6; byte_test:1,&gt;,31,30; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13221</id>
        <msg>EXPLOIT Motorola Timbuktu crafted login request buffer overflow attempt</msg>
        <url>ftp-xo.netopia.com/evaluation/docs/timbuktu/win/865/relnotes/TB2Win865Evalrn.pdf</url>
      </rule>
      <rule>
        <bugtraq>25454</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4221</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 407</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; content:&quot;|00 23 07|&quot;; depth:3; offset:6; byte_test:1,&gt;,31,30; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13222</id>
        <msg>EXPLOIT Motorola Timbuktu crafted login request buffer overflow attempt</msg>
        <url>ftp-xo.netopia.com/evaluation/docs/timbuktu/win/865/relnotes/TB2Win865Evalrn.pdf</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Attached&quot;; nocase; content:&quot;|28|ZIP&quot;; distance:0; nocase; content:&quot;file|29|&quot;; distance:0; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;this&quot;; distance:0; nocase; content:&quot;email&quot;; distance:0; nocase; content:&quot;are&quot;; distance:0; nocase; content:&quot;the&quot;; distance:0; nocase; content:&quot;activity&quot;; distance:0; nocase; content:&quot;logs&quot;; distance:0; nocase; content:&quot;that&quot;; distance:0; nocase; content:&quot;you&quot;; distance:0; nocase; content:&quot;have&quot;; distance:0; nocase; content:&quot;requested.&quot;; distance:0; nocase; pcre:&quot;/Attached\s+\x28ZIP\s+file\x29\s+to\s+this\s+email\s+are\s+the\s+activity\s+logs\s+that\s+you\s+have\s+requested\x2E/smi&quot;; flowbits:set,ActiveKeylogger392_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13236</id>
        <msg>SPYWARE-PUT Keylogger active Keylogger 3.9.2 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Computer&quot;; distance:0; nocase; content:&quot;Monitor&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*Computer\s+Monitor/smi&quot;; flowbits:set,ComputerMonitor11_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13243</id>
        <msg>SPYWARE-PUT Keylogger computer monitor 1.1 by lastcomfort runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;/index&quot;; nocase; flowbits:set,Troya_1_4_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13245</id>
        <msg>BACKDOOR troya 1.4 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Req_Conn&quot;; depth:8; nocase; flowbits:set,Yuri_1_2_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13247</id>
        <msg>BACKDOOR yuri 1.2 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Advanced&quot;; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;Report&quot;; distance:0; nocase; content:&quot;for&quot;; distance:0; nocase; pcre:&quot;/Advanced\s+Spy\s+Report\s+for/smi&quot;; flowbits:set,AdvancedSpy_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13278</id>
        <msg>SPYWARE-PUT Keylogger advanced spy 4.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Chilkat&quot;; distance:0; nocase; content:&quot;Software&quot;; distance:0; nocase; content:&quot;Inc&quot;; distance:0; nocase; pcre:&quot;/^X\x2DMailer\x3A[^\r\n]*Chilkat\s+Software\s+Inc/smi&quot;; flowbits:set,EmailSpyMonitor_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13280</id>
        <msg>SPYWARE-PUT Keylogger email spy monitor 6.9 runtime detection</msg>
      </rule>
      <rule>
        <bugtraq>26791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6015</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|5C|MAILSLOT|5C|NET|5C|NTLOGON&quot;; fast_pattern; pcre:&quot;/^\x00+/R&quot;; content:&quot;|12 00 00 00|&quot;; within:4; pcre:&quot;/^\x00\x00\x00\x00[^\x00]{262}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>13291</id>
        <msg>EXPLOIT Samba send_mailslot buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26773</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6401</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; content:&quot;|A9|ART&quot;; byte_test:4, &gt;, 512, 0, relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13316</id>
        <msg>WEB-CLIENT 3ivx MP4 file parsing ART buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26773</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6401</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; content:&quot;|A9|nam&quot;; byte_test:4, &gt;, 512, 0, relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13317</id>
        <msg>WEB-CLIENT 3ivx MP4 file parsing nam buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26773</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6401</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; content:&quot;|A9|cmt&quot;; byte_test:4, &gt;, 512, 0, relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13318</id>
        <msg>WEB-CLIENT 3ivx MP4 file parsing cmt buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26773</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6401</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; content:&quot;|A9|des&quot;; byte_test:4, &gt;, 512, 0, relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13319</id>
        <msg>WEB-CLIENT 3ivx MP4 file parsing des buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26773</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6401</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; content:&quot;|A9|cpy&quot;; byte_test:4, &gt;, 512, 0, relative; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13320</id>
        <msg>WEB-CLIENT 3ivx MP4 file parsing cpy buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;DS|00 00 00 00 01 00 00 00 00 FE 01 00 00 F1 00 00 00 00|&quot;; depth:20; nocase; flowbits:set,RemoteDesktopInspector_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13346</id>
        <msg>SPYWARE-PUT Snoopware remote desktop inspector runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-4731</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5005</filter1>
        <filter2>flow:to_server,established; content:&quot;!Ce|87 15 00 00 00|&quot;; byte_test:4,&gt;,844,8,relative,little; isdataat:1092,relative; content:!&quot;|00|&quot;; within:256; distance:836; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13365</id>
        <msg>EXPLOIT Trend Micro ServerProtect TMregChange buffer overflow attempt</msg>
        <url>www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt</url>
      </rule>
      <rule>
        <bugtraq>20364</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5142</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>flow:to_server; content:&quot;mailslot|5C|cheyenneds&quot;; nocase; isdataat:24,relative; content:!&quot;|00|&quot;; within:20; distance:4; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13415</id>
        <msg>EXPLOIT CA BrightStor cheyenneds mailslot overflow</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;|22|FindNot&quot;; distance:0; nocase; content:&quot;GuardDog|22|&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*\x22FindNot\s+GuardDog\x22/smi&quot;; flowbits:set,FindNotGuardDog_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13479</id>
        <msg>SPYWARE-PUT Keylogger findnot guarddog 4.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/barcab/&quot;; fast_pattern; nocase; http_uri; content:&quot;tn=&quot;; nocase; http_uri; content:&quot;baiducb&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; pcre:&quot;/update/barcab/.*?tn=.*id=.*version=/smi&quot;; flowbits:set,BaiduToolbar_detection; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>13483</id>
        <msg>SPYWARE-PUT Hijacker baidu toolbar runtime detection - updates automatically</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:set,Evilotus_detection; content:&quot;|0C|~|7F D8 13 00 00 00|d|C8 00 00 0B 00 00 00 07 00 00 00 80 E7 03 0C|~|7F D8|&quot;; depth:27; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13506</id>
        <msg>BACKDOOR evilotus 1.3.2 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; offset:1; content:&quot;Minutes&quot;; nocase; content:&quot;|00 A1 0F 00 00 00|&quot;; distance:0; flowbits:set,Xploit1_4_5_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13508</id>
        <msg>BACKDOOR xploit 1.4.5 runtime detection</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0033</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;idsc&quot;; byte_test:4,&lt;,94,-8,relative,big; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>13517</id>
        <msg>EXPLOIT Apple QTIF malformed idsc atom</msg>
      </rule>
      <rule>
        <bugtraq>27329</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0356</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2512:2513</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF|&quot;; depth:3; byte_test:1, &gt;, 195, 0; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13519</id>
        <msg>EXPLOIT Citrix MetaFrame IMA buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27467</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0467</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 13|&quot;; depth:4; content:&quot;|1C|&quot;; within:80; byte_test:1,&gt;,0x81,0,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13522</id>
        <msg>EXPLOIT Firebird Database Server username handling buffer overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0112</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; nocase; http_method; content:&quot;.csv&quot;; nocase; http_uri; flowbits:set,csv.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>13584</id>
        <msg>WEB-CLIENT csv file download request</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-014.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;OPTIONS&quot;; depth:7; nocase; content:!&quot;Via|3A|&quot;; nocase; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>13587</id>
        <msg>VOIP-SIP OPTIONS request missing RFC-mandated Via field</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;OPTIONS&quot;; depth:7; nocase; content:!&quot;Call-ID|3A|&quot;; nocase; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>13588</id>
        <msg>VOIP-SIP OPTIONS request missing RFC-mandated Call-ID field</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;OPTIONS&quot;; depth:7; nocase; content:&quot;Via|3A|&quot;; nocase; pcre:&quot;/^OPTIONS.+\r\n\r\n(.+)?^Via\x3A/smi&quot;; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>13589</id>
        <msg>VOIP-SIP OPTIONS request misplaced Via field - after terminating newline</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;OPTIONS&quot;; depth:7; nocase; content:&quot;Call-ID|3A|&quot;; nocase; pcre:&quot;/^OPTIONS.+\r\n\r\n(.+)?^Call-ID\x3A/smi&quot;; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>13590</id>
        <msg>VOIP-SIP OPTIONS request misplaced Call-ID field - after terminating newline</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>6849</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0095</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;1|C0 0B|E|10 05|P|00 00 00 05|L|00 00 00 FF 00|@@@@|FF 00|XXP1|C0 C3|&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13617</id>
        <msg>SPECIFIC-THREATS Oracle database version 8 username buffer overflow attempt</msg>
        <url>otn.oracle.com/deploy/security/pdf/2003alert51.pdf</url>
      </rule>
      <rule>
        <bugtraq>28228</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1357</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 8082</filter1>
        <filter2>content:&quot;Type=|22|AgentWakeup|22|&quot;; fast_pattern:only; content:&quot;|22 FA E5|&quot;; content:&quot;|8F|&quot;; within:212; distance:20; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13631</id>
        <msg>MISC McAfee ePolicy Orchestrator Framework Services log handling format string attempt</msg>
        <url>knowledge.mcafee.com/article/234/615103_f.sal_public.html</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Zango/Setup.exe&quot;; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:policy-violation;</filter2>
        <id>13632</id>
        <msg>WEB-CLIENT Zango adware installation request</msg>
        <url>www.ftc.gov/os/caselist/0523130/index.shtm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:set,Nuclear_RAT_2_1_detection; content:&quot;|FF 00|&quot;; depth:2; content:&quot;|00 00 00 01 00 00 00 00 00 00|&quot;; within:10; distance:1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13654</id>
        <msg>BACKDOOR nuclear rat 2.1 runtime detection - init connection</msg>
      </rule>
      <rule>
        <bugtraq>23047</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1542</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Remote-Party-ID|3A|&quot;; fast_pattern:only; pcre:&quot;/^Remote-Party-ID\x3A\s+[^\r\n]+\x40[^\r\n]*?[\x80-\xFF]/smi&quot;; metadata:policy security-ips alert; classtype:attempted-admin;</filter2>
        <id>13664</id>
        <msg>VOIP-SIP hexadecimal characters in IP address portion of Remote-Party-ID field</msg>
        <url>www.cisco.com/en/US/products/products_security_response09186a00808075ad.html</url>
      </rule>
      <rule>
        <bugtraq>28308</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1289</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:to_server; content:&quot;a=rtpmap|3A|&quot;; nocase; byte_test:9,&gt;,256,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>13693</id>
        <msg>VOIP-SIP invalid RTP payload type - possible Asterisk memory overwrite</msg>
        <url>www.asterisk.org/node/48466</url>
      </rule>
      <rule>
        <bugtraq>28569</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1697</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7510</filter1>
        <filter2>flow:to_server,established; content:&quot;GET &quot;; depth:4; nocase; isdataat:165,relative; content:&quot;/topology/homeBaseView&quot;; pcre:&quot;/GET\s+\w[^\x0a\x20]{165}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13715</id>
        <msg>WEB-MISC HP OpenView Network Node Manager HTTP handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|01 00 01 00 03 00 01 00 14 00 01 01 01 00 DD DD DD DD 00 00 00 00|&quot;; depth:22; metadata:policy balanced-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>13764</id>
        <msg>SPYWARE-PUT Snoopware xpress remote runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=XpressRemote&amp;threatid=29388</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;CYBERsitter&quot;; distance:0; nocase; content:&quot;Report&quot;; distance:0; nocase; content:&quot;for|3A|&quot;; distance:0; nocase; pcre:&quot;/Subject\x3A[^\r\n]*CYBERsitter\s+Report\s+for\x3A/smi&quot;; flowbits:set,cyberSitter_detection; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>13767</id>
        <msg>SPYWARE-PUT Keylogger cyber sitter runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MZ&quot;; byte_jump:4,58,little,relative; content:&quot;PE|00 00|&quot;; within:4; distance:-64; content:&quot;APECO&quot;; distance:0; flowbits:set,download.pecompact.binary; flowbits:noalert;  classtype:misc-activity;</filter2>
        <id>13797</id>
        <msg>WEB-CLIENT pe compact binary download</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-1965</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;cai|3A|&quot;; nocase; content:&quot;-launcher&quot;; distance:0; nocase; pcre:&quot;/\x3c[^\x3e]+((\x22cai\x3a[^\x3e]*?\x2522[^\x3e\x22]*-launcher[^\x3e\x22]*\x22)|(\x27cai\x3a[^\x3e]*?(\x2522|\x22)[^\x3e\x27]*-launcher[^\x3e\x27]*\x27)|(cai\x3a[^\x3e]*?(\x2522|\x22)[^\x3e]*-launcher[^\x3e]*?\s+))\s*\x3e/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>13799</id>
        <msg>WEB-CLIENT IBM Lotus Expeditor cai URI Handler Command Execution attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Content-Type|3A|&quot;; nocase; http_header; content:&quot;text/rtf&quot;; fast_pattern; nocase; http_header; flowbits:set,http.rtf; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:protocol-command-decode;</filter2>
        <id>13801</id>
        <msg>WEB-CLIENT RTF file download</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0011</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13824, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13824</id>
        <msg>WEB-CLIENT malformed mjpeg arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>28616</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2008-1329</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; content:&quot;rxrReceiveFileFromServer~~8~~&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:web-application-activity;</filter2>
        <id>13839</id>
        <msg>MISC CA ARCServ NetBackup remote file upload attempt</msg>
        <url>support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173105</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-4305</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; content:&quot;database=&quot;; nocase; isdataat:18,relative; content:!&quot;|0A|&quot;; within:18; content:!&quot;&amp;&quot;; within:18; content:!&quot;|3B|&quot;; within:18; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13843</id>
        <msg>EXPLOIT MaxDB WebDBM get buffer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2002-0055</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;0123AUTH LOGIN&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>13844</id>
        <msg>SPECIFIC-THREATS BDAT size longer than contents exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2002-0055</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;b00mAUTH LOGIN&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>13845</id>
        <msg>SPECIFIC-THREATS BDAT size public exploit attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/popwin/&quot;; nocase; http_uri; content:&quot;/update.txt&quot;; nocase; http_uri; flowbits:set,Trojan-Spy.Win32.Delf.uv_Detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13877</id>
        <msg>BACKDOOR trojan-spy.win32.delf.uv runtime detection</msg>
      </rule>
      <rule>
        <bugtraq>29328</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2499</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1533,8082]</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; content:&quot;CommunityCBR/CC.&quot;; pcre:&quot;/\d\d\.[^\s\n\r]{40}/Rsmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13902</id>
        <msg>EXPLOIT IBM Lotus Sametime multiplexer stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.bak&quot;; nocase; http_uri; flowbits:set,backup_file.request; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>13915</id>
        <msg>WEB-MISC backup file download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-4193</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4000</filter1>
        <filter2>flow:established,to_server; content:&quot;username=&quot;; nocase; isdataat:450,relative; content:!&quot;&amp;&quot;; within:450; content:!&quot;|0A|&quot;; within:450; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>13916</id>
        <msg>EXPLOIT Alt-N SecurityGateway username buffer overflow attempt</msg>
        <url>secunia.com/advisories/30497/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ver.txt&quot;; fast_pattern; nocase; http_uri; flowbits:set,AdWare_Ejik.ec_Detection; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>13938</id>
        <msg>SPYWARE-PUT Hijacker adware.win32.ejik.ec variant runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cc.txt&quot;; fast_pattern; nocase; http_uri; flowbits:set,Dropper_Agent.rqg_Detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>13943</id>
        <msg>SPYWARE-PUT Trickler dropper agent.rqg runtime detection</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3021</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13946, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13946</id>
        <msg>WEB-CLIENT Apple PICT/Quickdraw image converter packType 4 buffer overflow exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-044.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3018</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13947, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13947</id>
        <msg>WEB-CLIENT Apple PICT/Quickdraw image converter packType 3 buffer overflow exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-044.mspx</url>
      </rule>
      <rule>
        <bugtraq>30177</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2008-2607</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1521,5560]</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_AQELM&quot;; pcre:&quot;/SET_(SENDFROM|MAILHOST)\x28\x27[^\x27]{256}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>13951</id>
        <msg>WEB-MISC Oracle Database Server buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/dir1/archive.asp?id=z ANd&quot;; nocase; http_uri; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>13953</id>
        <msg>BOTNET-CNC Asprox trojan initial query</msg>
        <url>www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0121</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.ppt; metadata: engine shared, soid 3|13969, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>13969</id>
        <msg>WEB-CLIENT Powerpoint Viewer malformed msoDrawing property table buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-051.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.m3u&quot;; nocase; http_uri; flowbits:set, http.m3u.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>14017</id>
        <msg>WEB-CLIENT MPEG Layer 3 playlist file request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pls&quot;; nocase; http_uri; flowbits:set, http.pls.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>14018</id>
        <msg>WEB-CLIENT PLS multimedia playlist file request</msg>
      </rule>
      <rule>
        <bugtraq>30467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2935</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Type|3A| text/xml&quot;; nocase; http_header; content:&quot;xsl|3A|stylesheet&quot;; fast_pattern; nocase; content:&quot;crypto|3A|rc4_&quot;; nocase; pcre:&quot;/crypto\x3Arc4_(encrypt|decrypt)\x28\x27[^\x27]{129}/smiH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14039</id>
        <msg>EXPLOIT GNOME Project libxslt RC4 key string buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2935</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Type|3A| text/xml&quot;; nocase; http_header; content:&quot;xsl|3A|transform&quot;; fast_pattern:only; content:&quot;crypto|3A|rc4_&quot;; nocase; pcre:&quot;/crypto\x3Arc4_(encrypt|decrypt)\x28\x27[^\x27]{129}/smiH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14040</id>
        <msg>EXPLOIT GNOME Project libxslt RC4 key string buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30467</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2935</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Type|3A| text/xml&quot;; nocase; http_header; content:&quot;xsl|3A|version&quot;; fast_pattern:only; content:&quot;crypto|3A|rc4_&quot;; pcre:&quot;/crypto\x3Arc4_(encrypt|decrypt)\x28\x27[^\x27]{129}/smiH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14041</id>
        <msg>EXPLOIT GNOME Project libxslt RC4 key string buffer overflow attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>24773</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3614</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /webdbm&quot;; nocase; content:&quot;HTTP_COOKIE&quot;; nocase; isdataat:250,relative; pcre:&quot;/HTTP_COOKIE=[^\x0a\x0d\x26\x3f\x20]{250}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>14230</id>
        <msg>EXPLOIT SAP DB web server stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-5348</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|14261, service http, policy security-ips drop;</filter2>
        <id>14261</id>
        <msg>WEB-CLIENT GDI VML gradient size heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>29634</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2639</cve>
        <filter1>tcp $EXTERNAL_NET ANY -&gt; $HOME_NET 20222</filter1>
        <filter2>flow:established,to_server; content:&quot;|02 00 00 00 00|&quot;; depth:9; byte_test:4,&gt;,256,0,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>14265</id>
        <msg>SCADA CitectSCADA ODBC buffer overflow attempt</msg>
        <url>www.citect.com/index.php?option=com_content&amp;task=view&amp;id=1374&amp;Itemid=223</url>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $HOME_NET 8002 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Oracle Applications One-Hour Install&quot;; metadata:policy security-ips drop; classtype:bad-unknown;</filter2>
        <id>1464</id>
        <msg>ATTACK-RESPONSES oracle one hour install</msg>
        <nessus>10737</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-4023</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|14646, service ldap, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>14646</id>
        <msg>DOS Active Directory malformed baseObject denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-060.mspx</url>
      </rule>
      <rule>
        <bugtraq>31418</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4322</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 910</filter1>
        <filter2>flow:to_server,established; content:&quot;|10 23|Tg&quot;; depth:4; isdataat:726,relative; content:!&quot;|10 23|Tg&quot;; within:712; distance:14; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>14769</id>
        <msg>EXPLOIT DATAC RealWin SCADA System FC_INFOTAG/SET_CONTROL buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|D9 EE D9|t|24 F4|X&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>14986</id>
        <msg>SHELLCODE x86 fldz get eip shellcode</msg>
      </rule>
      <rule>
        <bugtraq>30694</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-2234</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8889</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A|&quot;; nocase; content:&quot;Basic&quot;; nocase; isdataat:256,relative; pcre:&quot;/^Authorization\x3a\s*Basic[^\n]{256}/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>14992</id>
        <msg>WEB-MISC Openwsman HTTP basic authentication buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.wav&quot;; nocase; flowbits:set,wav_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15079</id>
        <msg>WEB-MISC WAV Formatfile download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15082, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15082</id>
        <msg>EXPLOIT rtf malformed dpcallout buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4269</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15116, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15116</id>
        <msg>WEB-CLIENT Windows search protocol handler access attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-075.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.rtf&quot;; nocase; http_uri; flowbits:set,http.rtf; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15123</id>
        <msg>WEB-CLIENT Rich Text Format file request</msg>
      </rule>
      <rule>
        <bugtraq>32518</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5286</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; depth:8; content:&quot;IHDR&quot;; content:&quot;|02|&quot;; within:1; distance:9; byte_test:4,&gt;,1431655765,-6,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15145</id>
        <msg>EXPLOIT Apple CUPS TrueColor PNG filter overly large image height integer overflow attempt</msg>
        <url>www.cups.org/str.php?L2974</url>
      </rule>
      <rule>
        <bugtraq>32518</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5286</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; depth:8; content:&quot;IHDR&quot;; content:&quot;|06|&quot;; within:1; distance:9; byte_test:4,&gt;,1431655765,-6,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15146</id>
        <msg>EXPLOIT Apple CUPS RGB+Alpha PNG filter overly large image height integer overflow attempt</msg>
        <url>www.cups.org/str.php?L2974</url>
      </rule>
      <rule>
        <bugtraq>30177</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-2595</cve>
        <filter1>tcp $EXTERNAL_NET any &lt;&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|15149, service ldap, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15149</id>
        <msg>DOS Oracle Internet Directory pre-auth ldap denial of service attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4558</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,xspf_file.request; file_data; content:&quot;|3C|identifier|3E|&quot;; pcre:&quot;/\x3cidentifier\x3E[^\x3c]*\x2d\d/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15157</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player XSPF memory corruption attempt TEST</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.xspf&quot;; nocase; http_uri; flowbits:set,xspf_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15158</id>
        <msg>WEB-MISC XML Shareable Playlist Format file download attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/40e800&quot;; depth:7; nocase; http_uri; pcre:&quot;/^\x2F40e800[0-9A-F]{30,}$/Ui&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15165</id>
        <msg>BACKDOOR Pushdo client communication attempt</msg>
        <url>www.eweek.com/c/a/Security/Inside-a-Modern-Malware-Distribution-System/</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-5036</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,realplayer.playlist; content:&quot;&lt;time &quot;; nocase; pcre:&quot;/\x3ctime\x20[^\x3e]*(begin|end)\x3d\x22[^\x22]{13}/Osmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15166</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player RealText buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31688</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3641</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;PW&quot;; fast_pattern:only; pcre:&quot;/PW\x2E?[0-9]+\s*,\s*/&quot;; byte_test:4,&gt;=,1024,0,relative,string,dec; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15186</id>
        <msg>MISC Multiple vendors CUPS HPGL filter remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>31688</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3641</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;PW&quot;; fast_pattern:only; pcre:&quot;/PW\x2E?[0-9]+\s*,\s*/&quot;; byte_test:4,&lt;,0,0,relative,string,dec; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15187</id>
        <msg>MISC Multiple vendors CUPS HPGL filter remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>31688</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3641</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;PC&quot;; byte_test:4,&gt;=,1024,0,relative,string,dec; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15188</id>
        <msg>MISC Multiple vendors CUPS HPGL filter remote code execution attempt</msg>
        <url>www.cups.org/str.php?L2911</url>
      </rule>
      <rule>
        <bugtraq>31688</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3641</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;PC&quot;; byte_test:4,&lt;,0,0,relative,string,dec; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15189</id>
        <msg>MISC Multiple vendors CUPS HPGL filter remote code execution attempt</msg>
        <url>www.cups.org/str.php?L2911</url>
      </rule>
      <rule>
        <bugtraq>31416</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-6415</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 808</filter1>
        <filter2>flow:to_server,established; content:&quot;CONNECT &quot;; nocase; isdataat:1024,relative; pcre:&quot;/^CONNECT\s[^\s]{1024}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15190</id>
        <msg>WEB-MISC Youngzsoft CCProxy CONNECT Request buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23620</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2193</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;/* XPM */&quot;; pcre:&quot;/^\s*\x22[^\x22\n]{300}/mi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15236</id>
        <msg>WEB-CLIENT ACD Systems ACDSee XPM file format overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.rm&quot;; nocase; http_uri; flowbits:set,realmedia_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15239</id>
        <msg>WEB-MISC RealMedia format file download attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.rv&quot;; nocase; http_uri; flowbits:set,realmedia_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15240</id>
        <msg>WEB-MISC RealMedia format file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5444</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 09 01|&quot;; depth:20; offset:12; pcre:&quot;/^.{12}\x00{6}\x09\x01.{16}.{300}/&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15255</id>
        <msg>ORACLE Secure Backup msgid 0x901 username field overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5448</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php?&quot;; http_uri; content:!&quot;clear=yes&quot;; http_uri; content:&quot;ora_osb_bgcookie&quot;; http_uri; content:&quot;button=Logout&quot;; http_uri; content:&quot;rbtool&quot;; http_uri; pcre:&quot;/ora_osb_bgcookie\x3d[^\x20\x26\x3b]{1}/U&quot;; pcre:&quot;/rbtool\x3d[^\x20\x26\x3b]{1}/U&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15261</id>
        <msg>ORACLE Secure Backup exec_qr command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5448</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST &quot;; depth:5; content:&quot;login.php&quot;; http_uri; content:!&quot;clear=yes&quot;; http_client_body; content:&quot;ora_osb_bgcookie&quot;; http_client_body; content:&quot;button=Logout&quot;; http_client_body; content:&quot;rbtool&quot;; http_client_body; pcre:&quot;/ora_osb_bgcookie\x3d[^\x20\x26\x3b]{1}/P&quot;; pcre:&quot;/rbtool\x3d[^\x20\x26\x3b]{1}/P&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15262</id>
        <msg>ORACLE Secure Backup POST exec_qr command injection attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;newmain.exe&quot;; nocase; http_uri; pcre:&quot;/[A-Z]{7,12}\/newmain.exe/Ui&quot;; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15296</id>
        <msg>BOTNET-CNC Trojan.Bankpatch.C malicious file download attempt</msg>
        <url>www.threatexpert.com/threats/trojan-bankpatch-c.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dlyainfy.php&quot;; nocase; content:&quot;Host|3A| www.crabindustry.ru&quot;; nocase; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15297</id>
        <msg>BOTNET-CNC Trojan.Bankpatch.C report home attempt</msg>
        <url>www.threatexpert.com/threats/trojan-bankpatch-c.html</url>
      </rule>
      <rule>
        <bugtraq>33299</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0241</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8652</filter1>
        <filter2>flow:to_server,established; content:&quot;/&quot;; depth:1; isdataat:256,relative; content:!&quot;/&quot;; within:256; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15364</id>
        <msg>EXPLOIT Ganglia Meta Daemon process_path stack buffer overflow attempt</msg>
        <url>www.mail-archive.com/ganglia-developers@lists.sourceforge.net/msg04929.html</url>
      </rule>
      <rule>
        <bugtraq>25898</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4568</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7100</filter1>
        <filter2>flow:to_server,established; content:&quot;|12 01 03 00|&lt;|00 00 00|AAAA&quot;; fast_pattern:only; metadata:policy security-ips drop, service font-service; classtype:attempted-admin;</filter2>
        <id>15382</id>
        <msg>SPECIFIC-THREATS X.Org X Font Server QueryXBitmaps and QueryXExtents Handlers integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-0093</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15386, service dns, policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop;</filter2>
        <id>15386</id>
        <msg>BAD-TRAFFIC wpad dynamic update request</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-008.mspx</url>
      </rule>
      <rule>
        <bugtraq>10386</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0397</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;get-dated-rev&quot;; pcre:&quot;/get-dated-rev\x20\x28\x20\d{1,4}\x3a([^T\x2d\x3a]{9}|[^\x2d]{4}\x2d[^\x2d]{3}|[^\x2d]{4}\x2d[^\x2d]{2}\x2d[^\x2d]{3})/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15388</id>
        <msg>EXPLOIT Subversion 1.0.2 get-dated-rev buffer overflow over http attempt</msg>
      </rule>
      <rule>
        <bugtraq>24165</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2881</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1080</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 06|&quot;; depth:2; content:&quot;PPPPPPPPPPPPXXXXXXXXXXXX&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15422</id>
        <msg>SPECIFIC-THREATS Sun One web proxy server overflow attempt</msg>
        <url>sunsolve.sun.com/search/document.do?assetkey=1-26-102927-1</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.maki&quot;; nocase; http_uri; flowbits:set,maki_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15426</id>
        <msg>WEB-CLIENT MAKI file request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.svg&quot;; nocase; http_uri; flowbits:set,svg_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15427</id>
        <msg>WEB-MISC SVG file request</msg>
      </rule>
      <rule>
        <bugtraq>34235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1169</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;xsl|3A|key name=|22|label|22| match=|22|item2|22| use=|22|w00t|28 29 22|/&gt;&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15431</id>
        <msg>SPECIFIC-THREATS Firefox 3 xsl parsing heap overflow attempt</msg>
        <url>www.mozilla.org/security/announce/2009/mfsa2009-12.html</url>
      </rule>
      <rule>
        <bugtraq>34134</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0920</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/OVCgi/Toolbar.exe&quot;; nocase; http_uri; content:&quot;Cookie&quot;; nocase; http_cookie; content:&quot;OvOSLocale&quot;; http_cookie; pcre:&quot;/^Cookie\s*\x3a.*?OvOSLocale\s*\x3d\s*[^\x3b\s]{249}/Cmi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15434</id>
        <msg>WEB-MISC HP OpenView Network Node Manager OvOSLocale parameter buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34077</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-4563</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1500</filter1>
        <filter2>flow:to_server,established; content:&quot;*|A5|&quot;; byte_test:2,&gt;,0x41,19,relative,big; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15436</id>
        <msg>EXPLOIT IBM Tivoli Storage Manager Express Backup counter heap corruption attempt</msg>
        <url>www-01.ibm.com/support/docview.wss?uid=swg21377388</url>
      </rule>
      <rule>
        <bugtraq>34077</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-4563</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1500</filter1>
        <filter2>flow:to_server,established; content:&quot;*|A5|&quot;; offset:4; byte_test:2,&lt;,0x17,-4,relative,big; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15437</id>
        <msg>EXPLOIT IBM Tivoli Storage Manager Express Backup message length heap corruption attempt</msg>
        <url>www-01.ibm.com/support/docview.wss?uid=swg21377388</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.caf&quot;; nocase; http_uri; flowbits:set,caff_request; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15444</id>
        <msg>WEB-MISC Core Audio Format file download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4014</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9700</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /BPELConsole/default/activities.jsp&quot;; depth:39; nocase; pcre:&quot;/(\x3F|\x26)[^\x3D]*(\x27|%27)[^\x3D]*(\x3C|%3c)script(\x3E|%3e)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15445</id>
        <msg>ORACLE Oracle Application Server BPEL module cross site scripting attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-0089</cve>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|15456, service ssl, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15456</id>
        <msg>EXPLOIT WinHTTP SSL/TLS impersonation attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-013.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0084</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15457, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15457</id>
        <msg>EXPLOIT DirectShow MJPEG arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-011.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.asp&quot;; nocase; flowbits:set,asp.upload; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>15471</id>
        <msg>WEB-CLIENT asp file upload</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0237</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15475, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15475</id>
        <msg>WEB-CLIENT ISA Server cross-site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-016.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server; content:&quot;X-Request-Kind-Code|3A|&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15476</id>
        <msg>SPYWARE-PUT Waledac spam bot HTTP POST request</msg>
        <url>blogs.technet.com/mmpc/archive/2009/04/14/wheres-waledac.aspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2008-5457</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;JSESSIONID&quot;; http_uri; isdataat:300,relative; pcre:&quot;/JSESSIONID\x3d[^\x20\x26\x0a]{300}/smiU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>15477</id>
        <msg>EXPLOIT Oracle BEA WebLogic overlong JESSIONID buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15480, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15480</id>
        <msg>WEB-CLIENT TRUFFLEHUNTER SFVRT-1003 attack attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server; content:&quot;/w/update.dat&quot;; nocase; http_uri; content:&quot;Host|3A| chartseye.cn&quot;; nocase; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15481</id>
        <msg>BOTNET-CNC Zeus/Zbot malware config file download request</msg>
        <url>www.viruslist.com/en/viruses/encyclopedia?virusid=21782783</url>
      </rule>
      <rule>
        <bugtraq>26146</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5544</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Disposition|3A| attachment|3B|&quot;; content:&quot;filename=|22|poc.doc|22|&quot;; distance:0; content:&quot;Mb4AAACr&quot;; distance:0; content:&quot;WnoHAQQABAAAAAUAtQFUaGlzIGlzIGEgdGVzdA0K&quot;; distance:0; content:&quot;/wAB5kBBQUFB//8&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>15485</id>
        <msg>SPECIFIC-THREATS IBM Lotus Notes DOC attachment viewer buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>10386</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0397</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;dated-rev-report&quot;; nocase; content:&quot;&lt;D|3A|CREATIONDATE&gt;XXXXXXX&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15491</id>
        <msg>EXPLOIT Subversion 1.0.2 dated-rev-report buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1129</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,ppt.download; metadata: engine shared, soid 3|15499, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15499</id>
        <msg>WEB-CLIENT PowerPoint 95 converter CString in ExEmbed container buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15503, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15503</id>
        <msg>WEB-CLIENT Download of PowerPoint 95 file</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1137</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15504, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15504</id>
        <msg>WEB-CLIENT Download of PowerPoint 4.0 file</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-017.mspx</url>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2009-0172</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:to_server,established; content:&quot;|10|A&quot;; depth:2; offset:8; byte_jump:2, -10, relative; content:&quot;|10|n&quot;; within:2; distance:6; metadata:policy balanced-ips drop, policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>15509</id>
        <msg>DOS IBM DB2 database server CONNECT denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>35017</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1252</cve>
        <filter1>udp $EXTERNAL_NET 123 -&gt; $HOME_NET 123</filter1>
        <filter2>flow:to_server; dsize:&gt; 200; content:&quot;|01|&quot;; depth:1; offset:49; byte_test:4,&gt;,200,14,relative,big; metadata:policy balanced-ips drop, policy security-ips drop, service ntp; classtype:attempted-admin;</filter2>
        <id>15514</id>
        <msg>EXPLOIT Multiple Vendors NTP Daemon Autokey stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.avi&quot;; nocase; http_uri; flowbits:set,http.avi; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15516</id>
        <msg>WEB-CLIENT AVI multimedia file request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.eot&quot;; nocase; http_uri; flowbits:set,eot.download; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>15518</id>
        <msg>WEB-MISC Embedded Open Type Font download request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <cve>2009-0228</cve>
        <filter1>tcp $EXTERNAL_NET [139,445] -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:protocol-command-decode; metadata: engine shared, soid 3|15523, service netbios-ssn, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15523</id>
        <msg>EXPLOIT srvsvc NetrShareEnum netname overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-022.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1528</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15534, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15534</id>
        <msg>WEB-CLIENT IE XML HttpRequest race condition exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1529</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15535, service http, policy security-ips drop;</filter2>
        <id>15535</id>
        <msg>WEB-CLIENT IE setCapture heap corruption exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1530</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15536, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15536</id>
        <msg>WEB-CLIENT IE invalid object modification exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-019.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mrow_pin/?id&quot;; nocase; http_uri; pcre:&quot;/\x2Fmrow\x5Fpin\x2F\x3Fid\d+[a-z]{5,}\d{5}\x26rnd\x3D\d+/smi&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15553</id>
        <msg>BOTNET-CNC Sality virus HTTP GET request</msg>
        <url>www.threatexpert.com/report.aspx?md5=b61aaef4d4dfbddbd8126c987fb77374</url>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0993</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [6000:6199]</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP&quot;; nocase; pcre:&quot;/^(GET|POST|HEAD)\s+[^\x25]*\x25[\x23\x24\x27\x2a\x2b\x2d\x2ehlqjzt1234567890]*[diouxefgacspn]/i&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15554</id>
        <msg>ORACLE Oracle Application Server 10g OPMN service format string vulnerability exploit attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</url>
      </rule>
      <rule>
        <bugtraq>34672</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1430</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 38292</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF FF FF FF FF FF|&quot;; depth:8; content:&quot;|00 00 00 00 00 00 00 00|&quot;; within:8; distance:10; content:&quot;|03|&quot;; within:1; distance:23; content:&quot;BIND&quot;; within:4; distance:8; content:&quot;BIND|00|&quot;; within:5; distance:17; fast_pattern; byte_test:2,&gt;,0x400,0,relative,big; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15555</id>
        <msg>EXPLOIT Symantec Alert Management System Intel Alert Originator Service buffer overflow attempt</msg>
        <url>www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</url>
      </rule>
      <rule>
        <bugtraq>34675</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1431</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12174</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; pcre:&quot;/^\x00\x00\x00\x00.{2}(\x2f{2}|\x5c{2}|([A-F0-9\x21\x23-\x27\x2a\x2b\x2d\x2f\x3d\x3f\x5e\x5f\x60\x7b-\x7e]+\x2e){2})/si&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15556</id>
        <msg>EXPLOIT Symantec Alert Management System Intel File Transfer Service arbitrary program execution attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /cgi-bin/generator.pl HTTP/1.0|0D 0A|User-Agent|3A| &quot;; http_header; content:&quot;1|3B|7017|3B|&quot;; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15563</id>
        <msg>SPYWARE-PUT RSPlug Trojan server connection attempt</msg>
        <url>www.sophos.com/security/analyses/viruses-and-spyware/osxrsplugf.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|23|!/bin/sh&quot;; nocase; content:&quot;4A4*FD32[8|22|-|29|Y|22|4|28|EB|28 22|!&amp;0H|28 22|8&quot;; distance:50; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15564</id>
        <msg>SPYWARE-PUT RSPlug Trojan file download attempt</msg>
        <url>www.sophos.com/security/analyses/viruses-and-spyware/osxrsplugf.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|23|!/bin/sh&quot;; nocase; content:&quot;&lt;|22|!0&lt;FEM87|29|Y4V5R=FEC92!|5C 28|'-E9|22|`&quot;; distance:50; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15565</id>
        <msg>SPYWARE-PUT RSPlug Trojan file download attempt</msg>
        <url>www.sophos.com/security/analyses/viruses-and-spyware/osxrsplugf.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gumblar.cn&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2Fgumblar\x2Ecn\x2Frss\x2F\x3Fid\x3D\d+/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15566</id>
        <msg>SPYWARE-PUT Gumblar HTTP GET request attempt</msg>
        <url>www.us-cert.gov/current/archive/2009/06/01/archive.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/martuz.cn&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2Fmartuz\x2Ecn\x2Fvid\x2F\x3Fid\x3D\d+/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15567</id>
        <msg>SPYWARE-PUT Martuz HTTP GET request attempt</msg>
        <url>www.us-cert.gov/current/archive/2009/06/01/archive.html</url>
      </rule>
      <rule>
        <bugtraq>33072</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 2775</filter1>
        <filter2>flow:established,to_server; content:&quot;|02|03|3A|&quot;; content:&quot;|09|052|3A|2|09|&quot;; distance:0; content:&quot;|09|033|3A|&quot;; pcre:&quot;/\x09033\x3a(?=[^\s]+\x40[^\s]+)[^\x20\x09]{33}/&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>15572</id>
        <msg>DOS Curse of Silence Nokia SMS DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>33059</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5911</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SET_PARAMETER&quot;; depth:13; content:&quot;DataConvertBuffer&quot;; distance:0; nocase; pcre:&quot;/\x0a\x0d?\x0a[A-Z0-9\x2b\x2f\s]*[^A-Z0-9\x2b\x2f\s\x3d]/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15573</id>
        <msg>EXPLOIT RealNetworks Helix Server RTSP SET_PARAMETER heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12220</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0097</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; content:&quot;Proxy-Authorization|3A| NTLM TlRMTVNTUAADAAAAGAAYAFcAAAAYABgAbwAAAAQABABIAAAABwAHAEwAAAAEAAQAUwAAAAAAAACHAAAABoIAAgUAkwgAAAAPQUxJRgNTVE9JQU5BTElG0rctVCv8MHcFVYLyVeJ+Bz+VWpKGpuw68j7CBi5V2JlRVrF65wtddQTYeTHCnpF3&quot;; http_header; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>15579</id>
        <msg>SPECIFIC-THREATS Squid NTLM fakeauth_auth Helper denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>12412</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>2005-0241</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Length|3A| 3|0D 0A|Server|3A| AAAAAA&quot;; http_header; metadata:policy security-ips drop, service http; classtype:bad-unknown;</filter2>
        <id>15580</id>
        <msg>SPECIFIC-THREATS Squid oversized reply header handling exploit attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.arj&quot;; nocase; http_uri; flowbits:set,arj_file.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15582</id>
        <msg>WEB-MISC ARJ format file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>12515</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0350</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,arj_file.request; content:&quot;|0A|`|EA|&quot;; pcre:&quot;/\x0a\x0d?\x0a\x60\xea(.{36}[^\x00]{256}|.+\x60\xea.{32}[^\x00]{256})/s&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15583</id>
        <msg>WEB-CLIENT F-Secure AntiVirus library heap overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.ppt&quot;; nocase; http_uri; flowbits:set,http.ppt; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>15586</id>
        <msg>WEB-CLIENT Powerpoint file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0566</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15681, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15681</id>
        <msg>EXPLOIT Publisher 2007 file format arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-030.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15683, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15683</id>
        <msg>WEB-MISC ISA Server OTP-based Forms-authorization fallback policy bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-031.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0231</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,eot.download; metadata: engine shared, soid 3|15693, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15693</id>
        <msg>WEB-CLIENT Embedded Open Type Font malformed name table overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-029.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0232</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,eot.download; metadata: engine shared, soid 3|15694, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15694</id>
        <msg>WEB-CLIENT Embedded Open Type Font malformed name table integer overflow attempt </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-029.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0232</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,eot.download; metadata: engine shared, soid 3|15695, service http, policy security-ips drop;</filter2>
        <id>15695</id>
        <msg>WEB-CLIENT Embedded Open Type Font malformed name table platform type 3 integer overflow attempt </msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-029.mspx</url>
      </rule>
      <rule>
        <bugtraq>35668</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0692</cve>
        <filter1>udp $HOME_NET [67,68] -&gt; $HOME_NET [67,68]</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15700, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15700</id>
        <msg>EXPLOIT dhclient subnet mask option buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35267</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1420</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3443</filter1>
        <filter2>flow:to_server,established; content:&quot;/OvCgi/webappmon.exe&quot;; nocase; content:&quot;act=rping&quot;; distance:0; nocase; pcre:&quot;/sel\x3d[^\x26\x0a]{73}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15726</id>
        <msg>EXPLOIT HP OpenView Network Node Manager URI rping stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;tip&quot;; nocase; content:&quot;&amp;cli&quot;; distance:0; nocase; pcre:&quot;/tip\x3D[a-zA-Z]+\x26cli\x3D[a-zA-Z]+\x26tipo\x3Dcli\x26inf\x3D/smi&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15730</id>
        <msg>BOTNET-CNC Delf Trojan POST attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=858295d163762748bf4821db5de041a1</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-0696</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|15734, policy balanced-ips drop, policy security-ips drop, service dns;</filter2>
        <id>15734</id>
        <msg>BAD-TRAFFIC BIND named 9 dynamic update message remote dos attempt</msg>
        <url>www.isc.org/software/bind/advisories/cve-2009-0696</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1133</cve>
        <filter1>tcp $EXTERNAL_NET 3389 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15850, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15850</id>
        <msg>EXPLOIT Remote Desktop orderType remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-044.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.mp4&quot;; nocase; http_uri; flowbits:set,http.mp4; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>15865</id>
        <msg>WEB-CLIENT MP4 file request</msg>
      </rule>
      <rule>
        <bugtraq>31126</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3529</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;!ENTITY&quot;; isdataat:200,relative; pcre:&quot;/\x3c\x21ENTITY\s*[^\s\x3e]{200}/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15866</id>
        <msg>WEB-CLIENT libxml2 XML file processing long entity name buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.4xm&quot;; nocase; http_uri; flowbits:set,4xm.request; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>15870</id>
        <msg>WEB-MISC 4xm file request</msg>
      </rule>
      <rule>
        <bugtraq>33502</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0385</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,4xm.request; content:&quot;strk|28 00 00 00|&quot;; byte_test:4,&gt;,0x7ffffffe,0,relative,little; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15871</id>
        <msg>WEB-CLIENT FFmpeg 4xm processing memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>35758</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2469</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;.watch|28|&quot;; nocase; content:&quot;__defineSetter__|28|&quot;; nocase; pcre:&quot;/(?P&lt;obj&gt;\w+)\.watch\((?P&lt;q1&gt;\x22|\x27|)(?P&lt;prop&gt;[A-Z0-9\x2d\x5f]+)(?P=q1).*(?P=obj)\.__defineSetter__\((?P&lt;q2&gt;\x22|\x27|)(?P=prop)(?P=q2)/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15872</id>
        <msg>WEB-CLIENT Firefox defineSetter function pointer memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>35803</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-2654</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;window.open|28|&quot;; nocase; pcre:&quot;/window\x2Eopen\x28(\x22[^\x22]+(\x25[^0-9a-f]|\x2C)|\x27[^\x27]+(\x25[^0-9a-f]|\x2C))/smi&quot;; metadata:policy security-ips alert, service http; classtype:misc-attack;</filter2>
        <id>15873</id>
        <msg>WEB-CLIENT Firefox location spoofing via invalid window.open characters</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-0127</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1718</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|?/|05|%*&quot;; depth:6; pcre:&quot;/^\x01\x3F\x2F\x05\x25\x2A[^\x0D\x0A]{300}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15882</id>
        <msg>EXPLOIT McAfee E-Business Server remote preauth code execution attempt</msg>
        <url>www.infigo.hr/en/in_focus/advisories/INFIGO-2008-01-06</url>
      </rule>
      <rule>
        <bugtraq>27613</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0621</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|&quot;; depth:1; content:!&quot;|0A|&quot;; within:400; metadata:policy security-ips drop, service ldp; classtype:attempted-admin;</filter2>
        <id>15883</id>
        <msg>EXPLOIT SAPLPD 0x01 command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27613</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0621</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|02|&quot;; depth:1; content:!&quot;|0A|&quot;; within:400; metadata:policy security-ips drop, service ldp; classtype:attempted-admin;</filter2>
        <id>15884</id>
        <msg>EXPLOIT SAPLPD 0x02 command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27613</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0621</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|03|&quot;; depth:1; content:&quot; &quot;; distance:0; content:!&quot;|0A|&quot;; within:2000; metadata:policy security-ips drop, service ldp; classtype:attempted-admin;</filter2>
        <id>15885</id>
        <msg>EXPLOIT SAPLPD 0x03 command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27613</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0621</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; isdataat:400; content:&quot;|05|&quot;; depth:1; content:!&quot; &quot;; within:400; metadata:policy security-ips drop, service ldp; classtype:attempted-admin;</filter2>
        <id>15887</id>
        <msg>EXPLOIT SAPLPD 0x05 command buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27613</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-0621</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;S&quot;; depth:1; dsize:&lt;4; metadata:policy security-ips drop, service ldp; classtype:attempted-dos;</filter2>
        <id>15892</id>
        <msg>DOS SAPLPD 0x53 command denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.aiff&quot;; nocase; http_uri; flowbits:set,aiff_file.request; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15898</id>
        <msg>WEB-MISC Audio Interchange File Format download request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.aif&quot;; nocase; http_uri; flowbits:set,aiff_file.request; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15899</id>
        <msg>WEB-MISC Audio Interchange File Format file request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.aifc&quot;; nocase; http_uri; flowbits:set,aiff_file.request; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15900</id>
        <msg>WEB-MISC Audio Interchange File Format request</msg>
      </rule>
      <rule>
        <bugtraq>19409</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3439</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|C7 0B|GGGG|81|7&quot;; content:&quot;u|F4|&quot;; within:2; distance:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>15902</id>
        <msg>SHELLCODE x86 win2k-2k3 decoder base shellcode</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.mp3&quot;; nocase; http_uri; flowbits:set,http.mp3; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15922</id>
        <msg>WEB-CLIENT mp3 file download request</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 27374 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;connected.&quot;; nocase; content:&quot;Legends&quot;; distance:0; fast_pattern; nocase; pcre:&quot;/^connected\x2e[^\x0D\x0A]*20\d\d[^\x0D\x0A]*ver\x3A\s+Legends\s2\x2e1/smi&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>15938</id>
        <msg>BOTNET-CNC Backdoor SubSeven client connection to server</msg>
        <url>www.threatexpert.com/report.aspx?md5=da8d7529a8a37335064ade9d04df08ad</url>
      </rule>
      <rule>
        <bugtraq>23085</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1560</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; content:&quot;TRACE&quot;; depth:5; content:&quot;Max-Forwards|3A| 0|0D 0A|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15941</id>
        <msg>DOS Squid Proxy TRACE request remote DoS attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.rss&quot;; nocase; http_uri; flowbits:set,rss.download; flowbits:noalert; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>15945</id>
        <msg>WEB-CLIENT RSS file download request</msg>
      </rule>
      <rule>
        <bugtraq>12832</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0644</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;-lh0-&quot;; content:&quot;|02 C9 C5|M|88 00 02|DDDD&quot;; within:11; distance:13; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15950</id>
        <msg>SPECIFIC-THREATS McAfee LHA Type-2 file handling overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13727</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2005-1252</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8484</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /what.jsp?|5C|..|5C|..&quot;; metadata:policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>15953</id>
        <msg>WEB-MISC Ipswitch IMail Calendaring arbitrary file read attempt</msg>
      </rule>
      <rule>
        <bugtraq>13978</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1266</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A| hello|3B|&quot;; fast_pattern:only; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>15954</id>
        <msg>SPECIFIC-THREATS SpamAssassin malformed email header DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>13420</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1382</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4000</filter1>
        <filter2>flow:to_server,established; content:&quot;webcacheadmin?&quot;; content:&quot;SCREEN_ID=CGA.CacheDump&quot;; content:&quot;ACTION=Submit&amp;index=1&quot;; content:&quot;cache_dump_file=&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>15955</id>
        <msg>ORACLE Application Server 9i Webcache file corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>14270</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1530</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;PK|03 04|&quot;; content:&quot;|0C 00|&quot;; within:2; distance:4; content:&quot;-|00 00 00 F9 00 00 00 05 00 FF FF|&quot;; within:12; distance:8; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>15957</id>
        <msg>WEB-CLIENT Sophos Anti-Virus zip file handling DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>14715</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2005-2020</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21700</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; depth:3; content:&quot;../../boot.ini&quot;; within:14; distance:23; metadata:policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>15961</id>
        <msg>SPECIFIC-THREATS 3Com Network Supervisor directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>14287</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2297</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WebConsole/Login.jsp|3B EA EA EA EA EA EA EA EA|&quot;; http_uri; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15962</id>
        <msg>SPECIFIC-THREATS Sybase EAServer WebConsole overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10243</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0234</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;!|C3|-lh0-|18 00 00 00 05 00 00 00 FA BB|m0 |01 08|testfile|F8 1B|U|05 00|P|B4 81 94 01 01|UUUU&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15966</id>
        <msg>SPECIFIC-THREATS F-Secure Anti-Virus LHA processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2004-0362</cve>
        <filter1>udp any any -&gt; any 5190</filter1>
        <filter2>flow:to_server; content:&quot;|05 00|&quot;; depth:2; content:&quot;|12 02|&quot;; within:2; distance:5; byte_test:1,&gt;,1,12,relative; content:&quot;|05 00|&quot;; content:&quot;n|00|&quot;; within:2; distance:5; content:&quot;|05 00|&quot;; content:&quot;|DE 03|&quot;; within:2; distance:5; byte_test:2,&gt;,512,-11,relative,little; metadata:policy security-ips drop; classtype:misc-attack;</filter2>
        <id>15967</id>
        <msg>SPECIFIC-THREATS ICQ SRV_MULTI/SRV_META_USER overflow attempt</msg>
        <url>www.eeye.com/html/Research/Advisories/AD20040318.html</url>
      </rule>
      <rule>
        <bugtraq>31193</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2468</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12175</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|15968, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15968</id>
        <msg>EXPLOIT LANDesk Management Suite QIP service heal packet buffer overflow attempt</msg>
        <url>community.landesk.com/support/docs/DOC-3276</url>
      </rule>
      <rule>
        <bugtraq>11039</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0369</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500</filter1>
        <filter2>flow:to_server; content:&quot;|A8|`|87|o|15 A9|0|F4 00 00 00 00 00 00 00 00 01 10 02 00 00 00 00 00 00 00 00|0|00 00 00 14 00 00 00 01 00 00 00 05 00 00 7F FF|&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>15969</id>
        <msg>SPECIFIC-THREATS Symantec Multiple Products ISAKMPd denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>10519</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0413</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3690</filter1>
        <filter2>flow:to_server,established; content:&quot;|28| 2 |28| edit-pipeline |29| 4294967295|3A|AAAA&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15970</id>
        <msg>SPECIFIC-THREATS Subversion svn pProtocol string parsing heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11245</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0646</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.jsp&quot;; http_uri; content:&quot;HOST&quot;; nocase; pcre:&quot;/^HOST\s*\x3a\s*[^\x0a]{1000}/mi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15978</id>
        <msg>WEB-MISC Macromedia JRun 4 mod_jrun buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11051</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0797</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;x|9C 85 C1 B9 11 80|0|10 04|A|EC A9 9A A0 C4|+|1E 91 7F FE D8 EB|p|DD AD FD 93 B9| KA|D6 82|l|05 D9 0B|r|14 A4|'9|93 5C|I|EE 24|O|92 91 E4|M2}yw[|86|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>15981</id>
        <msg>SPECIFIC-THREATS zlib Denial of Service</msg>
      </rule>
      <rule>
        <bugtraq>11110</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0799</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;prn&quot;; http_uri; pcre:&quot;/^(GET|POST)\s+[^\x0a]*?\x2fprn\x2e(htm|html|asp|cgi)/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>15982</id>
        <msg>WEB-MISC Ipswitch WhatsUp Gold DOS Device HTTP request denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>11281</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0815</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|5C 00|/|00|.|00|/|00|/|00|/|00|/|00|/|00|e|00|t|00|c|00|/|00|h|00|o|00|s|00|t|00|s|00|.|00|d|00|e|00|n|00|y|00 00 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:misc-attack;</filter2>
        <id>15983</id>
        <msg>SPECIFIC-THREATS Samba arbitrary file access exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>11055</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0829</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|05 00 00 03 10 00 00 00 BC 00 00 00 01 00 00 00 A4 00 00 00 00 00|E|00 28 91|9|00 15 00 00 00 00 00 00 00 15 00 00 00 5C 00 5C 00|s|00|l|00|a|00|w|00|e|00|k|00|.|00|v|00|r|00|t|00 5C 00|p|00|r|00|i|00|n|00|t|00|e|00|r|00 00 00|&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:attempted-dos;</filter2>
        <id>15984</id>
        <msg>SPECIFIC-THREATS Samba Printer Change Notification Request DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>11678</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2004-0882</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMB-|00 00 00 00 08 01 C8 00 00 00 00 00 00 00 00 00 00 00 00 01 00 92|&lt;d|00 07 00 0F FF 00 00 00 00 00|@|00 06 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00|%|04 00 5C 00|t|00|e|00|s|00|t|00 5C 00|A&quot;; metadata:policy security-ips drop, service netbios-ssn; classtype:misc-attack;</filter2>
        <id>15986</id>
        <msg>SPECIFIC-THREATS Samba unicode filename buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36091</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2855</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; content:&quot;Cookie|3A| user=va,lue|0A|&quot;; http_header; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>15994</id>
        <msg>SPECIFIC-THREATS Squid strListGetItem denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0011</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15995, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>15995</id>
        <msg>EXPLOIT malformed avi file mjpeg compression arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-033.mspx</url>
      </rule>
      <rule>
        <bugtraq>20971</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5782</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3465</filter1>
        <filter2>flow:to_server,established; content:&quot;8899|00|test|00|test|00|radcrecv.exe|0A|&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>15998</id>
        <msg>SPECIFIC-THREATS HP OpenView Client Configuration Manager Radia Notify Daemon code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>22207</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0462</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 9A 00 00 00 FF 80|P|00 00 00 00 00 14 00 14 00 02|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16001</id>
        <msg>SPECIFIC-THREATS Apple QuickDraw PICT images ARGB records handling memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>28468</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1705</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1315,2315]</filter1>
        <filter2>flow:to_server,established; content:&quot;|04 00 00 00|nnnn|04 00 00 00|aaaa|D2 07 00 00 14 00 00 00|%n%n%n%n%n%n%n%n%n%n&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16013</id>
        <msg>SPECIFIC-THREATS IBM solidDB logging function format string exploit attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1658</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;href=3D|22|c|3A|/windows/system32/winrm?|5C|wmicimv2/Win32_Service?Name=3Dspooler|22|=|0D 0A|&gt;Click=20|0D 0A|here!&quot;; nocase; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>16022</id>
        <msg>SPECIFIC-THREATS Windows Vista Windows mail file execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-1658</cve>
        <filter1>tcp $EXTERNAL_NET [110,143] -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;href=3D|22|c|3A|/windows/system32/winrm?|5C|wmicimv2/Win32_Service?Name=3Dspooler|22|=|0D 0A|&gt;Click=20|0D 0A|here!&quot;; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16023</id>
        <msg>SPECIFIC-THREATS Windows Vista Windows mail file execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-034.mspx</url>
      </rule>
      <rule>
        <bugtraq>20316</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4511</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8300</filter1>
        <filter2>flow:established,to_server; content:&quot;POST /login&quot;; depth:11; nocase; content:&quot;tag=NM_A_PARM1&amp;cmd=0&amp;val=&quot;; distance:0; fast_pattern; nocase; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16028</id>
        <msg>SPECIFIC-THREATS Groupwise Messenger parameters invalid memory access</msg>
      </rule>
      <rule>
        <bugtraq>18290</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-2447</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 783</filter1>
        <filter2>flow:to_server,established; content:&quot;user&quot;; fast_pattern:only; pcre:&quot;/^user\s*\x3a[^\r\n]*[\x3b\x26\x7c]/mi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16040</id>
        <msg>EXPLOIT SpamAssassin spamd vpopmail and paranoid options code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>16764</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-0300</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;GNU.sparse.numblocks=&quot;; nocase; pcre:&quot;/GNU\x2esparse\x2enumblocks\s*\x3d\s*(0|[6-9]\d{4})/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>16053</id>
        <msg>WEB-CLIENT GNU tar PAX extended headers handling overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17637</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2006-0230</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8004,8005]</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;key mod=|22|784607708866&quot;; content:&quot;pub=|22|75429754206&quot;; metadata:policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>16056</id>
        <msg>WEB-MISC Symantec Scan Engine authentication bypass attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.xpm&quot;; fast_pattern; nocase; http_uri; flowbits:set,http.xpm; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>16061</id>
        <msg>MISC X PixMap file download</msg>
      </rule>
      <rule>
        <bugtraq>28198</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1526</filter1>
        <filter2>flow:established,to_server; content:&quot;sq&quot;; depth:2; pcre:&quot;/^.{8}[^\s]+(\s+[^\s]+){49}/smOR&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16069</id>
        <msg>EXPLOIT IBM Informix server argument processing overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27352</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0006</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|01|fcp|08 00 00 00 01 00 00 00 0E 00 00 00 A0 02 00 00|&quot;; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16070</id>
        <msg>SPECIFIC-THREATS X.org PCF parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28307</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0047</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:established,to_server; content:&quot;/?query=..........&quot;; nocase; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16072</id>
        <msg>SPECIFIC-THREATS CUPS server query metacharacter buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10454</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0536</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2049</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 00 00|&quot;; depth:4; offset:4; content:&quot;|00 00 00 09|&quot;; within:4; distance:12; content:&quot;|CA BA EB FE CB|F|00 00 02 00 00 00 08 03 00 00 08 03 00 00 CB|F|00 00 AF|H|C3 8E 00 00 00 00 00 00 00 07|asd%nmv&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16076</id>
        <msg>SPECIFIC-THREATS Tripwire format string vulnerability nfs exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>10546</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0607</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500</filter1>
        <filter2>flow:to_server; content:&quot;|AA FF|Fk|09 89 01 B9 B2 F4 E2|^Pdx|17 05 10 02 01 00 00 00 00|&quot;; depth:24; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16080</id>
        <msg>SPECIFIC-THREATS KAME racoon X509 certificate verification bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>12269</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-0218</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;a href=|22|data|3A|application/octet-stream|3B|base64,WDVPIVAlQEFQWzRcUFpYNTQoUF4pN0NDKTd9JEVJQ0FSLVNUQU5EQVJELUFOVElWSVJVUy1URVNULUZJTEUhJEgrSCo=|22|&gt;&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>16087</id>
        <msg>SPECIFIC-THREATS Multiple vendor AV gateway virus detection bypass attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;GHOST|0D 0A|&quot;; depth:7; nocase; flowbits:set,BugsPrey_detection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>16093</id>
        <msg>BACKDOOR bugsprey runtime detection - initial connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ljs.txt&quot;; nocase; http_uri; content:&quot;winssco.exe&quot;; nocase; http_header; pcre:&quot;/User-Agent\x3a[^\r\n]*winssco\x2eexe/iH&quot;; metadata:policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16098</id>
        <msg>BACKDOOR win32.cekar variant runtime detection</msg>
        <url>vil.nai.com/vil/content/v_141463.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;v1ct1m&quot;; depth:6; nocase; flowbits:set,LostDoor3_InitConn; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>16103</id>
        <msg>BACKDOOR lost door 3.0 runtime detection - init</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Sin&quot;; depth:3; nocase; pcre:&quot;/^Sin[^\r\n]*\x0D\x0A\d+\x0D\x0A/smi&quot;; flowbits:set,SynRat2.1_initconn; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>16106</id>
        <msg>BACKDOOR synrat 2.1 pro runtime detection - init</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 8392</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00|O|95 00 00 00 04|echo&quot;; depth:12; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16140</id>
        <msg>BACKDOOR torpig-mebroot command and control checkin</msg>
        <url>www.f-secure.com/weblog/archives/00001393.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;controller|2E|php|3F|action|3D|&quot;; nocase; http_uri; content:&quot;entity_list|3D|&quot;; nocase; http_uri; content:&quot;rnd|3D|&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16144</id>
        <msg>SPYWARE-PUT Bredolab bot contact to C&amp;C server attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=b5a530185d35ea8305d3742e2ee5669f</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0555</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16157, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16157</id>
        <msg>WEB-CLIENT malformed ASF voice codec memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-051.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2525</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16158, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16158</id>
        <msg>WEB-CLIENT malformed ASF codec memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-051.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-2510</cve>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|16180, service ssl, policy security-ips drop;</filter2>
        <id>16180</id>
        <msg>WEB-CLIENT Windows CryptoAPI common name spoofing attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2511</cve>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16181, service ssl, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16181</id>
        <msg>WEB-CLIENT Windows CryptoAPI ASN.1 integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0084</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16187, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16187</id>
        <msg>EXPLOIT DirectShow MJPEG arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>35672</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php?&quot;; nocase; http_uri; content:&quot;attempt=&quot;; nocase; http_uri; content:&quot;uname=&quot;; nocase; http_uri; pcre:&quot;/uname\x3d[^\x26]*[\x3c\x3e]/iU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16191</id>
        <msg>ORACLE Oracle Secure Backup Administration server authentication bypass attempt - via GET</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</url>
      </rule>
      <rule>
        <bugtraq>35672</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1977</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php&quot;; nocase; http_uri; content:&quot;attempt=&quot;; nocase; http_client_body; content:&quot;uname=&quot;; nocase; http_client_body; pcre:&quot;/uname\x3d[^\x26]*\x253[CE]/iP&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16192</id>
        <msg>ORACLE Oracle Secure Backup Administration server authentication bypass attempt - via POST</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0457</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8443</filter1>
        <filter2>flow:to_server,established; content:&quot;|17 03 00 02 01 87 09|k]dg]|86|T|D0 F4|'|EF|+2|CA A3 D3 FA 97 AA|@|14 ED|'|15 D2 9B 06 EA 07 09|}|B8 D2|ai|CD|mtR|F9 8A|&quot;; depth:48; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service ssl; classtype:misc-activity;</filter2>
        <id>16196</id>
        <msg>SPECIFIC-THREATS Symantec Backup Exec System Recovery Manager unauthorized file upload attempt</msg>
      </rule>
      <rule>
        <bugtraq>30013</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-2952</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>flow:to_server,established; content:&quot;|1F 80 80 00 84|aaaa&quot;; depth:9; metadata:policy security-ips drop, service ldap; classtype:attempted-dos;</filter2>
        <id>16197</id>
        <msg>SPECIFIC-THREATS OpenLDAP ber_get_next BER decoding denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>15373</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-3351</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot; b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A| b|0A|&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>16199</id>
        <msg>SPECIFIC-THREATS SpamAssassin long message header denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>14888</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2968</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;a href=|22|http|3A|//`echo&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>16200</id>
        <msg>SPECIFIC-THREATS Firefox command line URL shell command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>33668</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4562</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ovlaunch.exe&quot;; nocase; http_uri; content:&quot;host|3A|&quot;; nocase; isdataat:300,relative; pcre:&quot;/^host\x3a\s*[^\r\n]{300}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16204</id>
        <msg>WEB-CLIENT HP OpenView Network Node Manager ovlaunch host field overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.bmp&quot;; nocase; http_uri; flowbits:set,http.bmp; flowbits:noalert; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16205</id>
        <msg>WEB-MISC bitmap file download request</msg>
      </rule>
      <rule>
        <bugtraq>36015</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:to_server,established; content:&quot;CSeq&quot;; nocase; pcre:&quot;/^\s*\x3a\s*\d{11}/R&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16210</id>
        <msg>DOS Digium Asterisk SIP sscanf denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>36015</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Length&quot;; nocase; pcre:&quot;/^\s*\x3a\s*\d{11}/R&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16211</id>
        <msg>DOS Digium Asterisk SIP sscanf denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>36015</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:to_server,established; content:&quot;rtpmap&quot;; nocase; pcre:&quot;/^\s*\x3a\s*\d{11}/R&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16212</id>
        <msg>DOS Digium Asterisk SIP sscanf denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>30869</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2928</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9830</filter1>
        <filter2>flow:to_server,established; content:&quot;Accept-Language&quot;; fast_pattern:only; pcre:&quot;/^Accept-Language\s*\x3a\s*([^\x2c\x2d\n]+[\x2c\x2d]){16}/im&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>16213</id>
        <msg>EXPLOIT Red Hat Directory Server Accept-Language HTTP header parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35812</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2009-2622</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;-100&quot;; fast_pattern:only; content:&quot;HTTP&quot;; offset:0; nocase; pcre:&quot;/^HTTP[^\n]+\x2D100/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:denial-of-service;</filter2>
        <id>16214</id>
        <msg>DOS Squid Proxy invalid HTTP response code denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;/sso/jsp/login.jsp?&quot;; nocase; content:&quot;site2pstoretoken&quot;; distance:0; nocase; pcre:&quot;/^GET\s+\x2Fsso\x2Fjsp\x2Flogin\x2Ejsp\x3F[^\s\x0D\x0A]*site2pstoretoken\x3D[^\x26\x0D\x0A]*(\x22|\x2522)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16215</id>
        <msg>ORACLE Oracle Application Server Portal cross site scripting attempt</msg>
        <url>secunia.com/advisories/33761</url>
      </rule>
      <rule>
        <bugtraq>34738</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2438</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2954</filter1>
        <filter2>flow:to_server,established; content:&quot;45 10 10 1073741824 4 aaa&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16217</id>
        <msg>SPECIFIC-THREATS HP OpenView Network Node Manager ovalarmsrv opcode 45 integer overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3678</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.bmp; metadata: engine shared, soid 3|16222, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16222</id>
        <msg>WEB-CLIENT Malformed BMP dimensions arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-043.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2512</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [5357,5358]</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16227, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16227</id>
        <msg>WEB-MISC Web Service on Devices API 'WSDAPI' URL processing buffer corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-063.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2514</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; flowbits:isset,http.ttf; metadata: engine shared, soid 3|16232, service http, policy security-ips drop;</filter2>
        <id>16232</id>
        <msg>WEB-CLIENT Windows TrueType font file parsing integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-065.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/in.php&quot;; http_uri; content:&quot;url=&quot;; http_uri; content:&quot;affid=&quot;; http_uri; flowbits:set,systemsecurity2009; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>16254</id>
        <msg>BACKDOOR rogue software system security 2009 installtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453154339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1503</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 00|&quot;; depth:7; offset:1; content:&quot;|AA AA AA AA|&quot;; within:4; distance:4; fast_pattern; flowbits:set,SRat_1.6; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>16270</id>
        <msg>BACKDOOR srat 1.6 runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.ttf&quot;; nocase; http_uri; flowbits:set,http.ttf; flowbits:noalert; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>16286</id>
        <msg>WEB-MISC TrueType font file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-3676</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|00 00 00 9A FE|SMB&quot;; depth:8; isdataat:126,relative; content:&quot;|1E 00| LM `|1C|&quot;; within:8; distance:118; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16287</id>
        <msg>SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server; content:&quot;/l1/ms32clod.dll&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16289</id>
        <msg>BACKDOOR Clob bot traffic</msg>
        <url>www.threatexpert.com/report.aspx?md5=1474e6d74aa29127c5d6df716650d724</url>
      </rule>
      <rule>
        <bugtraq>14998</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-3142</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;MSCF&quot;; byte_test:2,&amp;,0x0003,26,relative,little; byte_test:2,!&amp;,0x0004,26,relative,little; pcre:&quot;/^.{32}([^\x00]*\x00)?[^\x00]{256}/sR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16295</id>
        <msg>WEB-CLIENT Kaspersky antivirus library heap buffer overflow - without optional fields</msg>
      </rule>
      <rule>
        <bugtraq>14998</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-3142</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|0D 0A 0D 0A|MSCF&quot;; byte_test:2,&amp;,0x0003,26,relative,little; byte_test:2,&amp;,0x0004,26,relative,little; byte_jump:2,32,relative,little; pcre:&quot;/^.{2}([^\x00]*\x00)?[^\x00]{256}/sR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16296</id>
        <msg>WEB-CLIENT Kaspersky antivirus library heap buffer overflow - with optional fields</msg>
      </rule>
      <rule>
        <bugtraq>13120</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0553</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;createComment&quot;; pcre:&quot;/(\w+)\s*=\s*\w+\.createComment\(((\x22\x22|\x27\x27)|([A-z]\w*))\)\s*\;.*?\w+\.(insertBefore|insertAfter|appendChild)\(\1\)\;|\w\.(insertBefore|insertAfter|appendChild)\(\w+\.createComment\(((\x22\x22|\x27\x27)|([A-z]\w*))\)/s&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16300</id>
        <msg>WEB-CLIENT HTML DOM invalid DHTML comment creation attempt</msg>
        <nessus>10861</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms05-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>37085</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4054</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;getElement&quot;; nocase; content:&quot;outerHTML&quot;; nocase; content:&quot;overflow&quot;; fast_pattern; nocase; pcre:&quot;/([^\s]+)\s*=\s*document\.getElement\w+\s*\x28\s*([\x22\x27])STYLE\2.*\1\.outerHTML/si&quot;; pcre:&quot;/\x7b[^\x7d]*(overflow[^\x7d]*margin\s*\x3a\s*0\s*\x3b|margin\s*\x3a\s*0\s*\x3b[^\x7d]*overflow)/si&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16310</id>
        <msg>WEB-CLIENT IE 6/7 outerHTML invalid reference arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <bugtraq>37085</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4054</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document.getElementsByTagName|28|'STYLE'|29|[0].outerHTML&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16311</id>
        <msg>WEB-CLIENT IE 6/7 single line outerHTML invalid reference arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-072.mspx</url>
      </rule>
      <rule>
        <bugtraq>34671</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1429</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12174</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; byte_test:5,&gt;,0,0,relative,dec,string; pcre:&quot;/^\x00{4}[\x30-\x39]+\x00[\x09\x20-\x7E]+\x00/&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16332</id>
        <msg>EXPLOIT Symantec System Center Alert Management System arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>37167</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3608</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;Type/ObjStm&quot;; nocase; pcre:&quot;/Type\x2FObjStm[^&gt;]*?\x2FN\s+\d{7}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16335</id>
        <msg>WEB-CLIENT xpdf ObjectStream integer overflow</msg>
      </rule>
      <rule>
        <bugtraq>33258</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0173</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:to_server,established; content:&quot;|24 14|&quot;; byte_test:1,=,0xd0,-8,relative; byte_test:1,&amp;,4,-7,relative; byte_test:1,!&amp;,3,-7,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16341</id>
        <msg>EXPLOIT IBM DB2 Database Server invalid data stream denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-activity; flowbits:isset,http.pdf; metadata: engine shared, soid 3|16343, service http, policy security-ips drop, policy balanced-ips drop;</filter2>
        <id>16343</id>
        <msg>WEB-CLIENT obfuscated header in PDF</msg>
        <url>www.adobe.com/devnet/acrobat/pdfs/PDF32000_2008.pdf</url>
      </rule>
      <rule>
        <bugtraq>36588</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;[Setnet32]&quot;; fast_pattern; nocase; content:&quot;HostSize=&quot;; distance:0; byte_test:4,&gt;,296,0,relative,dec,string; pcre:&quot;/HostList=([^\r\n\x3B]{,296}\x3B)*[^\r\n\x3B]{297}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16345</id>
        <msg>WEB-CLIENT IBM Informix Client SDK NFX file HostList processing stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36588</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3691</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;[Setnet32]&quot;; fast_pattern; nocase; content:&quot;ServerSize=&quot;; distance:0; byte_test:4,&gt;,293,0,relative,dec,string; pcre:&quot;/InformixServerList=([^\r\n\x3B]{,293}\x3B)*[^\r\n\x3B]{294}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16346</id>
        <msg>WEB-CLIENT IBM Informix Client SDK NFX file InformixServerList processing stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>36465</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;OggS&quot;; content:&quot;|82|theora&quot;; distance:0; byte_test:1,!&amp;,0xE0,0,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16353</id>
        <msg>WEB-CLIENT FFmpeg OGV file format memory corruption attempt</msg>
        <url>secunia.com/advisories/36805</url>
      </rule>
      <rule>
        <bugtraq>36703</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-3604</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; content:&quot;/Subtype&quot;; content:&quot;/Image&quot;; within:20; content:&quot;/FlateDecode&quot;; pcre:&quot;/\x3C{2}(?=[^\x3E]*\x2F(Height|Width)\s*\d{6})(?=[^\x3E]*\x2FFlateDecode)[^\x3E]*\x2FSubtype\s*\x2FImage/&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16355</id>
        <msg>WEB-CLIENT Xpdf Splash DrawImage integer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/evil/services/bid_register.php?BID=&quot;; nocase; http_uri; pcre:&quot;/\x2Fevil\x2Fservices\x2Fbid_register\x2Ephp\x3FBID\x3D[A-Za-z]{6}\x26IP\x3D\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x26cipher\x3D[A-Za-z]{9}/smiU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16362</id>
        <msg>SPECIFIC-THREATS SpyForms malware call home attempt</msg>
        <url>threatexpert.com/report.aspx?md5=acf30e13cbcf7eafc8475e976f7af3ec</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nbok01/&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16365</id>
        <msg>SPECIFIC-THREATS Trojan OnlineGames download atttempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=6f489b3bd2ccbbf4ff8ad0c744f7be34</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 443</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF FF FF FF 00 00 FE FF FF FF FF FF FF FF FF FF 88 FF|&quot;; depth:20; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16368</id>
        <msg>BOTNET-CNC Hydraq/Aurora connection to C&amp;C server attempt</msg>
        <url>www.virustotal.com/analisis/9051f618a5a8253a003167e65ce1311fa91a8b70d438a384be48b02e73ba855c-1263878624</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16375, service ldap, policy security-ips drop;</filter2>
        <id>16375</id>
        <msg>EXPLOIT LDAP object parameter name buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30935</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-3697</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8222</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; depth:4; nocase; content:&quot;.pl&quot;; nocase; pcre:&quot;/^content-length\s*\x3A/mi&quot;; byte_test:10,&gt;,49152,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16384</id>
        <msg>DOS VMware Server ISAPI Extension remote denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server; content:&quot;user_id=&quot;; nocase; http_uri; content:&quot;version_id=&quot;; nocase; http_uri; content:&quot;passphrase=&quot;; http_uri; content:&quot;socks=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;crc=&quot;; nocase; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16391</id>
        <msg>BOTNET-CNC Gozi Trojan connection to C&amp;C attempt</msg>
        <url>www.virustotal.com/de/analisis/02e2428657cc20c9206b92474157e59e64d348b47d69dd320cb5e909e9150b99-1264446753</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0027</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16414, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16414</id>
        <msg>WEB-CLIENT Windows Shell Handler remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-007.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0028</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.jpeg; metadata: engine shared, soid 3|16422, service http, policy security-ips drop;</filter2>
        <id>16422</id>
        <msg>EXPLOIT JPEG with malformed SOFx field</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-005</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0555</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16423, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16423</id>
        <msg>WEB-CLIENT IE7/8 execute local file in Internet zone redirect attempt</msg>
        <url>www.microsoft.com/technet/security/advisory/980088.mspx</url>
      </rule>
      <rule>
        <bugtraq>37926</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0073</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5556</filter1>
        <filter2>flow:established,to_server; content:&quot;EXECSCRIPT&quot;; nocase; pcre:&quot;/^EXECSCRIPT\s+\.\.[\x2F\x5C]\.\./smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16438</id>
        <msg>ORACLE WebLogic Server Node Manager arbitrary command execution attempt</msg>
        <url>www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| _TEST_&quot;; http_header; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16439</id>
        <msg>BOTNET-CNC Possible Zeus User-Agent - _TEST_</msg>
        <url>en.wikipedia.org/wiki/Zeus_(trojan_horse)</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| ie|0D 0A|&quot;; http_header; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16440</id>
        <msg>BOTNET-CNC Possible Zeus User-Agent - ie</msg>
        <url>en.wikipedia.org/wiki/Zeus_(trojan_horse)</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| Download|0D 0A|&quot;; http_header; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16441</id>
        <msg>BOTNET-CNC Possible Zeus User-Agent - Download</msg>
        <url>en.wikipedia.org/wiki/Zeus_(trojan_horse)</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-1661</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1100</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 02 00 01|'0&quot;; depth:6; content:&quot;|1E 00 00 00 01 00 01 00 00 01 F4|AAAAAAAAA&quot;; within:20; distance:45; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16444</id>
        <msg>SPECIFIC-THREATS HP StorageWorks storage mirroring double take service code execution attempt</msg>
        <url>h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01362558</url>
      </rule>
      <rule>
        <bugtraq>28901</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-1897</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4569</filter1>
        <filter2>flow:to_server; content:&quot;|80 EB 00 00 00 00 00 0A 00 00 06 04|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16445</id>
        <msg>SPECIFIC-THREATS Digium Asterisk IAX2 ack response denial of service attempt</msg>
        <url>downloads.digium.com/pub/security/AST-2008-006.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0483</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;vbscript&quot;; nocase; content:&quot;.hlp&quot;; nocase; content:&quot;|5C|&quot;; pcre:&quot;/\\\\[^\x20\x0a\x0d]*\.hlp/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16452</id>
        <msg>WEB-CLIENT IE .hlp samba share download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-3676</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; dsize:4; content:&quot;|00 00 00 9A|&quot;; depth:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16454</id>
        <msg>SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt - empty SMB 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Ryeol HTTP Client Class&quot;; nocase; http_header; content:&quot;jaiku.com&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3A\s+Ryeol\s+HTTP\s+Client\s+Class/smiH&quot;; pcre:&quot;/^Host\x3A\s+.*jaiku\x2Ecom/smiH&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16459</id>
        <msg>BOTNET-CNC Trojan command and control communication attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=9a546564bf213ff866f48848f0f14027</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;&amp;c_ms=&quot;; nocase; http_uri; content:&quot;&amp;c_hi=&quot;; http_uri; content:&quot;&amp;c_fb=&quot;; http_uri; content:&quot;&amp;c_tg=&quot;; http_uri; metadata:impact_flag red, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16483</id>
        <msg>BOTNET-CNC Koobface worm submission of collected data to C&amp;C server attempt</msg>
        <url>threatexpert.com/report.aspx?md5=18395e9476bde417692f3a7ab807ac44</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; http_method; content:&quot;/cap/?a=get&amp;i=&quot;; nocase; http_uri; pcre:&quot;/\d+&amp;/miR&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16484</id>
        <msg>BOTNET-CNC Koobface contact to C&amp;C server attempt</msg>
        <url>threatexpert.com/report.aspx?md5=efbc47d5e8f3ed68a13968cda586d68d</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; http_method; content:&quot;/cap/temp/&quot;; nocase; http_uri; pcre:&quot;/^\x2Fcap\x2Ftemp\x2F[A-Za-z0-9]+\x2Ejpg/miU&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16485</id>
        <msg>BOTNET-CNC Koobface request for captcha attempt</msg>
        <url>threatexpert.com/report.aspx?md5=efbc47d5e8f3ed68a13968cda586d68d</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-0103</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;|C2 E5 E5 E5 9E DD A4 A3 D4 A6 D4 D3 D1 C8 A0 A7 A1 D3 C8 D1 87 D7 87 C8 A7 A6 D4 A3 C8 D3 D1 D3 D2 D1 A0 DC DD A4 D2 D4 D5 98 E5|&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16486</id>
        <msg>SPECIFIC-THREATS Arucer backdoor traffic - command execution attempt</msg>
        <url>www.virustotal.com/analisis/1c7f6f75617dd69a68d60224277a17f0720e7d68e4d321b7ae246f9c7dd2cfcf-1268074309</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-0103</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;|C2 E5 E5 E5 9E A0 D7 A4 A6 D0 D5 DD DC C8 D6 DD D7 D5 C8 D1 D6 83 80 C8 DD A4 D1 A1 C8 A4 D2 D5 D7 DD A3 A4 A1 DD A6 D7 DD 98 E5|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16487</id>
        <msg>SPECIFIC-THREATS Arucer backdoor traffic - yes command attempt</msg>
        <url>www.virustotal.com/analisis/1c7f6f75617dd69a68d60224277a17f0720e7d68e4d321b7ae246f9c7dd2cfcf-1268074309</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <cve>2010-0103</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;|C2 E5 E5 E5 9E DC DD A1 DC D0 DD A3 A6 C8 A1 D5 A4 D7 C8 D1 83 D4 86 C8 A7 DD D1 D4 C8 D7 D6 D7 A4 A7 D6 D0 D2 A0 D2 A6 DD 98 E5|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16488</id>
        <msg>SPECIFIC-THREATS Arucer backdoor traffic - write file attempt</msg>
        <url>www.virustotal.com/analisis/1c7f6f75617dd69a68d60224277a17f0720e7d68e4d321b7ae246f9c7dd2cfcf-1268074309</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;&amp;wr=&quot;; http_uri; content:&quot;/reg?&quot;; http_uri; pcre:&quot;/\x26tv\x3d\d\.\d\.\d{4}\.\d{4}/smiU&quot;; pcre:&quot;/u=[\dA-Fa-f]{8}/smiU&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16489</id>
        <msg>SPYWARE-PUT Bobax botnet contact to C&amp;C server attempt</msg>
        <url>threatexpert.com/report.aspx?md5=89f6a4c3973f54c2bee9f50f62428278</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;TT-Bot&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*TT-Bot/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16493</id>
        <msg>SPYWARE-PUT TT-bot botnet contact to C&amp;C server attempt</msg>
        <url>anubis.iseclab.org/index.php?action=result&amp;format=html&amp;task_id=1494581651ca480640538ead93feabed2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;spm/page.php?&quot;; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;tick=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;smtp=&quot;; nocase; http_uri; content:&quot;task=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16494</id>
        <msg>SPYWARE-PUT Cutwail spambot server communication attempt</msg>
        <url>threatexpert.com/report.aspx?md5=0ecab7ac6e393be442cd834f9573622b</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;spm/s_alive.php?&quot;; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;tick=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;smtp=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16495</id>
        <msg>SPYWARE-PUT Rustock botnet contact to C&amp;C server attempt</msg>
        <url>threatexpert.com/report.aspx?md5=2a375d5f8ee2fe851f9b6407ae0d00e0</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update&quot;; nocase; http_uri; content:&quot;Mozilla/4.75&quot;; fast_pattern; nocase; http_header; pcre:&quot;/\x2Fupdate\w\x2Ephp\x3Fp\x3D\d+.*User\x2DAgent\x3A\s+Mozilla\x2F4\x2E75\s\x5Ben\x5D\s\x28X11\x3B\sU\x3B\sLinux\s2\x2E2\x2E16\x2D3\si686\x29/smiH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16496</id>
        <msg>SPYWARE-PUT Trojan hacktool attempt to contact server</msg>
        <url>www.threatexpert.com/report.aspx?md5=f602982724b3562b80f435f0d87c6a5f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|User-Agent|3A| Tear Application&quot;; fast_pattern; nocase; http_header; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16497</id>
        <msg>SPYWARE-PUT Tear Application downloader attempt to contact server</msg>
        <url>www.threatexpert.com/report.aspx?md5=48f1270338bc233839ffefa7e5eefde7</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files&quot;; nocase; http_uri; content:&quot;|29|.|28|t|29|&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16498</id>
        <msg>SPYWARE-PUT PC Antispyware 2010 FakeAV download/update attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=37fa737aab25dd0d90cd0821538fae15</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3974</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1000:</filter1>
        <filter2>flow:to_server,established; content:&quot;sys.olapimpl_t.odcitablestart|28|&quot;; nocase; pcre:&quot;/sys\x2eolapimpl\x5ft\x2eodcitablestart\x28[^\x2c]+\x2c[^\x2c]+\x2c\x27?[^\x2c\x27]{303}/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16516</id>
        <msg>ORACLE Database sys.olapimpl_t package odcitablestart overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33555</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0184</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-bittorrent&quot;; nocase; http_header; content:&quot;7|3A|comment&quot;; nocase; byte_test:6,&gt;,100000,0,relative,dec,string; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16517</id>
        <msg>WEB-CLIENT Free Download Manager .torrent parsing comment overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33555</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0184</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-bittorrent&quot;; nocase; http_header; content:&quot;8|3A|announce&quot;; nocase; byte_test:6,&gt;,100000,0,relative,dec,string; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16518</id>
        <msg>WEB-CLIENT Free Download Manager .torrent parsing announce overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33555</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0184</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-bittorrent&quot;; nocase; http_header; content:&quot;4|3A|name&quot;; nocase; byte_test:6,&gt;,10000,0,relative,dec,string; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16519</id>
        <msg>WEB-CLIENT Free Download Manager .torrent parsing name overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33555</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0184</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;application/x-bittorrent&quot;; nocase; http_header; content:&quot;4|3A|pathl&quot;; nocase; byte_test:6,&gt;,10000,0,relative,dec,string; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16520</id>
        <msg>WEB-CLIENT Free Download Manager .torrent parsing path overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33604</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0478</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; content:&quot; http/&quot;; nocase; pcre:&quot;/^[^\s]+\s+[^\s]+\s+http\x2f(\d+\x2e)?\d{10}/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16521</id>
        <msg>WEB-CLIENT Squid Proxy http version number overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 7382</filter1>
        <filter2>flow:to_server,established; content:&quot;JOIN |23|siwa&quot;; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16526</id>
        <msg>BOTNET-CNC VanBot IRC communication attempt</msg>
        <url>owned-nets.blogspot.com/2009/05/italianswiifatecihnocombaadshah-from.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dofyru.bmp&quot;; nocase; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16527</id>
        <msg>BOTNET-CNC Zbot malware config file download request</msg>
        <url>www.threatexpert.com/report.aspx?md5=4cc069b84270be48bd84b7068dc3bf1a</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/reklam/config&quot;; nocase; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16528</id>
        <msg>BOTNET-CNC Zbot malware config file download request</msg>
        <url>www.threatexpert.com/report.aspx?md5=2a2419d34c7990297d9a2f7413a9af2a</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pjpeg&quot;; nocase; http_uri; flowbits:set,http.jpeg; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>16529</id>
        <msg>WEB-MISC JPEG file download attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0487</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16530, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16530</id>
        <msg>WEB-CLIENT CAB SIP authenticode alteration attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-019.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;malware&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*malware/miH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16551</id>
        <msg>SPYWARE-PUT Malware contact to server attempt</msg>
        <url>www.virustotal.com/analisis/c55e2acfed1996ddbd17ddd4cba57530dd34c207be9f9b327fa3fdbb10cdaa7c-1270750352</url>
      </rule>
      <rule>
        <bugtraq>34134</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0921</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/OVCgi/Toolbar.exe&quot;; nocase; http_uri; content:&quot;Cookie|3A|&quot;; http_header; content:&quot;OvAcceptLang=&quot;; http_header; pcre:&quot;/^Cookie\x3a\s*[^\n]*OvAcceptLang\x3d[^\x3b\n]{300}/smH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16555</id>
        <msg>WEB-MISC HP Openview Network Node Manager OvAcceptLang overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/s/im.php&quot;; nocase; http_uri; flowbits:set,lmageshack.request; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>16556</id>
        <msg>SPECIFIC-THREATS 2imaegshack/lmageshack IM worm get request attempt</msg>
        <url>anubis.iseclab.org/?action=result&amp;task_id=1d4d78a7507bb63143d45d2a5898fe3bf&amp;format=html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET [4244,10369] -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;get5.lost|0D 0A|&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16558</id>
        <msg>SPECIFIC-THREATS SdBot IRC Trojan server to client communication attempt</msg>
        <url>anubis.iseclab.org/?action=result&amp;task_id=1418ebbc56c0b5a34c11afd1af2ba9881&amp;format=html</url>
      </rule>
      <rule>
        <bugtraq>21206</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6063</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;ASX VERSION=|22|3|22|&gt;&quot;; nocase; content:&quot;&lt;Entry&gt;&quot;; distance:0; nocase; content:&quot;&lt;ref href=|22|file|3A|//&quot;; distance:0; nocase; pcre:&quot;/^\S{501}/R&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16582</id>
        <msg>WEB-CLIENT Un4seen Developments XMPlay crafted ASX file buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>21206</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6063</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;ASX VERSION=|22|3|22|&gt;&quot;; nocase; content:&quot;&lt;Entry&gt;&quot;; distance:0; nocase; content:&quot;&lt;ref href=|22|file|3A|//&quot;; distance:0; nocase; pcre:&quot;/^\S{501}/R&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16583</id>
        <msg>WEB-CLIENT Un4seen Developments XMPlay crafted ASX file buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;&lt;=2035&quot;; fast_pattern:only; content:&quot;window.location=&quot;; content:&quot;'.html'|3B|&quot;; within:30; nocase; content:&quot;classid=|22|&quot;; distance:0; nocase; content:&quot;.dll|23|&quot;; within:100; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16598</id>
        <msg>SPECIFIC-THREATS Green Dam URL handling overflow attempt</msg>
        <url>secunia.com/advisories/35435</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;Google Bot&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3A\s*Google\sBot/smiH&quot;; metadata:policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16600</id>
        <msg>BACKDOOR Otlard Trojan activity</msg>
        <url>www.threatexpert.com/report.aspx?md5=19354eda9db43a501b7172489d67d454</url>
      </rule>
      <rule>
        <bugtraq>37261</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-4179</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/OVCgi/ovalarm.exe&quot;; nocase; http_uri; content:&quot;OVABverbose=&quot;; nocase; http_uri; pcre:&quot;/^(true|on)/iR&quot;; pcre:&quot;/(Cookie\s*\x3A\s*[^\n]*OvAcceptLang\s*\x3D\s*[^\x3B\n]{69}|Accept-Language\s*\x3A\s*[^\n]{69})/iH&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16604</id>
        <msg>WEB-MISC HP OpenView Network Node Manager ovalarm.exe Accept-Language buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1016</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 443</filter1>
        <filter2>flow:to_server,established; isdataat:100; content:&quot;|16 03|&quot;; depth:2; content:&quot;|0B|&quot;; within:1; distance:3; byte_test:2,&gt;,3072,-3,relative; byte_test:3,&gt;,3072,3,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>16606</id>
        <msg>ORACLE BEA WebLogic Server Plug-ins Certificate overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-0217</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:misc-attack; metadata: engine shared, soid 3|16636, policy security-ips drop;</filter2>
        <id>16636</id>
        <msg>MISC .NET framework XMLDsig data tampering attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-041.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2010-1264</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 80</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|16660, service http, policy security-ips drop;</filter2>
        <id>16660</id>
        <msg>DOS SharePoint Server 2007 help.aspx denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-039.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1879</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.avi; metadata: engine shared, soid 3|16661, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>16661</id>
        <msg>EXPLOIT quartz.dll MJPEG content processing memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-033.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2E|php|3F|guid|3D|&quot;; nocase; http_uri; content:&quot;ccrc|3D|&quot;; fast_pattern; nocase; http_uri; content:&quot;ver|3D|&quot;; nocase; http_uri; content:&quot;stat|3D|&quot;; nocase; http_uri; content:&quot;cpu|3D|&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16669</id>
        <msg>SPYWARE-PUT Spyeye bot contact to C&amp;C server attempt</msg>
        <url>www.threatexpert.com/report.aspx?md5=84714c100d2dfc88629531f6456b8276</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2E|sys|2F 3F|getexe|3D|&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>16670</id>
        <msg>SPYWARE-PUT Koobface worm executable download attempt</msg>
        <url>www.virustotal.com/analisis/c55e2acfed1996ddbd17ddd4cba57530dd34c207be9f9b327fa3fdbb10cdaa7c-1270750352</url>
      </rule>
      <rule>
        <bugtraq>8375</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2003-0727</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization|3A|&quot;; pcre:&quot;/^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s[^\n]{512}/smi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>16681</id>
        <msg>WEB-MISC Basic Authorization string overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2009-2445</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.jsp&quot;; nocase; http_uri; content:&quot;|3A 3A 24|DATA&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>16682</id>
        <msg>WEB-MISC Sun ONE Web Server JSP source code disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>34803</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-4828</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1584</filter1>
        <filter2>flow:to_server,established; content:&quot;|08 A5 00 01|&quot;; depth:4; offset:2; pcre:&quot;/^.{2}\x08\xa5\x00\x01.{14}(([^\x00]|\x00[\x81-\xFF])|.{4}([^\x00]|\x00[\x81-\xFF]))/s&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16685</id>
        <msg>EXPLOIT IBM Tivoli Storage Manager Client dsmagent.exe NodeName length buffer overflow attempt</msg>
        <url>www-01.ibm.com/support/docview.wss?uid=swg21384389</url>
      </rule>
      <rule>
        <bugtraq>34001</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2009-0855</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9060</filter1>
        <filter2>flow:to_server, established; content:&quot;/ibm/console/&quot;; content:&quot;script&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>16686</id>
        <msg>WEB-CLIENT IBM WebSphere application server cross site scripting attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2010-0475</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established, to_server; content:&quot;/esp/editUser.esp&quot;; fast_pattern; nocase; http_uri; content:&quot;role=&quot;; nocase; http_uri; pcre:&quot;/[\x3f\x26]role=[^\x26]*?[^\x26a-z0-9\x5b\x5d\x2d]/Usmi&quot;; metadata:policy security-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>16689</id>
        <msg>WEB-CLIENT Palo Alto Networks Firewall editUser.esp XSS attempt</msg>
        <url>osvdb.org/show/osvdb/64717</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.plf&quot;; nocase; http_uri; flowbits:set,http.plf; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>16691</id>
        <msg>WEB-CLIENT PLF playlist file download request</msg>
      </rule>
      <rule>
        <bugtraq>35732</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2534</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SETUP&quot;; depth:5; nocase; pcre:&quot;/^\s+(rtsp\x3a\x2f{2}|\x2f+)\s+/iR&quot;; metadata:policy security-ips drop, service rtsp; classtype:attempted-dos;</filter2>
        <id>16694</id>
        <msg>DOS RealNetworks Helix Server RTSP SETUP request denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2F 3F|b|3D|1s1&quot;; fast_pattern; nocase; http_uri; content:&quot;Mozilla&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3A\s*Mozilla\x0d?$/smiH&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>16695</id>
        <msg>SPYWARE-PUT Rogue AV download/update atttempt</msg>
        <url>www.virustotal.com/analisis/2063df10f553afa6b1257e576fbf88cf98093ec1ae15c079e947994a96fbfadd-1274312088</url>
      </rule>
      <rule>
        <bugtraq>21657</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6665</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|3C|DeepBurner_record&quot;; nocase; content:&quot;|3C|data_cd&quot;; distance:0; nocase; content:&quot;|3C|file&quot;; distance:0; nocase; pcre:&quot;/^\s*[^\x3E]*path\s*=\s*(\x22[^\x22]{272}|\x27[^\x27]{272}|[^\s\x3E]{272})/iR&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16696</id>
        <msg>WEB-CLIENT Astonsoft Deepburner dbr file name buffer overflow attempt</msg>
        <url>osvdb.org/show/osvdb/32356</url>
      </rule>
      <rule>
        <bugtraq>35731</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2533</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SET_PARAMETER&quot;; depth:13; content:&quot;DataConvertBuffer&quot;; distance:0; nocase; pcre:!&quot;/^Content-Length\s*\x3A\s*[1-9]/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service rtsp; classtype:attempted-dos;</filter2>
        <id>16709</id>
        <msg>DOS RealNetworks Helix Server RTSP SET_PARAMETERS empty DataConvertBuffer header denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>35673</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1975</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7001</filter1>
        <filter2>flow:to_server,established; content:&quot;|2F|consolehelp|2F|console-help|2E|portal&quot;; nocase; content:&quot;searchQuery|3D|&quot;; distance:0; nocase; pcre:&quot;/^[^\x26\s]*(\x3e|\x253e)/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16710</id>
        <msg>EXPLOIT Oracle BEA Weblogic server console-help.portal cross-site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>35681</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1968</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777</filter1>
        <filter2>flow:to_server,established; content:&quot;search|2F|query|2F|search&quot;; nocase; content:&quot;search_p_groups|3D|&quot;; distance:0; nocase; pcre:&quot;/^[^\x26\s]*(\x3e|\x253e)/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16717</id>
        <msg>ORACLE Oracle Secure Enterprise Search search_p_groups cross-site scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>24330</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2864</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;MSCF&quot;; within:4; byte_test:2,=,1,24,relative,little; byte_jump:4,12,relative,post_offset -20,little; pcre:&quot;/^.{16}[^\x00]{256}/sR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16719</id>
        <msg>WEB-CLIENT CA multiple product AV engine CAB header parsing stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>31813</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-4654</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|F5 46 7A BD 00 00 00 02 00 02 00 00|&quot;; within:12; byte_test:4,&gt;,32,8,relative,big; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16720</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player TY processing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>38436</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2010-0688</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;OrbitalFileV1.0|0D 0A|&quot;; within:17; pcre:&quot;/^[^\h\x00]{512}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16721</id>
        <msg>WEB-CLIENT Orbital Viewer .orb stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;ActiveXObject|28 27|APWebGrabber.Object|27 29 3B|&quot;; fast_pattern:only; nocase; content:&quot;unescape|28 27 25|u&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16725</id>
        <msg>SPECIFIC-THREATS ActivePDF WebGrabber APWebGrb.ocx GetStatus method overflow attempt</msg>
        <url>osvdb.org/show/osvdb/64579</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;Mjik&quot;; within:4; pcre:&quot;/^[^\s\x00]{512}/R&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16726</id>
        <msg>WEB-CLIENT gAlan malformed file stack overflow attempt</msg>
        <url>osvdb.org/60897</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4265</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|0D 0A|[Group,Export,Yes]|0D 0A|&quot;; within:22; content:&quot;Computer=&quot;; distance:0; pcre:&quot;/^[^\s\x00]{512}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16727</id>
        <msg>WEB-CLIENT IDEAL Administration IPJ file handling stack overflow attempt</msg>
        <url>osvdb.org/show/osvdb/60681</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3214</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;Photodex|28|R|29| ProShow|28|TM|29| Show File Version&quot;; within:41; content:&quot;cell[0].images[0].image=&quot;; distance:0; isdataat:512,relative; content:!&quot;|0A|&quot;; within:512; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16730</id>
        <msg>WEB-CLIENT ProShow Gold PSH file handling overflow attempt</msg>
        <url>osvdb.org/show/osvdb/57226</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3214</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;ProShow Gold - Built-In Content/Backgrounds/Abstract_02.jpgAAAAAAAAAAAAAAA&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16731</id>
        <msg>SPECIFIC-THREATS ProShow Gold PSH file handling overflow attempt</msg>
        <url>osvdb.org/show/osvdb/57226</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-3861</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|5B|HKEY_LOCAL_MACHINE|5C|SOFTWARE|5C|IRE|5C|SafeNet|2F|Soft-PK|5C|ACL|5C|GROUPDEFS|5C|_SafeNet_Default_Group|5D|&quot;; content:&quot;|22|GROUPNAME|22 3D 22|&quot;; distance:0; isdataat:256,relative; content:!&quot;|22|&quot;; within:256; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16732</id>
        <msg>WEB-CLIENT SafeNet SoftRemote multiple policy file local overflow attempt</msg>
        <url>osvdb.org/show/osvdb/59724</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1260</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;[CloneCD]&quot;; within:9; content:&quot;INDEX 1=&quot;; distance:0; isdataat:256,relative; content:!&quot;|0A|&quot;; within:256; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16733</id>
        <msg>WEB-CLIENT UltraISO CCD file handling overflow attempt</msg>
        <url>osvdb.org/show/osvdb/53275</url>
      </rule>
      <rule>
        <bugtraq>24140</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2888</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;FILE |22|&quot;; within:6; isdataat:512,relative; content:!&quot;|22|&quot;; within:512; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16734</id>
        <msg>WEB-CLIENT UltraISO CUE file handling stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12352</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0308</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|D4 30 00 00 00 00 00 00 00 00 00 00 E0 30 00 00 F0 30 00 00 F8 30 00 00 00 31 00 00 00 00 00 00 78 02|&quot;; isdataat:256,relative; content:!&quot;|00|&quot;; within:256; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16735</id>
        <msg>SPECIFIC-THREATS URSoft W32Dasm Import/Export function buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>38815</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|34 87 01 00 00 00 00 00 25 5C 1F 85|&quot;; within:12; pcre:&quot;/^[^\x0a\x3d]{512}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16736</id>
        <msg>WEB-CLIENT VariCAD multiple products DWB file handling overflow attempt</msg>
        <url>osvdb.org/show/osvdb/63067</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;AAAAAAAA|EB 06 90 90 4B 3F 01 11 90 90 90 90|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16738</id>
        <msg>SPECIFIC-THREATS Xenorate Media Player XPL file handling overflow attempt - 2</msg>
        <url>osvdb.org/show/osvdb/57162</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.rdp&quot;; nocase; http_uri; flowbits:set,http.rdp; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>16742</id>
        <msg>WEB-MISC remote desktop configuration file download request</msg>
      </rule>
      <rule>
        <bugtraq>35273</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2011</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;dxstudio&quot;; fast_pattern:only; nocase; content:&quot;&lt;?xml&quot;; content:&quot;shell.execute&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16744</id>
        <msg>WEB-CLIENT DX Studio Player plug-in command injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>35500</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2484</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset, http.m3u.download; content:&quot;smb|3A 2F 2F|&quot;; pcre:&quot;/smb\x3A\x2F\x2F[^\s\x0D\x0A\x3C]{251}/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16751</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35500</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2484</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,xspf_file.request; content:&quot;smb|3A 2F 2F|&quot;; pcre:&quot;/smb\x3A\x2F\x2F[^\s\x0A\x0D\x3C]{251}/mi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16752</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35500</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2484</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; nocase; http_method; content:&quot;|2F|requests|2F|status.xml&quot;; nocase; http_uri; content:&quot;smb&quot;; http_uri; pcre:&quot;/^GET\s+.*\x2Frequests\x2Fstatus.xml\x3F.*smb\x3A\x2F\x2F[^\s\x0A\x0D]{251}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16753</id>
        <msg>WEB-CLIENT VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-5441</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 09 00|&quot;; depth:8; offset:12; content:!&quot;|00 00 00 00|&quot;; within:4; distance:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16777</id>
        <msg>ORACLE Secure Backup NDMP packet handling DoS attempt</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-5441</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10000</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00 00 00 09 02|&quot;; depth:8; offset:12; content:!&quot;|00 00 00 00|&quot;; within:4; distance:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>16778</id>
        <msg>ORACLE Secure Backup NDMP packet handling DoS attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-4850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;clsid|3A|17A54E7D-A9D4-11D8-9552-00E04CB09903&quot;; content:&quot;|3C|param name|3D 22|SceneURL|22| value|3D 22|http|3A 2F 2F|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16785</id>
        <msg>SPECIFIC-THREATS AwingSoft Winds3D Player SceneURL method command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>39895</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [5800,5900:5999]</filter1>
        <filter2>flow:to_server,established; flowbits:isset,vnc.traffic; content:&quot;|06 00 00 00|&quot;; depth:4; byte_test:1,&amp;,0x80,0,relative; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>16788</id>
        <msg>EXPLOIT RealVNC VNC Server ClientCutText message memory corruption attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0187</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;classid|3D 27|clsid|3A|3F1D494B-0CEF-4468-96C9-386E2E4DEC90|27|&quot;; content:&quot;String|28 27|http|3A 2F 2F|&quot;; distance:0; content:!&quot;|27|&quot;; within:255; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>16798</id>
        <msg>SPECIFIC-THREATS Orbit Downloader long URL buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-1135</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17041, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17041</id>
        <msg>WEB-MISC ISA Server OTP-based Forms-authorization fallback policy bypass attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-031.mspx</url>
      </rule>
      <rule>
        <bugtraq>34671</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1429</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12174</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 00|&quot;; depth:4; content:&quot;cmd /c&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17048</id>
        <msg>EXPLOIT Symantec Multiple Products Intel Common Base Agent CreateProcessA Function remote command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>41596</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0907</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php&quot;; nocase; http_uri; content:&quot;attempt&quot;; nocase; http_client_body; content:&quot;uname=&quot;; nocase; http_client_body; pcre:&quot;/uname\x3D[^\x26\x2D\s]*?\x2D/iP&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17049</id>
        <msg>WEB-MISC Oracle Secure Backup Administration Server authentication bypass attempt via POST</msg>
      </rule>
      <rule>
        <bugtraq>41596</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0907</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;login.php&quot;; nocase; http_uri; content:&quot;attempt&quot;; nocase; http_uri; content:&quot;uname=&quot;; nocase; http_uri; pcre:&quot;/uname\x3D[^\x26\x2D\s]*?\x2D/iU&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17050</id>
        <msg>WEB-MISC Oracle Secure Backup Administration Server authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0991</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1521</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 02 D4 20 08 FF 03 01 00 12|44444&quot;; content:&quot;|BC C3 CC 07 00 00 00 00|&quot;; distance:0; content:&quot;|00 00 00 00 00 00 00 00 89 C0 B1 C3 08 1D|&quot;; within:14; distance:4; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17055</id>
        <msg>SPECIFIC-THREATS Oracle Database DBMS TNS Listener denial of service attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</url>
      </rule>
      <rule>
        <bugtraq>33630</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|3C|opml&quot;; nocase; content:&quot;|3C|outline&quot;; distance:0; nocase; pcre:&quot;/[^\x3E]*?text\s*\x3D\s*(\x27[^\x27]{500}|\x22[^\x22]{500}|\S{500})/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17104</id>
        <msg>WEB-CLIENT FeedDemon OPML file handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33630</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0546</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|3C 00|o|00|p|00|m|00|l|00|&quot;; nocase; content:&quot;|3C 00|o|00|u|00|t|00|l|00|i|00|n|00|e|00|&quot;; distance:0; nocase; pcre:&quot;/[^\x3E]*?t\x00e\x00x\x00t\x00(\s\x00)*\x3D\x00(\s\x00)*(\x27\x00(?!(..){0,500}\x27\x00)|\x22\x00(?!(..){0,500}\x22\x00)|(?!(..){0,500}\s\x00))/isOR&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17105</id>
        <msg>WEB-CLIENT FeedDemon unicode OPML file handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>39077</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2010-0842</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;IREZ&quot;; within:4; content:&quot;MThd&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>17106</id>
        <msg>WEB-MISC download of RMF file - potentially malicious</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.asx&quot;; nocase; http_uri; flowbits:set,http.asx; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>17116</id>
        <msg>WEB-CLIENT asx file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17120, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17120</id>
        <msg>WEB-CLIENT rich text format unexpected field type memory corruption attempt 1</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17121, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17121</id>
        <msg>WEB-CLIENT rich text format unexpected field type memory corruption attempt 2</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17122, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17122</id>
        <msg>WEB-CLIENT rich text format unexpected field type memory corruption attempt 3</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-1902</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17123, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17123</id>
        <msg>WEB-CLIENT rich text format invalid field size memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2553</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.avi; metadata: engine shared, soid 3|17128, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17128</id>
        <msg>EXPLOIT Cinepak Codec VIDC decompression remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-055.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2557</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17130, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17130</id>
        <msg>WEB-CLIENT IE boundElements arbitrary code execution</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-053.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2559</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17131, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17131</id>
        <msg>WEB-CLIENT IE8 parent style rendering arbitrary code execution</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms10-053.mspx</url>
      </rule>
      <rule>
        <bugtraq>40298</bugtraq>
        <classtype>misc-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imc/report/DownloadReportSource&quot;; nocase; http_uri; content:&quot;fileName&quot;; http_uri; pcre:&quot;/fileName=.*?\x2E\x2E(\x2F|\x5C)/sI&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-attack;</filter2>
        <id>17137</id>
        <msg>WEB-MISC HP Intelligent Management Center information disclosure attempt</msg>
        <url>secunia.com/advisories/39891</url>
      </rule>
      <rule>
        <bugtraq>41327</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-2221</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1024:]</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01 00 08|&quot;; depth:4; content:&quot;|00 00 00 20|&quot;; within:4; distance:8; byte_test:4,&gt;,1008,0,relative,big; byte_test:2,&gt;,1024,4,big; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17138</id>
        <msg>EXPLOIT iSCSI target multiple implementations iSNS stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>41959</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 38292</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF FF|&quot;; depth:4; content:&quot;PRGX&quot;; within:4; distance:26; fast_pattern; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17139</id>
        <msg>EXPLOIT Symantec Alert Management System HNDLRSVC arbitrary command execution attempt</msg>
        <url>osvdb.org/show/osvdb/66807</url>
      </rule>
      <rule>
        <bugtraq>40428</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.avi; file_data; content:&quot;|50 4B 03 04|&quot;; within:4; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17148</id>
        <msg>WEB-CLIENT VideoLAN VLC renamed zip file handling code execution attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>40428</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp3; file_data; content:&quot;|50 4B 03 04|&quot;; within:4; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17149</id>
        <msg>WEB-CLIENT VideoLAN VLC renamed zip file handling code execution attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>40428</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.mp4; file_data; content:&quot;|50 4B 03 04|&quot;; within:4; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17150</id>
        <msg>WEB-CLIENT VideoLAN VLC renamed zip file handling code execution attempt - 3</msg>
      </rule>
      <rule>
        <bugtraq>40298</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imc/reportscript/sqlserver/deploypara.properties&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17157</id>
        <msg>WEB-MISC HP Intelligent Management Center database credentials information disclosure attempt - 1</msg>
        <url>secunia.com/advisories/39891</url>
      </rule>
      <rule>
        <bugtraq>40298</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rpt/reportscript/sqlserver/deploypara.properties&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17158</id>
        <msg>WEB-MISC HP Intelligent Management Center database credentials information disclosure attempt - 2</msg>
        <url>secunia.com/advisories/39891</url>
      </rule>
      <rule>
        <bugtraq>40298</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imc/reportscript/oracle/deploypara.properties&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17159</id>
        <msg>WEB-MISC HP Intelligent Management Center database credentials information disclosure attempt - 3</msg>
        <url>secunia.com/advisories/39891</url>
      </rule>
      <rule>
        <bugtraq>38084</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0557</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 19300</filter1>
        <filter2>flow:to_server,established; content:&quot;Authorization&quot;; offset:0; nocase; content:&quot;Basic&quot;; within:50; nocase; content:&quot;Y3hzZGs6a2RzeGM=&quot;; within:100; fast_pattern; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17207</id>
        <msg>EXPLOIT IBM Cognos Server backdoor account remote code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>38212</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2010-0639</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4827</filter1>
        <filter2>flow:to_server; byte_test:1,!&amp;,3,6; byte_test:1,&amp;,4,6; byte_test:1,!&amp;,8,6; content:&quot;|00 03|GET&quot;; depth:7; offset:14; nocase; content:!&quot;|3A 2F 2F|&quot;; within:30; distance:2; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17208</id>
        <msg>EXPLOIT Squid Proxy HTCP packet processing denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>14784</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2871</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;HREF=http://&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&amp;#xAD&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17219</id>
        <msg>SPECIFIC-THREATS Firefox domain name handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14784</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2871</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;HREF=https|3A AD AD AD AD AD AD AD AD AD AD AD AD AD|&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17220</id>
        <msg>SPECIFIC-THREATS Firefox domain name handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14784</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2871</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;HREF=https|3A|--------------------&quot;; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17221</id>
        <msg>SPECIFIC-THREATS Firefox domain name handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14784</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2871</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|22|http|3A 2F 2F 22 20 2B 0A|&quot;; nocase; content:&quot;|22|%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD|22|&quot;; within:100; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17222</id>
        <msg>SPECIFIC-THREATS Firefox domain name handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-2631</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3000</filter1>
        <filter2>flow:established,to_server; content:&quot;ComposeUser=Anyinvaliduser&quot;; depth:26; offset:150; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17225</id>
        <msg>SPECIFIC-THREATS Alt-N MDaemon WorldClient invalid user</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;II|2A 00|&quot;; within:4; flowbits:set,http.tiff.little; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>17229</id>
        <msg>WEB-CLIENT Tiff file download - little-endian</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;MM|00 2A|&quot;; within:4; flowbits:set,http.tiff.big; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>17230</id>
        <msg>WEB-CLIENT Tiff file download - big-endian</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SendEmail|2E|iq&quot;; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17234</id>
        <msg>SPECIFIC-THREATS VBMania mass mailing worm activity</msg>
        <url>www.virustotal.com/file-scan/report.html?id=fedb7b404754cf85737fb7e50f33324b84eb4c0b98024c7d3302039a901b04b7-1284133892</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|53 00 65 00 6E 00 64 00 45 00 6D 00 61 00 69 00 6C 00 2E 00 64 00 6C 00 6C 00 00 00|&quot;; content:&quot;|2E 00 69 00 71 00 00 00|&quot;; distance:0; content:&quot;|2E 00 69 00 71 00 00 00|&quot;; distance:0; content:&quot;|2E 00 69 00 71 00 00 00|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17235</id>
        <msg>SPECIFIC-THREATS VBMania mass mailing worm download attempt</msg>
        <url>www.virustotal.com/file-scan/report.html?id=fedb7b404754cf85737fb7e50f33324b84eb4c0b98024c7d3302039a901b04b7-1284133892</url>
      </rule>
      <rule>
        <bugtraq>37685</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xbm; file_data; content:&quot;|23|define&quot;; content:&quot;|5F|width&quot;; distance:0; pcre:&quot;/\x23define\s*(?=[\S]{57})\S*\x5Fwidth/&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17238</id>
        <msg>WEB-CLIENT ACD Systems ACDSee Products XBM file handling buffer overflow attempt</msg>
        <url>osvdb.org/show/osvdb/63643</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-2720</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|2A 2A 41 43 45 2A 2A|&quot;; within:7; distance:7; content:&quot;|01 80 1C 00 00 00 BE 02 00 00 C5 5A 08 33 20 00 00 00 80 98 92 84 02 03 0A 00 54 45 07 02|&quot;; distance:0; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17244</id>
        <msg>SPECIFIC-THREATS Antivirus ACE file handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.mov&quot;; nocase; http_uri; flowbits:set,http.quicktime; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>17259</id>
        <msg>WEB-CLIENT .mov file request</msg>
      </rule>
      <rule>
        <bugtraq>38115</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-0866</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;@DECLARE PERMS&quot;; nocase; content:&quot;java.io.filepermission&quot;; distance:0; nocase; content:&quot;execute&quot;; within:27; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17264</id>
        <msg>ORACLE Permission declaration exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>12793</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|13 00 00 00 46 53 43 1B 5B 32 50 4F 43 1B 5B 30 3B 35 39 2E 74 78 74 0B F0 66 66 E1 62 00 01 A3|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17266</id>
        <msg>SPECIFIC-THREATS Multiple vendor malformed ZIP archive Antivirus detection bypass attempt</msg>
        <url>lists.grok.org.uk/pipermail/full-disclosure/2005-March/032530.html</url>
      </rule>
      <rule>
        <bugtraq>12793</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|73 74 07 1B 5B 32 4A 1B 5B 32 3B 35 6D 1B 5B 31 3B 33 31 6D 48 41 43 4B 45 52 20 41 54 54 41 43|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17267</id>
        <msg>SPECIFIC-THREATS Multiple vendor malformed ZIP archive Antivirus detection bypass attempt</msg>
        <url>lists.grok.org.uk/pipermail/full-disclosure/2005-March/032530.html</url>
      </rule>
      <rule>
        <bugtraq>14757</bugtraq>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; file_data; content:&quot;Content-Disposition|3A 20|attachment&quot;; content:&quot;|55 45 73 44 42 41 6F 41 41 41 41 41 41 44 57 43|&quot;; distance:0; content:&quot;|42 55 41 54 43 30 33 4C 6E 70 70 63 46 56 55 43|&quot;; distance:0; content:&quot;|44 33 54 49 6E 51 39 30 79 4A 30 4E 56 65 41 51|&quot;; distance:0; metadata:policy security-ips drop, service smtp; classtype:attempted-dos;</filter2>
        <id>17275</id>
        <msg>SPECIFIC-THREATS Symantec Brightmail AntiSpam nested Zip handling denial of service attempt</msg>
        <url>ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/release_notes_p157.txt</url>
      </rule>
      <rule>
        <bugtraq>15291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1939</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8022</filter1>
        <filter2>flow:to_server,established; content:&quot;|2E 2E 2F 2E 2E 2F 2E 2E 2F|&quot;; depth:100; pcre:&quot;/^(GET|POST)\h+[^\n]*?\x2E\x2E\x2F\x2E\x2E\x2F\x2E\x2E\x2F[^\n]*?HTTP/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17279</id>
        <msg>WEB-MISC Ipswitch Whatsup Small Business directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>15291</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1939</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8022</filter1>
        <filter2>flow:to_server,established; content:&quot;|2E 2E 5C 2E 2E 5C 2E 2E 5C|&quot;; depth:100; pcre:&quot;/^(GET|POST)\h+[^\n]*?\x2E\x2E\x5C\x2E\x2E\x5C\x2E\x2E\x5C[^\n]*?HTTP/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17280</id>
        <msg>WEB-MISC Ipswitch Whatsup Small Business directory traversal attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-3922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|40 29 23 28 00 00 83 08 24 48 B0 A0 C1 83 08 13 2A 5C C8 B0 A1 C3 87 10 23 4A 9C 48 B1 A2 C5 8B|&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17281</id>
        <msg>SPECIFIC-THREATS Panda Antivirus ZOO archive decompression buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4335</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|1F A0 AB CD FF FF FF FF FF FF FF FF FF FF FF FF|&quot;; depth:16; rawbytes; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17289</id>
        <msg>SPECIFIC-THREATS GNU gzip LZH decompression make_table overflow attempt</msg>
        <url>secunia.com/advisories/21996/</url>
      </rule>
      <rule>
        <bugtraq>20588</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5340</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;sdo_lrs.convert_to_lrs_layer&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*\x27\s*[^\x2c\x29]/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17293</id>
        <msg>ORACLE sdo_lrs.convert_to_lrs_layer buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23558</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2137</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1918,6014,10110,14206,18302]</filter1>
        <filter2>flow:to_server,established; dsize:&gt;1002; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17298</id>
        <msg>MISC IBM Tivoli Monitoring Express Universal Agent Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>23738</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-2241</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $DNS_SERVERS 53</filter1>
        <filter2>content:&quot;|03 77 77 77 04 74 65 73 74 03 63 6F 6D 00 00 2E 00 01|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service dns; classtype:attempted-dos;</filter2>
        <id>17299</id>
        <msg>SPECIFIC-THREATS ISC BIND RRSIG query denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0318</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00|&quot;; content:&quot;|00 00 2E 70 65 74 69 74 65 00 00 D0 0D 00 00 30 FF FF A3 D1|&quot;; within:20; distance:288; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17305</id>
        <msg>SPECIFIC-THREATS ClamAV libclamav PE file handling integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17246</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1705</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;CREATE VIEW&quot;; nocase; content:&quot;FROM&quot;; distance:0; nocase; content:&quot;sys.te6sttable t1, sys.testtable t2&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17313</id>
        <msg>ORACLE database server crafted view privelege escalation attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; file_data; content:&quot;|D0 CF 11 E0 A1 B1 1A E1|&quot;; within:8; flowbits:set,http.ole; flowbits:noalert; metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>17314</id>
        <msg>WEB-CLIENT OLE Document file download</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|D9 E1 D9 34 24|&quot;; content:&quot;|E7 31 C9 66 81 E9|&quot;; distance:6; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17335</id>
        <msg>SHELLCODE x86 OS agnostic fnstenv geteip byte xor decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|EB 10|&quot;; content:&quot;|31 C9 66 81 E9|&quot;; distance:1; content:&quot;|E2 FA EB 05 E8 EB FF FF FF|&quot;; distance:5; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17336</id>
        <msg>SHELLCODE x86 OS agnostic call geteip byte xor decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|8B 6C 24 24 8B 45 3C 8B 7C 05 78 01 EF 8B 4F 18 8B 5F 20 01 EB 49 8B 34 8B|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17337</id>
        <msg>SHELLCODE x86 Win32 export table enumeration variant</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|6A|&quot;; content:&quot;|6B 3C 24 0B 60 03 0C 24 6A|&quot;; distance:1; content:&quot;03 0c 24 6a 04&quot;; distance:1; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17341</id>
        <msg>SHELLCODE x86 OS agnostic alpha UTF8 tolower avoidance decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;j|00|X|00|A|00|Q|00|A|00|D|00|A|00|Z|00|A|00|B|00|A|00|R|00|A|00|L|00|A|00|Y|00|A|00|I|00|A|00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17342</id>
        <msg>SHELLCODE x86 OS agnostic unicode mixed case decoder</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;Q|00|A|00|T|00|A|00|X|00|A|00|Z|00|A|00|P|00|U|00|3|00|Q|00|A|00|D|00|A|00|Z|00|A|00|B|00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:shellcode-detect;</filter2>
        <id>17343</id>
        <msg>SHELLCODE x86 OS agnostic unicode upper case decoder</msg>
      </rule>
      <rule>
        <bugtraq>14164</bugtraq>
        <classtype>string-detect</classtype>
        <cve>2005-2175</cve>
        <filter1>tcp $EXTERNAL_NET 110 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;&lt;SCRIPT&gt;|0D 0A|alert|28 22|&quot;; nocase; metadata:policy security-ips drop; classtype:string-detect;</filter2>
        <id>17346</id>
        <msg>SPECIFIC-THREATS IBM Lotus Notes Cross Site Scripting attempt</msg>
      </rule>
      <rule>
        <bugtraq>14319</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2372</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;f90servlet?form=&quot;; nocase; http_uri; pcre:&quot;/form=[cde]\x3a(\x5C|\x2F)/Ui&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17350</id>
        <msg>ORACLE Application Server Forms Arbitrary System Command Execution Attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.xbm&quot;; nocase; http_uri; flowbits:set,http.xbm; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>17359</id>
        <msg>WEB-CLIENT xbm image file download request</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0197</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.dmg; content:&quot;|00 00 00 00 4C 41 42 4C|&quot;; byte_test:2,&gt;,254,12,relative; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17363</id>
        <msg>WEB-CLIENT Apple computer finder DMG volume name memory corruption</msg>
      </rule>
      <rule>
        <bugtraq>14977</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2005-2917</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; content:&quot;Proxy-Authorization: NTLM&quot;; flowbits:set,ntlm_authentication; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17370</id>
        <msg>WEB-MISC Squid authentication headers handling denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>14977</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-2917</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:to_server,established; flowbits:isset,ntlm_authentication; content:&quot;Proxy-Authorization: &quot;; content:!&quot;NTLM&quot;; within:4; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17371</id>
        <msg>WEB-MISC Squid authentication headers handling denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-1965</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;cai|3A|&quot;; nocase; content:&quot;-launcher&quot;; distance:0; nocase; pcre:&quot;/\x3c[^\x3e]+(\x22|\x27)?cai\x3a[^\x3e]*(\x22|\x2522)[^\x3e\x22]*-launcher/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17376</id>
        <msg>WEB-MISC IBM Lotus Expeditor cai URI handler command execution attempt</msg>
        <url>www-01.ibm.com/support/docview.wss?uid=swg21303813</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.png&quot;; nocase; http_uri; flowbits:set,http.png; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17380</id>
        <msg>WEB-CLIENT PNG file download request</msg>
      </rule>
      <rule>
        <bugtraq>32555</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-5314</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; file_data; content:&quot;|FF D8 FF|&quot;; content:&quot;|FF ED|&quot;; content:&quot;8BIM&quot;; within:4; distance:16; nocase; pcre:&quot;/\xff\xed.{16}8BIM\x04(\x09|\x0c)/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>17390</id>
        <msg>DOS ClamAV Antivirus Function Denial of Service attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.gif&quot;; nocase; http_uri; flowbits:set,http.gif; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>17394</id>
        <msg>WEB-CLIENT GIF file download request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET [5800,5900:5999]</filter1>
        <filter2>flow:established,to_server; content:&quot;RFB 0&quot;; depth:5; content:&quot;.0&quot;; depth:2; offset:7; flowbits:set,vnc.auth; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17396</id>
        <msg>EXPLOIT VNC client authentication response</msg>
      </rule>
      <rule>
        <bugtraq>33568</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0388</cve>
        <filter1>tcp $EXTERNAL_NET [5800,5900:5999] -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,vnc.auth; content:&quot;|00 00 00|&quot;; depth:3; content:&quot;|7F FF FF FF|&quot;; within:4; distance:1; pcre:&quot;/^\x00{3}[\x00\x01]\x7f\xff{3}/m&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17397</id>
        <msg>EXPLOIT VNCViewer Authenticate buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-4138</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.hlp&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17407</id>
        <msg>WEB-CLIENT Windows help file download request</msg>
      </rule>
      <rule>
        <bugtraq>14935</bugtraq>
        <classtype>denial-of-service</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ORDSYS.ORD&quot;; nocase; pcre:&quot;/(Image|Doc)/iR&quot;; pcre:&quot;/(Set|Check)\x10Properties/iR&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>17416</id>
        <msg>ORACLE Database Intermedia Denial of Service Attempt</msg>
      </rule>
      <rule>
        <bugtraq>14935</bugtraq>
        <classtype>denial-of-service</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;TO_BLOB(HEXTORAW&quot;; nocase; pcre:&quot;/^\s*\x28\s*\x27[^\x27]*0{4,6}\s*\x27\s*\x29\s*/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:denial-of-service;</filter2>
        <id>17417</id>
        <msg>ORACLE Database Intermedia Denial of Service Attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $HOME_NET $ORACLE_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server, established; content:&quot;(DESCRIPTION=(CONNECT_DATA=(SERVICE_NAME=&quot;; fast_pattern:only; flowbits:set,oracle.connect; flowbits:noalert; classtype:attempted-user;</filter2>
        <id>17418</id>
        <msg>ORACLE Oracle connection established</msg>
      </rule>
      <rule>
        <bugtraq>13379</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1077</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|3C|AppData|3E|&quot;; nocase; content:&quot;|3C|AppInStartmenu|20|value|3D 22|True|22|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17420</id>
        <msg>WEB-MISC Citrix Program Neighborhood Agent Arbitrary Shortcut Creation attempt</msg>
      </rule>
      <rule>
        <bugtraq>35758</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-2469</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;p.type=|27|xxx|27|&quot;; nocase; content:&quot;__defineSetter__|28|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17422</id>
        <msg>SPECIFIC-THREATS Firefox defineSetter function pointer memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>13373</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1078</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|3C|AppData|3E|&quot;; nocase; content:&quot;|3C|InName|3E|&quot;; pcre:&quot;/InName\x3E[^\x3C]{100}/i&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17423</id>
        <msg>WEB-MISC Citrix Program Neighborhood Agent Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.rat&quot;; nocase; http_uri; flowbits:set,http.rat; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>17426</id>
        <msg>WEB-CLIENT RAT file download request</msg>
      </rule>
      <rule>
        <bugtraq>13509</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1496</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS any</filter1>
        <filter2>flow:to_server, established; content:&quot;DBMS_SCHEDULER.RUN_JOB&quot;; nocase; content:&quot;|28 27|somejobdefinitiong|27 29 3B 20|END|3B 0A|&quot;; fast_pattern:only; nocase; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17427</id>
        <msg>SPECIFIC-THREATS Oracle database DBMS_Scheduler privilege escalation attempt</msg>
      </rule>
      <rule>
        <bugtraq>32396</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5409</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pdf; file_data; content:&quot;|25 50 44 46 2D 31 2E 33 0A 25 E2 E3 CF D3 0A 33|&quot;; within:16; content:&quot;|3C 3C 2F 46 69 6C 74 65 72 20 5B 2F 46 6C 61 74 65 44 65 63 6F 64 65 20 2F 41 53 43 49 49 48 65 78 44 65 63 6F 64 65 5D|&quot;; within:40; distance:8; content:&quot;|78 9C ED C2 31 0D 00 00 00 02 A0 4C 6E F6 CF 66 0D 0F 06 4D 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 30 4B 03 6A 32|&quot;; within:45; distance:22; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17430</id>
        <msg>SPECIFIC-THREATS BitDefender Antivirus PDF processing memory corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>12276</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-0094</cve>
        <filter1>tcp $EXTERNAL_NET 70 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|30 41 73 09 30 2F 61 61 61 61 61 61 61 61 61 61 61 61 61 61|&quot;; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17432</id>
        <msg>WEB-MISC Squid Gopher protocol handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26424</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4734</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;IISWebAgent&quot;; nocase; http_uri; content:&quot;Redirect&quot;; nocase; http_uri; content:&quot;url|3D|&quot;; nocase; http_uri; pcre:&quot;/IISWebAgent[^\r\n]*\x2edll\x3F[^\r\n]*?url\x3d[^\r\n]{257}/Ui&quot;; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17440</id>
        <msg>WEB-MISC RSA authentication agent for web redirect buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.lnk&quot;; nocase; http_uri; flowbits:set,http.lnk; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>17441</id>
        <msg>WEB-MISC .lnk file download attempt</msg>
      </rule>
      <rule>
        <bugtraq>34235</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1169</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;xsl|3A|key name=|22|poc|22| match=|22|nodeB|22| use=|22|does_not_exist|28 29 22|/&gt;&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17444</id>
        <msg>SPECIFIC-THREATS Firefox 3 xsl parsing heap overflow attempt</msg>
        <url>www.mozilla.org/security/announce/2009/mfsa2009-12.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2008-0457</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8443</filter1>
        <filter2>flow:to_server,established; content:&quot;|17 03 00 02 01 87 09 6B 5D 64 67 5D 86 54 D0 F4 27 EF 2B 32 CA A3 D3 FA 97 AA 40 14 ED 27 15 D2 9B 06 EA 07 09 7D B8 D2 61 69 CD 6D 74 52 F9 8A|&quot;; depth:48; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service ssl; classtype:misc-activity;</filter2>
        <id>17445</id>
        <msg>SPECIFIC-THREATS Symantec Backup Exec System Recovery Manager unauthorized file upload attempt</msg>
        <url>seer.entsupport.symantec.com/docs/297171.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;407&quot;; http_stat_code; flowbits:set,http.stat_code_407; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>17447</id>
        <msg>WEB-MISC 407 Proxy Authentication Required</msg>
      </rule>
      <rule>
        <bugtraq>16407</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0468</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>flow:to_server,established; content:&quot;|80|&quot;; content:&quot;|FF FF FF FF|&quot;; within:8; distance:1; pcre:&quot;/\x80(\x84|\x85\x00|\x86\x00\x00|\x87\x00\x00\x00)\xFF\xFF\xFF\xFF/smi&quot;; metadata:policy security-ips drop, service ldap; classtype:attempted-user;</filter2>
        <id>17450</id>
        <msg>WEB-MISC CommuniGate Systems CommuniGate Pro LDAP Server buffer overflow attempt</msg>
        <url>www.gleg.net/cg_advisory.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|1F 8B 08 08 E3 43 C1 49 00 03 3C 68 31 3E 20 69 64 3D 22 68 65 61 64 65 72 22 20 6F 6E 6D 6F 75 73 65 6D 6F 76 65 3D 22 61 6C 65 72 74 28 27 41 73 73 75 72 65 6E 74 20 53 65 63 75 72 65 20 54|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17458</id>
        <msg>WEB-CLIENT BitDefender Internet Security script code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|52 61 72 21 1A 07 00 CF 90|&quot;; within:9; content:&quot;|3C 68 31 3E 20 69 64 3D 22 68 65 61 64 65 72 22 20 6F 6E 6D 6F 75 73 65 6D 6F 76 65 3D 22 61 6C 65 72 74 28 27 41 73 73 75 72 65 6E 74 20 53 65 63 75 72 65 20 54|&quot;; within:54; distance:43; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17459</id>
        <msg>WEB-CLIENT BitDefender Internet Security script code execution attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;PK|03 04 0A|&quot;; within:5; content:&quot;|3C 68 31 3E 20 69 64 3D 22 68 65 61 64 65 72 22 20 6F 6E 6D 6F 75 73 65 6D 6F 76 65 3D 22 61 6C 65 72 74 28 27 41 73 73 75 72 65 6E 74 20 53 65 63 75 72 65 20 54|&quot;; within:54; distance:25; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17460</id>
        <msg>WEB-CLIENT BitDefender Internet Security script code execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>31473</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3827</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;.RMF&quot;; within:4; content:&quot;|14 76 69 64 65 6F 2F 78 2D 70 6E 2D 72 65 61 6C 76 69 64 65 6F 00 00 00 1A 59 49 59 55 56 49 44 4F 52 56 32 30 00 01 00 01 00 1E 59 49 59 55 00 00|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17469</id>
        <msg>SPECIFIC-THREATS Mplayer Real Demuxer stream_read heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.EXTEND_WINDOW(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17473</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.EXTEND_WINDOW arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.CREATE_SUBSCRIPTION(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17474</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.CREATE_SUBSCRIPTION arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17475</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.PURGE_WINDOW(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17476</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.PURGE_WINDOW arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.DROP_SUBSCRIPTION(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17477</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.DROP_SUBSCRIPTION arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_SUBSCRIBE.SUBSCRIBE(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17478</id>
        <msg>ORACLE DBMS_CDC_SUBSCRIBE.SUBSCRIBE arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_ISUBSCRIBE.SUBSCRIBE(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17479</id>
        <msg>ORACLE DBMS_CDC_ISUBSCRIBE.SUBSCRIBE arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>13236</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-1197</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;DBMS_CDC_ISUBSCRIBE.CREATE_SUBSCRIPTION(|27 27 27 7C 7C|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17480</id>
        <msg>ORACLE DBMS_CDC_ISUBSCRIBE.CREATE_SUBSCRIPTION arbitrary command execution attempt</msg>
      </rule>
      <rule>
        <bugtraq>15865</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1929</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; isdataat:1420; content:&quot;isaNVWRequest.dll&quot;; nocase; http_uri; content:&quot;Transfer-Encoding|3A|&quot;; nocase; http_header; content:&quot;chunked&quot;; nocase; http_header; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17486</id>
        <msg>WEB-MISC Trend Micro Control Manager Chunked overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>19381</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4018</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;|34 66 75 67 34 41 74 41 6E 4E 49 62 67 42 54 4D 30 68 56 47|&quot;; content:&quot;|67 68 44 41 6B 43 43 50 51 6F 47 53 35 51 76 6A 52 6F 4B 33|&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17493</id>
        <msg>SPECIFIC-THREATS ClamAV UPX FileHandling Heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>35232</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-1122</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|6F 76 00 00 19 FE 6D 6F 6F 76 00 00 19 F6 6D 6F|&quot;; content:&quot;|6F 76 00 00 19 CE 6D 6F 6F 76 00 00 19 C6 6D 6F|&quot;; offset:32; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17527</id>
        <msg>SPECIFIC-THREATS VideoLAN VLC Media Player MP4_BoxDumpStructure Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>36384</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2629</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;GET |2F 25|23|2E 2E|&quot;; fast_pattern:only; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17528</id>
        <msg>SPECIFIC-THREATS nginx URI parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-2881</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server, established; content:&quot;|FF FE 32 00 36 00 37 00 00 00|&quot;; depth:72; content:&quot;|20 00 31 00 31 00 31 00 31 00 31 00 31 00 31 00 31 00 00 00 20 00|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17530</id>
        <msg>SPECIFIC-THREATS HP OpenView Storage Data Protector Stack Buffer Overflow</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:established,to_server; content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/ipp&quot;; distance:1; nocase; flowbits:set,ipp.application; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17534</id>
        <msg>MISC IPP Application Content</msg>
      </rule>
      <rule>
        <bugtraq>31690</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3640</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:established,to_server; flowbits:isset,ipp.application; content:&quot;printer-uri&quot;; nocase; content:&quot;ipp://&quot;; within:6; distance:2; pcre:&quot;/(((c|l)pi\x00.{1}(-\d|0)\x21)|(columns\x00.{1}(-\d|0)\x21)|(page-(right|left|top|bottom)\x00.{1}(-\d|0|((3-9)\d{5}|24\d{4}|236\d{3}|23593\d{1}|23592(2-9))\x21)))/is&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17535</id>
        <msg>MISC Apple CUPS Text to PostScript Filter Integer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0183</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;Authorization|3A 20|Basic&quot;; nocase; isdataat:1332,relative; content:!&quot;|0D 0A 0D 0A|&quot;; within:1332; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17536</id>
        <msg>WEB-MISC Free Download Manager Remote Control Server HTTP Auth Header buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.lzh&quot;; nocase; http_uri; flowbits:set,http.lzh; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17540</id>
        <msg>WEB-CLIENT LZH file download</msg>
      </rule>
      <rule>
        <bugtraq>19903</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-4626</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.lzh; content:&quot;|19 4C 2D 6C 68 30 2D 53 0C 00 00 2C 00 00 00 28 94 28 35 20|&quot;; depth:20; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>17541</id>
        <msg>SPECIFIC-THREATS Avast! Antivirus Engine Remote LHA buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>37985</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2010-0304</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 921</filter1>
        <filter2>content:&quot;|00 00 01 5D 00 00 00 00 4B 49 1C 52 00 01 00 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 01|&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17544</id>
        <msg>SPECIFIC-THREATS Wireshark LWRES Dissector getaddrsbyname buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>27403</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-0387</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 18 00 00 61 61 00 00 61 61|&quot;; depth:12; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17556</id>
        <msg>SPECIFIC-THREATS Firebird database invalid state memory corruption</msg>
      </rule>
      <rule>
        <bugtraq>28544</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-1373</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>flow:to_server,established; content:&quot;GIF89a&quot;; content:&quot;|3A 00 0B 00 00 0D 2C 00 FF|&quot;; within:1024; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17558</id>
        <msg>SPECIFIC-THREATS CUPS Gif Decoding Routine Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28454</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5405</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Transfer-Encoding|3A 20|quoted-printable|0D 0A|&quot;; nocase; content:&quot;Content-Disposition|3A 20|attachment&quot;; distance:0; nocase; content:&quot;|2A|BEGIN GRAPHICS VERSION&quot;; within:23; distance:25; nocase; pcre:&quot;/VERSION\x3d3D\d{3}[^\r\n]*\r\n/i&quot;; content:&quot;ENCODING&quot;; within:8; nocase; pcre:&quot;/^\x3d3D7BIT[^\r\n]{20}/Ri&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-admin;</filter2>
        <id>17559</id>
        <msg>SPECIFIC-THREATS IBM Lotus Notes Applix Graphics Parsing Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>32438</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5381</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;6BF52A52-394A-11d3-B153-00C04F79FAA6&quot;; fast_pattern:only; nocase; content:&quot;&lt;param &quot;; nocase; content:&quot;URL&quot;; distance:0; nocase; pcre:&quot;/&lt;param\s+name\s*=\s*(?P&lt;q1&gt;\x22|\x27|)URL(?P=q1)[^&gt;]+?value\s*=\s*(\x22|\x27)[^\x22\x27]{500}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17573</id>
        <msg>WEB-CLIENT ffdshow codec URL parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12749</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2005-0701</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;UTL_FILE.FOPEN&quot;; nocase; content:&quot;|5C 5C 2E 5C|&quot;; distance:0; fast_pattern; pcre:&quot;/UTL_FILE\.FOPEN\s*\x28(?P&lt;q1&gt;\x22|\x27).*?(?P=q1)[\s\x40]*\x2C[\s\x40]*[\x22\x27]\x5C\x5C\x2E\x5C/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:misc-attack;</filter2>
        <id>17584</id>
        <msg>ORACLE UTL_FILE directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>19586</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-4257</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:established,to_server; content:&quot;|D0|&quot;; content:&quot;|10 6D|&quot;; within:2; distance:5; content:!&quot;|21 10|&quot;; flowbits:set,ibmdb2.accsec; flowbits:noalert; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17598</id>
        <msg>SPECIFIC-THREATS IBM DB2 Universal Database accsec command without rdbnam</msg>
      </rule>
      <rule>
        <bugtraq>19586</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-4257</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50000</filter1>
        <filter2>flow:established,to_server; flowbits:isset,ibmdb2.accsec; content:&quot;|D0|&quot;; content:&quot;|10 6D|&quot;; within:2; distance:5; content:&quot;|21 10|&quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17599</id>
        <msg>SPECIFIC-THREATS IBM DB2 Universal Database rdbname denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;.xul&quot;; http_uri; pcre:&quot;/.xul([\?\x5c\x2f]|$)/Usi&quot;; flowbits:set, xul.download; flowbits:noalert; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>17600</id>
        <msg>WEB-CLIENT .xul document retrieval</msg>
      </rule>
      <rule>
        <bugtraq>30994</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-1389</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client, established; content:&quot;ITSF&quot;; content:&quot;|11 FD 01 7C AA 7B D0 11 9E 0C 00 A0 C9 22 E6 EC|&quot;; within:16; distance:36; content:&quot;ITSP&quot;; distance:0; byte_test:4,&lt;,8,12,relative,little; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>17602</id>
        <msg>WEB-CLIENT ClamAV antivirus CHM file handling denial of service</msg>
        <url>sourceforge.net/project/shownotes.php?group_id=86638&amp;release_id=623661</url>
      </rule>
      <rule>
        <bugtraq>40617</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4662</filter1>
        <filter2>flow:to_server,established; content:&quot;|E3|&quot;; depth:1; content:&quot;|01|&quot;; within:1; distance:4; content:&quot;|74 65 73 74 03 01 00 11 3C 00|&quot;; within:10; distance:32; fast_pattern; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>17607</id>
        <msg>SPECIFIC-THREATS Xi Software Net Transport eDonkey Protocol Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>17246</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-1705</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;CREATE VIEW&quot;; nocase; content:&quot;FROM&quot;; distance:0; nocase; content:&quot;sys.testtable t1, sys.testtable t2&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17619</id>
        <msg>ORACLE database server crafted view privelege escalation attempt</msg>
      </rule>
      <rule>
        <bugtraq>26108</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-5530</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1521</filter1>
        <filter2>flow:to_server,established; content:&quot;|06 00|&quot;; depth:2; offset:4; byte_test:1,&amp;,2,3,relative; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>17625</id>
        <msg>ORACLE Oracle Database Core RDBMS component denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>28990</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-2214</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 162</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17632, service snmp, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17632</id>
        <msg>SNMP Castle Rock Computing SNMPc Network Manager community string attempted stack overflow</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0195</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;JBIG2Decode&quot;; content:&quot;|03 FF FD FF 02 FE FE FE 00 00 00 36 FF FF FF F0 94 6B 62 1B|&quot;; within:1000; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17641</id>
        <msg>SPECIFIC-THREATS CUPS and Xpdf JBIG2 symbol dictionary buffer overflow attempt</msg>
        <url>www.cups.org/str.php?L3129</url>
      </rule>
      <rule>
        <bugtraq>12771</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;|50 4B 03 04 0A 00 00 00 00 00 E0 98 B8 28 00 00 00 00 44 00 00 00 44 00 00 00 09 00 00 00 65 69 63 61 72 2E 63 6F 6D 58|&quot;; within:40; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17651</id>
        <msg>SPECIFIC-THREATS Multiple AV vendor invalid archive checksum bypass attempt</msg>
        <url>archives.neohapsis.com/archives/fulldisclosure/2005-03/0207.html</url>
      </rule>
      <rule>
        <bugtraq>16287</bugtraq>
        <classtype>string-detect</classtype>
        <cve>2006-0272</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS any</filter1>
        <filter2>flow:established,to_server; content:&quot;xdb.dbms_xmlschema.generateschema&quot;; nocase; pcre:&quot;/\s*\x28\x27[^\x27]/R&quot;; isdataat:64,relative; metadata:policy balanced-ips drop, policy security-ips drop; classtype:string-detect;</filter2>
        <id>17659</id>
        <msg>ORACLE xdb.dbms_xmlschema buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-6015</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 138</filter1>
        <filter2>content:&quot;|5C|MAILSLOT|5C|NET|5C|NTLOGON&quot;; nocase; pcre:&quot;/^\x00+/R&quot;; content:&quot;|12 00 00 00|&quot;; within:4; pcre:&quot;/^\x00\x00\x00\x00[^\x00]{260}/R&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service netbios-dgm; classtype:attempted-admin;</filter2>
        <id>17661</id>
        <msg>EXPLOIT Samba send_mailslot buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-3639</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 631</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17663, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17663</id>
        <msg>EXPLOIT Apple CUPS SGI image format decoding imagetops filter buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>34461</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0993</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [6000:6199]</filter1>
        <filter2>flow:to_server,established; content:&quot;HTTP&quot;; nocase; content:&quot;%n%s%n%s%n%s&quot;; fast_pattern:only; pcre:&quot;/^(GET|POST|HEAD)\s+[^\x25]*\x25[\x23\x24\x27\x2a\x2b\x2d\x2ehlqjzt1234567890]*[diouxefgacspn]/i&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17669</id>
        <msg>SPECIFIC-THREATS Oracle Application Server 10g OPMN service format string vulnerability exploit attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server, established; content:&quot;.dmg&quot;; nocase; http_uri; flowbits:set,http.dmg; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>17679</id>
        <msg>WEB-MISC Apple disk image download request</msg>
      </rule>
      <rule>
        <classtype>unknown</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:unknown; flowbits:set,httpifnonematch; flowbits:noalert; metadata: engine shared, soid 3|17681, service http;</filter2>
        <id>17681</id>
        <msg>MISC TRUFFLEHUNTER SFVRT-1008 attack attempt</msg>
      </rule>
      <rule>
        <classtype>unknown</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:unknown; flowbits:set,httpifnonematch; flowbits:noalert; metadata: engine shared, soid 3|17683, service http;</filter2>
        <id>17683</id>
        <msg>MISC TRUFFLEHUNTER SFVRT-1008 attack attempt</msg>
      </rule>
      <rule>
        <bugtraq>10243</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;-lh0-&quot;; nocase; content:&quot;AAAAAAAA&quot;; within:50; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17704</id>
        <msg>SPECIFIC-THREATS McAfee LHA file parsing buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26146</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5544</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;attachment|3B|&quot;; content:&quot;filename=|22|poc.wpd|22|&quot;; distance:0; content:&quot;00=00=c9mup=B6=89a=88&quot;; distance:0; nocase; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17716</id>
        <msg>SPECIFIC-THREATS IBM Lotus Notes DOC attachment viewer buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>33177</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3979</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cast_to_raw|28 27|CgkJCUNSRUFU&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17718</id>
        <msg>SPECIFIC-THREATS Oracle MDSYS drop table trigger injection attempt</msg>
      </rule>
      <rule>
        <bugtraq>27229</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0339</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;XDB.XDB_PITRIG_PKG.PITRIG_&quot;; nocase; pcre:&quot;/XDB\x2EXDB_PITRIG_PKG\x2EPITRIG_(DROP|TRUNCATE)\s*\x28[^\x29]*\x27[^\x27]{800}/smi&quot;; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>17722</id>
        <msg>ORACLE Oracle XDB.XDB_PITRIG_PKG buffer overflow attempt</msg>
        <url>www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html</url>
      </rule>
      <rule>
        <bugtraq>24004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2788</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,java_class_file.request; content:&quot;|BC 08 59 03 02 54 59 04 10 D8 54 59 05 02 54 59|&quot;; fast_pattern:only; metadata:policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17727</id>
        <msg>SPECIFIC-THREATS Sun JDK image parsing library ICC buffer overflow attempt</msg>
        <url>scary.beasts.org/security/CESA-2006-004.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-0093</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 53</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17731, service dns, policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop;</filter2>
        <id>17731</id>
        <msg>BAD-TRAFFIC wpad dynamic update request</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-008.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.tif&quot;; nocase; http_uri; flowbits:set,http.tiff; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17732</id>
        <msg>WEB-CLIENT TIFF file request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|2E|xml&quot;; nocase; http_uri; pcre:&quot;/^[^\?]*\.xml([\?\x5c\x2f]|$)/Usi&quot;; flowbits:set,xml.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>17733</id>
        <msg>WEB-MISC XML file download request</msg>
      </rule>
      <rule>
        <bugtraq>12832</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0644</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:to_server,established; content:&quot;IcMtbGgwLRgAAAAFAAAA+rttMCABCHRlc3RmaWxl+BtVBQBQtIGUAQFVVVVV&quot;; metadata:policy security-ips drop, service smtp; classtype:attempted-user;</filter2>
        <id>17736</id>
        <msg>SPECIFIC-THREATS McAfee LHA Type-2 file handling overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 443</filter1>
        <filter2>flow:established, to_server; ssl_version:tls1.0; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|0B|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.certificate; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>17748</id>
        <msg>WEB-MISC TLSv1 Client_Certificate handshake</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.otf&quot;; nocase; http_uri; flowbits:set,http.otf; flowbits:noalert; metadata:policy balanced-ips alert, policy security-ips alert, service http; classtype:protocol-command-decode;</filter2>
        <id>17751</id>
        <msg>WEB-CLIENT OpenType Font file download request</msg>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2010-2741</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:denial-of-service; flowbits:isset,http.otf; metadata: engine shared, soid 3|17752, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17752</id>
        <msg>EXPLOIT OpenType Font file parsing denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-078.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2740</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.otf; metadata: engine shared, soid 3|17765, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17765</id>
        <msg>WEB-CLIENT OpenType Font file parsing buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS10-078.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17766, service http, policy security-ips drop;</filter2>
        <id>17766</id>
        <msg>EXPLOIT IE8 XSS in toStaticHTML API attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3324</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17767, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17767</id>
        <msg>EXPLOIT IE8 XSS in toStaticHTML API 2 attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-072.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17768, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17768</id>
        <msg>EXPLOIT IE8 object event handler use after free exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3328</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17769, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17769</id>
        <msg>EXPLOIT IE8 CSS invalid mapping exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-XXX.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3325</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|17774, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>17774</id>
        <msg>EXPLOIT IE8 CSS XSRF exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-071.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-0850</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;PK|03 04 0A|&quot;; content:&quot;|3C 68 31 3E 20 69 64 3D 22 68 65 61 64 65 72 22 20 6F 6E 6D 6F 75 73 65 6D 6F 76 65 3D 22 61 6C 65 72 74 28 27 41 73 73 75 72 65 6E 74 20 53 65 63 75 72 65 20 54|&quot;; distance:0; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-user;</filter2>
        <id>17778</id>
        <msg>SPECIFIC-THREATS BitDefender Internet Security script code execution attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;application/x-director&quot;; fast_pattern:only; flowbits:set,http.dir; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17801</id>
        <msg>WEB-CLIENT Director Movie File Embeded</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.DCR&quot;; nocase; http_uri; flowbits:set,http.dir; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>17802</id>
        <msg>WEB-CLIENT Director Movie File Download</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/server32.exe&quot;; nocase; http_uri; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17810</id>
        <msg>WEB-MISC potential malware - download of server32.exe</msg>
        <url>en.wikipedia.org/wiki/Zeus_(trojan_horse)</url>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/svchost.exe&quot;; nocase; http_uri; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17811</id>
        <msg>WEB-MISC potential malware - download of svchost.exe</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/iexplore.exe&quot;; nocase; http_uri; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17812</id>
        <msg>WEB-MISC potential malware - download of iexplore.exe</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/iprinp.dll&quot;; nocase; http_uri; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17813</id>
        <msg>WEB-MISC potential malware - download of iprinp.dll</msg>
      </rule>
      <rule>
        <classtype>suspicious-filename-detect</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/winzf32.dll&quot;; nocase; http_uri; metadata:policy connectivity-ips drop, policy security-ips drop, service http; classtype:suspicious-filename-detect;</filter2>
        <id>17814</id>
        <msg>WEB-MISC potential malware - download of winzf32.dll</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;index_new.php&quot;; nocase; http_uri; content:&quot;id=roger&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17815</id>
        <msg>SPYWARE-PUT Thinkpoint fake antivirus - user display</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2010-090610-2408-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;bill.php&quot;; nocase; http_uri; content:&quot;cs1=roger&quot;; nocase; http_client_body; content:&quot;product_id=&quot;; nocase; http_client_body; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17816</id>
        <msg>SPYWARE-PUT Thinkpoint fake antivirus - credit card submission</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2010-090610-2408-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|30 B6 AD D9 C7 B7 41 8E 75 6E 65 78 70 30 65 B4 26 6D|&quot;; content:&quot;|BA 3A 0D 0A 4F E8 7A 65 7E 66 B5 05 EF AD 61 49 C9 80 75 6D 58|&quot;; within:100; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>17817</id>
        <msg>SPECIFIC-THREATS Thinkpoint fake antivirus binary download</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2010-090610-2408-99</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3337</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18071, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18071</id>
        <msg>WEB-CLIENT pptimpconv.dll access</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-2734</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|18074, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18074</id>
        <msg>WEB-CLIENT Forefront UAG URL XSS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-3936</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|18076, service http, policy balanced-ips drop, policy security-ips drop;</filter2>
        <id>18076</id>
        <msg>WEB-CLIENT Forefront UAG URL XSS alternate attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-089.mspx</url>
      </rule>
      <rule>
        <bugtraq>18165</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-2723</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;document.write|28 27|&lt;html&gt;&lt;marquee&gt;&lt;h1&gt;|27|+buffer+buffer|29 3B|&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:attempted-dos;</filter2>
        <id>18188</id>
        <msg>SPECIFIC-THREATS Multiple browser marquee tag denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3144</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18202, service http, policy security-ips drop;</filter2>
        <id>18202</id>
        <msg>WEB-CLIENT Windows Address Book smmscrpt.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-097.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3147</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18204, service http, policy security-ips drop;</filter2>
        <id>18204</id>
        <msg>WEB-CLIENT Windows Address Book wab32res.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-096.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3147</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18205, service http, policy security-ips drop;</filter2>
        <id>18205</id>
        <msg>WEB-CLIENT Windows Address Book msoeres32.dll malicious DLL load</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-096.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-3966</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|18208, service http, policy security-ips drop;</filter2>
        <id>18208</id>
        <msg>WEB-CLIENT Windows 7 Home peerdist.dll dll-load exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-095.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2569</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|18212, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18212</id>
        <msg>SPECIFIC-THREATS MS Publisher tyo.oty field heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-103.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2570</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|18213, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18213</id>
        <msg>SPECIFIC-THREATS MS Publisher column and row remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-103.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-2571</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.pub; metadata: engine shared, soid 3|18214, service http, policy balanced-ips drop, policy security-ips alert;</filter2>
        <id>18214</id>
        <msg>SPECIFIC-THREATS MS Publisher 97 conversion remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-103.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;.pct&quot;; nocase; http_uri; flowbits:set,http.pct; flowbits:noalert; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>18234</id>
        <msg>WEB-MISC QuickDraw/PICT file download request</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| ErrCode&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:trojan-activity;</filter2>
        <id>18247</id>
        <msg>BLACKLIST USER-AGENT known malicious User-Agent ErrCode - W32/Fujacks.htm</msg>
        <url>www.mcafee.com/threat-intelligence/malware/default.aspx?id=141161</url>
      </rule>
      <rule>
        <bugtraq>9576</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2006-2162</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Length|3A|&quot;; nocase; byte_test:10,&gt;,0x7FFFFFFF,1,relative,string,dec; metadata:policy security-ips drop; classtype:misc-attack;</filter2>
        <id>2278</id>
        <msg>WEB-MISC client negative Content-Length attempt</msg>
      </rule>
      <rule>
        <classtype>successful-user</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|Referer|3A| res|3A|/C|3A|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:successful-user;</filter2>
        <id>2412</id>
        <msg>ATTACK-RESPONSES successful cross site scripting forced download attempt</msg>
      </rule>
      <rule>
        <bugtraq>9382</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0045</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 119</filter1>
        <filter2>flow:to_server,established; content:&quot;newgroup&quot;; fast_pattern:only; pcre:&quot;/^newgroup\x3a[^\n]{32}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service nntp; classtype:attempted-admin;</filter2>
        <id>2430</id>
        <msg>NNTP newgroup overflow attempt</msg>
        <nessus>11984</nessus>
      </rule>
      <rule>
        <bugtraq>9382</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0045</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 119</filter1>
        <filter2>flow:to_server,established; content:&quot;rmgroup&quot;; fast_pattern:only; pcre:&quot;/^rmgroup\x3a[^\n]{32}/smi&quot;; metadata:policy balanced-ips drop, policy security-ips drop, service nntp; classtype:attempted-admin;</filter2>
        <id>2431</id>
        <msg>NNTP rmgroup overflow attempt</msg>
        <nessus>11984</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,sslv3.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>2520</id>
        <msg>WEB-MISC SSLv3 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HTTP_SERVERS 443 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,sslv3.client_hello.request; content:&quot;|16 03 00|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,sslv3.server_hello.request; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>2521</id>
        <msg>WEB-MISC SSLv3 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/NessusTest&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop, service http; classtype:attempted-recon;</filter2>
        <id>2585</id>
        <msg>WEB-MISC nessus 2.x 404 probe</msg>
        <nessus>10386</nessus>
      </rule>
      <rule>
        <bugtraq>11015</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|01 00 02|&quot;; depth:3; offset:2; byte_test:1,&gt;,127,0; flowbits:set,sslv2.client_hello.request; flowbits:noalert;  byte_test:2,&gt;,32,9; metadata:service ssl; classtype:attempted-admin;</filter2>
        <id>2656</id>
        <msg>WEB-MISC SSLv2 Client_Hello Challenge Length overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>2658</id>
        <msg>WEB-MISC SSLv2 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&lt;,128,0; content:&quot;|01|&quot;; depth:1; offset:3; content:&quot;|00 02|&quot;; depth:2; offset:6; flowbits:set,sslv2.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>2659</id>
        <msg>WEB-MISC SSLv2 Client_Hello with pad request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HTTP_SERVERS 443 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sslv2.client_hello.request; content:&quot;|04|&quot;; depth:1; offset:2; content:&quot;|00 02|&quot;; depth:2; offset:5; flowbits:set,sslv2.server_hello.request; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>2660</id>
        <msg>WEB-MISC SSLv2 Server_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|01|&quot;; depth:1; offset:5; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>2661</id>
        <msg>WEB-MISC TLSv1 Client_Hello request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HTTP_SERVERS 443 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,tlsv1.client_hello.request; content:&quot;|16 03 01|&quot;; depth:3; content:&quot;|02|&quot;; depth:1; offset:5; flowbits:set,tlsv1.server_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>2662</id>
        <msg>WEB-MISC TLSv1 Server_Hello request</msg>
      </rule>
      <rule>
        <bugtraq>11173</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0200</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Content-Type&quot;; nocase; http_header; content:&quot;image/&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3A\s*image\x2F/smiH&quot;; file_data; content:&quot;|FF D8|&quot;; within:2; fast_pattern; pcre:&quot;/^.*\xFF[\xE1\xE2\xED\xFE]\x00[\x00\x01]/sR&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>2705</id>
        <msg>WEB-CLIENT JPEG parser heap overflow attempt</msg>
        <url>www.microsoft.com/security/bulletins/200409_jpeg.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20034</filter1>
        <filter2>flow:to_server,established; content:&quot;BN |00 02 00|&quot;; depth:6; content:&quot;|05 00|&quot;; depth:2; offset:8; flowbits:set,backdoor.netbus_2.connect; flowbits:noalert; classtype:misc-activity;</filter2>
        <id>3009</id>
        <msg>BACKDOOR NetBus Pro 2.0 connection request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22222</filter1>
        <filter2>flow:to_server,established; content:&quot;WINDIR&quot;; depth:6; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3010</id>
        <msg>BACKDOOR RUX the Tick get windows directory attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22222</filter1>
        <filter2>flow:to_server,established; content:&quot;SYSDIR&quot;; depth:6; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3011</id>
        <msg>BACKDOOR RUX the Tick get system directory attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 22222</filter1>
        <filter2>flow:to_server,established; content:&quot;ABCJZDATEIV&quot;; depth:11; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3012</id>
        <msg>BACKDOOR RUX the Tick upload/execute arbitrary file attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 23432</filter1>
        <filter2>flow:to_server,established; content:&quot;RQS&quot;; depth:3; flowbits:set,backdoor.asylum.connect; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3013</id>
        <msg>BACKDOOR Asylum 0.1 connection request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 23432 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.asylum.connect; content:&quot;GNT&quot;; depth:3; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3014</id>
        <msg>BACKDOOR Asylum 0.1 connection established</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 2000 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Insane Network vs 4.0 by Suid Flow|0A 0D|www.blackcode.com|0A 0D|[r00t]|23|&quot;; depth:62; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3015</id>
        <msg>BACKDOOR Insane Network 4.0 connection established</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 63536 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Insane Network vs 4.0 by Suid Flow|0A 0D|www.blackcode.com|0A 0D|[r00t]|23|&quot;; depth:62; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3016</id>
        <msg>BACKDOOR Insane Network 4.0 connection established port 63536</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,sslv2.client_hello.request; flowbits:isnotset,sslv3.client_hello.request; flowbits:isnotset,tlsv1.client_hello.request; byte_test:1,&gt;,127,0; content:&quot;|01|&quot;; depth:1; offset:2; content:&quot;|03 01|&quot;; depth:2; offset:3; flowbits:set,tlsv1.client_hello.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>3059</id>
        <msg>WEB-MISC TLSv1 Client_Hello via SSLv2 handshake request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1020</filter1>
        <filter2>flow:to_server,established; content:&quot;Hello...&quot;; depth:8; flowbits:set,backdoor.vampire_12.connect; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3063</id>
        <msg>BACKDOOR Vampire 1.2 connection request</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 1020 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.vampire_12.connect; content:&quot;Vampire v1.2 Server On-Line.....&quot;; depth:32; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3064</id>
        <msg>BACKDOOR Vampire 1.2 connection confirmation</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 5880 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;connected&quot;; depth:9; flowbits:set,backdoor.y3krat_15.connect; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3081</id>
        <msg>BACKDOOR Y3KRAT 1.5 Connect</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5880</filter1>
        <filter2>flow:to_server,established; flowbits:isset,backdoor.y3krat_15.connect; content:&quot;getclient&quot;; depth:9; flowbits:set,backdoor.y3krat_15.client.response; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3082</id>
        <msg>BACKDOOR Y3KRAT 1.5 Connect Client Response</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 5880 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.y3krat_15.client.response; content:&quot;client&quot;; depth:7; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>3083</id>
        <msg>BACKDOOR Y3KRAT 1.5 Connection confirmation</msg>
      </rule>
      <rule>
        <bugtraq>11523</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5503</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; content:&quot;IHDR&quot;; within:8; byte_test:4,&gt;,32767,0,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3132</id>
        <msg>WEB-CLIENT PNG large image width download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-009.mspx</url>
      </rule>
      <rule>
        <bugtraq>11523</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5503</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; content:&quot;IHDR&quot;; within:8; byte_test:4,&gt;,32767,4,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3133</id>
        <msg>WEB-CLIENT PNG large image height download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-009.mspx</url>
      </rule>
      <rule>
        <bugtraq>5874</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-1043</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;adb880a6-d8ff-11cf-9377-00aa003b7a11&quot;; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*adb880a6-d8ff-11cf-9377-00aa003b7a11/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3148</id>
        <msg>WEB-CLIENT winhelp clsid attempt</msg>
        <url>www.ngssoftware.com/advisories/ms-winhlp.txt</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 31337</filter1>
        <filter2>flow:to_server,established; content:&quot;1j|D0 D9|&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>3155</id>
        <msg>BACKDOOR BackOrifice 2000 Inbound Traffic</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;image/&quot;; nocase; http_header; pcre:&quot;/^Content-Type\x3a(\s*|\s*\r?\n\s+)image\x2fgif/smiH&quot;; flowbits:set,http.gif; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>3535</id>
        <msg>WEB-CLIENT GIF transfer</msg>
      </rule>
      <rule>
        <classtype>not-suspicious</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.hta&quot;; nocase; http_uri; pcre:&quot;/\.hta(\b|$)/Ui&quot;; flowbits:set,http.hta; flowbits:noalert; metadata:policy security-ips drop; classtype:not-suspicious;</filter2>
        <id>3551</id>
        <msg>WEB-CLIENT .hta download attempt</msg>
      </rule>
      <rule>
        <bugtraq>11171</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;image/bmp&quot;; nocase; http_header; pcre:&quot;/^Content-type\x3a(\s*|\s*\r?\n\s+)image\x2fbmp/smiH&quot;; file_data; content:&quot;BM&quot;; distance:0; byte_test:4,&gt;,83386080,16,relative,little; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>3632</id>
        <msg>WEB-CLIENT Bitmap width integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-052.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;image/bmp&quot;; nocase; pcre:&quot;/^Content-type\x3a(\s*|\s*\r?\n\s+)image\x2fbmp/smi&quot;; flowbits:set,http.bmp; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>3633</id>
        <msg>WEB-CLIENT bitmap transfer</msg>
      </rule>
      <rule>
        <bugtraq>11171</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-3015</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.bmp; content:&quot;BM&quot;; byte_test:4,&gt;,83386080,16,relative,little; metadata:policy security-ips drop; classtype:attempted-admin;</filter2>
        <id>3634</id>
        <msg>WEB-CLIENT Bitmap width integer overflow multipacket attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-052.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23032 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected To Amanda 2.0&quot;; depth:23; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>3635</id>
        <msg>BACKDOOR Amanda 2.0 connection established</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 17499 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Crazzynet&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>3636</id>
        <msg>BACKDOOR Crazzy Net 5.0 connection established</msg>
      </rule>
      <rule>
        <bugtraq>2524</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0154</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Content-Type|3A|&quot;; nocase; http_header; content:&quot;audio/&quot;; fast_pattern; nocase; http_header; pcre:&quot;/Content-Type\x3A\s+audio\/(x-wav|mpeg|x-midi)/iH&quot;; content:&quot;filename=&quot;; nocase; http_header; pcre:&quot;/filename=[\x22\x27]?.{1,221}\.(vbs|exe|scr|pif|bat)/Hi&quot;; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>3683</id>
        <msg>WEB-CLIENT spoofed MIME-Type auto-execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS01-020.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;text/plain&quot;; nocase; http_header; pcre:&quot;/^Content-type\x3a(\s*|\s*\r?\n\s+)text\x2fplain/smiH&quot;; flowbits:set,chm_content_type; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>3819</id>
        <msg>WEB-CLIENT multipacket CHM file transfer start</msg>
      </rule>
      <rule>
        <bugtraq>13953</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1208</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;text/plain&quot;; nocase; http_header; pcre:&quot;/^Content-type\x3a(\s*|\s*\r?\n\s+)text\x2fplain/smiH&quot;; pcre:&quot;/^ITSF/sm&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>3821</id>
        <msg>WEB-CLIENT CHM file transfer attempt</msg>
        <nessus>18482</nessus>
        <url>www.microsoft.com/technet/security/bulletin/ms05-026.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.rt&quot;; nocase; http_uri; pcre:&quot;/\S{190}.rt/Usmi&quot;; flowbits:set,realtext.request; flowbits:noalert; metadata:service http; classtype:protocol-command-decode;</filter2>
        <id>3822</id>
        <msg>WEB-MISC Real Player realtext long URI request</msg>
      </rule>
      <rule>
        <bugtraq>14594</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2127</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F&quot;; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4132</id>
        <msg>WEB-CLIENT msdds clsid attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;083863F1-70DE-11d0-BD40-00A0C911CE86&quot;; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*083863F1-70DE-11d0-BD40-00A0C911CE86/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4133</id>
        <msg>WEB-CLIENT devenum clsid attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>14511</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-1990</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5&quot;; nocase; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5/si&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4134</id>
        <msg>WEB-CLIENT blnmgr clsid attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-038.mspx</url>
      </rule>
      <rule>
        <bugtraq>13389</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1279</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 646</filter1>
        <filter2>flow:stateless; content:&quot;|00 00|&quot;; depth:2; offset:12; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>4140</id>
        <msg>DOS tcpdump tcp LDP print zero length message denial of service attempt</msg>
        <url>www.frsirt.com/english/advisories/2005/0410</url>
      </rule>
      <rule>
        <bugtraq>13389</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-1279</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 646</filter1>
        <filter2>flow:to_server; content:&quot;|00 00|&quot;; depth:2; offset:12; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>4141</id>
        <msg>DOS tcpdump udp LDP print zero length message denial of service attempt</msg>
        <url>www.frsirt.com/english/advisories/2005/0410</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|02|&quot;; depth:1; pcre:&quot;/\x02[^\x0a]+\x3a[^\x0a]+\x0a/&quot;; flowbits:set,lp.cascade; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>4143</id>
        <msg>EXPLOIT lpd receive printer job cascade adaptor protocol request</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;text/plain&quot;; nocase; http_header; pcre:&quot;/^Content-type\x3a(\s*|\s*\r?\n\s+)text\x2fplain/smiH&quot;; flowbits:set,bookmark_link_content_type; flowbits:noalert; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>4194</id>
        <msg>WEB-CLIENT multipacket CBO CBL CBM file transfer start</msg>
      </rule>
      <rule>
        <bugtraq>13944</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3448</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,bookmark_link_content_type; content:&quot;Interactive Training]&quot;; pcre:&quot;/\[(Microsoft |Microsoft Press )?Interactive Training\]/&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4195</id>
        <msg>WEB-CLIENT multipacket CBO CBL CBM file transfer attempt</msg>
        <nessus>18492</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-031.mspx</url>
      </rule>
      <rule>
        <bugtraq>15070</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2122</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;L|00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00|F&quot;; byte_test:1,!&amp;,4,0,relative,little; byte_jump:2,56,relative,little; byte_jump:2,0,relative,little; byte_jump:2,-2,relative,multiplier 2,little; byte_jump:2,0,relative,multiplier 2,little; byte_jump:2,0,relative,little; content:&quot;|CC 00 00 00|&quot;; within:4; distance:-2; isdataat:72,relative; content:!&quot;|00 00|&quot;; within:32; distance:40; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4643</id>
        <msg>WEB-CLIENT malformed windows shortcut file buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-049.mspx</url>
      </rule>
      <rule>
        <bugtraq>15070</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2122</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;L|00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00|F&quot;; byte_test:1,&amp;,4,0,relative,little; byte_jump:2,56,relative,little; byte_jump:2,0,relative,little; byte_jump:2,-2,relative,multiplier 2,little; byte_jump:2,0,relative,multiplier 2,little; byte_jump:2,0,relative,multiplier 2,little; byte_jump:2,0,relative,little; content:&quot;|CC 00 00 00|&quot;; within:4; distance:-2; isdataat:72,relative; content:!&quot;|00 00|&quot;; within:32; distance:40; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>4644</id>
        <msg>WEB-CLIENT malformed windows shortcut file with comment buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS05-049.mspx</url>
      </rule>
      <rule>
        <bugtraq>1806</bugtraq>
        <classtype>bad-unknown</classtype>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; content:&quot;Command completed&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:bad-unknown;</filter2>
        <id>494</id>
        <msg>ATTACK-RESPONSES command completed</msg>
      </rule>
      <rule>
        <bugtraq>1806</bugtraq>
        <classtype>bad-unknown</classtype>
        <cve>2000-0884</cve>
        <filter1>tcp $HTTP_SERVERS $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established; content:&quot;1 file|28|s|29| copied&quot;; nocase; metadata:policy balanced-ips drop, policy security-ips drop; classtype:bad-unknown;</filter2>
        <id>497</id>
        <msg>ATTACK-RESPONSES file copied ok</msg>
      </rule>
      <rule>
        <classtype>bad-unknown</classtype>
        <filter1>ip any any -&gt; any any</filter1>
        <filter2>content:&quot;uid=0|28|root|29|&quot;; metadata:policy balanced-ips drop, policy security-ips drop; classtype:bad-unknown;</filter2>
        <id>498</id>
        <msg>ATTACK-RESPONSES id check returned root</msg>
      </rule>
      <rule>
        <bugtraq>16074</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-4560</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|01 00 09 00 00 03|R|1F 00 00 06 00|=|00 00 00 00 00|&quot;; content:&quot;&amp;|06 09 00 16 00|&quot;; metadata:policy security-ips drop; classtype:web-application-attack;</filter2>
        <id>5319</id>
        <msg>WEB-CLIENT Metasploit Windows picture and fax viewer wmf arbitrary code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-001.mspx</url>
      </rule>
      <rule>
        <bugtraq>16516</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-0020</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|D7 CD C6 9A|&quot;; byte_test:2,&lt;,8,25,relative,little; metadata:policy security-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>5713</id>
        <msg>WEB-CLIENT Windows Metafile invalid header size integer overflow</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-004.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A| SoftActivity Mailer&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5742</id>
        <msg>SPYWARE-PUT Keylogger activitylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080822</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gate.php?plugin=&quot;; nocase; http_uri; content:&quot;Host|3A| www.actualnames.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5743</id>
        <msg>SPYWARE-PUT Hijacker actualnames runtime detection - plugin list</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074941</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/lzRedirect.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;act=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5745</id>
        <msg>SPYWARE-PUT Hijacker adultlinks runtime detection - redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072505</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/logurl/loadURL/&quot;; fast_pattern; nocase; http_uri; content:&quot;.ADbar|3A|X&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5746</id>
        <msg>SPYWARE-PUT Hijacker adultlinks runtime detection - load url</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072505</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/hits/log.cgi/&quot;; fast_pattern; nocase; http_uri; content:&quot;.ADbar|3A|X&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5747</id>
        <msg>SPYWARE-PUT Hijacker adultlinks runtime detection - log hits</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072505</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exit/exit.html?act=&quot;; fast_pattern; nocase; http_uri; content:&quot;.ADbar|3A|X&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5748</id>
        <msg>SPYWARE-PUT Hijacker adultlinks runtime detection - ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072505</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Infospace Toolbar&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5750</id>
        <msg>SPYWARE-PUT Adware dogpile runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079953</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/search/p/exactad/?Keywords=&quot;; fast_pattern; nocase; http_uri; content:&quot;Partners=exactad&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5751</id>
        <msg>SPYWARE-PUT Adware exactsearch runtime detection - switch search engine 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072519</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setup.asp?src=exact&amp;query=&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5752</id>
        <msg>SPYWARE-PUT Adware exactsearch runtime detection - switch search engine 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072519</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?Keywords=&quot;; fast_pattern; nocase; http_uri; content:&quot;partner=bar&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5753</id>
        <msg>SPYWARE-PUT Adware exactsearch runtime detection - topsearches</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072519</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezsb&quot;; nocase; http_uri; content:&quot;/bar_pl/shdoclc.fcgi?&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2Fezsb\d{4}\x2Fbar_pl\x2Fshdoclc\.fcgi/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5754</id>
        <msg>SPYWARE-PUT Hijacker ezcybersearch runtime detection - ie auto search hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072520</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezsb&quot;; nocase; http_uri; content:&quot;/bar_pl/chk.fcgi&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2Fezsb\d{4}\x2Fbar_pl\x2Fchk\.fcgi/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5755</id>
        <msg>SPYWARE-PUT Hijacker ezcybersearch runtime detection - check update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072520</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezsb&quot;; nocase; http_uri; content:&quot;/bar_pl/fav.fcgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;aff_id=&quot;; nocase; http_uri; pcre:&quot;/\x2Fezsb\d{4}\x2Fbar_pl\x2Ffav\.fcgi/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5756</id>
        <msg>SPYWARE-PUT Hijacker ezcybersearch runtime detection - add coolsites to ie favorites</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072520</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezsb&quot;; nocase; http_uri; content:&quot;/bar_pl/chk_bar.fcgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;aff_id=&quot;; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; pcre:&quot;/\x2Fezsb\d{4}\x2Fbar_pl\x2Fchk_bar\.fcgi/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5757</id>
        <msg>SPYWARE-PUT Hijacker ezcybersearch runtime detection - check toolbar setting</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072520</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezsb&quot;; nocase; http_uri; content:&quot;/bar_pl/b.fcgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;aff_id=&quot;; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; pcre:&quot;/\x2Fezsb\d{4}\x2Fbar_pl\x2Fb\.fcgi/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5758</id>
        <msg>SPYWARE-PUT Hijacker ezcybersearch runtime detection - download fastclick pop-under code</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072520</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;STOR&quot;; nocase; content:&quot;FKS_&quot;; distance:0; nocase; pcre:&quot;/^STOR\s+FKS_\w+_\d+-\d+-\d+\.log/i&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5759</id>
        <msg>SPYWARE-PUT Keylogger fearlesskeyspy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076298</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/w/pop.cgi?&quot;; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;u=http&quot;; nocase; http_uri; content:&quot;bearshare&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5761</id>
        <msg>SPYWARE-PUT Trickler bearshare runtime detection - ads popup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060286</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gwcache/lynnx.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;client=BEAR&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;urlfile=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5762</id>
        <msg>SPYWARE-PUT Trickler bearshare runtime detection - p2p information request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060286</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/chat/chat.php&quot;; nocase; http_uri; content:&quot;nick=&quot;; nocase; content:&quot;initchan=BearShare&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5763</id>
        <msg>SPYWARE-PUT Trickler bearshare runtime detection - chat request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060286</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/ico/&quot;; nocase; http_uri; content:&quot;.ico&quot;; nocase; http_uri; pcre:&quot;/\x2Ftoolbar\x2Fico\x2F[a-zA-Z0-9_%]*\.ico/Ui&quot;; content:&quot;Host|3A| begin2search.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5765</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - ico query</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/install.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;afid=b2search&quot;; nocase; http_uri; content:&quot;user_id=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5766</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - install spyware trafficsector</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.compress&quot;; nocase; http_uri; pcre:&quot;/\x2F(dist|SupportFiles)\x2F[^\r\n]*\.compress/Ui&quot;; content:&quot;User-Agent|3A| NSISDL&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5767</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - download unauthorized code</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/client/fcgi/stats-post2.fcgi&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| WebConnLib&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5768</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - pass information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adpage2.asp?sourceid=&quot;; nocase; http_uri; content:&quot;Host|3A| www.take5bingo.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5769</id>
        <msg>SPYWARE-PUT Hijacker begin2search runtime detection - play bingo ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/logs7.asp&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Casino&quot;; nocase; http_header; content:&quot;MsgID=&quot;; nocase; http_header; content:&quot;Data=&quot;; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5770</id>
        <msg>SPYWARE-PUT Snoopware casinoonnet runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1254</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 05 00 00 00|&quot;; depth:8; offset:2; nocase; flowbits:set,Farsighter; flowbits:noalert; classtype:successful-recon-limited;</filter2>
        <id>5771</id>
        <msg>SPYWARE-PUT Screen-Scraper farsighter runtime detection - initial connection</msg>
        <url>www.spywareguide.com/product_show.php?id=587</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Dripline&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5773</id>
        <msg>SPYWARE-PUT Adware forbes runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075448</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/getcard.php?uid=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| FSW&quot;; nocase; http_header; content:&quot;Host|3A| www.freescratchandwin.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5774</id>
        <msg>SPYWARE-PUT Hijacker freescratch runtime detection - get card</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073903</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scratch.php?uid=&quot;; nocase; http_uri; content:&quot;Host|3A| www.freescratchandwin.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5775</id>
        <msg>SPYWARE-PUT Hijacker freescratch runtime detection - scratch card</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073903</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;P2P-Agent|3A| Grokster&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5776</id>
        <msg>SPYWARE-PUT Trickler grokster runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060425</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A| GURL Watcher&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5777</id>
        <msg>SPYWARE-PUT Keylogger gurl watcher runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080847</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;HWPE Windows Activity LOG&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5778</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwpe windows activity logs</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;HWPE Shell/File LOG&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5779</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwpe shell file logs</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;HWAE Windows Activity LOG&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5781</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwae windows activity logs</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;HWAE Keystrokes LOG&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5783</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwae keystrokes log</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;HWAE URLS Browsed LOG&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5784</id>
        <msg>SPYWARE-PUT Keylogger runtime detection - hwae urls browsed log</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080851</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xml/hithopper.xml&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5785</id>
        <msg>SPYWARE-PUT Adware hithopper runtime detection - get xml setting</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079079</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/redirectf.php3?&quot;; fast_pattern; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;adid=&quot;; nocase; http_uri; content:&quot;search_parsed=&quot;; nocase; http_uri; content:&quot;rank=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5786</id>
        <msg>SPYWARE-PUT Adware hithopper runtime detection - redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079079</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?search=&quot;; nocase; http_uri; content:&quot;Host|3A| www.hithopper.com&quot;; fast_pattern:only; pcre:&quot;/\x2Fs(earch)?\x2Ephp3?\x3Fsearch\x3D/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5787</id>
        <msg>SPYWARE-PUT Adware hithopper runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079079</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xml/toolbar/&quot;; nocase; http_uri; content:&quot;Host|3A| www.hithopper.com&quot;; fast_pattern:only; pcre:&quot;/\x2Fxml\x2Ftoolbar\x2F(sports)|(news)|(horoscope2)|(horoscope)|(weather2)|(weather)\.php/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5788</id>
        <msg>SPYWARE-PUT Adware hithopper runtime detection - click toolbar buttons</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079079</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index_a.htm&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;ActMon&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5789</id>
        <msg>SPYWARE-PUT keylogger pc actmon pro runtime detection - http</msg>
        <url>www.spywareguide.com/product_show.php?id=1989</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/getpin.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;did=&quot;; nocase; http_uri; content:&quot;refid=&quot;; nocase; http_uri; content:&quot;udata=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5791</id>
        <msg>SPYWARE-PUT Dialer pluginaccess runtime detection - get pin</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074883</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/activeproxy.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;did=&quot;; nocase; http_uri; content:&quot;pin=&quot;; nocase; http_uri; content:&quot;refid=&quot;; nocase; http_uri; content:&quot;udata=&quot;; nocase; http_uri; content:&quot;resdir=&quot;; nocase; http_uri; content:&quot;selectbox=&quot;; nocase; http_uri; content:&quot;lmi=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5792</id>
        <msg>SPYWARE-PUT Dialer pluginaccess runtime detection - active proxy</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074883</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dlrdir.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;DiallerIP=&quot;; nocase; http_uri; content:&quot;dialled=&quot;; nocase; http_uri; content:&quot;site=&quot;; nocase; http_uri; content:&quot;did=&quot;; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;refid=&quot;; nocase; http_uri; content:&quot;udata=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5793</id>
        <msg>SPYWARE-PUT Dialer pluginaccess runtime detection - redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074883</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/open_console_out.php&quot;; fast_pattern; nocase; http_uri; content:&quot;n=&quot;; nocase; http_uri; content:&quot;pin=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5794</id>
        <msg>SPYWARE-PUT Hijacker coolwebsearch.aboutblank variant runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;adv_id=&quot;; nocase; http_uri; content:&quot;campaign=&quot;; nocase; http_uri; content:&quot;origin=&quot;; nocase; http_uri; content:&quot;program_id=&quot;; nocase; http_uri; content:&quot;subprogram_id=&quot;; nocase; http_uri; content:&quot;site_id=&quot;; nocase; http_uri; content:&quot;ref_url=&quot;; nocase; http_uri; content:&quot;Host|3A| www.power-cleaner.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5795</id>
        <msg>SPYWARE-PUT Adware ist powerscan runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077266</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ping.html&quot;; nocase; http_uri; content:&quot;User-Agent|3A| My AppName&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5796</id>
        <msg>SPYWARE-PUT Adware keenvalue runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094138</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mySpeedbarConfig.jsp?&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;MyWay&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5800</id>
        <msg>SPYWARE-PUT Trackware myway speedbar runtime detection - request config</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tr.js?&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;r=&quot;; nocase; http_uri; content:&quot;Host|3A| c4.myway.com&quot;; fast_pattern:only;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5801</id>
        <msg>SPYWARE-PUT Trackware myway speedbar / mywebsearch toolbar runtime detection - track activity 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/images/nocache/tr/gca/m.gif?&quot;; fast_pattern; nocase; http_uri; content:&quot;rand=&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;r=&quot;; nocase; http_uri; content:&quot;w=&quot;; nocase; http_uri; content:&quot;myway.com&quot;; nocase; http_uri;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5803</id>
        <msg>SPYWARE-PUT Trackware myway speedbar / mywebsearch toolbar runtime detection - collect information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;PG=SPEEDBAR&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\.(jsp)|(html)\?[^\r\n]*PG=SPEEDBAR/Ui&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5805</id>
        <msg>SPYWARE-PUT Trackware myway speedbar runtime detection - switch engines</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SAHSelect=GUID=&quot;; nocase; content:&quot;CustomerID=&quot;; nocase; content:&quot;stealth=&quot;; nocase; content:&quot;InstallerLocation=&quot;; fast_pattern:only; content:&quot;LastPrefs=&quot;; nocase; content:&quot;AgentVersion=&quot;; nocase; content:&quot;CTG=&quot;; nocase; content:&quot;WSS_GW=&quot;; nocase;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5807</id>
        <msg>SPYWARE-PUT Hijacker shopathomeselect runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074921</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GR_check_site.html&quot;; nocase; http_uri; content:&quot;User-Agent|3A| SAH Agent&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5808</id>
        <msg>SPYWARE-PUT Hijacker shop at home search merchant redirect check</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/frameset3.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;MID=&quot;; nocase; http_uri; content:&quot;ruleID=&quot;; nocase; http_uri; content:&quot;popupID=&quot;; nocase; http_uri; content:&quot;doPopup=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;requested=&quot;; nocase; http_uri; content:&quot;CustomerID=&quot;; nocase; http_uri; content:&quot;owner=&quot;; nocase; http_uri; content:&quot;refer=&quot;; nocase; http_uri; content:&quot;LastPrefs=&quot;; http_uri; content:&quot;GUID=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5809</id>
        <msg>SPYWARE-PUT Hijacker shop at home select merchant redirect in progress</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GRInstallCL.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;E=&quot;; nocase; http_uri; content:&quot;MID=&quot;; nocase; http_uri; content:&quot;Refer=&quot;; nocase; http_uri; content:&quot;WGR=&quot;; nocase; http_uri; content:&quot;Prev=&quot;; nocase; http_uri; content:&quot;sGUID=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5810</id>
        <msg>SPYWARE-PUT Hijacker shop at home select installation in progress</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;C0EF89EE-EEC7-4535-A041-F1EBF79560A7&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*C0EF89EE-EEC7-4535-A041-F1EBF79560A7/si&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5811</id>
        <msg>SPYWARE-PUT shop at home select installation in progress - clsid detected</msg>
        <url>www.nuker.com/container/details/shop_at_home_select.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A| |22|Stealth Redirector|22|&quot;; fast_pattern:only; content:&quot;Subject|3A| My IP address&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5812</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - email notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;CONN&quot;; depth:10; offset:6; nocase; pcre:&quot;/^\x2F(TC|FT)PD\s+CONN/smi&quot;; flowbits:set,StealthRedirector_CreateRedirection; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5813</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - create redirection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_CreateRedirection; content:&quot;Created a connection redirect&quot;; depth:29; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5814</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - create redirection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;DISC&quot;; depth:10; offset:6; nocase; pcre:&quot;/^\x2F(TC|FT)PD\s+DISC/smi&quot;; flowbits:set,StealthRedirector_DestoryRedirection; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5815</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory redirection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_DestoryRedirection; content:&quot;Redirection&quot;; nocase; content:&quot;destroyed&quot;; distance:0; nocase; pcre:&quot;/^(TC|FT)P\s+Redirections?\s+destroyed\x21/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5816</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory redirection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;/STAT&quot;; depth:5; nocase; flowbits:set,StealthRedirector_StatusCheck3; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5817</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_StatusCheck3; content:&quot;TCP Redirection is&quot;; fast_pattern:only; flowbits:set,StealthRedirector_StatusCheck4; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5818</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_StatusCheck4; content:&quot;FTP Redirection is&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5819</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;/LOGD&quot;; depth:5; nocase; flowbits:set,StealthRedirector_DestoryLog; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5820</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory log</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_DestoryLog; content:&quot;Deleting &quot;; depth:9; nocase; content:&quot;ATTENTION|3A|&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5821</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory log</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;/NETS&quot;; fast_pattern:only; flowbits:set,StealthRedirector_ViewNetstat; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5822</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - view netstat</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,StealthRedirector_ViewNetstat; content:&quot;Proto Local IP&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5823</id>
        <msg>SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - view netstat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076952</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Strip-Player&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5824</id>
        <msg>SPYWARE-PUT Dialer stripplayer runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072548</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsurfer4/mainplocal.htm?&quot;; fast_pattern; nocase; http_uri; content:&quot;brand=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;call=&quot;; nocase; http_uri; content:&quot;speed=&quot;; nocase; http_uri; content:&quot;unlock=&quot;; nocase; http_uri; content:&quot;archive=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5825</id>
        <msg>SPYWARE-PUT Adware broadcasturban tuner runtime detection - start tuner</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=BroadcastURBAN%20tuner&amp;threatid=6093</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsurfer4/&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x2Fnewsurfer4\x2F((register\.asp)|(survey\.asp\?nUserId=))/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5826</id>
        <msg>SPYWARE-PUT Adware broadcasturban tuner runtime detection - pass user info to server</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=BroadcastURBAN%20tuner&amp;threatid=6093</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsurfer4/getgateway.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;userid=&quot;; nocase; http_uri; content:&quot;call=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5827</id>
        <msg>SPYWARE-PUT Adware broadcasturban tuner runtime detection - get gateway</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=BroadcastURBAN%20tuner&amp;threatid=6093</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsurfer4/&quot;; fast_pattern; nocase; http_uri; content:&quot;brand=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;speed=&quot;; nocase; http_uri; content:&quot;title=&quot;; nocase; http_uri; content:&quot;artist=&quot;; nocase; http_uri; content:&quot;show=&quot;; nocase; http_uri; content:&quot;call=&quot;; nocase; http_uri; content:&quot;archive=&quot;; nocase; http_uri; pcre:&quot;/\x2Fnewsurfer4\x2F[a-zA-Z0-9_-]*\.asp\?brand=/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5828</id>
        <msg>SPYWARE-PUT Adware broadcasturban tuner runtime detection - connect to station</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=BroadcastURBAN%20tuner&amp;threatid=6093</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/omnidirect.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;SID=&quot;; nocase; http_uri; content:&quot;PID=&quot;; nocase; http_uri; content:&quot;LID=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;PARMR=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5829</id>
        <msg>SPYWARE-PUT Trickler clipgenie runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073486</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;Gamespy Arcade&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5835</id>
        <msg>SPYWARE-PUT Adware gamespy_arcade runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1241</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/PopupV&quot;; fast_pattern; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;mSkip=&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5836</id>
        <msg>SPYWARE-PUT Trickler nictech.bm2 runtime detection</msg>
        <url>&quot;research.sunbelt-software.com/threat_display.cfm?name=NicTech.BM2&amp;threatid=15195&quot;</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iis2ucms.asp&quot;; nocase; content:&quot;RequestString=&quot;; distance:0; nocase; content:&quot;UCMXML&quot;; distance:0; nocase; content:&quot;User-Agent|3A| EI&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5837</id>
        <msg>SPYWARE-PUT Trackware ucmore runtime detection - track activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=58660</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iis2ucms_getsponsorlinks.asp&quot;; nocase; content:&quot;RequestString=&quot;; distance:0; nocase; content:&quot;UCMXML&quot;; distance:0; nocase; content:&quot;User-Agent|3A| EI&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5838</id>
        <msg>SPYWARE-PUT Trackware ucmore runtime detection - get sponsor/ad links</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=58660</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/click.asp?&quot;; nocase; http_uri; content:&quot;Host|3A| sponsor2.ucmore.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5839</id>
        <msg>SPYWARE-PUT Trackware ucmore runtime detection - click sponsor/ad link</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=58660</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad/?&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;SE=&quot;; nocase; http_uri; content:&quot;SID=&quot;; nocase; http_uri; content:&quot;Host|3A| www.searchreslt.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5840</id>
        <msg>SPYWARE-PUT Hijacker sep runtime detection</msg>
        <url>process.networktechs.com/sep.dll.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WxDataISAPI/WxDataISAPI.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;Magic=&quot;; nocase; http_uri; content:&quot;RegNum=&quot;; nocase; http_uri; content:&quot;ZipCode=&quot;; nocase; http_uri; content:&quot;StationID=&quot;; nocase; http_uri; content:&quot;Units=&quot;; nocase; http_uri; content:&quot;Version=&quot;; nocase; http_uri; content:&quot;Fore=&quot;; nocase; http_uri; content:&quot;t=&quot;; nocase; http_uri; content:&quot;lv=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5841</id>
        <msg>SPYWARE-PUT Trickler minibug runtime detection - retrieve weather information</msg>
        <url>www.spywareguide.com/product_show.php?id=2178</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/RealMedia/ads/adstream_sx.cgi/www.wbug.com/&quot;; fast_pattern; nocase; http_uri; content:&quot;A1=&quot;; nocase; http_uri; content:&quot;A2=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5842</id>
        <msg>SPYWARE-PUT Trickler minibug runtime detection - ads</msg>
        <url>www.spywareguide.com/product_show.php?id=2178</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.aspx?&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;client=SSKD&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5843</id>
        <msg>SPYWARE-PUT Hijacker surfsidekick runtime detection - hijack ie auto search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090721</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/requestimpression.aspx?&quot;; nocase; content:&quot;ver=&quot;; distance:0; nocase; content:&quot;guid=&quot;; distance:0; nocase; content:&quot;host=&quot;; distance:0; nocase; content:&quot;Host|3A| ads.surfsidekick.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5844</id>
        <msg>SPYWARE-PUT Hijacker surfsidekick runtime detection - post request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090721</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rinfo.htm?&quot;; fast_pattern; nocase; http_uri; content:&quot;host=&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;bundle=&quot;; nocase; http_uri; content:&quot;client=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5845</id>
        <msg>SPYWARE-PUT Hijacker surfsidekick runtime detection - update request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090721</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a/Drk.syn&quot;; nocase; http_uri; content:&quot;adcontext=&quot;; nocase; http_uri; content:&quot;countrycodein=&quot;; fast_pattern; nocase; http_uri; content:&quot;lastAdTime=&quot;; nocase; http_uri; content:&quot;lastAdCode=&quot;; nocase; http_uri; content:&quot;cookie1=&quot;; nocase; http_uri; content:&quot;cookie2=&quot;; nocase; http_uri; content:&quot;cookie3=&quot;; nocase; http_uri; content:&quot;cookie4=&quot;; nocase; http_uri; content:&quot;InstID=&quot;; nocase; http_uri; content:&quot;status=&quot;; nocase; http_uri; content:&quot;smode=&quot;; nocase; http_uri; content:&quot;bho=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5846</id>
        <msg>SPYWARE-PUT Trickler VX2/DLmax/BestOffers/Aurora runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096297</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/home.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;co=&quot;; nocase; http_uri; content:&quot;NewUser=&quot;; nocase; http_uri; content:&quot;info=WDC&quot;; nocase; http_uri; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5847</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - p2p client home</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updn.php?ver=&quot;; nocase; http_uri; content:&quot;Host|3A| data.warezclient.com&quot;; fast_pattern:only; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5849</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - update request</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upd/check?&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;localeId=&quot;; nocase; http_uri; content:&quot;affid=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;windowsVersion=&quot;; nocase; http_uri; content:&quot;rVersion=&quot;; nocase; http_uri; content:&quot;updateValue=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Download Agent&quot;; fast_pattern:only; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5850</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - check update</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;Indy Library&quot;; nocase; http_header; content:&quot;Host|3A| data.warezclient.com&quot;; fast_pattern:only; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5851</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - .txt .dat and .lst requests</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cache/data/cache.dat&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Warez Beta Client&quot;; fast_pattern:only;  metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5852</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - cache.dat request</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?e=&quot;; nocase; http_uri; content:&quot;&amp;v=&quot;; nocase; http_uri; content:&quot;Host|3A| adserver.warezclient.com&quot;; fast_pattern; nocase; http_header;  metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5853</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - download ads</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cache/cache.php?&quot;; nocase; http_uri; content:&quot;host=&quot;; nocase; http_uri; content:&quot;state=&quot;; nocase; http_uri; content:&quot;nat=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Warez Beta Client&quot;; fast_pattern:only; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>5854</id>
        <msg>SPYWARE-PUT Adware warez_p2p runtime detection - pass user information</msg>
        <url>www.spywareguide.com/category_show.php?id=5</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mySpeedbarCfg2.jsp?&quot;; fast_pattern; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;p=ZB&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;e=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5855</id>
        <msg>SPYWARE-PUT Hijacker funbuddyicons runtime detection - request config</msg>
        <url>www.pchell.com/support/funbuddyicons.shtml</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mysaconfg.jsp?&quot;; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;MyWebSearchSearchAssistant&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5857</id>
        <msg>SPYWARE-PUT Hijacker funbuddyicons runtime detection - mysaconfg request</msg>
        <url>www.pchell.com/support/funbuddyicons.shtml</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/&quot;; nocase; http_uri; content:&quot;Host|3A| www.praize.com&quot;; fast_pattern:only; pcre:&quot;/\x2Ftoolbar\x2F((version\x2Etxt)|(notifytoolbar\x2Ehtml))/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5858</id>
        <msg>SPYWARE-PUT Adware praizetoolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079048</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/advers/zl/version.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| daosearch.com&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5859</id>
        <msg>SPYWARE-PUT Hijacker daosearch runtime detection - information request</msg>
        <url>securityresponse.symantec.com/avcenter/venc/data/adware.daosearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;o.php?&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| daosearch.com&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5860</id>
        <msg>SPYWARE-PUT Hijacker daosearch runtime detection - search hijack</msg>
        <url>securityresponse.symantec.com/avcenter/venc/data/adware.daosearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xml.php&quot;; nocase; http_uri; content:&quot;tid=&quot;; nocase; http_uri; content:&quot;ref=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Toolbar&quot;; fast_pattern:only; pcre:&quot;/tid\x3D\x7B([0-9A-z]+\x2D){4}[0-9A-z]+\x7D/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5861</id>
        <msg>SPYWARE-PUT Hijacker isearch runtime detection - toolbar information request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082740</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dns.php?&quot;; nocase; http_uri; content:&quot;text=&quot;; nocase; http_uri; content:&quot;Host|3A| auto.isearch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5862</id>
        <msg>SPYWARE-PUT Hijacker isearch runtime detection - search hijack 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082740</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/phrase.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;text=&quot;; nocase; http_uri; content:&quot;tid=&quot;; nocase; http_uri; content:&quot;ref=%user_id&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5863</id>
        <msg>SPYWARE-PUT Hijacker isearch runtime detection - search hijack 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082740</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;qry_str=&quot;; fast_pattern; nocase; http_uri; content:&quot;src=tbi&quot;; nocase; http_uri; content:&quot;tid=&quot;; nocase; http_uri; content:&quot;ref=&quot;; nocase; http_uri; pcre:&quot;/tid\x3D\x7B([0-9A-z]+\x2D){4}[0-9A-z]+\x7D/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5864</id>
        <msg>SPYWARE-PUT Hijacker isearch runtime detection - search in toolbar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082740</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cbb/frame.asp?&quot;; nocase; http_uri; content:&quot;cbb=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;Host|3A| www.zapspot.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5865</id>
        <msg>SPYWARE-PUT Adware zapspot runtime detection - pop up ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075441</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CBXml.asp?&quot;; nocase; http_uri; content:&quot;tc=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Toolbar&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5866</id>
        <msg>SPYWARE-PUT Hijacker couponbar runtime detection - download new coupon offers and links</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079137</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CouponBar/CBXmlFiles/&quot;; fast_pattern; nocase; http_uri; content:&quot;.bmp&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Toolbar&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5867</id>
        <msg>SPYWARE-PUT Hijacker couponbar runtime detection - get updates to toolbar buttons</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079137</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/CBTerms.asp&quot;; nocase; http_uri; content:&quot;Host|3A| couponbar.coupons.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5868</id>
        <msg>SPYWARE-PUT Hijacker couponbar runtime detection - view coupon offers</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079137</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bi/servlet/Thinstall&quot;; fast_pattern:only; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;.exe&quot;; nocase; http_header; pcre:&quot;/\x2Fbi\x2Fservlet\x2FThinstall(Pre|Result).*^User-Agent\x3A[^\r\n]*\.exe[^\r\n]*\x7B[\dA-Za-z]{8}-[\dA-Za-z]{4}-[\dA-Za-z]{4}-[\dA-Za-z]{4}-[\dA-Za-z]{12}\x7D\x7C[\dA-Za-z]{8}\x7C\d{5}-\d{3}-\d{7}-\d{5}/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5871</id>
        <msg>SPYWARE-PUT Trickler VX2/ABetterInternet transponder thinstaller runtime detection - post information</msg>
        <url>www.geekstogo.com/forum/Aurora_spyware_Nailexe-t24344.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/lm/rtl3i.asp&quot;; nocase; http_uri; content:&quot;si=&quot;; nocase; http_uri; content:&quot;k=&quot;; nocase; http_uri; content:&quot;Host|3A| www.serverlogic3.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5872</id>
        <msg>SPYWARE-PUT Snoopware hyperlinker runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090785</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A| mPOP Web-Mail&quot;; fast_pattern:only; flowbits:set,PCAcmePro; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5873</id>
        <msg>SPYWARE-PUT Snoopware pc acme pro runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2271</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,PCAcmePro; content:&quot;Attached file is PC Acme report&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5874</id>
        <msg>SPYWARE-PUT Snoopware pc acme pro runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2271</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 871</filter1>
        <filter2>flow:to_server,established; content:&quot;Detonate&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5875</id>
        <msg>SPYWARE-PUT Hacker-Tool eraser runtime detection - detonate</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072642</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 871</filter1>
        <filter2>flow:to_server,established; content:&quot;Disinfect&quot;; depth:9; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5876</id>
        <msg>SPYWARE-PUT Hacker-Tool eraser runtime detection - disinfect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072642</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;This is an alert notification from SpyAgent&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5882</id>
        <msg>SPYWARE-PUT Keylogger spyagent runtime detect - alert notification</msg>
        <url>www.spywareguide.com/product_show.php?id=22</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;op=&quot;; nocase; http_uri; content:&quot;vic=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; fast_pattern; nocase; http_uri; content:&quot;pass=&quot;; nocase; http_uri; pcre:&quot;/pass=(YAHOO|(XP\s+)?MSN|PALTALK)/Ui&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5883</id>
        <msg>SPYWARE-PUT Other-Technologies saria 1.0 runtime detection - send user information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080923</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/software/meta/Update/VersionCheckInfo.ini?c=&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5884</id>
        <msg>SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - check toolbar &amp; category info</msg>
        <url>www.copernic.com/en/products/meta/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/copern.light/redirs_all.htm?&quot;; fast_pattern; nocase; http_uri; content:&quot;pgtarg=&quot;; nocase; http_uri; content:&quot;qcat=&quot;; nocase; http_uri; content:&quot;qkw=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5885</id>
        <msg>SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - ie autosearch &amp; search assistant hijack</msg>
        <url>www.copernic.com/en/products/meta/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/sr/?&quot;; nocase; http_uri; content:&quot;xargs=&quot;; nocase; http_uri; content:&quot;yargs=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;metaresults.copernic.com&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5886</id>
        <msg>SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - pass info to server</msg>
        <url>www.copernic.com/en/products/meta/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/9899/search/results.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;source=&quot;; nocase; http_uri; content:&quot;pa=&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5887</id>
        <msg>SPYWARE-PUT Hijacker shopnav runtime detection - ie search assistant hijack</msg>
        <url>www.spywareguide.com/product_show.php?id=582</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchcat.jsp?p=&quot;; fast_pattern; nocase; http_uri; content:&quot;appid=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; metadata:policy balanced-ips drop, policy security-ips drop, service http; classtype:misc-activity;</filter2>
        <id>5888</id>
        <msg>SPYWARE-PUT Hijacker shopnav runtime detection - ie auto search hijack</msg>
        <url>www.spywareguide.com/product_show.php?id=582</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dat/bgf/trpix.gif?&quot;; nocase; http_uri; content:&quot;rdm=&quot;; nocase; http_uri; content:&quot;dlv=&quot;; nocase; http_uri; content:&quot;dmn=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;search2.ad.shopnav.com/9899/search/results.php&quot;; nocase; http_header;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5889</id>
        <msg>SPYWARE-PUT Hijacker shopnav runtime detection - collect information</msg>
        <url>www.spywareguide.com/product_show.php?id=582</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/9899/srng/reg.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;IpAddr=&quot;; nocase; http_uri; content:&quot;OS=&quot;; nocase; http_uri; content:&quot;RegistryChanged=&quot;; nocase; http_uri; content:&quot;RegistryUpdate=&quot;; nocase; http_uri; content:&quot;Basedir=&quot;; nocase; http_uri; content:&quot;SrngInstalled=&quot;; nocase; http_uri; content:&quot;SrngVer=&quot;; nocase; http_uri; content:&quot;PCID=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5890</id>
        <msg>SPYWARE-PUT Hijacker shopnav runtime detection - self-update request 1</msg>
        <url>www.spywareguide.com/product_show.php?id=582</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/9899/srng/jrnl.php&quot;; nocase; content:&quot;PCID=&quot;; distance:0; nocase; content:&quot;OS=&quot;; distance:0; nocase; content:&quot;Category=&quot;; distance:0; nocase; content:&quot;Field=&quot;; distance:0; nocase; content:&quot;Description=&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5891</id>
        <msg>SPYWARE-PUT Hijacker shopnav runtime detection - self-update request 2</msg>
        <url>www.spywareguide.com/product_show.php?id=582</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|5C 00|T|00|B|00|2|00|&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5894</id>
        <msg>SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - smb</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076680</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 407</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 01|&quot;; depth:2; content:&quot;|00|R|00|%&quot;; offset:4; flowbits:set,Timbuktu_Pro_TCPPort_407; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5895</id>
        <msg>SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - tcp port 407</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 407 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Timbuktu_Pro_TCPPort_407; content:&quot;|01 01|&quot;; depth:2; content:&quot;|00 8E 00|%&quot;; offset:4;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5896</id>
        <msg>SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - tcp port 407</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076680</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 407</filter1>
        <filter2>flow:to_server; content:&quot;|00|%|00 22|&quot;; depth:4;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5897</id>
        <msg>SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - udp port 407</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076680</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/acts/tracking/track.asp&quot;; nocase; content:&quot;Data=&quot;; distance:0; nocase; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;AdTools&quot;; nocase; http_header; content:&quot;Host|3A| trackcl.adtoolsinc.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5898</id>
        <msg>SPYWARE-PUT Trackware adtools runtime detection - track user activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/roche.asp?&quot;; nocase; http_uri; content:&quot;zip=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;AdTools&quot;; nocase; http_header; content:&quot;Host|3A| www.flustar.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5899</id>
        <msg>SPYWARE-PUT Trackware adtools-screenmate runtime detection - generate desktop alert</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;yourname=&quot;; nocase; content:&quot;youremail=&quot;; distance:0; nocase; content:&quot;recipname=&quot;; distance:0; fast_pattern; nocase; content:&quot;recipemail=&quot;; distance:0; nocase; content:&quot;AD=&quot;; distance:0; nocase; content:&quot;User-Agent|3A| Async HTTP Agent&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5900</id>
        <msg>SPYWARE-PUT Trackware adtools-communicator runtime detection - collect information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/clientcontent/StewieGriffin/selfupdate.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;i=&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;FI=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;AdTools&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5901</id>
        <msg>SPYWARE-PUT Trackware adtools-communicator runtime detection - download self-update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/ads9.dll?&quot;; fast_pattern; nocase; http_uri; content:&quot;HTML=&quot;; nocase; http_uri; content:&quot;DAUI=&quot;; nocase; http_uri; content:&quot;INC=&quot;; nocase; http_uri; content:&quot;DL=&quot;; nocase; http_uri; content:&quot;CX=&quot;; nocase; http_uri; content:&quot;CY=&quot;; nocase; http_uri; content:&quot;IIA=&quot;; nocase; http_uri; content:&quot;IIG=&quot;; nocase; http_uri; content:&quot;IIP=&quot;; nocase; http_uri; content:&quot;III=&quot;; nocase; http_uri; content:&quot;V=&quot;; nocase; http_uri;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5903</id>
        <msg>SPYWARE-PUT Adware download accelerator plus runtime detection - get ads</msg>
        <url>reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/MirrorSearch.dll?&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| DA&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5904</id>
        <msg>SPYWARE-PUT Adware download accelerator plus runtime detection - download files</msg>
        <url>reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GamesTab_realarcade.asp&quot;; fast_pattern; nocase; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5905</id>
        <msg>SPYWARE-PUT Adware download accelerator plus runtime detection - games center request</msg>
        <url>reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/update.dll?&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| dapupd&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5906</id>
        <msg>SPYWARE-PUT Adware download accelerator plus runtime detection - update</msg>
        <url>reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/go/check?&quot;; nocase; http_uri; content:&quot;build=&quot;; nocase; http_uri; content:&quot;source=&quot;; nocase; http_uri; content:&quot;Host|3A| e2give.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5907</id>
        <msg>SPYWARE-PUT Trackware e2give runtime detection - check update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075049</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fs-bin/click?&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;offerid=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;Referer|3A| e2give.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5908</id>
        <msg>SPYWARE-PUT Trackware e2give runtime detection - redirect affiliate site request 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075049</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fs-bin/swat?&quot;; nocase; http_uri; content:&quot;lsnsig=&quot;; nocase; http_uri; content:&quot;offerid=&quot;; nocase; http_uri; content:&quot;Referer|3A| e2give.com&quot;; fast_pattern; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5909</id>
        <msg>SPYWARE-PUT Trackware e2give runtime detection - redirect affiliate site request 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075049</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Set-Cookie|3A| &quot;; nocase; content:&quot;Domain=casalemedia.com&quot;; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5910</id>
        <msg>SPYWARE-PUT Trackware casalemedia runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082755</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adserv/GetAd.pl&quot;; fast_pattern; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;rfs=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;uri=&quot;; nocase; http_uri; content:&quot;sn=&quot;; nocase; http_uri; content:&quot;cv=&quot;; nocase; http_uri; content:&quot;mdm=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5911</id>
        <msg>SPYWARE-PUT Adware smartpops runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074758</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| My Agent&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5913</id>
        <msg>SPYWARE-PUT Trickler smasoft webdownloader runtime detection</msg>
        <url>www.megasecurity.org/trojans/w/webdownloader/Webdownloader1.2.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download/toolbar/locatorstoolbar&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5914</id>
        <msg>SPYWARE-PUT Hijacker locatorstoolbar runtime detection - configuration download</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076978</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download/toolbar/dnserror.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;type=dns&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5915</id>
        <msg>SPYWARE-PUT Hijacker locatorstoolbar runtime detection - autosearch hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076978</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;sidebar=method&quot;; fast_pattern; nocase; http_uri; content:&quot;que=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5916</id>
        <msg>SPYWARE-PUT Hijacker locatorstoolbar runtime detection - sidebar search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076978</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dir/&quot;; nocase; http_uri; content:&quot;Host|3A| www.locators.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5917</id>
        <msg>SPYWARE-PUT Hijacker locatorstoolbar runtime detection - toolbar search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076978</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ping&quot;; nocase; content:&quot;Host|3A| 195.225.&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5918</id>
        <msg>SPYWARE-PUT Hijacker painter runtime detection - ping 'alive' signal</msg>
        <url>www.spywareguide.com/product_show.php?id=2730</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| www.klikvipsearch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5919</id>
        <msg>SPYWARE-PUT Hijacker painter runtime detection - redirect to klikvipsearch</msg>
        <url>www.spywareguide.com/product_show.php?id=2730</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mtc/yahoo/search.php?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| online-casino-searcher.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5920</id>
        <msg>SPYWARE-PUT Hijacker painter runtime detection - redirect yahoo search through online-casino-searcher</msg>
        <url>www.spywareguide.com/product_show.php?id=2730</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/downloads/toolbar/related.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;cli=&quot;; nocase; http_uri; content:&quot;dat=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| www.fast-finder.com&quot;; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5921</id>
        <msg>SPYWARE-PUT Trackware fftoolbar toolbar runtime detection - send user url request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097640</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/downloads/toolbar/ticker.xml&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| www.fast-finder.com&quot;; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5922</id>
        <msg>SPYWARE-PUT Trackware fftoolbar toolbar runtime detection - display advertisement news</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097640</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sidebar.asp?&quot;; nocase; http_uri; content:&quot;search=&quot;; nocase; http_uri; content:&quot;Host|3A| sidebar.activeshopper.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5923</id>
        <msg>SPYWARE-PUT Adware active shopper runtime detection - side search request</msg>
        <url>www.spywareguide.com/product_show.php?id=2410</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/active/redir_sidecheck.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;search=&quot;; nocase; http_uri; content:&quot;dom=&quot;; nocase; http_uri; content:&quot;Host|3A| data2.activshopper.com&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5924</id>
        <msg>SPYWARE-PUT Adware active shopper runtime detection - redirect</msg>
        <url>www.spywareguide.com/product_show.php?id=2410</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/check.asp?&quot;; nocase; http_uri; content:&quot;search=&quot;; nocase; http_uri; content:&quot;dom=&quot;; nocase; http_uri; content:&quot;Host|3A| sidebar.activeshopper.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5925</id>
        <msg>SPYWARE-PUT Adware active shopper runtime detection - check</msg>
        <url>www.spywareguide.com/product_show.php?id=2410</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/HG?&quot;; nocase; http_uri; content:&quot;hc=&quot;; nocase; http_uri; content:&quot;vcon=ActiveShopper&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5926</id>
        <msg>SPYWARE-PUT Adware active shopper runtime detection - collect information</msg>
        <url>www.spywareguide.com/product_show.php?id=2410</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cbn/&quot;; nocase; http_uri; content:&quot;.smx?&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| ads.cashsurfers.com&quot;; fast_pattern:only; pcre:&quot;/\x2Fcbn\x2F(c|b)\.smx\?[^\r\n]*u=/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5927</id>
        <msg>SPYWARE-PUT Adware cashbar runtime detection - .smx requests</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076621</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ads.aspx?&quot;; nocase; http_uri; content:&quot;Host|3A| ads.grokads.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5928</id>
        <msg>SPYWARE-PUT Adware cashbar runtime detection - ads request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076621</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;si=&quot;; nocase; http_uri; content:&quot;Host|3A| www.metareward.com&quot;; fast_pattern:only; pcre:&quot;/\x2F(f|s)\?[^\r\n]*si=/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5929</id>
        <msg>SPYWARE-PUT Adware cashbar runtime detection - pop-up ad 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076621</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/asp/offers.asp?url=http|3A|/cashsurfers.metareward.com&quot;; fast_pattern; nocase; http_uri;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5930</id>
        <msg>SPYWARE-PUT Adware cashbar runtime detection - pop-up ad 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076621</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/connect.cgi?&quot;; nocase; http_uri; content:&quot;usr=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;title=CashSurfers&quot;; fast_pattern; nocase; http_uri;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5932</id>
        <msg>SPYWARE-PUT Adware cashbar runtime detection - stats track</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076621</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi?&quot;; nocase; http_uri; content:&quot;source=&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;Host|3A| search.dropspam.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5933</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - search request 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi?&quot;; nocase; http_uri; content:&quot;tbid=&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;Host|3A| search.dropspam.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5934</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - search request 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi&quot;; nocase; content:&quot;source=lifestyle&quot;; nocase; content:&quot;query=&quot;; distance:0; nocase; content:&quot;select=&quot;; distance:0; nocase; content:&quot;Host|3A| desksearch.dropspam.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5935</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - search request 3</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sidesearch.htm&quot;; nocase; http_uri; content:&quot;Host|3A| sidesearch.dropspam.com&quot;; fast_pattern:only; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5936</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - side search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r.php?&quot;; nocase; http_uri; content:&quot;apid=&quot;; nocase; http_uri; content:&quot;ldid=&quot;; nocase; http_uri; content:&quot;tpid=&quot;; nocase; http_uri; content:&quot;ttid=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;cdurl=&quot;; nocase; http_uri; content:&quot;srurl=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;mysearch.dropspam.com/index.php?tpid=&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5937</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - pass information to its controlling server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/sr/?&quot;; nocase; http_uri; content:&quot;xargs=&quot;; nocase; http_uri; content:&quot;yargs=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;mysearch.dropspam.com/index.php?tpid=&quot;; nocase; http_header; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5938</id>
        <msg>SPYWARE-PUT Hijacker dropspam runtime detection - third party information collection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/desktop/&quot;; nocase; http_uri; content:&quot;/toolbar/supremetb&quot;; fast_pattern; nocase; http_uri; content:&quot;.cfg&quot;; nocase; http_uri; pcre:&quot;/\x2Fdesktop\x2F\d+\x2Ftoolbar\x2Fsupremetb\d+\.cfg/Ui&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5939</id>
        <msg>SPYWARE-PUT Trackware supreme toolbar runtime detection - get cfg</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097530</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php?tpid=&quot;; nocase; http_uri; content:&quot;tspid=&quot;; nocase; http_uri; content:&quot;prid=&quot;; nocase; http_uri; content:&quot;ttid=&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;Host|3A| supremetoolbar.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5940</id>
        <msg>SPYWARE-PUT Trackware supreme toolbar runtime detection - search request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097530</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ctx/imptrack.php?&quot;; nocase; http_uri; content:&quot;build=&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;adv=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;supremetoolbar.com/index.php?tpid=&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5941</id>
        <msg>SPYWARE-PUT Trackware supreme toolbar runtime detection - track</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097530</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r.php?&quot;; nocase; http_uri; content:&quot;apid=&quot;; nocase; http_uri; content:&quot;ldid=&quot;; nocase; http_uri; content:&quot;tpid=&quot;; nocase; http_uri; content:&quot;ttid=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;cdurl=&quot;; nocase; http_uri; content:&quot;srurl=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;supremetoolbar.com/index.php?tpid=&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5942</id>
        <msg>SPYWARE-PUT Trackware supreme toolbar runtime detection - pass information to its controlling server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/sr/?&quot;; nocase; http_uri; content:&quot;xargs=&quot;; nocase; http_uri; content:&quot;yargs=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;supremetoolbar.com/index.php?tpid=&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5943</id>
        <msg>SPYWARE-PUT Trackware supreme toolbar runtime detection - third party information collection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| FreeAccessBar&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5944</id>
        <msg>SPYWARE-PUT Adware free access bar runtime detection 1</msg>
        <url>www.spywareguide.com/product_show.php?id=2493</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/request/req.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;gu=TN-internal&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;sp=&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;sn=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;AID=&quot;; nocase; http_uri; content:&quot;FT=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5946</id>
        <msg>SPYWARE-PUT Adware weirdontheweb runtime detection - monitor user web activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094260</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi/logurl.cgi&quot;; nocase; content:&quot;form-data|3B| name=|22|pid|22|&quot;; fast_pattern:only; content:&quot;internal&quot;; nocase; content:&quot;User-Agent|3A| MyPost&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5947</id>
        <msg>SPYWARE-PUT Adware weirdontheweb runtime detection - log url</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094260</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/notifier/&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;b=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;metadata=&quot;; nocase; http_uri; content:&quot;Host|3A| www.weirdontheweb.net&quot;; fast_pattern:only; pcre:&quot;/\x2Fnotifier\x2F(configINTERNAL\.ini)|(update\.cgi)\?/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5948</id>
        <msg>SPYWARE-PUT Adware weirdontheweb runtime detection - update notifier</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094260</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Browser/CT48638/1_Simpleticker.htm&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5949</id>
        <msg>SPYWARE-PUT Trackware iggsey toolbar detection - simpleticker.htm request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094796</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iis2ebs.asp&quot;; nocase; content:&quot;User-Agent|3A| EI&quot;; nocase; http_header; content:&quot;RequestString=&quot;; nocase; content:&quot;GENERAL_PARAM1&quot;; distance:0; nocase; content:&quot;GENERAL_PARAM2&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5950</id>
        <msg>SPYWARE-PUT Trackware iggsey toolbar detection - pass information to server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094796</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?keywords=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| www.iggsey.com&quot;; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5951</id>
        <msg>SPYWARE-PUT Trackware iggsey toolbar detection - search request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094796</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/english.asp?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| www.123mania.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5952</id>
        <msg>SPYWARE-PUT Hijacker 123mania runtime detection - autosearch hijacking</msg>
        <url>www.spywareguide.com/product_show.php?id=940</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ie?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;hl=&quot;; nocase; http_uri; content:&quot;lr=&quot;; nocase; http_uri; content:&quot;ie=&quot;; nocase; http_uri; content:&quot;btnG=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;www.123mania.com/0409/ie.asp&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5953</id>
        <msg>SPYWARE-PUT Hijacker 123mania runtime detection - sidesearch hijacking</msg>
        <url>www.spywareguide.com/product_show.php?id=940</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Browser Pal&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5954</id>
        <msg>SPYWARE-PUT Trackware browserpal runtime detection - post user info to server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074906</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perl/adblocker.pl&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Popup Stopper |28|BDLL|29| Agent&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5955</id>
        <msg>SPYWARE-PUT Trackware browserpal runtime detection - adblocker function</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074906</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; http_uri; content:&quot;from=GhostVoiceServer&quot;; nocase; content:&quot;fromemail=&quot;; distance:0; nocase; content:&quot;subject=GhostVoice&quot;; distance:0; nocase; content:&quot;Online&quot;; distance:0; nocase; content:&quot;body=&quot;; distance:0; nocase; content:&quot;to=&quot;; distance:0; nocase; content:&quot;Send=&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5956</id>
        <msg>SPYWARE-PUT Hacker-Tool ghostvoice 1.02 icq notification of server installation</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073224</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;!Request!&quot;; depth:9; flowbits:set,GhostVoice_InitConnection_withpassword; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5957</id>
        <msg>SPYWARE-PUT Hacker-Tool ghostvoice 1.02 runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.m?&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;r=rxh&quot;; nocase; http_uri; content:&quot;Host|3A| www.raxsearch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5960</id>
        <msg>SPYWARE-PUT Hijacker raxsearch detection - pop-up raxsearch window</msg>
        <url>www.spywareguide.com/product_show.php?id=2485</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchfast/ticker.xml&quot;; nocase; http_uri; content:&quot;Host|3A| www.thecommunicator.net&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5961</id>
        <msg>SPYWARE-PUT Hijacker searchfast detection - news ticker</msg>
        <url>www.spywareguide.com/product_show.php?id=1694</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fstdirectory/searchResults.php?searchTerm=&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5963</id>
        <msg>SPYWARE-PUT Hijacker searchfast detection - search request</msg>
        <url>www.spywareguide.com/product_show.php?id=1694</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data?&quot;; nocase; http_uri; content:&quot;cli=&quot;; nocase; http_uri; content:&quot;dat=nsa&quot;; nocase; http_uri; content:&quot;ver=visicom&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| xml.alexa.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5964</id>
        <msg>SPYWARE-PUT Hijacker searchfast detection - track user activity &amp; get 'relates links' of the toolbar</msg>
        <url>www.spywareguide.com/product_show.php?id=1694</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchfast/&quot;; nocase; http_uri; content:&quot;/communicatortb&quot;; fast_pattern; nocase; http_uri; content:&quot;.cfg&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5965</id>
        <msg>SPYWARE-PUT Hijacker searchfast detection - get toolbar cfg</msg>
        <url>www.spywareguide.com/product_show.php?id=1694</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;said=bar&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| www.searchinweb.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5966</id>
        <msg>SPYWARE-PUT trackware searchinweb detection - search request</msg>
        <url>www.spywareguide.com/product_show.php?id=1787</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/click.php?&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Referer|3A| http|3A|//www.searchinweb.com/search.php?said=bar&amp;q=&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5967</id>
        <msg>SPYWARE-PUT trackware searchinweb detection - click result links</msg>
        <url>www.spywareguide.com/product_show.php?id=1787</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/go.php?c=&quot;; nocase; http_uri; content:&quot;Referer|3A| http|3A|//www.searchinweb.com/search.php?said=bar&amp;q=&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5968</id>
        <msg>SPYWARE-PUT trackware searchinweb detection - redirect</msg>
        <url>www.spywareguide.com/product_show.php?id=1787</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r?X=&quot;; nocase; http_uri; content:&quot;Referer|3A| http|3A|//www.searchinweb.com/search.php?said=bar&amp;q=&quot;; fast_pattern; nocase; http_header; content:&quot;Host|3A| c.goclick.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5969</id>
        <msg>SPYWARE-PUT trackware searchinweb detection - collect information</msg>
        <url>www.spywareguide.com/product_show.php?id=1787</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r/keys/keys&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Feat2 Updater&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5970</id>
        <msg>SPYWARE-PUT hijacker smart finder detection - keys update</msg>
        <url>www.spywareguide.com/product_show.php?id=2165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cnt/hp?&quot;; nocase; http_uri; content:&quot;Host|3A| www.trackhits.cc&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5971</id>
        <msg>SPYWARE-PUT hijacker smart finder detection - track hits</msg>
        <url>www.spywareguide.com/product_show.php?id=2165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sh.php?&quot;; nocase; http_uri; content:&quot;qq=&quot;; nocase; http_uri; content:&quot;pin=&quot;; nocase; http_uri; content:&quot;v0=&quot;; nocase; http_uri; content:&quot;HelpAgent|3A|&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5972</id>
        <msg>SPYWARE-PUT hijacker smart finder detection - ie autosearch hijack 1</msg>
        <url>www.spywareguide.com/product_show.php?id=2165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gc/xsearch.php?&quot;; nocase; http_uri; content:&quot;qq=&quot;; nocase; http_uri; content:&quot;pin=&quot;; nocase; http_uri; content:&quot;v0=&quot;; nocase; http_uri; content:&quot;Host|3A| presentsearch.net&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5973</id>
        <msg>SPYWARE-PUT hijacker smart finder detection - search engines hijack</msg>
        <url>www.spywareguide.com/product_show.php?id=2165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad/cc.php?&quot;; nocase; http_uri; content:&quot;pin=&quot;; nocase; http_uri; content:&quot;qq=&quot;; nocase; http_uri; content:&quot;v0=&quot;; nocase; http_uri; content:&quot;Host|3A| www.platinumfinder.net&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5974</id>
        <msg>SPYWARE-PUT hijacker smart finder detection - pop-up ads</msg>
        <url>www.spywareguide.com/product_show.php?id=2165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php?tpid=&quot;; nocase; http_uri; content:&quot;ttid=&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;Host|3A| ws1.appswebservice.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5975</id>
        <msg>SPYWARE-PUT hijacker topfive searchassistant detection - search request</msg>
        <url>www.spywareguide.com/product_show.php?id=2645</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php?&quot;; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;ldid=&quot;; nocase; http_uri; content:&quot;fpid=&quot;; nocase; http_uri; content:&quot;fdid=&quot;; nocase; http_uri; content:&quot;prid=&quot;; nocase; http_uri; content:&quot;tpid=&quot;; nocase; http_uri; content:&quot;ttid=&quot;; nocase; http_uri; content:&quot;tspid=&quot;; nocase; http_uri; content:&quot;pn=&quot;; nocase; http_uri; content:&quot;x=&quot;; nocase; http_uri; content:&quot;y=&quot;; nocase; http_uri; content:&quot;Referer|3A| ws1.appswebservice.com/index.php?tpid=&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5976</id>
        <msg>SPYWARE-PUT hijacker topfive searchassistant detection - side search</msg>
        <url>www.spywareguide.com/product_show.php?id=2645</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/downloads/rs.asp?&quot;; nocase; content:&quot;u=&quot;; distance:0; nocase; content:&quot;p=&quot;; distance:0; nocase; content:&quot;b=&quot;; distance:0; nocase; content:&quot;c=&quot;; distance:0; nocase; content:&quot;v=&quot;; distance:0; nocase; content:&quot;o=&quot;; distance:0; nocase; content:&quot;s=&quot;; distance:0; nocase; content:&quot;User-Agent|3A| TM_SEARCH3&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5977</id>
        <msg>SPYWARE-PUT hijacker topfive searchassistant detection - post user information to server</msg>
        <url>www.spywareguide.com/product_show.php?id=2645</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/downloads/record_download.asp?&quot;; nocase; content:&quot;c=&quot;; distance:0; nocase; content:&quot;psid=&quot;; distance:0; nocase; content:&quot;uuuid=&quot;; distance:0; nocase; content:&quot;ver=&quot;; distance:0; nocase; content:&quot;d=&quot;; distance:0; nocase; content:&quot;User-Agent|3A| TM_SEARCH3&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5978</id>
        <msg>SPYWARE-PUT hijacker topfive searchassistant detection - update</msg>
        <url>www.spywareguide.com/product_show.php?id=2645</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nieuws.dtd&quot;; nocase; http_uri; content:&quot;Host|3A| toolbar.anwb.nl&quot;; fast_pattern:only; content:&quot;Cookie&quot;; nocase; content:&quot;anwbtrack=&quot;; distance:0; nocase; content:&quot;ANWBWebService=&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5979</id>
        <msg>SPYWARE-PUT Trackware anwb toolbar runtime detection - track user ip address</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078342</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/weer.xml&quot;; nocase; http_uri; content:&quot;Host|3A| toolbar.anwb.nl&quot;; fast_pattern:only; content:&quot;Cookie&quot;; nocase; content:&quot;anwbtrack=&quot;; distance:0; nocase; content:&quot;ANWBWebService=&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5980</id>
        <msg>SPYWARE-PUT Trackware anwb toolbar runtime detection - display advertisement</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078342</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/results.jsp&quot;; nocase; http_uri; content:&quot;portal_id=&quot;; nocase; http_uri; content:&quot;domain=seeq.com&quot;; fast_pattern; nocase; http_uri; content:&quot;tag=toolbar&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5981</id>
        <msg>SPYWARE-PUT Hijacker seeqtoolbar runtime detection - autosearch hijack or search in toolbar</msg>
        <url>www.spywareguide.com/product_show.php?id=1026</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/lander.jsp&quot;; nocase; http_uri; content:&quot;referrer=&quot;; nocase; http_uri; content:&quot;domain=seeqmail.com&quot;; fast_pattern; nocase; http_uri; content:&quot;cm_mmc=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5982</id>
        <msg>SPYWARE-PUT Hijacker seeqtoolbar runtime detection - email login page</msg>
        <url>www.spywareguide.com/product_show.php?id=1026</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Subscriptions/NewsFeed.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;selection=&quot;; nocase; http_uri; content:&quot;distribution=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| POWRSTRP&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5983</id>
        <msg>SPYWARE-PUT Adware powerstrip runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074932</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stats/stats.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;userFile=&quot;; nocase; content:&quot;Host|3A| &quot;; nocase; content:&quot;push.com&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5984</id>
        <msg>SPYWARE-PUT Trackware push toolbar installtime detection - user information collect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079100</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchv2tb0200.php&quot;; fast_pattern; nocase; http_uri; content:&quot;barid=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>5985</id>
        <msg>SPYWARE-PUT Trackware push toolbar runtime detection - toolbar information request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079100</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;TeomaBar&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5986</id>
        <msg>SPYWARE-PUT Trickler teomasearchbar runtime detection</msg>
        <url>www.castlecops.com/tk731-Teoma_Bar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates/check_img.php?&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;i=&quot;; nocase; http_uri; content:&quot;now=&quot;; nocase; http_uri; content:&quot;Host|3A| toolbar.wishbone.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5987</id>
        <msg>SPYWARE-PUT Hijacker wishbone runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1784</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| ZC-Bridge&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>5988</id>
        <msg>SPYWARE-PUT Trackware windupdates-mediagateway runtime detection - post data</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094794</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/v2.asmx&quot;; nocase; content:&quot;SOAPAction|3A| |22|http|3A|//ws.broadcastpc.tv/GetConfig|22|&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5989</id>
        <msg>SPYWARE-PUT Adware broadcastpc runtime detection - get config</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074364</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/client/&quot;; nocase; http_uri; content:&quot;.aspx&quot;; nocase; http_uri; content:&quot;Host|3A| www.broadcastpc.tv&quot;; fast_pattern:only; pcre:&quot;/\x2Fclient\x2F(view|tvlistings|tvshowtickets|movietickets)\x2Easpx/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5990</id>
        <msg>SPYWARE-PUT Adware broadcastpc runtime detection - get up-to-date movie/tv/ad information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074364</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;KEYWORD=&quot;; nocase; http_uri; content:&quot;T=&quot;; nocase; http_uri; content:&quot;ERROR=&quot;; nocase; http_uri; content:&quot;Host|3A| websearch.getmirar.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>5991</id>
        <msg>SPYWARE-PUT Hijacker getmirar runtime detection - search request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077933</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/v70click.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;adurl=&quot;; nocase; http_uri; content:&quot;adtitle=&quot;; nocase; http_uri; content:&quot;adbody=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5993</id>
        <msg>SPYWARE-PUT Hijacker getmirar runtime detection - track activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077933</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/thumbnail.cgi?&quot;; nocase; http_uri; content:&quot;DURL=&quot;; nocase; http_uri; content:&quot;TAG=&quot;; nocase; http_uri; content:&quot;Host|3A| awbeta.net-nucleus.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5994</id>
        <msg>SPYWARE-PUT Hijacker getmirar runtime detection - click related button</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077933</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/103/co.aspx?&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;cv=&quot;; nocase; http_uri; content:&quot;cfv=&quot;; nocase; http_uri; content:&quot;sfv=&quot;; nocase; http_uri; content:&quot;ciso=&quot;; nocase; http_uri; content:&quot;Host|3A| dist.atlas-ia.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5995</id>
        <msg>SPYWARE-PUT Adware offeragent runtime detection - information checking</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096710</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/103/getad.aspx?&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;ciso=&quot;; nocase; http_uri; content:&quot;pcpi=&quot;; nocase; http_uri; content:&quot;Host|3A| dist.atlas-ia.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>5996</id>
        <msg>SPYWARE-PUT Adware offeragent runtime detection - ads request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096710</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;testforconnection|0D 0A|&quot;; depth:19; nocase; flowbits:set,CoolCat.1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6012</id>
        <msg>BACKDOOR coolcat runtime connection detection - tcp 1</msg>
        <url>www.spywareguide.com/product_show.php?id=555</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; flowbits:isset,CoolCat.1; content:&quot;password |22|&quot;; depth:10; nocase; flowbits:set,CoolCat.2; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6013</id>
        <msg>BACKDOOR coolcat runtime connection detection - tcp 2</msg>
        <url>www.spywareguide.com/product_show.php?id=555</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 800:</filter1>
        <filter2>flow:to_server,established; content:&quot;verifypass|3B|&quot;; depth:11; nocase; flowbits:set,DSK_Lite_1.0_TCP; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6015</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 800: -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,DSK_Lite_1.0_TCP; content:&quot;connect|3B|&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6016</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whitepages/page_me.php?&quot;; nocase; http_uri; content:&quot;from=DSK&quot;; nocase; http_uri; content:&quot;fromemail=Dsk&quot;; nocase; http_uri; content:&quot;subject=Vics&quot;; nocase; http_uri; content:&quot;body=DSK&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri; content:&quot;Send=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6018</id>
        <msg>BACKDOOR dsk lite 1.0 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075866</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 4225 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;+---|7C|&quot;; content:&quot;|7C|---+&quot;; distance:0; pcre:&quot;/\x2B\x2D{3}\x7C[^\r\n]*\x7C\x2D{3}\x2B/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6021</id>
        <msg>BACKDOOR silent spy 2.10 command response port 4225</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073048</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 4226 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;+---|7C|&quot;; content:&quot;|7C|---+&quot;; distance:0; pcre:&quot;/\x2B\x2D{3}\x7C[^\r\n]*\x7C\x2D{3}\x2B/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6022</id>
        <msg>BACKDOOR silent spy 2.10 command response port 4226</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073048</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/argh/notify.php?emailaddr=&quot;; nocase; http_uri; content:&quot;msg=SERVER&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SiLENT&quot;; nocase; http_header; content:&quot;SPY&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*SiLENT\s+SPY/smiH&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6023</id>
        <msg>BACKDOOR silent spy 2.10 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073048</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|C2 C5 CD C4 FD F9 FF 86 E4 9A F8 FF E5 9B 98 E5 FC E1 FD A9 FC C2 C5 99 C0 A9|&quot;; depth:26; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6024</id>
        <msg>BACKDOOR nuclear rat v6_21 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077717</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;DIMBUS&quot;; nocase; content:&quot;Server&quot;; distance:0; nocase; pcre:&quot;/\s{23}DIMBUS\s+Server\s+v\d+\x2E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6026</id>
        <msg>BACKDOOR dimbus 1.0 runtime detection - get pc info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060480</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 18001 -&gt; $EXTERNAL_NET 18000</filter1>
        <filter2>content:&quot;H02EXE&quot;; nocase; content:&quot;File&quot;; distance:0; nocase; content:&quot;Name|3A|&quot;; distance:0; nocase; content:&quot;CYBERPAKY&quot;; distance:0; nocase; content:&quot;Operating&quot;; distance:0; nocase; content:&quot;System&quot;; distance:0; nocase; pcre:&quot;/H02EXE\s+File\s+Name\x3A\s+CYBERPAKY\x0D\x0AOperating\s+System/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6028</id>
        <msg>BACKDOOR cyberpaky runtime detection</msg>
        <url>www.megasecurity.org/trojans/c/cyberpaky/Cyberpaky1.8.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;folder_id=&quot;; nocase; http_uri; content:&quot;params_count=&quot;; nocase; http_uri; content:&quot;nick_name=&quot;; nocase; http_uri; content:&quot;user_email=fkwp@yahoo.com&quot;; nocase; http_uri; content:&quot;user_uin=&quot;; nocase; content:&quot;friend_nickname=&quot;; nocase; content:&quot;friend_contact=&quot;; nocase; content:&quot;x=&quot;; nocase; content:&quot;y=&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6029</id>
        <msg>BACKDOOR fkwp 2.0 runtime detection - icq notification</msg>
        <url>www.spywareguide.com/spydet_3088_eltc_editorfkwp.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1024: -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;login_ok&quot;; nocase; content:&quot;MiniCommand&quot;; distance:0; nocase; content:&quot;version&quot;; distance:0; nocase; content:&quot;ready&quot;; distance:0; nocase; content:&quot;for&quot;; distance:0; nocase; content:&quot;action&quot;; distance:0; nocase; pcre:&quot;/^login_ok\x5EMiniCommand\s+version\s+\d+\.\d+\.\d+\s+ready\s+for\s+action\x2E/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6035</id>
        <msg>BACKDOOR minicommand runtime detection - initial connection server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075932</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;NetBus&quot;; distance:0; nocase; content:&quot;server&quot;; distance:0; nocase; content:&quot;is&quot;; distance:0; nocase; content:&quot;up&quot;; distance:0; nocase; content:&quot;and&quot;; distance:0; nocase; content:&quot;running&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3A[^\r\n]*NetBus\s+server\s+is\s+up\s+and\s+running/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6037</id>
        <msg>BACKDOOR netbus 1.7 runtime detection - email notification</msg>
        <url>www.2-spyware.com/file-backdoor-netbus-12-exe.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;win=&quot;; nocase; http_uri; content:&quot;rpass=&quot;; nocase; http_uri; content:&quot;ServerType=Fade&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6039</id>
        <msg>BACKDOOR fade 1.0 runtime detection - notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076292</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;877110&quot;; depth:6; flowbits:set,Fade_kl; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6040</id>
        <msg>BACKDOOR fade 1.0 runtime detection - enable keylogger</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076292</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;QTAze1l9&quot;; depth:8; nocase; flowbits:set,fear_0_2.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6044</id>
        <msg>BACKDOOR fear 0.2 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,fear_0_2.conn.1; content:&quot;QTAz&quot;; depth:4; nocase; flowbits:set,fear_0_2.conn.2; flowbits:unset,fear_0_2.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6045</id>
        <msg>BACKDOOR fear 0.2 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,fear_0_2.conn.2; content:&quot;QTAxe1h9e1l9&quot;; nocase; flowbits:unset,fear_0_2.conn.2; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6046</id>
        <msg>BACKDOOR fear 0.2 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8799</filter1>
        <filter2>flow:to_server,established; content:&quot;|AD 86 01 00 08 00 00 00|&quot;; content:&quot;1^Merlin&quot;; distance:0; nocase; pcre:&quot;/^\xad\x86\x01\x00\x08\x00\x00\x001\x5EMerlin/smi&quot;; flowbits:set,FunFactory_conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6047</id>
        <msg>BACKDOOR fun factory runtime detection - connect</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8799 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,FunFactory_conn; content:&quot;100013Agentsvr^^Merlin&quot;; nocase; pcre:&quot;/^100013Agentsvr\x5E\x5EMerlin/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6048</id>
        <msg>BACKDOOR fun factory runtime detection - connect</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8799</filter1>
        <filter2>flow:to_server,established; content:&quot;|AB 86 01 00 12 00 00 00|&quot;; flowbits:set,FunFactory_upload; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6049</id>
        <msg>BACKDOOR fun factory runtime detection - upload</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8799 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,FunFactory_upload; content:&quot;100011&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6050</id>
        <msg>BACKDOOR fun factory runtime detection - upload</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8799</filter1>
        <filter2>flow:to_server,established; content:&quot;|B0 86 01 00 01 00 00 00|0&quot;; flowbits:set,FunFactory_volume; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6051</id>
        <msg>BACKDOOR fun factory runtime detection - set volume</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8799 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,FunFactory_volume; content:&quot;100016&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6052</id>
        <msg>BACKDOOR fun factory runtime detection - set volume</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8799</filter1>
        <filter2>flow:to_server,established; content:&quot;|AE 86 01 00|&quot;; flowbits:set,FunFactory_doscript; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6053</id>
        <msg>BACKDOOR fun factory runtime detection - do script remotely</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8799 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,FunFactory_doscript; content:&quot;100014&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6054</id>
        <msg>BACKDOOR fun factory runtime detection - do script remotely</msg>
        <url>www.spywareguide.com/product_show.php?id=1649</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 91|I|16 1B|e|1C|&quot;; flowbits:set,bifrose.rev_conn.1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6055</id>
        <msg>BACKDOOR bifrose 1.1 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1464</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,bifrose.rev_conn.1; content:&quot;|02 00 00 00|4x&quot;; flowbits:set,bifrose.rev_conn.2; flowbits:unset,bifrose.rev_conn.1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6056</id>
        <msg>BACKDOOR bifrose 1.1 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1464</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Uin=&quot;; nocase; http_uri; content:&quot;Name=The Hosts port is&quot;; nocase; http_uri; content:&quot;Name=Your Host is&quot;; nocase; http_uri; content:&quot;Send=yes&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6058</id>
        <msg>BACKDOOR neurotickat1.3 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=31859</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 831</filter1>
        <filter2>flow:to_server,established; content:&quot;VER &quot;; depth:4; nocase; flowbits:set,neurotickat.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6060</id>
        <msg>BACKDOOR neurotickat1.3 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=31859</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 831</filter1>
        <filter2>flow:to_server,established; flowbits:isset,neurotickat.1; content:&quot;FTPON&quot;; nocase; content:&quot;TIME&quot;; distance:0; nocase; pcre:&quot;/FTPON\d+\s+TIME\d+\s+/smi&quot;; flowbits:set,neurotickat.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6061</id>
        <msg>BACKDOOR neurotickat1.3 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=31859</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 831 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,neurotickat.2; content:&quot;One&quot;; nocase; content:&quot;more&quot;; distance:0; nocase; content:&quot;step&quot;; distance:0; nocase; content:&quot;until&quot;; distance:0; nocase; content:&quot;connection.&quot;; distance:0; nocase; pcre:&quot;/One\s+more\s+step\s+until\s+connection\x2E/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6062</id>
        <msg>BACKDOOR neurotickat1.3 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=31859</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21212</filter1>
        <filter2>flow:to_server,established; content:&quot;ver&quot;; depth:3; nocase; flowbits:set,schwindler; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6063</id>
        <msg>BACKDOOR schwindler 1.82 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=5287</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 21212 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,schwindler; content:&quot;Schwindler&quot;; depth:10; nocase; content:&quot;Servidor&quot;; distance:0; nocase; content:&quot;Porta&quot;; distance:0; nocase; pcre:&quot;/Schwindler\s+Servidor\x2E\s+Porta\s+\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6064</id>
        <msg>BACKDOOR schwindler 1.82 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=5287</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;password|3B|1|3B|Optix Lite Server Ready&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6066</id>
        <msg>BACKDOOR optixlite 1.0 runtime detection - connection success server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;from=Optix Lite&quot;; nocase; http_uri; content:&quot;fromemail=&quot;; nocase; http_uri; content:&quot;subject=From Optix Lite&quot;; nocase; http_uri; content:&quot;body=&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6069</id>
        <msg>BACKDOOR optixlite 1.0 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 6667</filter1>
        <filter2>flow:to_server,established; content:&quot;NICK&quot;; nocase; content:&quot;FrEaK_ViCTiM&quot;; distance:0; nocase; pcre:&quot;/^NICK\s+FrEaK_ViCTiM\x0D\x0A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6070</id>
        <msg>BACKDOOR freak 1.0 runtime detection - irc notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073808</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; content:&quot;from=FrEaK_ViCTiM&quot;; nocase; content:&quot;fromemail=FrEaK&quot;; nocase; content:&quot;subject=FrEaK+SERVER&quot;; nocase; content:&quot;body=&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6071</id>
        <msg>BACKDOOR freak 1.0 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073808</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1024: -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;027FrEaK_ViCTiM&quot;; depth:15; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6073</id>
        <msg>BACKDOOR freak 1.0 runtime detection - initial connection server-to-client</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453073808</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7648</filter1>
        <filter2>flow:to_server,established; content:&quot;UAIIA&quot;; depth:5; nocase; content:&quot;XHX&quot;; distance:0; nocase; content:&quot;YANER&quot;; distance:0; nocase; pcre:&quot;/^UAIIA\s+XHX\s+YANER/smi&quot;; flowbits:set,xhx_cts; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6074</id>
        <msg>BACKDOOR xhx 1.6 runtime detection - initial connection client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084140</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7648 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,xhx_cts; content:&quot; [&quot;; depth:2; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6075</id>
        <msg>BACKDOOR xhx 1.6 runtime detection - initial connection server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084140</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1204</filter1>
        <filter2>flow:to_server,established; content:&quot;23L'esclave|09|49152|09|65535&quot;; depth:23; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6076</id>
        <msg>BACKDOOR amiboide uploader runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088579</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3505</filter1>
        <filter2>flow:to_server,established; content:&quot;info&quot;; depth:4; flowbits:set,AutoSpy_GetInformation; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6077</id>
        <msg>BACKDOOR autospy runtime detection - get information</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3505 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AutoSpy_GetInformation; content:&quot;Product Name&quot;; depth:12; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6078</id>
        <msg>BACKDOOR autospy runtime detection - get information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59685</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3505</filter1>
        <filter2>flow:to_server,established; content:&quot;frmauto&quot;; depth:7; flowbits:set,AutoSpy_ShowAutoSpy; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6079</id>
        <msg>BACKDOOR autospy runtime detection - show autospy</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3505 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AutoSpy_ShowAutoSpy; content:&quot;autoSpY shown&quot;; depth:13; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6080</id>
        <msg>BACKDOOR autospy runtime detection - show autospy</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59685</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3505</filter1>
        <filter2>flow:to_server,established; content:&quot;nraider&quot;; depth:7; flowbits:set,AutoSpy_ShowNudePicture; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6081</id>
        <msg>BACKDOOR autospy runtime detection - show nude pic</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3505 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AutoSpy_ShowNudePicture; content:&quot;nude Raider pic&quot;; depth:15; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6082</id>
        <msg>BACKDOOR autospy runtime detection - show nude pic</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59685</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3505</filter1>
        <filter2>flow:to_server,established; content:&quot;taskhide&quot;; depth:8; flowbits:set,AutoSpy_HideTaskbar; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6083</id>
        <msg>BACKDOOR autospy runtime detection - hide taskbar</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3505 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AutoSpy_HideTaskbar; content:&quot;Taskbar hidden&quot;; depth:14; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6084</id>
        <msg>BACKDOOR autospy runtime detection - hide taskbar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59685</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3505</filter1>
        <filter2>flow:to_server,established; content:&quot;mkdir&quot;; depth:5; flowbits:set,AutoSpy_MakeDirectory; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6085</id>
        <msg>BACKDOOR autospy runtime detection - make directory</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3505 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AutoSpy_MakeDirectory; content:&quot;folder created&quot;; depth:14; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6086</id>
        <msg>BACKDOOR autospy runtime detection - make directory</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59685</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;resp1Conectado&quot;; depth:14; flowbits:set,A_Trojan_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6087</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,A_Trojan_InitConnection; content:&quot;conec&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6088</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=611</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;infme&quot;; depth:5; flowbits:set,A_Trojan_GetMemoryInfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6089</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,A_Trojan_GetMemoryInfo; content:&quot;infme&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6090</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection - get memory info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=611</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;infhd&quot;; depth:5; flowbits:set,A_Trojan_GetHarddiskInfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6091</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,A_Trojan_GetHarddiskInfo; content:&quot;infhd&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6092</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection - get harddisk info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=611</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;infdr&quot;; depth:5; flowbits:set,A_Trojan_GetDriveInfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6093</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,A_Trojan_GetDriveInfo; content:&quot;infdr&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6094</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection - get drive info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=611</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;infsy&quot;; depth:5; flowbits:set,A_Trojan_GetSysInfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6095</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,A_Trojan_GetSysInfo; content:&quot;infsy&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6096</id>
        <msg>BACKDOOR a trojan 2.0 runtime detection - get system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=611</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27184</filter1>
        <filter2>flow:to_server; content:&quot;st&quot;; depth:2; nocase; flowbits:set,Alvgus_CheckServer; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6097</id>
        <msg>BACKDOOR alvgus 2000 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 27184 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Alvgus_CheckServer; content:&quot;stAlvgus&quot;; depth:8; nocase; content:&quot;Trojan&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;2000&quot;; distance:0; nocase; pcre:&quot;/^stAlvgus\'s\s+Trojan\s+Server\s+2000/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6098</id>
        <msg>BACKDOOR alvgus 2000 runtime detection - check server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27184</filter1>
        <filter2>flow:to_server; content:&quot;di&quot;; depth:2; nocase; flowbits:set,Alvgus_ViewDirectory; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6099</id>
        <msg>BACKDOOR alvgus 2000 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 27184 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Alvgus_ViewDirectory; content:&quot;diGetting&quot;; depth:9; nocase; content:&quot;content&quot;; distance:0; nocase; content:&quot;directory&quot;; distance:0; nocase; pcre:&quot;/^diGetting\s+content\s+of\s+directory\x3A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6100</id>
        <msg>BACKDOOR alvgus 2000 runtime detection - view content of directory</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27184</filter1>
        <filter2>flow:to_server; content:&quot;fe&quot;; depth:2; nocase; flowbits:set,Alvgus_ExecuteCommand; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6101</id>
        <msg>BACKDOOR alvgus 2000 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 27184 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Alvgus_ExecuteCommand; content:&quot;feExecuting&quot;; depth:11; nocase; content:&quot;program&quot;; distance:0; nocase; pcre:&quot;/^feExecuting\s+program\x3A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6102</id>
        <msg>BACKDOOR alvgus 2000 runtime detection - execute command</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27184</filter1>
        <filter2>flow:to_server; content:&quot;tt&quot;; depth:2; nocase; flowbits:set,Alvgus_UploadFile; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6103</id>
        <msg>BACKDOOR alvgus 2000 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 27184 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Alvgus_UploadFile; content:&quot;ttTransferring&quot;; depth:14; nocase; content:&quot;file&quot;; distance:0; nocase; content:&quot;to&quot;; distance:0; nocase; pcre:&quot;/^ttTransferring\s+file\s+to\x3A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6104</id>
        <msg>BACKDOOR alvgus 2000 runtime detection - upload file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 27184</filter1>
        <filter2>flow:to_server; content:&quot;tf&quot;; depth:2; nocase; flowbits:set,Alvgus_DownloadFile; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6105</id>
        <msg>BACKDOOR alvgus 2000 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 27184 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Alvgus_DownloadFile; content:&quot;tfTransferring&quot;; depth:14; nocase; content:&quot;file&quot;; distance:0; nocase; content:&quot;from&quot;; distance:0; nocase; pcre:&quot;/^tfTransferring\s+file\s+from\x3A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6106</id>
        <msg>BACKDOOR alvgus 2000 runtime detection - download file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;ExecuteUnloadAll&quot;; depth:16; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6107</id>
        <msg>BACKDOOR backage 3.1 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=698</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2589</filter1>
        <filter2>flow:to_server,established; content:&quot;|0B 00 00 00 07 00 00 00|Connect&quot;; depth:15; nocase; flowbits:set,backdoor.dagger.1.1.40.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6108</id>
        <msg>BACKDOOR dagger v1.1.40 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1477</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2589 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.dagger.1.1.40.conn; content:&quot;|07 00 00 00 03 00 00 00|Yes&quot;; depth:11; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6109</id>
        <msg>BACKDOOR dagger v1.1.40 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1641</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 9999 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ForCed&quot;; depth:6; nocase; content:&quot;EnTrY&quot;; distance:0; nocase; content:&quot;|0D 0A 0D 0A 0D 0A|Connection&quot;; distance:0; nocase; content:&quot; Stable&quot;; distance:0; nocase; pcre:&quot;/^ForCed\s+EnTrY\s+\d+\x2E\d+\x2E\d+\x0D\x0A\x0D\x0A\x0D\x0AConnection\s+Stable/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6110</id>
        <msg>BACKDOOR forced entry v1.1 beta runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=2160</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot; |0D 0A|&quot;; depth:3; nocase; flowbits:set,back.optix.1.32.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6111</id>
        <msg>BACKDOOR optix 1.32 runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453085748</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,back.optix.1.32.conn.1; content:&quot;022|AC|&quot;; depth:4; nocase; flowbits:set,back.optix.1.32.conn.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6112</id>
        <msg>BACKDOOR optix 1.32 runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453085748</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,back.optix.1.32.conn.2; content:&quot;001|AC|Optix&quot;; depth:9; nocase; content:&quot;Pro&quot;; distance:0; nocase; content:&quot;Connected&quot;; distance:0; nocase; content:&quot;Successfully!&quot;; distance:0; nocase; pcre:&quot;/^001\xACOptix\s+Pro\s+v\d+\x2E\d+\s+Connected\s+Successfully\x21/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6113</id>
        <msg>BACKDOOR optix 1.32 runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453085748</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;!!!Optix&quot;; nocase; content:&quot;Pro&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;Online!!!&quot;; distance:0; nocase; pcre:&quot;/^\x21{3}Optix\s+Pro\s+v\d+\x2E\d+\s+Server\s+Online\x21{3}/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6114</id>
        <msg>BACKDOOR optix 1.32 runtime detection - email notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453085748</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whitepages/page_me/1,,,00.html&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; content:&quot;from=&quot;; nocase; content:&quot;fromemail=&quot;; nocase; content:&quot;body=&quot;; nocase; pcre:&quot;/body=\x2521\x2521\x2521Optix\s+Pro\s+v\d+\x252E\d+\S+sErver\s+Online\x2521\x2521\x2521/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6115</id>
        <msg>BACKDOOR optix 1.32 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453085748</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 50766</filter1>
        <filter2>flow:to_server,established; content:&quot;access flatboost6302&quot;; depth:20; nocase; flowbits:set,back.fore.v1.0.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6116</id>
        <msg>BACKDOOR fore v1.0 beta runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086922</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 50766 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,back.fore.v1.0.conn.1; content:&quot;access ok &quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6117</id>
        <msg>BACKDOOR fore v1.0 beta runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086922</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1023</filter1>
        <filter2>flow:to_server,established; content:&quot;|0E|Get Resolution&quot;; depth:15; nocase; flowbits:set,NetRunner_Init_Connection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6118</id>
        <msg>BACKDOOR net runner runtime detection - initial connection client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077503</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1023 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetRunner_Init_Connection; content:&quot;|0F|New Resoltutione&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6119</id>
        <msg>BACKDOOR net runner runtime detection - initial connection server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077503</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1023</filter1>
        <filter2>flow:to_server,established; content:&quot;|0D|Download File&quot;; depth:14; nocase; flowbits:set,NetRunner_Download_File; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6120</id>
        <msg>BACKDOOR net runner runtime detection - download file client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077503</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1023 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetRunner_Download_File; content:&quot;|08|New File File&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6121</id>
        <msg>BACKDOOR net runner runtime detection - download file server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077503</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20001</filter1>
        <filter2>flow:to_server,established; content:&quot;Millenium&quot;; depth:9; nocase; pcre:&quot;/^Millenium\s+\d+\x2E\d+\x2D/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6122</id>
        <msg>BACKDOOR millenium v1.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076392</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 10666</filter1>
        <filter2>flow:to_server; content:&quot;10&quot;; depth:2; nocase; flowbits:set,Ambush_Ping; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6123</id>
        <msg>BACKDOOR ambush 1.0 runtime detection - ping client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=238</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 10666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Ambush_Ping; content:&quot;=======&gt;&gt; AMBUSH v&quot;; depth:18; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6124</id>
        <msg>BACKDOOR ambush 1.0 runtime detection - ping server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=238</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server; content:&quot;This is made by yyt_hac!&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6127</id>
        <msg>BACKDOOR dkangel runtime detection - udp client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076278</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13473</filter1>
        <filter2>flow:to_server,established; content:&quot;getowner&quot;; depth:8; flowbits:set,Chupacabra_GetComputerName; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6129</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 13473 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Chupacabra_GetComputerName; content:&quot;Owner|3A|&quot;; depth:6; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6130</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection - get computer name</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=21339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13473</filter1>
        <filter2>flow:to_server,established; content:&quot;getname&quot;; depth:7; flowbits:set,Chupacabra_GetUserName; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6131</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 13473 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Chupacabra_GetUserName; content:&quot;Current&quot;; nocase; content:&quot;User&quot;; distance:0; nocase; content:&quot;Logged&quot;; distance:0; nocase; pcre:&quot;/^Current\s+User\s+Logged\s+on\x3A/&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6132</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection - get user name</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=21339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13473</filter1>
        <filter2>flow:to_server,established; content:&quot;sndmsg|5C|&quot;; depth:7; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6133</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection - send messages</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=21339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13473</filter1>
        <filter2>flow:to_server,established; content:&quot;delete|5C|&quot;; depth:7; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6134</id>
        <msg>BACKDOOR chupacabra 1.0 runtime detection - delete file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=21339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12566</filter1>
        <filter2>flow:to_server,established; content:&quot;&gt;&gt;Send Capture&quot;; depth:14; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6136</id>
        <msg>BACKDOOR clindestine 1.0 runtime detection - capture big screen</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12566</filter1>
        <filter2>flow:to_server,established; content:&quot;small&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6137</id>
        <msg>BACKDOOR clindestine 1.0 runtime detection - capture small screen</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12566</filter1>
        <filter2>flow:to_server,established; content:&quot;info&quot;; depth:4; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6138</id>
        <msg>BACKDOOR clindestine 1.0 runtime detection - get computer info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12566</filter1>
        <filter2>flow:to_server,established; content:&quot;system&quot;; depth:6; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6139</id>
        <msg>BACKDOOR clindestine 1.0 runtime detection - get system directory</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6666</filter1>
        <filter2>flow:to_server,established; content:&quot;DCIClient12|0A|&quot;; depth:12; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6143</id>
        <msg>BACKDOOR dark connection inside v1.2 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075571</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;notifuin&quot;; depth:8; nocase; flowbits:set,Mantis_Notify1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6144</id>
        <msg>BACKDOOR mantis runtime detection - sent notify option client-to-server 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3648</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Mantis_Notify1; content:&quot;sendsubject&quot;; depth:11; nocase; flowbits:set,Mantis_Notify2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6145</id>
        <msg>BACKDOOR mantis runtime detection - sent notify option server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3648</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Mantis_Notify2; content:&quot;notifsubject&quot;; depth:12; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6146</id>
        <msg>BACKDOOR mantis runtime detection - sent notify option client-to-server 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3648</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;gotoadres&quot;; depth:9; nocase; flowbits:set,Mantis_GotoAdress; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6147</id>
        <msg>BACKDOOR mantis runtime detection - go to address client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3648</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Mantis_GotoAdress; content:&quot;adressgoneto&quot;; depth:12; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6148</id>
        <msg>BACKDOOR mantis runtime detection - go to address server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3648</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;con&quot;; depth:3; nocase; flowbits:set,backdoor.netcontro.1.0.8.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6149</id>
        <msg>BACKDOOR netcontrol v1.0.8 runtime detection</msg>
        <url>www.system-help.com/spyware/netcontrol/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6969 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.netcontro.1.0.8.conn; content:&quot;con1.08&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6150</id>
        <msg>BACKDOOR netcontrol v1.0.8 runtime detection</msg>
        <url>www.system-help.com/spyware/netcontrol/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 33812 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot; You&quot;; depth:4; nocase; content:&quot;are&quot;; distance:0; nocase; content:&quot;now&quot;; distance:0; nocase; content:&quot;connected&quot;; distance:0; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;an&quot;; distance:0; nocase; content:&quot;BackAtTaCk&quot;; distance:0; nocase; content:&quot;server&quot;; distance:0; nocase; pcre:&quot;/You\s+are\s+now\s+connected\s+to\s+an\s+BackAtTaCk\s+server/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6151</id>
        <msg>BACKDOOR back attack v1.4 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074438</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4950</filter1>
        <filter2>flow:to_server; content:&quot;chdir &quot;; depth:6; nocase; flowbits:set,Dirtxt_Chdir; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6152</id>
        <msg>BACKDOOR dirtxt runtime detection - chdir client-to-server</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 4950 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Dirtxt_Chdir; content:&quot;chdir &quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6153</id>
        <msg>BACKDOOR dirtxt runtime detection - chdir server-to-client</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4950</filter1>
        <filter2>flow:to_server; content:&quot;info&quot;; depth:4; nocase; flowbits:set,Dirtxt_Info; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6154</id>
        <msg>BACKDOOR dirtxt runtime detection - info client-to-server</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 4950 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Dirtxt_Info; content:&quot;info&quot;; depth:4; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6155</id>
        <msg>BACKDOOR dirtxt runtime detection - info server-to-client</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4950</filter1>
        <filter2>flow:to_server; content:&quot;view&quot;; depth:4; nocase; flowbits:set,Dirtxt_View; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6156</id>
        <msg>BACKDOOR dirtxt runtime detection - view client-to-server</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 4950 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,Dirtxt_View; content:&quot;view&quot;; depth:4; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6157</id>
        <msg>BACKDOOR dirtxt runtime detection - view server-to-client</msg>
        <url>www.spywareguide.com/spydet_1396_dirtxt_trojan.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:to_server,established; content:&quot;enableklog&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6159</id>
        <msg>BACKDOOR delirium of disorder runtime detection - enable keylogger</msg>
        <url>www.megasecurity.org/trojans/d/deleriumofdisorder/Deleriumofdisorder.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6071</filter1>
        <filter2>flow:to_server,established; content:&quot;stopklog&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6160</id>
        <msg>BACKDOOR delirium of disorder runtime detection - stop keylogger</msg>
        <url>www.megasecurity.org/trojans/d/deleriumofdisorder/Deleriumofdisorder.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|03 00 1C 00 00 00 00 00 01|Furax &quot;; depth:15; nocase; content:&quot;Server|00|&quot;; distance:0; pcre:&quot;/^\x03\x00\x1c\x00\x00\x00\x00\x00\x01Furax\s+\d+\.\d+\w+\s+Server\x00/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6161</id>
        <msg>BACKDOOR furax 1.0 b2 runtime detection</msg>
        <url>www.megasecurity.org/trojans/f/furax/Furax1.0b2.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;GOODPWD&quot;; depth:7; nocase; flowbits:set,backdoor.psyrat.runtime.detection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6164</id>
        <msg>BACKDOOR psyrat 1.0 runtime detection</msg>
        <url>www.megasecurity.org/trojans/p/psyrat/Psyrat1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.psyrat.runtime.detection; content:&quot;PsyRAT_10A&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6165</id>
        <msg>BACKDOOR psyrat 1.0 runtime detection</msg>
        <url>www.megasecurity.org/trojans/p/psyrat/Psyrat1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected to&quot;; depth:12; nocase; pcre:&quot;/^Connected\s+to\s+[^\r\n]*\x28\d+\.\d+\.\d+\.\d+\x29/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6166</id>
        <msg>BACKDOOR unicorn runtime detection - initial connection</msg>
        <url>www.spywareguide.com/product_show.php?id=1506</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 666</filter1>
        <filter2>flow:to_server,established; content:&quot;WALLPAPER &quot;; depth:10; nocase; flowbits:set,Unicore_SetWallpaper; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6167</id>
        <msg>BACKDOOR unicorn runtime detection - set wallpaper client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=1506</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Unicore_SetWallpaper; content:&quot;Wallpaper Changed&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6168</id>
        <msg>BACKDOOR unicorn runtime detection - set wallpaper server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=1506</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2600</filter1>
        <filter2>flow:to_server,established; content:&quot;iiiiiiinfo&quot;; depth:10; nocase; flowbits:set,backdoor.digital.rootbeer.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6169</id>
        <msg>BACKDOOR digital rootbeer runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1641</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2600 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.digital.rootbeer.conn; content:&quot;/NFO,Registered&quot;; depth:15; nocase; content:&quot;Owner|3A|&quot;; distance:0; nocase; content:&quot;|0D 0A|Current&quot;; distance:0; nocase; content:&quot; user|3A|&quot;; distance:0; nocase; pcre:&quot;/^\x2FNFO\x2CRegistered\s+Owner\x3A\s+[^\r\n]*\x0D\x0ACurrent\s+user\x3A\s+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6170</id>
        <msg>BACKDOOR digital rootbeer runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1641</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;ver|0D 0A|&quot;; depth:5; flowbits:set,CookieMonster_GetVersionInfo; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6171</id>
        <msg>BACKDOOR cookie monster 0.24 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6969 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CookieMonster_GetVersionInfo; content:&quot;Cookie&quot;; content:&quot;Monster&quot;; distance:0; content:&quot;server&quot;; distance:0; content:&quot;engine&quot;; distance:0; pcre:&quot;/Cookie\s+Monster\s+server\s+engine/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6172</id>
        <msg>BACKDOOR cookie monster 0.24 runtime detection - get version info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084262</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;ls|0D 0A|&quot;; depth:4; flowbits:set,CookieMonster_FileExplorer; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6173</id>
        <msg>BACKDOOR cookie monster 0.24 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6969 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CookieMonster_FileExplorer; content:&quot;ls|01|.|01|..|01|&quot;; depth:8;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6174</id>
        <msg>BACKDOOR cookie monster 0.24 runtime detection - file explorer</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084262</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6969</filter1>
        <filter2>flow:to_server,established; content:&quot;krnlkill|0D 0A|&quot;; depth:10; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6175</id>
        <msg>BACKDOOR cookie monster 0.24 runtime detection - kill kernel</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084262</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Server|3A|&quot;; nocase; content:&quot;Guptachar&quot;; distance:0; nocase; pcre:&quot;/^Server\x3A\s+Guptachar\s+\d+\x2E\d+/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6176</id>
        <msg>BACKDOOR guptachar 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073814</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Killpro|7C|&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6177</id>
        <msg>BACKDOOR ultimate destruction runtime detection - kill process client-to-server</msg>
        <url>www.splintersecurity.com</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Killwidows|7C|&quot;; depth:11; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6178</id>
        <msg>BACKDOOR ultimate destruction runtime detection - kill windows client-to-server</msg>
        <url>www.splintersecurity.com</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5400 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Blade Runner&quot;; depth:12; nocase; pcre:&quot;/^Blade\s+Runner\s+ver\s+\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6179</id>
        <msg>BACKDOOR bladerunner 0.80 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=862</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 57341</filter1>
        <filter2>flow:to_server,established; content:&quot;NSClient-sPISPJ99&quot;; depth:17; nocase; flowbits:set,backdoor.netraider.0.0.runtime; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6180</id>
        <msg>BACKDOOR netraider 0.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3979</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 57341 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.netraider.0.0.runtime; content:&quot;NSServer-sPISPJ99&quot;; depth:17; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6181</id>
        <msg>BACKDOOR netraider 0.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3979</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/trackedevent.aspx?&quot;; fast_pattern; nocase; http_uri; content:&quot;eid=&quot;; nocase; http_uri; content:&quot;mt=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;basename=&quot;; nocase; http_uri; content:&quot;time=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6183</id>
        <msg>SPYWARE-PUT Adware 180Search assistant runtime detection - tracked event URL</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config.aspx?&quot;; nocase; http_uri; content:&quot;did=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;duid=&quot;; nocase; http_uri; content:&quot;partner_id=&quot;; nocase; http_uri; content:&quot;product_id=&quot;; http_uri; content:&quot;Host|3A| config.180solutions.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6184</id>
        <msg>SPYWARE-PUT Adware 180Search assistant runtime detection - config upload</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| SpywareStrike&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6186</id>
        <msg>SPYWARE-PUT Other-Technologies SpywareStrike Runtime Detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2438</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ist/scripts/&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6187</id>
        <msg>SPYWARE-PUT Adware ISTBar runtime detection - scripts</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075516</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ist/bars/istbar&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6188</id>
        <msg>SPYWARE-PUT Adware ISTBar runtime detection - bar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075516</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Try2Find Toolbar&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6189</id>
        <msg>SPYWARE-PUT Trackware try2find detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096392</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-SpectorSerial|3A|&quot;; nocase; content:&quot;X-SpectorMachineID|3A|&quot;; fast_pattern:only; content:&quot;X-SpectorBuild|3A|&quot;; nocase; content:&quot;eBlaster&quot;; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6190</id>
        <msg>SPYWARE-PUT Keylogger eblaster 5.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090687</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Visicom&quot;; fast_pattern:only; content:&quot;Host|3A| onetoolbar&quot;; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6191</id>
        <msg>SPYWARE-PUT Trackware onetoolbar runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2746</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/display.aspx?&quot;; nocase; http_uri; content:&quot;adid=&quot;; nocase; http_uri; content:&quot;kwid=&quot;; nocase; http_uri; content:&quot;umt=&quot;; nocase; http_uri; content:&quot;inid=&quot;; nocase; http_uri; content:&quot;Referer|3A| &quot;; nocase; http_header; content:&quot;tv.seekmo.com/showme.aspx?keyword=&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6193</id>
        <msg>SPYWARE-PUT Adware seekmo runtime detection - pop up ads</msg>
        <url>www.spywareguide.com/product_show.php?id=2368</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config.aspx?&quot;; nocase; http_uri; content:&quot;did=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;duid=&quot;; nocase; http_uri; content:&quot;partner_id=&quot;; nocase; http_uri; content:&quot;product_id=&quot;; nocase; http_uri; content:&quot;Host|3A| config.seekmo.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6194</id>
        <msg>SPYWARE-PUT Adware seekmo runtime detection - config upload</msg>
        <url>www.spywareguide.com/product_show.php?id=2368</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/downloads/ff/&quot;; nocase; http_uri; content:&quot;/seekmo/npclntax.CAB&quot;; nocase; http_uri; content:&quot;Host|3A| installs.seekmo.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6195</id>
        <msg>SPYWARE-PUT Adware seekmo runtime detection - download .cab</msg>
        <url>www.spywareguide.com/product_show.php?id=2368</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cs/cs.aspx?&quot;; nocase; http_uri; content:&quot;Host|3A| cs.smartshopper.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6196</id>
        <msg>SPYWARE-PUT Hijacker smart shopper runtime detection - services requests</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_133312.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;smrtshpr-cs-&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6197</id>
        <msg>SPYWARE-PUT Hijacker smart shopper runtime detection - track/upgrade/report activities</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_133312.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/content/logUserAction.do&quot;; fast_pattern; nocase; http_uri; content:&quot;uuid=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;stsb_SitelistVersion=&quot;; nocase; http_uri; content:&quot;stsb_Os=&quot;; nocase; http_uri; content:&quot;stsb_Browser&quot;; nocase; http_uri; content:&quot;stsb_Version&quot;; nocase; http_uri; content:&quot;stsb_Download&quot;; nocase; http_uri; content:&quot;stsb_InstallVersion&quot;; nocase; http_uri; content:&quot;usageEnabled&quot;; nocase; http_uri; content:&quot;phishingEnabled&quot;; nocase; http_uri; content:&quot;shoppingEnabled&quot;; nocase; http_uri; content:&quot;User-Agent|3A| SQTR_VERIFY&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6198</id>
        <msg>SPYWARE-PUT Trackware squaretrade side bar runtime detection - collect user information</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_137515.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files/adframe.aspx?&quot;; nocase; http_uri; content:&quot;SE=&quot;; nocase; http_uri; content:&quot;ST=&quot;; nocase; http_uri; content:&quot;Host|3A| www.searchreslt.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6199</id>
        <msg>SPYWARE-PUT Hijacker smart search runtime detection - hijack/ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078876</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/settings/&quot;; nocase; content:&quot;Host|3A| www.searchreslt.com&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6200</id>
        <msg>SPYWARE-PUT Hijacker smart search runtime detection - get settings</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078876</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/twain/servlet/Twain&quot;; fast_pattern; nocase; http_uri; content:&quot;adcontext=&quot;; nocase; http_uri; content:&quot;contextpeak=&quot;; nocase; http_uri; content:&quot;contextcount=&quot;; nocase; http_uri; content:&quot;countrycodein=&quot;; nocase; http_uri; content:&quot;cookie1=&quot;; nocase; http_uri; content:&quot;cookie2=&quot;; nocase; http_uri; content:&quot;InstID=&quot;; nocase; http_uri; content:&quot;status=&quot;; nocase; http_uri; content:&quot;smode=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6201</id>
        <msg>SPYWARE-PUT Adware twaintec runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078844</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a/Aid.sen?StubName=farmmext&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| Stubby&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6202</id>
        <msg>SPYWARE-PUT Trickler farmmext installtime/update request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090784</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a/Drk.syn?&quot;; fast_pattern; nocase; http_uri; content:&quot;bho=&quot;; nocase; http_uri; content:&quot;DistID=&quot;; nocase; http_uri; content:&quot;MM_RECO.EXE&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6203</id>
        <msg>SPYWARE-PUT Trickler farmmext runtime detection - drk.syn request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090784</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/imp/servlet/ImpServe?&quot;; fast_pattern; nocase; http_uri; content:&quot;urlContext=&quot;; nocase; http_uri; content:&quot;domainContext=&quot;; nocase; http_uri; content:&quot;distID=&quot;; nocase; http_uri; content:&quot;MM_RECO.EXE&quot;; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;transponderID=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6204</id>
        <msg>SPYWARE-PUT Trickler farmmext runtime detection - track activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090784</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 7001 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;hello&gt;WELCOMEwho do u want to phuk today&gt;&quot;; depth:41; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6205</id>
        <msg>SPYWARE-PUT Hacker-Tool freak 88 das runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=2181</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 42</filter1>
        <filter2>flow:to_server,established; content:&quot;|07|MESSAGE|00 00 00 00|&quot;; depth:12;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6206</id>
        <msg>SPYWARE-PUT Hacker-Tool sin stealer 1.1 runtime detection</msg>
        <url>www.megasecurity.org/trojans/s/sinstealer/Sinstealer1.1.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/GetAd/&quot;; nocase; http_uri; content:&quot;Host|3A| &quot;; nocase; content:&quot;deskwizz.com&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6209</id>
        <msg>SPYWARE-PUT Adware deskwizz/zquest runtime detection - get config information / ad banner</msg>
        <url>www.symantec.com/avcenter/venc/data/adware.zquest.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/select/Get&quot;; nocase; http_uri; pcre:&quot;/select\x2FGet(One|SbAts)\x2Ephp/Ui&quot;; content:&quot;Host|3A| &quot;; nocase; content:&quot;deskwizz.com&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6211</id>
        <msg>SPYWARE-PUT Adware deskwizz runtime detection - pop-up ad request</msg>
        <url>www.spywareguide.com/product_show.php?id=1127</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| CommonName Agent&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6212</id>
        <msg>SPYWARE-PUT Adware commonname runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078618</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.aspx?&quot;; nocase; http_uri; content:&quot;userid=&quot;; nocase; http_uri; content:&quot;affiliateid=&quot;; nocase; http_uri; content:&quot;Host|3A| client.browseraccelerator.com&quot;; fast_pattern:only; pcre:&quot;/\x2F(word)|(news)|(weather)|(joke)|(tip)\x2Easpx\?/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6213</id>
        <msg>SPYWARE-PUT Hijacker 7fasst runtime detection - auto requests</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072502</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchweb.aspx?&quot;; fast_pattern; nocase; http_uri; content:&quot;userid=&quot;; nocase; http_uri; content:&quot;affiliateid=&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;theurl=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6214</id>
        <msg>SPYWARE-PUT Hijacker 7fasst runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072502</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data/track.aspx?&quot;; fast_pattern; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;userid=&quot;; nocase; http_uri; content:&quot;affiliateid=&quot;; nocase; http_uri; content:&quot;theurl=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6215</id>
        <msg>SPYWARE-PUT Hijacker 7fasst runtime detection - track</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072502</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/copilot/copilotcfg.jsp?&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;iWon&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6216</id>
        <msg>SPYWARE-PUT Adware aornum/iwon copilot runtime detection - config</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072491</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad_string.js?&quot;; fast_pattern; nocase; http_uri; content:&quot;tagad&quot;; nocase; http_uri; content:&quot;site=iwon&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6218</id>
        <msg>SPYWARE-PUT Adware aornum/iwon copilot runtime detection - ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072491</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bonzibuddy/&quot;; fast_pattern; nocase; http_uri; content:&quot;.nbd&quot;; nocase; http_uri; pcre:&quot;/\x2Fbonzibuddy\x2F(updates|products|daily)\x2Enbd/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6219</id>
        <msg>SPYWARE-PUT Adware bonzibuddy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=59256</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A| Boss Everyware&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6220</id>
        <msg>SPYWARE-PUT Keylogger boss everyware runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=4</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A| keys&lt;keys@hotpop.com&gt;&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6221</id>
        <msg>SPYWARE-PUT Keylogger computerspy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072991</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Delfin/ini.html&quot;; nocase; http_uri; content:&quot;pBrd&quot;; nocase; http_uri; content:&quot;pIsp&quot;; nocase; http_uri; content:&quot;pVer&quot;; nocase; http_uri; content:&quot;pSer&quot;; nocase; http_uri; content:&quot;User-Agent|3A| PromulGate&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6222</id>
        <msg>SPYWARE-PUT Adware delfin media viewer runtime detection - contact server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076775</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Delfin/schedule.html&quot;; nocase; http_uri; content:&quot;pBrd&quot;; nocase; http_uri; content:&quot;pSch&quot;; nocase; http_uri; content:&quot;pIsp&quot;; nocase; http_uri; content:&quot;pVer&quot;; http_uri; content:&quot;pZip&quot;; nocase; http_uri; content:&quot;pSer&quot;; nocase; http_uri; content:&quot;User-Agent|3A| PromulGate&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6223</id>
        <msg>SPYWARE-PUT Adware delfin media viewer runtime detection - retrieve schedule</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076775</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/q.cgi?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| wwd.ieplugin&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6224</id>
        <msg>SPYWARE-PUT Hijacker ieplugin runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072530</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bar/links.php?affid=&quot;; nocase; http_uri; content:&quot;Host|3A| toolbar.i-lookup.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6230</id>
        <msg>SPYWARE-PUT Hijacker i-lookup runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074914</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/thumbnail.cgi&quot;; nocase; http_uri; content:&quot;DURL&quot;; nocase; http_uri; content:&quot;Host|3A| www.mirarsearch.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6232</id>
        <msg>SPYWARE-PUT Adware mirar runtime detection - thumbnail</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078818</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/delayed.cgi&quot;; nocase; http_uri; content:&quot;g&quot;; nocase; http_uri; content:&quot;edata&quot;; nocase; http_uri; content:&quot;q&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Mirar_KeywordContent&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6233</id>
        <msg>SPYWARE-PUT Adware mirar runtime detection - delayed</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078818</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/v70click.cgi&quot;; nocase; http_uri; content:&quot;Host|3A| www.mirarsearch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6234</id>
        <msg>SPYWARE-PUT Adware mirar runtime detection - ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078818</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/abt?data=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Travel Update&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6236</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - pass info to server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upd/check?version=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Download UBAgent&quot;; fast_pattern:only; content:&quot;Host|3A| upd.lop.com&quot;; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6237</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - check update request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tba/&quot;; nocase; content:&quot;guid=&quot;; distance:0; nocase; content:&quot;version=&quot;; distance:0; nocase; content:&quot;clientid=&quot;; distance:0; nocase; content:&quot;time=&quot;; distance:0; nocase; content:&quot;locale=&quot;; distance:0; nocase; content:&quot;session=&quot;; distance:0; nocase; content:&quot;id=&quot;; distance:0; nocase; content:&quot;idle=&quot;; distance:0; nocase; content:&quot;queued=&quot;; distance:0; nocase; content:&quot;crc=&quot;; distance:0; nocase; content:&quot;User-Agent|3A| TPSystem&quot;; fast_pattern:only; pcre:&quot;/\x2Ftba\x2F(cm)|(cu)\?/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6238</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - collect info request 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tba/p?&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;clientid=&quot;; nocase; http_uri; content:&quot;time=&quot;; nocase; http_uri; content:&quot;locale=&quot;; nocase; http_uri; content:&quot;session=&quot;; nocase; http_uri; content:&quot;idle=&quot;; nocase; http_uri; content:&quot;crc=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| TPSystem&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6239</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - collect info request 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/prod/C2mediapops/pop3.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;mt=&quot;; nocase; http_uri; content:&quot;popid=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| TPSystem&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6240</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - pop up ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exe/dns.html&quot;; nocase; http_uri; content:&quot;User-Agent|3A| TPSystem&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6241</id>
        <msg>SPYWARE-PUT Adware lop runtime detection - ie autosearch hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;svc=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;mode=&quot;; nocase; http_uri; content:&quot;art=&quot;; nocase; http_uri; content:&quot;acct=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;category=&quot;; fast_pattern; nocase; http_uri; content:&quot;view=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6242</id>
        <msg>SPYWARE-PUT Hijacker coolwebsearch.cameup runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/justas.css&quot;; nocase; http_uri; content:&quot;Host|3A| www.kliksearch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6243</id>
        <msg>SPYWARE-PUT Hijacker coolwebsearch cameup runtime detection - home page hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/notfound.php&quot;; nocase; http_uri; content:&quot;Host|3A| www.cameup.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6244</id>
        <msg>SPYWARE-PUT Hijacker coolwebsearch cameup runtime detection - ie auto search hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/2gt.php&quot;; nocase; http_uri; content:&quot;cp=&quot;; nocase; http_uri; content:&quot;dn=daosearch.com&quot;; fast_pattern; nocase; http_uri; content:&quot;ckey=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;iphsh=&quot;; nocase; http_uri; content:&quot;tm=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6245</id>
        <msg>SPYWARE-PUT Hijacker coolwebsearch startpage runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=599</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/404/search.php?&quot;; nocase; http_uri; content:&quot;p=&quot;; nocase; http_uri; content:&quot;Keywords=&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;Host|3A| www.navisearch.net&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6246</id>
        <msg>SPYWARE-PUT Hijacker exact navisearch runtime detection - search hijack</msg>
        <url>www.spywareguide.com/product_show.php?id=1169</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/IntermixWO/Redirect/HelpRedirect.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;var=&quot;; nocase; http_uri; content:&quot;Host|3A| www.ezula.com&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6247</id>
        <msg>SPYWARE-PUT Adware ezula toptext runtime detection - help redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072551</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/TopText/pop-popup.html&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| www.ezula.com&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6248</id>
        <msg>SPYWARE-PUT Adware ezula toptext runtime detection - popup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072551</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/IntermixWO/redirect/redirect.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;DS_ID=&quot;; nocase; http_uri; content:&quot;PubName=&quot;; nocase; http_uri; content:&quot;UV_ID=&quot;; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;region=&quot;; nocase; http_uri; content:&quot;city=&quot;; nocase; http_uri; content:&quot;zip=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6249</id>
        <msg>SPYWARE-PUT Adware ezula toptext runtime detection - redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072551</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;hotbar&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*?hotbar/Hsmi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6250</id>
        <msg>SPYWARE-PUT Adware hotbar runtime detection - hotbar user-agent</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075474</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;hostie&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*?hostie/Hsmi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6251</id>
        <msg>SPYWARE-PUT Adware hotbar runtime detection - hostie user-agent</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075474</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tbar?&quot;; nocase; http_uri; content:&quot;prt=&quot;; nocase; http_uri; content:&quot;nnreq=&quot;; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;Host|3A| quick.qsrch.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6252</id>
        <msg>SPYWARE-PUT Trackware quicksearch toolbar runtime detection - search request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/log/log.cgi?&quot;; nocase; http_uri; content:&quot;Host|3A| quick.qsrch.com&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6253</id>
        <msg>SPYWARE-PUT Trackware quicksearch toolbar runtime detection - log user ativity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tbar?&quot;; nocase; http_uri; content:&quot;upartner=&quot;; nocase; http_uri; content:&quot;ps=&quot;; nocase; http_uri; content:&quot;bidpart=&quot;; nocase; http_uri; content:&quot;rank=&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;redir=&quot;; nocase; http_uri; content:&quot;Host|3A| quick.qsrch.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6254</id>
        <msg>SPYWARE-PUT Trackware quicksearch toolbar runtime detection - redirect</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;tag=&quot;; nocase; http_uri; content:&quot;ptr=&quot;; nocase; http_uri; content:&quot;source=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| ToolBar&quot;; nocase; http_header; content:&quot;Host|3A| upgrade.qsrch.info&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6255</id>
        <msg>SPYWARE-PUT Trackware quicksearch toolbar runtime detection - update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;907CA0E5-CE84-11D6-9508-02608CDD2846&quot;; fast_pattern:only; pcre:&quot;/&lt;OBJECT\s+[^&gt;]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3A\s*\x7B?\s*907CA0E5-CE84-11D6-9508-02608CDD2846/si&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6256</id>
        <msg>SPYWARE-PUT Adware searchsquire installtime/auto-update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094363</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/testgeonew.php&quot;; nocase; http_uri; content:&quot;Referer|3A| http|3A|//ad.searchsquire.com/blank.html&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6257</id>
        <msg>SPYWARE-PUT Adware searchsquire runtime detection - testgeonew query</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094363</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/engine&quot;; nocase; http_uri; content:&quot;.txt&quot;; nocase; http_uri; pcre:&quot;/\x2Fengine2?\x2Etxt/Ui&quot;; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Agent&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Agent[0-9]{7}/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6258</id>
        <msg>SPYWARE-PUT Adware searchsquire runtime detection - get engine file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094363</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;domain=&quot;; nocase; http_uri; content:&quot;term=&quot;; nocase; http_uri; content:&quot;partner=searchsquire&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6259</id>
        <msg>SPYWARE-PUT Adware searchsquire runtime detection - search forward</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094363</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cmapp/zx-popup.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;m=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;url=http&quot;; nocase; http_uri; content:&quot;Host|3A| newads1.com&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6260</id>
        <msg>SPYWARE-PUT Adware overpro runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090731</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;Keywords=&quot;; nocase; http_uri; content:&quot;Host|3A| www.slinkyslate&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6261</id>
        <msg>SPYWARE-PUT Trickler slinkyslate toolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082746</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adi/fandango.dart/theaterselectionpage|3B|&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6263</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - collect information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/superbar/movie.php&quot;; fast_pattern; nocase; http_uri; content:&quot;requests=&quot;; nocase; content:&quot;guid=&quot;; nocase; content:&quot;camp=&quot;; nocase; content:&quot;build=&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6264</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - movie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/superbar/engine.php&quot;; fast_pattern; nocase; http_uri; content:&quot;requests=&quot;; nocase; content:&quot;engine=&quot;; nocase; content:&quot;guid=&quot;; nocase; content:&quot;camp=&quot;; nocase; content:&quot;build=&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6265</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - engine</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/superbar/seupdate.php&quot;; fast_pattern; nocase; http_uri; content:&quot;action=checkUpdate&quot;; nocase; content:&quot;guid=&quot;; nocase; content:&quot;camp=&quot;; nocase; content:&quot;build=&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6266</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - check update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/superbar/seupdate.php&quot;; fast_pattern; nocase; http_uri; content:&quot;action=getUpdate&quot;; nocase; content:&quot;fileName=&quot;; nocase; content:&quot;guid=&quot;; nocase; content:&quot;camp=&quot;; nocase; content:&quot;build=&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6267</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - get update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SUPERBARINSTALL_2.2.1.EXE&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6268</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - download exe</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/superbar/event.php&quot;; fast_pattern; nocase; http_uri; content:&quot;event=&quot;; nocase; content:&quot;gmt=&quot;; nocase; content:&quot;guid=&quot;; nocase; content:&quot;camp=&quot;; nocase; content:&quot;build=&quot;; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6269</id>
        <msg>SPYWARE-PUT Hijacker gigatech superbar runtime detection - track event</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075466</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bin/findwhat.dll&quot;; nocase; http_uri; content:&quot;getresults&quot;; nocase; http_uri; content:&quot;base=&quot;; nocase; http_uri; content:&quot;mt=&quot;; nocase; http_uri; content:&quot;dc=&quot;; nocase; http_uri; content:&quot;aff_id=&quot;; nocase; http_uri; content:&quot;ip_addr=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| MyBrowser&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6270</id>
        <msg>SPYWARE-PUT Hijacker topicks runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094103</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/AD/UCMD?&quot;; fast_pattern; nocase; http_uri; content:&quot;&amp;ID={&quot;; nocase; http_uri; content:&quot;&amp;rand=&quot;; nocase; http_uri; metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>6271</id>
        <msg>SPYWARE-PUT Trickler bundleware runtime detection</msg>
        <url>www.xp-vista.com/spyware-removal/antimalwareguard-antimalware-guard-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ca/servlet/Alchem&quot;; http_uri; content:&quot;StubName&quot;; nocase; content:&quot;alchem&quot;; distance:0; nocase; content:&quot;User-Agent|3A| Stubby&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6274</id>
        <msg>SPYWARE-PUT Trickler clickalchemy runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1095</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.cfm&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;pc=&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; content:&quot;Cookie|3A| &quot;; nocase; http_header; content:&quot;source=IncrediFind&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6275</id>
        <msg>SPYWARE-PUT Hijacker incredifind runtime detection - cookie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;target=&quot;; nocase; http_uri; content:&quot;tv=&quot;; nocase; http_uri; content:&quot;tu=&quot;; nocase; http_uri; content:&quot;td=&quot;; nocase; http_uri; content:&quot;account_id=&quot;; nocase; http_uri; content:&quot;tt=&quot;; http_uri; content:&quot;search_string=&quot;; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6279</id>
        <msg>SPYWARE-PUT Hijacker sidefind runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1147</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/javascripts/common.js&quot;; fast_pattern; nocase; http_uri; content:&quot;Cookie|3A| &quot;; nocase; http_header; content:&quot;origin=sidefind&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6280</id>
        <msg>SPYWARE-PUT Hijacker sidefind runtime detection - cookie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088285</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| istsvc&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6281</id>
        <msg>SPYWARE-PUT Hijacker yoursitebar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453093992</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| &quot;; nocase; http_header; content:&quot;YOUR CUSTOM TOOLBAR&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6282</id>
        <msg>SPYWARE-PUT Hijacker customtoolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074937</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sitereview.asmx/GetReview&quot;; fast_pattern; nocase; http_uri; content:&quot;URL=&quot;; nocase; http_uri; content:&quot;SITE=&quot;; nocase; http_uri; content:&quot;TUID=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6283</id>
        <msg>SPYWARE-PUT Hijacker websearch runtime detection - sitereview</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074933</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WebStat.asmx/GetXML2&quot;; fast_pattern; nocase; http_uri; content:&quot;sDate=&quot;; nocase; http_uri; content:&quot;sModule=&quot;; nocase; http_uri; content:&quot;sCID=&quot;; nocase; http_uri; content:&quot;sIP=&quot;; nocase; http_uri; content:&quot;sURL=&quot;; nocase; http_uri; content:&quot;sReferrer=&quot;; nocase; http_uri; content:&quot;sBT=&quot;; nocase; http_uri; content:&quot;sAgent=&quot;; nocase; http_uri; content:&quot;sName=&quot;; nocase; http_uri; content:&quot;sAction=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6284</id>
        <msg>SPYWARE-PUT Hijacker websearch runtime detection - webstat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074933</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;024&quot;; depth:3; nocase; flowbits:set,backdoor.antilamer1.1.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6285</id>
        <msg>BACKDOOR antilamer 1.1 runtime detection - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076222</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.antilamer1.1.conn; content:&quot;024|C2 E5 F0 F1 E8 FF| |F1 E5 F0 E2 E5 F0 E0| - 1.1&quot;; depth:23; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6286</id>
        <msg>BACKDOOR antilamer 1.1 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076222</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;We&quot;; nocase; content:&quot;got&quot;; distance:0; nocase; content:&quot;this&quot;; distance:0; nocase; content:&quot;GREAT&quot;; distance:0; nocase; content:&quot;Daemon&quot;; distance:0; nocase; content:&quot;Fictional&quot;; nocase; content:&quot;Daemon&quot;; distance:0; nocase; pcre:&quot;/^We\s+got\s+this\s+GREAT\s+Daemon.*Fictional\s+Daemon/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6287</id>
        <msg>BACKDOOR fictional daemon 4.4 runtime detection - telent</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074164</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7306</filter1>
        <filter2>flow:to_server,established; content:&quot;Netspy&quot;; nocase; content:&quot;Version&quot;; distance:0; nocase; content:&quot;service&quot;; distance:0; nocase; pcre:&quot;/^Netspy\s+Version\s+\d+\x2E\d+\r\nservice\x3A/smi&quot;; flowbits:set,Netspy_Command_Pattern; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6289</id>
        <msg>BACKDOOR netspy runtime detection - command pattern client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=434</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7306 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Netspy_Command_Pattern; content:&quot;Netspy&quot;; nocase; content:&quot;Version&quot;; distance:0; nocase; content:&quot;STATUS&quot;; distance:0; nocase; pcre:&quot;/^Netspy\s+Version\s+\d+\x2E\d+\r\nSTATUS\x3A/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6290</id>
        <msg>BACKDOOR netspy runtime detection - command pattern server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=434</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; http_uri; content:&quot;from=JJB+Server&quot;; nocase; content:&quot;fromemail=JJB&quot;; nocase; content:&quot;subject=JJB+Pager&quot;; nocase; content:&quot;body=JJ+BackDoor+-+v&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6291</id>
        <msg>BACKDOOR justjoke v2.6 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073017</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1337 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;MV 1.0&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6292</id>
        <msg>BACKDOOR joker ddos v1.0.1 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076749</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1337</filter1>
        <filter2>flow:to_server,established; content:&quot;C1 &quot;; depth:3; nocase; pcre:&quot;/^C1\s\d+\x2E\d+\x2E\d+\x2E\d+/smi&quot;; flowbits:set,backdoor.joker.ddos.1.0.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6293</id>
        <msg>BACKDOOR joker ddos v1.0.1 runtime detection - bomb - initial flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076749</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1337 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.joker.ddos.1.0.conn.1; content:&quot;M1 &quot;; depth:3; nocase; pcre:&quot;/^M1\s\d+\x2E\d+\x2E\d+\x2E\d+/smi&quot;; flowbits:set,backdoor.joker.ddos.1.0.conn.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6294</id>
        <msg>BACKDOOR joker ddos v1.0.1 runtime detection - bomb - second flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076749</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1337</filter1>
        <filter2>flow:to_server,established; flowbits:isset,backdoor.joker.ddos.1.0.conn.2; content:&quot;C2 &quot;; depth:3; nocase; pcre:&quot;/^C2\s\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6295</id>
        <msg>BACKDOOR joker ddos v1.0.1 runtime detection - bomb</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076749</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; http_uri; content:&quot;from=&quot;; nocase; content:&quot;fromemail=&quot;; nocase; content:&quot;subject=Insurrection+Page&quot;; nocase; content:&quot;body=&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6296</id>
        <msg>BACKDOOR insurrection 1.1.0 runtime detection - icq notification 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076744</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/blah.cgi&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;id=Insurrection&quot;; nocase; http_uri; content:&quot;win=&quot;; nocase; http_uri; content:&quot;rpass=&quot;; nocase; http_uri; content:&quot;connection=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6297</id>
        <msg>BACKDOOR insurrection 1.1.0 runtime detection - icq notification 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076744</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;sin&quot;; depth:3; nocase; pcre:&quot;/^sin\d+\x3A[^\r\n]*\x3A\d+\x3A\d+\x3A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6298</id>
        <msg>BACKDOOR insurrection 1.1.0 runtime detection - reverse connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076744</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Insurrection1&quot;; depth:13; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6299</id>
        <msg>BACKDOOR insurrection 1.1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076744</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/friendship/email_thank_you?&quot;; nocase; http_uri; content:&quot;nick_name=CIA-Test&quot;; nocase; http_uri; content:&quot;user_email=ciatest@icq.com&quot;; nocase; http_uri; content:&quot;friend_nickname=CIA-Notify-Tezt&quot;; nocase; http_uri; pcre:&quot;/\x2Ffriendship\x2Femail_thank_you\?[^\r\n]*nick_name=CIA-Test[^\r\n]*friend_nickname=CIA-Notify-Tezt/Ui&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6300</id>
        <msg>BACKDOOR cia 1.3 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076260</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;verifyPASS&quot;; depth:10; flowbits:set,CIA13_conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6302</id>
        <msg>BACKDOOR cia runtime detection - initial connection - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076260</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CIA13_conn; content:&quot;passcorrect|3B|&quot;; nocase; content:&quot;CIA&quot;; distance:0; nocase; pcre:&quot;/^passcorrect\x3B\d+\x3B\d+\x3BCIA/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6303</id>
        <msg>BACKDOOR cia runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076260</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1207 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;R|00|SoftWAR Server&quot;; depth:16; nocase; flowbits:set,bit.SoftWARShadowThiefInitialconnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6304</id>
        <msg>BACKDOOR softwar shadowthief runtime detection - initial connection - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=19977</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1207</filter1>
        <filter2>flow:from_client,established; flowbits:isset,bit.SoftWARShadowThiefInitialconnection; content:&quot;|01|SoftWAR Client|00|&quot;; depth:18; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6305</id>
        <msg>BACKDOOR softwar shadowthief runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=19977</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6912 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;SHIT-HEEP&quot;; depth:9; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6306</id>
        <msg>BACKDOOR shit heep runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=5451</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6660 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;accept|3A|&quot;; depth:7; nocase; flowbits:set,bit.LameSpyInitialconnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6307</id>
        <msg>BACKDOOR lamespy runtime detection - initial connection - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3370</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6660 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,bit.LameSpyInitialconnection; content:&quot;cname|3A|&quot;; depth:6; nocase; content:&quot;Command Sendet&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6308</id>
        <msg>BACKDOOR lamespy runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=3370</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;MSG &quot;; depth:4; nocase; pcre:&quot;/^MSG\s+[^\r\n]*\n/smi&quot;; flowbits:set,NetDemon_Msg; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6312</id>
        <msg>BACKDOOR net demon runtime detection - message send</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetDemon_Msg; content:&quot;WAIT|0A|&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6313</id>
        <msg>BACKDOOR net demon runtime detection - message response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;openbrowser &quot;; depth:12; nocase; pcre:&quot;/^openbrowser\s+[^\r\n]*\n/smi&quot;; flowbits:set,NetDemon_OpenBrowser; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6314</id>
        <msg>BACKDOOR net demon runtime detection - open browser request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetDemon_OpenBrowser; content:&quot;browseropened|0A|&quot;; depth:14; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6315</id>
        <msg>BACKDOOR net demon runtime detection - open browser response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;GETLIST &quot;; depth:8; nocase; pcre:&quot;/^GETLIST\s+[^\r\n]*\n/smi&quot;; flowbits:set,NetDemon_FileManager; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6316</id>
        <msg>BACKDOOR net demon runtime detection - file manager request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetDemon_FileManager; content:&quot;FILESIZE&gt;&quot;; depth:9; nocase; pcre:&quot;/^FILESIZE\x3E[^\r\n]*\x3E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6317</id>
        <msg>BACKDOOR net demon runtime detection - file manager response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4029</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 623 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;RTB&quot;; depth:3; nocase; content:&quot;666&quot;; distance:0; nocase; content:&quot;Firewall&quot;; distance:0; nocase; content:&quot;Guarded&quot;; distance:0; nocase; content:&quot;Port&quot;; distance:0; nocase; content:&quot;Your&quot;; distance:0; nocase; content:&quot;IP&quot;; distance:0; nocase; content:&quot;is&quot;; distance:0; nocase; pcre:&quot;/^RTB\s+666\s+v\x2E\d+\x2E\d+\x3B\s+Firewall\s+Guarded\s+Port\x2E\s+Your\s+IP\s+is/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6318</id>
        <msg>BACKDOOR rtb666 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1501</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 8012</filter1>
        <filter2>flow:to_server; content:&quot;aComprobar&quot;; nocase; content:&quot;si&quot;; distance:0; nocase; content:&quot;esta&quot;; distance:0; nocase; content:&quot;conectadoa&quot;; distance:0; nocase; pcre:&quot;/\x23\x31\x23aComprobar\s+si\s+esta\s+conectadoa\x232\x23\x233\x23\x23f\x23/smi&quot;; flowbits:set,PtakkS_Keepalive; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6320</id>
        <msg>BACKDOOR ptakks2.1 runtime detection - keepalive</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079909</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET 8012 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client; flowbits:isset,PtakkS_Keepalive; content:&quot;,jRj,&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6321</id>
        <msg>BACKDOOR ptakks2.1 runtime detection - keepalive acknowledgement</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079909</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 8012</filter1>
        <filter2>flow:to_server; content:&quot;,|3A|,j&quot;; nocase; content:&quot;G,o,,y,&quot;; distance:0; nocase; pcre:&quot;/\x2C\x3A\x2C\x6A[^\r\n]*\x47\x2C\x6F\x2C\x2C\x79\x2C/&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6322</id>
        <msg>BACKDOOR ptakks2.1 runtime detection - command pattern</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079909</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 47221</filter1>
        <filter2>flow:to_server,established; content:&quot;&amp;raport&quot;; depth:7; nocase; flowbits:set,bit.3xBackdoorconnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6323</id>
        <msg>BACKDOOR 3xBackdoor runtime detection - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 47221 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,bit.3xBackdoorconnection; content:&quot;Raport|3A| serwer aktywny&quot;; depth:22; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6324</id>
        <msg>BACKDOOR 3xBackdoor runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected to Server |3A|-|29|&quot;; depth:23; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6325</id>
        <msg>BACKDOOR fucktrojan 1.2 runtime detection - initial connection</msg>
        <url>megasecurity.org/trojans/f/fucktrojan/Fucktrojan1.2.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 666</filter1>
        <filter2>flow:to_server,established; content:&quot;Flood&quot;; nocase; flowbits:set,FuckTrojan_flood; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6326</id>
        <msg>BACKDOOR fucktrojan 1.2 runtime detection - flood</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,FuckTrojan_flood; content:&quot;Windows&quot;; nocase; content:&quot;Directory&quot;; distance:0; nocase; content:&quot;Flooded&quot;; distance:0; nocase; pcre:&quot;/Windows\s+Directory\s+Flooded/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6327</id>
        <msg>BACKDOOR fucktrojan 1.2 runtime detection - flood</msg>
        <url>megasecurity.org/trojans/f/fucktrojan/Fucktrojan1.2.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 11000 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Conectou&quot;; depth:8; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6328</id>
        <msg>BACKDOOR commando runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 11000</filter1>
        <filter2>flow:to_server,established; content:&quot;Cliente |3A|&quot;; flowbits:set,Commando; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6329</id>
        <msg>BACKDOOR commando runtime detection - chat client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 11000 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Commando; content:&quot;Servidor |3A|&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6330</id>
        <msg>BACKDOOR commando runtime detection - chat server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; content:&quot;from=MondoHack&quot;; nocase; content:&quot;fromemail=&quot;; nocase; content:&quot;subject=&quot;; nocase; content:&quot;body=&quot;; nocase; content:&quot;to=&quot;; nocase; content:&quot;send=&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6331</id>
        <msg>BACKDOOR globalkiller1.0 runtime detection - notification</msg>
        <url>www.spywareguide.com/product_show.php?id=1656</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1255 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Conectado&quot;; depth:9; nocase; content:&quot;Yeah!&quot;; distance:0; nocase; pcre:&quot;/^Conectado\s+Yeah\!/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6332</id>
        <msg>BACKDOOR globalkiller1.0 runtime detection - initial connection</msg>
        <url>www.spywareguide.com/product_show.php?id=1656</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2583 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;WinCrash&quot;; depth:8; nocase; content:&quot;Server&quot;; distance:0; nocase; pcre:&quot;/^WinCrash\s+Server\s+\d+\x2E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6333</id>
        <msg>BACKDOOR wincrash 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084089</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 11831 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;BackLash Server&quot;; depth:15; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6334</id>
        <msg>BACKDOOR backlash runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076823</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12624</filter1>
        <filter2>flow:to_server,established; content:&quot;*?!?&quot;; depth:4; flowbits:set,buttman.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6335</id>
        <msg>BACKDOOR buttman v0.9p runtime detection - remote control - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453089720</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 12624 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,buttman.1; content:&quot;|23|+|0D 0A|&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6336</id>
        <msg>BACKDOOR buttman v0.9p runtime detection - remote control</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453089720</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 18713</filter1>
        <filter2>flow:to_server,established; content:&quot;[LOAD&quot;; nocase; content:&quot;DRIVE&quot;; distance:0; nocase; content:&quot;DATA]&quot;; distance:0; nocase; pcre:&quot;/^\[LOAD\s+DRIVE\s+DATA\]/smi&quot;; flowbits:set,backdoor.HatredFriend.cts; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6337</id>
        <msg>BACKDOOR hatredfriend file manage command - set flowbit</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077215</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 18713 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.HatredFriend.cts; content:&quot;[DRIVE&quot;; nocase; content:&quot;LIST]&quot;; distance:0; nocase; pcre:&quot;/\[DRIVE\s+LIST\]\d(\x00[a-zA-Z]\x3A(\s+\[.*\])?)+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6338</id>
        <msg>BACKDOOR hatredfriend file manage command</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077215</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;IP&quot;; distance:0; nocase; content:&quot;Contact&quot;; distance:0; nocase; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;EBT&quot;; distance:0; nocase; content:&quot;Reporter&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Vic&quot;; distance:0; nocase; content:&quot;Ip&quot;; distance:0; nocase; content:&quot;Addy&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*IP\s+Contact.*X-Mailer\x3A[^\r\n]*EBT\s+Reporter.*Subject\x3A[^\r\n]*Vic\s+Ip\s+Addy/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6339</id>
        <msg>BACKDOOR hatredfriend email notification detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077215</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| &quot;; nocase; content:&quot;Handy Keylogger|3A|&quot;; distance:0; nocase; content:&quot;PRODUCED BY HANDY KEYLOGGER LOG PARSER&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6340</id>
        <msg>SPYWARE-PUT Keylogger handy keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096599</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Spedia&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6341</id>
        <msg>SPYWARE-PUT Hijacker spediabar user-agent string detected</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/tz.cgi&quot;; nocase; http_uri; content:&quot;run=&quot;; nocase; http_uri; content:&quot;Host|3A| spedia.net&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6342</id>
        <msg>SPYWARE-PUT Hijacker spediabar runtime detection - info check</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;TSA/&quot;; fast_pattern; nocase; http_header; content:&quot;Ts2/&quot;; nocase; http_header; content:&quot;OS/&quot;; nocase; http_header; content:&quot;IE/&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*?TSA\x2F[^\r\n]*?Ts2\x2F[^\r\n]*?OS\x2F[^\r\n]*?IE\x2F[^\r\n]*?CD\x2F[^\r\n]*?UID\x2F[^\r\n]*?AID\x2F/HsmiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6343</id>
        <msg>SPYWARE-PUT Adware targetsaver runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090707</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/speedbar/speedbarcfg.jsp&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Excite&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Excite/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6344</id>
        <msg>SPYWARE-PUT Adware excite search bar runtime detection - config</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078495</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tr.js&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;r=&quot;; nocase; http_uri; content:&quot;site=excite&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6345</id>
        <msg>SPYWARE-PUT Adware excite search bar runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078495</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/version/stationripper-getver&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6346</id>
        <msg>SPYWARE-PUT Adware stationripper update detection</msg>
        <url>stationripper.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/minimall&quot;; nocase; http_uri; content:&quot;w=&quot;; nocase; http_uri; content:&quot;h=&quot;; nocase; http_uri; content:&quot;client=&quot;; nocase; http_uri; content:&quot;noctxt=&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;url=http|3A|/www.stationripper.com/Portal/ad.htm&quot;; fast_pattern; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6347</id>
        <msg>SPYWARE-PUT Adware stationripper ad display detection</msg>
        <url>stationripper.com</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/engine&quot;; fast_pattern; nocase; http_uri; content:&quot;site=&quot;; nocase; http_uri; content:&quot;page=&quot;; nocase; http_uri; content:&quot;space=&quot;; nocase; http_uri; content:&quot;size=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;domain=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6348</id>
        <msg>SPYWARE-PUT Snoopware zenosearch runtime detection</msg>
        <url>www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW%5FZENO%2EA</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/news.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.richfind.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Erichfind\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6349</id>
        <msg>SPYWARE-PUT Hijacker richfind update detection</msg>
        <url>www.f-secure.com/sw-desc/iehijacker_richfind.shtml</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php&quot;; nocase; http_uri; content:&quot;qq=&quot;; nocase; http_uri; content:&quot;said=bar&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;richfind.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*richfind\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6350</id>
        <msg>SPYWARE-PUT Hijacker richfind auto search redirect detection</msg>
        <url>www.f-secure.com/sw-desc/iehijacker_richfind.shtml</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/abho/chkupdate.abs&quot;; fast_pattern; nocase; http_uri; content:&quot;cv=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;adblock.linkz.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*adblock\x2Elinkz\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6351</id>
        <msg>SPYWARE-PUT Hijacker adblock update detection</msg>
        <url>www.spywareguide.com/product_show.php?id=48</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/abho/autosrch.abs&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;adblock.linkz.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*adblock\x2Elinkz\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6352</id>
        <msg>SPYWARE-PUT Hijacker adblock auto search redirect detection</msg>
        <url>www.spywareguide.com/product_show.php?id=48</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iesearch.php&quot;; fast_pattern; nocase; http_uri; content:&quot;term=&quot;; nocase; http_uri; content:&quot;Submit=Search&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;linkz.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*linkz\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6353</id>
        <msg>SPYWARE-PUT Hijacker adblock ie search assistant redirect detection</msg>
        <url>www.spywareguide.com/product_show.php?id=48</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/simplesearch/update.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;ProxyDown&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*ProxyDown/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6354</id>
        <msg>SPYWARE-PUT Trickler wsearch runtime detection - auto update</msg>
        <url>www.zhongsou.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/zsmp3&quot;; nocase; http_uri; content:&quot;tps=&quot;; nocase; http_uri; content:&quot;word=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;mp3.zhongsou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*mp3\x2Ezhongsou\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6355</id>
        <msg>SPYWARE-PUT Trickler wsearch runtime detection - mp3 search</msg>
        <url>www.zhongsou.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/desksearch.cgi&quot;; nocase; http_uri; content:&quot;tps=&quot;; nocase; http_uri; content:&quot;word=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.zhongsou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ezhongsou\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6356</id>
        <msg>SPYWARE-PUT Trickler wsearch runtime detection - desktop search</msg>
        <url>www.zhongsou.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/speedbar/mySpeedbarCfg2.jsp&quot;; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Need2Find&quot;; nocase; http_header; content:&quot;Bar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Need2Find\s+Bar/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6357</id>
        <msg>SPYWARE-PUT Hijacker need2find initial configuration detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096250</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jsp/cfg_redir.jsp&quot;; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;searchfor=&quot;; nocase; http_uri; pcre:&quot;/url=[^\r\n]*kl\x2Esearch\x2Eneed2find\x2Ecom/Ui&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6358</id>
        <msg>SPYWARE-PUT Hijacker need2find search query detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096250</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pm/start.asp&quot;; nocase; http_uri; content:&quot;pmver=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.altnet.com&quot;; nocase; http_header; pcre:&quot;/^HOST\x3A[^\r\n]*www\x2Ealtnet\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6359</id>
        <msg>SPYWARE-PUT Adware altnet runtime detection - initial retrieval</msg>
        <url>www.spywareremove.com/removeAltnet.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Peer&quot;; nocase; http_header; content:&quot;Points&quot;; nocase; http_header; content:&quot;Manager&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Peer\s+Points\s+Manager/smiH&quot;; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;pm.altnet.com&quot;; nocase; http_header; pcre:&quot;/^HOST\x3A[^\r\n]*pm\x2Ealtnet\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6360</id>
        <msg>SPYWARE-PUT Adware altnet runtime detection - update</msg>
        <url>www.spywareremove.com/removeAltnet.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/backoffice.net/stats/Add.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;ST=&quot;; nocase; http_uri; content:&quot;PN=Altnet&quot;; nocase; http_uri; content:&quot;AN=Altnet&quot;; nocase; http_uri; content:&quot;LN=&quot;; nocase; http_uri; content:&quot;DN=&quot;; nocase; http_uri; content:&quot;GR=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.altnet.com&quot;; nocase; http_header; pcre:&quot;/^HOST\x3A[^\r\n]*www\x2Ealtnet\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6361</id>
        <msg>SPYWARE-PUT Adware altnet runtime detection - status report</msg>
        <url>www.spywareremove.com/removeAltnet.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;MGS-Internal-Web-Manager&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*MGS-Internal-Web-Manager/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6362</id>
        <msg>SPYWARE-PUT Hijacker microgaming runtime detection</msg>
        <url>www.spywareremove.com/removeMicrogaming.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sacc/popup.php&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SAcc&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*SAcc/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6363</id>
        <msg>SPYWARE-PUT adware surfaccuracy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094263</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;iMeshBar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*iMeshBar/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6364</id>
        <msg>SPYWARE-PUT Hijacker imeshbar runtime detection</msg>
        <url>www.file.net/process/imeshbar.dll.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SecureNet&quot;; nocase; http_header; content:&quot;Xtra&quot;; distance:0; nocase; pcre:&quot;/^User-Agent\x3A[^\r\n]*SecureNet\s+Xtra/smiH&quot;; pcre:&quot;/^Host\x3A[^\r\n]*sonymusic\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6365</id>
        <msg>SPYWARE-PUT Other-Technologies sony rootkit runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096362</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;eAnthMngr&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*eAnthMngr/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6366</id>
        <msg>SPYWARE-PUT Trickler eacceleration downloadreceiver user-agent string detected</msg>
        <url>www.spywareguide.com/product_show.php?id=398</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dlp_def/&quot;; nocase; http_uri; content:&quot;imod=&quot;; nocase; http_uri; content:&quot;prod=scanner&quot;; fast_pattern; nocase; http_uri; content:&quot;lng=&quot;; nocase; http_uri; content:&quot;geo=&quot;; nocase; http_uri; content:&quot;ftid=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;ui=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6367</id>
        <msg>SPYWARE-PUT Trickler eacceleration downloadreceiver runtime detection - stop-sign ads</msg>
        <url>www.spywareguide.com/product_show.php?id=398</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wsliveup/advisor/wsliveup.dat&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;spybl.cyberdefender.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*spybl\x2Ecyberdefender\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6372</id>
        <msg>SPYWARE-PUT Trickler spyblocs eblocs detection - get wsliveup.dat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/products/stbar/stbarpat.dat&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;download.eblocs.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*download\x2Eeblocs\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6373</id>
        <msg>SPYWARE-PUT Trickler spyblocs eblocs detection - stbarpat.dat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/products/spyblocs/&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;download.eblocs.com&quot;; nocase; http_header; pcre:&quot;/\x2Fproducts\x2Fspyblocs\x2F(spyblpat\d*\x2Edat\x2E\d+)|(spyblini\x2Eini)/UiH&quot;; pcre:&quot;/^Host\x3A[^\r\n]*download\x2Eeblocs\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6374</id>
        <msg>SPYWARE-PUT Trickler spyblocs eblocs detection - get spyblpat.dat/spyblini.ini</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cart11.html?affl=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.eblocs.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Eeblocs\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6375</id>
        <msg>SPYWARE-PUT Trickler spyblocs.eblocs detection - register request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/srv/c&quot;; nocase; http_uri; content:&quot;i=&quot;; nocase; http_uri; content:&quot;t=&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;GirafaClient&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*GirafaClient/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6376</id>
        <msg>SPYWARE-PUT Hijacker girafa toolbar - toolbar update</msg>
        <url>www.spywareguide.com/product_show.php?id=1135</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/srv/i?i=&quot;; fast_pattern; nocase; http_uri; content:&quot;r=http&quot;; nocase; http_uri; content:&quot;m=srch&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6377</id>
        <msg>SPYWARE-PUT Hijacker girafa toolbar - browser hijack</msg>
        <url>www.spywareguide.com/product_show.php?id=1135</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r/banner_iw_codigo_gtc.php&quot;; fast_pattern; nocase; http_uri; content:&quot;idrotador=&quot;; nocase; http_uri; content:&quot;tamano=&quot;; nocase; http_uri; content:&quot;iw_alternativo=&quot;; nocase; http_uri; content:&quot;www.adbars.com&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6378</id>
        <msg>SPYWARE-PUT Hijacker adbars runtime detection - homepage hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079049</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buscar.php?cadena=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.buscandoamigos.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ebuscandoamigos\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6379</id>
        <msg>SPYWARE-PUT Hijacker adbars runtime detection - search in toolbar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079049</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data.asp&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.dotcomtoolbar.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Edotcomtoolbar\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6380</id>
        <msg>SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - toolbar information retrieve</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076986</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.asp?&quot;; nocase; http_uri; content:&quot;group=searchbar-web&quot;; fast_pattern; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6381</id>
        <msg>SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - search in toolbar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076986</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/redirect.asp&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;linkid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;click.dotcomtoolbar.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*click\x2Edotcomtoolbar\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6382</id>
        <msg>SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - url hook</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076986</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 15163</filter1>
        <filter2>flow:to_server,established; content:&quot;|04 00 00 00|&quot;; depth:4; content:&quot;|FF D8 FF E0 00 10|JFIF|00 01 01 00 00 00 00 00 00 00 FF DB 00|C|00 08 06 06 07 06 05 08 07 07 07 09 09 08 0A 0C 14 0D 0C 0B 0B 0C 19 12 13 0F 14 1D 1A 1F 1E 1D 1A 1C 1C| |24|.' |22|,|23 1C 1C 28|7|29|,01444|1F|'9=82&lt;.342|FF DB 00|C|01|&quot;; distance:0; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6383</id>
        <msg>SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - tcp connection setup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075982</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 15164</filter1>
        <filter2>content:&quot;|0A 02 08 FE 00|&quot;; depth:5; offset:4;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6385</id>
        <msg>SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent status monitoring</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075982</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 15165</filter1>
        <filter2>content:&quot;|00 00 00 00 0A 02 08 A6|&quot;; depth:8; content:&quot;|02 00 00|v&quot;; distance:0;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6386</id>
        <msg>SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent up notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075982</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/query/&quot;; fast_pattern; nocase; http_uri; content:&quot;lt=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;cls=&quot;; nocase; http_uri; content:&quot;rid=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6387</id>
        <msg>SPYWARE-PUT Hijacker internet optimizer runtime detection - autosearch hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453093995</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;js=&quot;; nocase; http_uri; content:&quot;e=ERR404&quot;; fast_pattern; nocase; http_uri; content:&quot;u=http&quot;; nocase; http_uri; content:&quot;cls=&quot;; nocase; http_uri; content:&quot;rid=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6388</id>
        <msg>SPYWARE-PUT Hijacker internet optimizer runtime detection - error page hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453093995</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exclusionlist/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;client.contextual.esyndicate.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*client\x2Econtextual\x2Eesyndicate\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6389</id>
        <msg>SPYWARE-PUT Adware esyndicate runtime detection - postinstall request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094058</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/content/&quot;; fast_pattern; nocase; http_uri; flowbits:set,eSyndicate.ads; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6390</id>
        <msg>SPYWARE-PUT Adware esyndicate runtime detection - ads popup</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; flowbits:isset,eSyndicate.ads; content:&quot;/ad/zadframe.esyn&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;aw=&quot;; nocase; http_uri; content:&quot;ah=&quot;; nocase; http_uri; content:&quot;dt=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6391</id>
        <msg>SPYWARE-PUT Adware esyndicate runtime detection - ads popup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094058</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchbar/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.znext.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6392</id>
        <msg>SPYWARE-PUT Hijacker zeropopup runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075510</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;CodeguruBrowser&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*CodeguruBrowser\d+\x2E\d+/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6394</id>
        <msg>SPYWARE-PUT Hijacker adstart runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088444</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 16661 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;A-311 Death welcome&quot;; depth:19; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6395</id>
        <msg>BACKDOOR a-311 death runtime detection - initial connection server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076778</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;A-311 Server&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6396</id>
        <msg>BACKDOOR a-311 death user-agent string detected</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076778</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 80 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;html&gt;&lt;head&gt;&lt;title&gt;HTTP_RAT&lt;/title&gt;&quot;; nocase; content:&quot;&lt;h3&gt;z0mbie's HTTP_RAT&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>6398</id>
        <msg>BACKDOOR http rat runtime detection - http</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076346</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;  rad &quot;; depth:6; nocase; content:&quot;  &gt;&lt;  &quot;; distance:0; pcre:&quot;/^\s\srad\s\d+\x2E\d+\x2E\d+\s\s\x3E\x3C/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6399</id>
        <msg>BACKDOOR rad 1.2.3 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072457</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;DISK&quot;; depth:4; nocase; flowbits:set,snowdoor_cts; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6400</id>
        <msg>BACKDOOR snowdoor runtime detection client-to-server</msg>
        <url>www.megasecurity.org/trojans/s/snow/Snow1.3.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,snowdoor_cts; content:&quot;DISK&quot;; depth:4; nocase; pcre:&quot;/^DISK[A-z][0-9]/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6401</id>
        <msg>BACKDOOR snowdoor runtime detection server-to-client</msg>
        <url>www.megasecurity.org/trojans/s/snow/Snow1.3.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4125</filter1>
        <filter2>flow:to_server,established; content:&quot;netangel&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6402</id>
        <msg>BACKDOOR netangel connection client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086360</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [5800,5900:5999]</filter1>
        <filter2>flow:to_server,established; dsize:12; content:&quot;RFB 003.00&quot;; depth:10; content:!&quot;3&quot;; within:1; flowbits:set,vnc.handshake.client; flowbits:set,vnc.traffic; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>6469</id>
        <msg>EXPLOIT RealVNC connection attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $HOME_NET [5800,5900:5999] -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,vnc.handshake.client; flowbits:unset,vnc.handshake.client; pcre:&quot;/^[^\x00][^\x00\x01]+$/&quot;; flowbits:set,vnc.server.auth.types; flowbits:noalert; classtype:protocol-command-decode;</filter2>
        <id>6470</id>
        <msg>EXPLOIT RealVNC authentication types without None type sent attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2115</filter1>
        <filter2>flow:to_server,established; content:&quot;CURDIR|0D|&quot;; depth:7; nocase; flowbits:set,Bugs_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6472</id>
        <msg>BACKDOOR bugs runtime detection - file manager client-to-server</msg>
        <url>www.commodon.com/threat/threat-bugs.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2115 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Bugs_InitConnection; content:&quot;CURDIR &quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6473</id>
        <msg>BACKDOOR bugs runtime detection - file manager server-to-client</msg>
        <url>www.commodon.com/threat/threat-bugs.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/synctl/ping.pl&quot;; fast_pattern; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;speed=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6474</id>
        <msg>BACKDOOR w32.loosky.gen@mm runtime detection - notification</msg>
        <url>www.sophos.com/virusinfo/analyses/w32looskyl.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;badratpass&quot;; depth:10; nocase; flowbits:set,backdoor.badrat.1.1.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6475</id>
        <msg>BACKDOOR badrat 1.1 runtime detection - flowbit set</msg>
        <url>www.megasecurity.org/trojans/b/badrat/Badrat1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.badrat.1.1.conn; content:&quot;okpass&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6476</id>
        <msg>BACKDOOR badrat 1.1 runtime detection</msg>
        <url>www.megasecurity.org/trojans/b/badrat/Badrat1.1.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.searchingall.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Toolbar.*?Host\x3A[^\r\n]*www\x2Esearchingall\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>6478</id>
        <msg>SPYWARE-PUT Trackware searchingall toolbar runtime detection - send user url request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097487</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/e.aspx&quot;; nocase; content:&quot;ver=&quot;; nocase; content:&quot;host=&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.ZSearchResults.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2EZSearchResults\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>6479</id>
        <msg>SPYWARE-PUT Snoopware totalvelocity zsearch runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083031</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hpt/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.e-finder.cc&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ee-finder\x2Ecc/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6480</id>
        <msg>SPYWARE-PUT Hijacker cws.cameup runtime detection - home page</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchtb.php?q=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;fast-look.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*fast-look\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6481</id>
        <msg>SPYWARE-PUT Hijacker cws.cameup runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get/&quot;; nocase; http_uri; content:&quot;pv=&quot;; nocase; http_uri; content:&quot;iv=&quot;; nocase; http_uri; content:&quot;pn=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Host|3A| toolbarplace.com&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6482</id>
        <msg>SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - get info</msg>
        <url>www.spywaredetails.com/index.php?a=spyware&amp;act=read&amp;id=1607</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;said=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.vip-se.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Evip-se\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6483</id>
        <msg>SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - home page hijacker</msg>
        <url>www.spywaredetails.com/index.php?a=spyware&amp;act=read&amp;id=1607</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;said=&quot;; nocase; http_uri; content:&quot;qq=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.makemesearch.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Emakemesearch\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6484</id>
        <msg>SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - search</msg>
        <url>www.spywaredetails.com/index.php?a=spyware&amp;act=read&amp;id=1607</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/sbartb0300.cfg&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;acez&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*acez/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6487</id>
        <msg>SPYWARE-PUT Adware searchnugget toolbar runtime detection - check updates</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094349</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/error.php&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;searchnugget&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*searchnugget/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6488</id>
        <msg>SPYWARE-PUT Adware searchnugget toolbar runtime detection - redirect mistyped urls</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094349</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hp/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.webcruiser.cc&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ewebcruiser\x2Ecc/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6489</id>
        <msg>SPYWARE-PUT Hijacker analyze IE runtime detection - default page hijacker</msg>
        <url>www.spywaredetails.com/index.php?a=spyware&amp;act=read&amp;id=1680</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;snprtz|7C|dialno&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.otherchance.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*snprtz\x7Cdialno.*Host\x3A[^\r\n]*www\x2Eotherchance\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6490</id>
        <msg>SPYWARE-PUT Dialer yeaknet runtime detection - home page hijacker</msg>
        <url>www.spywareguide.com/product_show.php?id=2446</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ccRandom/&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;snprtz|7C|dialno&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;linkautomatici.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*snprtz\x7Cdialno.*Host\x3A[^\r\n]*linkautomatici\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6491</id>
        <msg>SPYWARE-PUT Dialer yeaknet runtime detection - post-installation</msg>
        <url>www.spywareguide.com/product_show.php?id=2446</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bsrv.php&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;socksport=&quot;; fast_pattern; nocase; http_uri; content:&quot;httpport=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6492</id>
        <msg>SPYWARE-PUT Trickler Backdoor-BAC.gen.e runtime detection - notification</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_138750.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dat7.php&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;xpsp2&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;lifeisfine.org&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*xpsp2-\d+.*Host\x3A[^\r\n]*lifeisfine\x2Eorg/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6493</id>
        <msg>SPYWARE-PUT Trickler Backdoor-BAC.gen.e runtime detection - post data</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_138750.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mbop/display.php3&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;yourenhancement.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*yourenhancement\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6494</id>
        <msg>SPYWARE-PUT Adware yourenhancement runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097585</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/trial.php&quot;; fast_pattern; nocase; http_uri; content:&quot;rest=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;a=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;httphost&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*httphost/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>6495</id>
        <msg>SPYWARE-PUT Hijacker troj_spywad.x runtime detection</msg>
        <url>www.sophos.com/virusinfo/analyses/trojspywadi.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/advertpro/servlet/view/dynamic/html/campaign&quot;; fast_pattern; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;media.top-banners.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*media\x2Etop-banners\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>6496</id>
        <msg>SPYWARE-PUT Adware adpowerzone runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1299</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21554</filter1>
        <filter2>flow:to_server,established; content:&quot;ver&quot;; depth:3; nocase; flowbits:set,backdoor.exploiter.1.0.conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6497</id>
        <msg>BACKDOOR exploiter 1.0 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1603</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 21554 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.exploiter.1.0.conn; content:&quot;Exploiter&quot;; depth:9; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;Port&quot;; distance:0; nocase; pcre:&quot;/^Exploiter\s+Server\s+\d+\x2E\d+\s+\x2E\s+Port\s+\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>6498</id>
        <msg>BACKDOOR exploiter 1.0 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1603</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;RequestName|7C|&quot;; depth:12; nocase; flowbits:set,Omerta_1_3_conn_1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>6499</id>
        <msg>BACKDOOR omerta 1.3 runtime detection</msg>
        <url>www.antivirusprogram.se/virusinfo/Backdoor.Omerta_4852.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;|89|PNG|0D 0A 1A 0A|&quot;; flowbits:set,http.client.png; flowbits:noalert; metadata:policy security-ips drop; classtype:protocol-command-decode;</filter2>
        <id>6688</id>
        <msg>WEB-CLIENT PNG file transfer</msg>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;sBIT&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6691</id>
        <msg>WEB-CLIENT Malformed PNG detected sBIT overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;bkGD&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6693</id>
        <msg>WEB-CLIENT Malformed PNG detected bKGD overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;hIST&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6694</id>
        <msg>WEB-CLIENT Malformed PNG detected hIST overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;tRNS&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6695</id>
        <msg>WEB-CLIENT Malformed PNG detected tRNS overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;pHYs&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6696</id>
        <msg>WEB-CLIENT Malformed PNG detected pHYs overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18385</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0025</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,http.client.png; content:&quot;tIME&quot;; byte_test:4,&gt;,3000,-8,relative; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>6698</id>
        <msg>WEB-CLIENT Malformed PNG detected tIME overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-024.mspx</url>
      </rule>
      <rule>
        <bugtraq>18838</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2006-3351</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;[InternetShortcut]&quot;; within:100; nocase; content:&quot;url=&quot;; distance:0; nocase; content:&quot;file|3A|file|3A|file|3A|&quot;; distance:0; nocase; metadata:policy security-ips drop, service http; classtype:denial-of-service;</filter2>
        <id>7022</id>
        <msg>WEB-CLIENT windows explorer invalid url file overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/uniq1.php&quot;; nocase; http_uri; content:&quot;exp=&quot;; nocase; http_uri; content:&quot;adv=&quot;; nocase; http_uri; content:&quot;code1=&quot;; nocase; http_uri; content:&quot;code2=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;1-extreme.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*1\-extreme\x2Ebiz/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7049</id>
        <msg>SPYWARE-PUT Hijacker extreme biz runtime detection - uniq1</msg>
        <url>vil.nai.com/vil/content/v_139122.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| FCTB1&quot;; fast_pattern; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7050</id>
        <msg>SPYWARE-PUT Hijacker freecruise toolbar runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newsys/options.xml&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;i-femdom.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*i\-femdom\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7051</id>
        <msg>SPYWARE-PUT Trickler generic downloader.g runtime detection - spyware injection</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_128719.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;adv=&quot;; nocase; http_uri; content:&quot;ads=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.topadwarereviews.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Etopadwarereviews\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7052</id>
        <msg>SPYWARE-PUT Trickler generic downloader.g runtime detection - adv</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_128719.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whois.xml&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;cache.everer.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*cache\x2Eeverer\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7053</id>
        <msg>SPYWARE-PUT Adware webredir runtime detection</msg>
        <url>castlecops.com/tk1907-pxwma_dll.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/b/info.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ccecaedbebfcaf.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*ccecaedbebfcaf\x2Ecom.*?uuid=.*?wv=.*?cargo=.*?check=/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7054</id>
        <msg>SPYWARE-PUT Trickler download arq variant runtime detection</msg>
        <url>vil.nai.com/vil/content/v_137359.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/progs/&quot;; nocase; http_uri; content:&quot;.php&quot;; nocase; http_uri; content:&quot;adv=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;vip01.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*vip01\x2Ebiz/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7055</id>
        <msg>SPYWARE-PUT Hijacker vip01 biz runtime detection - adv</msg>
        <url>forums.maddoktor2.com/index.php?showtopic=3601</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;SI|7C|Server|7C|&quot;; depth:10; nocase; pcre:&quot;/^SI\|Server\|[^\r\n]*\|\d+\x2E\d+\x2E\d+\x2E\d+\|/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7057</id>
        <msg>BACKDOOR charon runtime detection - initial connection</msg>
        <url>vil.nai.com/vil/content/v_138997.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;REQ|7C|&quot;; depth:4; nocase; pcre:&quot;/^REQ\|[A-Z]\x3A\x5C/smi&quot;; flowbits:set,charon_download_1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7058</id>
        <msg>BACKDOOR charon runtime detection - download file flowbit 1</msg>
        <url>vil.nai.com/vil/content/v_138997.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,charon_download_1; content:&quot;FREQ|7C|&quot;; depth:5; nocase; pcre:&quot;/^FREQ\x7C\d+/smi&quot;; flowbits:set,charon_download_2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7059</id>
        <msg>BACKDOOR charon runtime detection - download file/log flowbit 2</msg>
        <url>vil.nai.com/vil/content/v_138997.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,charon_download_2; content:&quot;SEND|7C|&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7060</id>
        <msg>BACKDOOR charon runtime detection - download file/log</msg>
        <url>vil.nai.com/vil/content/v_138997.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;REQ|7C 24|SYS|24|proc32.dll&quot;; depth:19; nocase; flowbits:set,charon_download_1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7061</id>
        <msg>BACKDOOR charon runtime detection - download log flowbit 1</msg>
        <url>vil.nai.com/vil/content/v_138997.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;from|3A|&quot;; nocase; content:&quot;cyber@yahoo.com&quot;; distance:0; nocase; content:&quot;subject|3A|&quot;; nocase; content:&quot;notification&quot;; distance:0; nocase; pcre:&quot;/^from\x3A[^\r\n]*cyber@yahoo\x2Ecom.*subject\x3A[^\r\n]*notification\d+\x2E\d+\x2E\d+\x2E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7064</id>
        <msg>BACKDOOR cybernetic 1.62 runtime detection - email notification</msg>
        <url>research.sunbelt-software.com/threat_display.cfm?name=CyberNetic&amp;threatid=41745</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;DmInf&quot;; depth:5; nocase; flowbits:set,backdoor.cybernetic.1.62.rev.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7065</id>
        <msg>BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1</msg>
        <url>research.sunbelt-software.com/threat_display.cfm?name=CyberNetic&amp;threatid=41745</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,backdoor.cybernetic.1.62.rev.conn.1; content:&quot;DmInf&quot;; depth:5; nocase; pcre:&quot;/^DmInf\^[^\r\n]*\^\d+\x2E\d+\x2E\d+\x2E\d+\^/smi&quot;; flowbits:set,backdoor.cybernetic.1.62.rev.conn.2; flowbits:unset,backdoor.cybernetic.1.62.rev.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7066</id>
        <msg>BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1</msg>
        <url>research.sunbelt-software.com/threat_display.cfm?name=CyberNetic&amp;threatid=41745</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,backdoor.cybernetic.1.62.rev.conn.2; content:&quot;connect&quot;; depth:7; nocase; flowbits:unset,backdoor.cybernetic.1.62.rev.conn.2; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7067</id>
        <msg>BACKDOOR cybernetic 1.62 runtime detection - reverse connection</msg>
        <url>research.sunbelt-software.com/threat_display.cfm?name=CyberNetic&amp;threatid=41745</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 47262 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; content:&quot;Delta&quot;; depth:5; nocase; content:&quot;Source&quot;; distance:0; nocase; pcre:&quot;/^Delta\s+Source\s+\d+\x2E\d+/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7068</id>
        <msg>BACKDOOR delta source 0.5 beta runtime detection - ping</msg>
        <url>www.spywareguide.com/product_show.php?id=840</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 47262 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client; content:&quot;Server&quot;; depth:6; nocase; content:&quot;info|3A|&quot;; distance:0; nocase; content:&quot;Delta&quot;; distance:0; nocase; content:&quot;Source&quot;; distance:0; nocase; pcre:&quot;/^Server\s+info\x3A\x0D\x0ADelta\s+Source\s+v\d+\x2E\d+/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7069</id>
        <msg>BACKDOOR delta source 0.5 beta runtime detection - pc info</msg>
        <url>www.spywareguide.com/product_show.php?id=840</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.fraggle.rock.2.0.lite.pc.info; content:&quot;info&quot;; depth:4; nocase; content:&quot;Information&quot;; distance:0; nocase; pcre:&quot;/^info\s+Information\s+for/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7072</id>
        <msg>BACKDOOR fraggle rock 2.0 lite runtime detection - pc info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077120</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin/logger.php&quot;; nocase; http_uri; content:&quot;p=&quot;; nocase; http_uri; content:&quot;machineid=&quot;; nocase; http_uri; content:&quot;connection=&quot;; nocase; http_uri; content:&quot;iplan=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;backtrust.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7073</id>
        <msg>BACKDOOR w32.dumaru.gen@mm runtime detection - notification</msg>
        <url>www.vil.mcafeesecurity.com/vil/content/v_125643.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin/socks/bot/cmd.txt&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;backtrust.com&quot;; nocase; http_header;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7074</id>
        <msg>BACKDOOR w32.dumaru.gen@mm runtime detection - cmd</msg>
        <url>www.vil.mcafeesecurity.com/vil/content/v_125643.htm</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;&amp;first&amp; &quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7075</id>
        <msg>BACKDOOR bandook 1.0 runtime detection</msg>
        <url>www.nuclearwinter.us/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/friendship/email_thank_you&quot;; nocase; http_uri; content:&quot;failed_url=&quot;; nocase; http_uri; content:&quot;folder_id=&quot;; nocase; http_uri; content:&quot;extra_params_counte=&quot;; nocase; http_uri; content:&quot;nick_name=&quot;; nocase; http_uri; content:&quot;user_email=&quot;; nocase; http_uri; content:&quot;user_uin=&quot;; nocase; http_uri; content:&quot;friend_nickname=&quot;; nocase; http_uri; content:&quot;friend_contact=&quot;; nocase; http_uri; content:&quot;friend_conta&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;http&quot;; nocase; http_header; content:&quot;protocol&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*http\s+protocol/smiH&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7077</id>
        <msg>BACKDOOR minimo v0.6 runtime detection - icq notification</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 10015 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;BOF&quot;; depth:3; nocase; pcre:&quot;/^BOF[a-z]\x3A\x5C/smi&quot;; flowbits:set,up_run_1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7078</id>
        <msg>BACKDOOR up and run v1.0 beta runtime detection flowbit 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088330</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 10015</filter1>
        <filter2>flow:to_server,established; flowbits:isset,up_run_1; content:&quot;NEXT&quot;; depth:4; nocase; flowbits:set,up_run_2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7079</id>
        <msg>BACKDOOR up and run v1.0 beta runtime detection flowbit 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088330</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 10015</filter1>
        <filter2>flow:to_server,established; flowbits:isset,up_run_2; content:&quot;NEXT&quot;; nocase; flowbits:set,up_run_3; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7080</id>
        <msg>BACKDOOR up and run v1.0 beta runtime detection flowbit 3</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088330</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 10015 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,up_run_3; content:&quot;EOF&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7081</id>
        <msg>BACKDOOR up and run v1.0 beta runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088330</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;KEY=&quot;; depth:4; nocase; content:&quot;Nickname=&quot;; distance:0; nocase; pcre:&quot;/^KEY=[^\s]*\s+Nickname=/smi&quot;; flowbits:set,MoSucker3_0; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7082</id>
        <msg>BACKDOOR mosucker3.0 runtime detection - client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083782</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 62358 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Erazer&quot;; depth:6; nocase; content:&quot;SIN&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; pcre:&quot;/^Erazer\s+SIN\s+Server/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7084</id>
        <msg>BACKDOOR erazer v1.1 runtime detection - sin notification</msg>
        <url>www.megasecurity.org/trojans/e/erazer/Erazer1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;000, Checking...&quot;; depth:16; nocase; flowbits:set,Erazer_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7085</id>
        <msg>BACKDOOR erazer v1.1 runtime detection</msg>
        <url>www.megasecurity.org/trojans/e/erazer/Erazer1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Erazer_InitConnection; content:&quot;000Ok&quot;; depth:5; nocase; content:&quot;echter&quot;; distance:0; nocase; content:&quot;server&quot;; distance:0; nocase; pcre:&quot;/^000Ok\s+echter\s+server\s+\?/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7086</id>
        <msg>BACKDOOR erazer v1.1 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/e/erazer/Erazer1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5555 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ServeMe 1.x&quot;; depth:11; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7091</id>
        <msg>BACKDOOR serveme runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453081036</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1480</filter1>
        <filter2>flow:to_server,established; content:&quot;logon|7C|&quot;; depth:6; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7096</id>
        <msg>BACKDOOR remote hack 1.5 runtime detection - logon</msg>
        <url>www.spywareguide.com/product_show.php?id=1523</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1480</filter1>
        <filter2>flow:to_server,established; content:&quot;executafile|7C|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7097</id>
        <msg>BACKDOOR remote hack 1.5 runtime detection - execute file</msg>
        <url>www.spywareguide.com/product_show.php?id=1523</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1480</filter1>
        <filter2>flow:to_server,established; content:&quot;kstart|7C|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7099</id>
        <msg>BACKDOOR remote hack 1.5 runtime detection - start keylogger</msg>
        <url>www.spywareguide.com/product_show.php?id=1523</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 0A 02|&quot;; depth:3; flowbits:set,GWBoy_InitConnection1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7101</id>
        <msg>BACKDOOR gwboy 0.92 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077181</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,GWBoy_InitConnection1; dsize:&lt;50; content:&quot;|02 01 03 05|&quot;; depth:4; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7103</id>
        <msg>BACKDOOR gwboy 0.92 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077181</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 30029</filter1>
        <filter2>flow:to_server,established; content:&quot;INFO&quot;; depth:4; nocase; flowbits:set,AOLAdmin1.1.connection; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7104</id>
        <msg>BACKDOOR aol admin runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=313</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 30029 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AOLAdmin1.1.connection; content:&quot;AOL Admin Server 1.1 By CHeeSeR&quot;; depth:31; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7105</id>
        <msg>BACKDOOR aol admin runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=313</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21554</filter1>
        <filter2>flow:to_server,established; content:&quot;ver&quot;; depth:3; nocase; flowbits:set,GirlFriend.1.35.connection; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7106</id>
        <msg>BACKDOOR girlfriend runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=834</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 777 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;STLUdt v3.3 - &quot;; depth:14; nocase; content:&quot;-|28|udt33vic|29|&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7108</id>
        <msg>BACKDOOR undetected runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=17265</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Pass-On&quot;; depth:7; nocase; flowbits:set,backdoor.fearless.runtime; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7111</id>
        <msg>BACKDOOR fearless lite 1.01 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078381</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.fearless.runtime; content:&quot;Pass-On0&quot;; depth:8; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7112</id>
        <msg>BACKDOOR fearless lite 1.01 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078381</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 23476</filter1>
        <filter2>flow:to_server,established; content:&quot;1|00|AF&amp;AY|00|pINg_|00|!|28|c|29 23|&quot;; depth:19; nocase; flowbits:set,backdoor.donalddick.1.5.b.3.conn; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7113</id>
        <msg>BACKDOOR donalddick v1.5b3 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1720</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23476 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.donalddick.1.5.b.3.conn; content:&quot;OK|00|1|00|AF&amp;AY|00|pINg_|00|!|28|c|29 23|&quot;; depth:22; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7114</id>
        <msg>BACKDOOR donalddick v1.5b3 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1720</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;ver|3A|Ghost version &quot;; depth:18; nocase; content:&quot;server&quot;; distance:0; nocase; pcre:&quot;/^ver\x3aGhost\s+version\s+\d+\x2E\d+\s+server/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7115</id>
        <msg>BACKDOOR ghost 2.3 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=42053</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;from=Y3K&quot;; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;fromemail=y3k&quot;; distance:0; nocase; content:&quot;subject=Y3K&quot;; distance:0; nocase; content:&quot;online&quot;; distance:0; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7116</id>
        <msg>BACKDOOR y3k 1.2 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ipwHTTP&quot;; nocase; http_header; content:&quot;devSoft&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*devSoft\x27s\s+ipwHTTP\s+Component/smiH&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7118</id>
        <msg>BACKDOOR y3k 1.2 runtime detection - user-agent string detected</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET 5881 -&gt; $HOME_NET 5882</filter1>
        <filter2>flow:to_server; content:&quot;Y3K&quot;; depth:3; nocase; flowbits:set,Y3K_InitConnection_1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7119</id>
        <msg>BACKDOOR y3k 1.2 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 5882 -&gt; $EXTERNAL_NET 5881</filter1>
        <filter2>flow:to_client; flowbits:isset,Y3K_InitConnection_1; content:&quot;C&quot;; depth:1; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7120</id>
        <msg>BACKDOOR y3k 1.2 runtime detection - init connection 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET 5887 -&gt; $HOME_NET 5888</filter1>
        <filter2>flow:to_server; content:&quot;login&quot;; depth:5; nocase; flowbits:set,Y3K_InitConnection_2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7121</id>
        <msg>BACKDOOR y3k 1.2 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 5888 -&gt; $EXTERNAL_NET 5887</filter1>
        <filter2>flow:to_client; flowbits:isset,Y3K_InitConnection_2; content:&quot;{}&quot;; depth:2; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7122</id>
        <msg>BACKDOOR y3k 1.2 runtime detection - init connection 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=33151</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates/update.php&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.alfacleaner.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ealfacleaner\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7123</id>
        <msg>SPYWARE-PUT Other-Technologies alfacleaner runtime detection - update</msg>
        <url>www.spywareguide.com/product_show.php?id=2733</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.dhtml&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;sub=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.alfacleaner.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ealfacleaner\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7124</id>
        <msg>SPYWARE-PUT Other-Technologies alfacleaner runtime detection - buy</msg>
        <url>www.spywareguide.com/product_show.php?id=2733</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/progs_exe/&quot;; nocase; http_uri; content:&quot;.php&quot;; nocase; http_uri; content:&quot;adv=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;traffbest.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*traffbest\x2Ebiz/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7125</id>
        <msg>SPYWARE-PUT Hijacker traffbest biz runtime detection - adv</msg>
        <url>forums.maddoktor2.com/index.php?showtopic=3601</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;/devrandom/r.php&quot;; nocase; http_uri; content:&quot;Host|3A| jupitersatellites.biz&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7126</id>
        <msg>SPYWARE-PUT Hijacker trojan proxy atiup runtime detection - notification</msg>
        <url>vil.nai.com/vil/content/v_137129.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;t.php&quot;; nocase; http_uri; content:&quot;sc_project=&quot;; fast_pattern; nocase; http_uri; content:&quot;resolution=&quot;; nocase; http_uri; content:&quot;camefrom=&quot;; nocase; http_uri; content:&quot;camefrom=&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;java=&quot;; nocase; http_uri; content:&quot;security=&quot;; nocase; http_uri; content:&quot;sc_random=&quot;; nocase; http_uri; pcre:&quot;/u=[^\r\n]*www.wowokay.com/Ui&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7127</id>
        <msg>SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - tracking</msg>
        <url>www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mb/text_group.php&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;col=&quot;; nocase; http_uri; content:&quot;br=&quot;; nocase; http_uri; content:&quot;dk=&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.wowokay.com/wowokaybar.php&quot;; nocase; http_header; pcre:&quot;/^Referer\x3A[^\r\n]*www\x2Ewowokay\x2Ecom/wowokaybar\x2Ephp/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7128</id>
        <msg>SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - advertising 1</msg>
        <url>www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ea.exe&quot;; nocase; http_uri; content:&quot;sb&quot;; nocase; http_uri; content:&quot;joelesoftware&quot;; nocase; http_uri; content:&quot;01&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.wowokay.com/wowokaybar.php&quot;; nocase; http_header; pcre:&quot;/^Referer\x3A[^\r\n]*www\x2Ewowokay\x2Ecom/wowokaybar\x2Ephp/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7129</id>
        <msg>SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - advertising 2</msg>
        <url>www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?s=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.weepee.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Eweepee\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7130</id>
        <msg>SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - search assissant hijacking</msg>
        <url>www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;IEP&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;drsnsrch.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*IEP/smiH&quot;; pcre:&quot;/^Host\x3A[^\r\n]*drsnsrch\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7135</id>
        <msg>SPYWARE-PUT Hijacker dsrch runtime detection - config info retrieval</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&amp;threatid=41080</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/url.cgi&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;badurl.grandstreetinteractive.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*badurl\x2Egrandstreetinteractive\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7136</id>
        <msg>SPYWARE-PUT Hijacker dsrch runtime detection - search assistant redirect</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&amp;threatid=41080</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sidesearch/sidesearch.html&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;websearch.drsnsrch.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*websearch\x2Edrsnsrch\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7137</id>
        <msg>SPYWARE-PUT Hijacker dsrch runtime detection - side search redirect</msg>
        <url>www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&amp;threatid=41080</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xversion.php&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;mode=&quot;; nocase; http_uri; content:&quot;click=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;loomcompany.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*loomcompany\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7138</id>
        <msg>SPYWARE-PUT Other-Technologies clicktrojan runtime detection - version check</msg>
        <url>sunbeltblog.blogspot.com/2006/01/seen-in-wild-new-pay-per-click-fraud.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.searchadv.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Esearchadv\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7139</id>
        <msg>SPYWARE-PUT Other-Technologies clicktrojan runtime detection - fake search query</msg>
        <url>sunbeltblog.blogspot.com/2006/01/seen-in-wild-new-pay-per-click-fraud.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/rb/cout.cgi&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ppcdomain.co.uk&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*ppcdomain\x2Eco\x2Euk/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7140</id>
        <msg>SPYWARE-PUT Adware pay-per-click runtime detection - configuration</msg>
        <url>ppcdomain.co.uk</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/1.hta&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dimattic.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*dimattic\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7141</id>
        <msg>SPYWARE-PUT Adware pay-per-click runtime detection - update</msg>
        <url>ppcdomain.co.uk</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mbop/index.php3&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Microsoft&quot;; nocase; http_header; content:&quot;URL&quot;; nocase; http_header; content:&quot;Control&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.digink.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Microsoft\s+URL\s+Control\s+-/smiH&quot;; pcre:&quot;/^Host\x3A\s+www\x2Edigink\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7143</id>
        <msg>SPYWARE-PUT Adware digink.com runtime detection</msg>
        <url>www.techsupportforum.com/archive/index.php/t-46308.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_other/dll/blank8.pac&quot;; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;WinInet&quot;; nocase; http_header; content:&quot;Test&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*WinInet\s+Test/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7144</id>
        <msg>SPYWARE-PUT Hijacker cool search runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079768</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin5/repeaterm2.fcgi&quot;; fast_pattern; nocase; http_uri; content:&quot;n=&quot;; nocase; http_uri; content:&quot;lastid=&quot;; nocase; http_uri; content:&quot;r=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;adfsgecoiwnf&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*adfsgecoiwnf/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7145</id>
        <msg>SPYWARE-PUT Other-Technologies spam maxy runtime detection</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_136735.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;Days&quot;; nocase; content:&quot;Hours&quot;; distance:0; nocase; content:&quot;Minutes&quot;; distance:0; nocase; content:&quot;Seconds&quot;; distance:0; nocase; pcre:&quot;/^0[^\r\n]*Days[^\r\n]*Hours[^\r\n]*Minutes[^\r\n]*Seconds\-[^\r\n]*\|\d+\-[^\r\n]*\-\|/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7146</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - sin notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/whitepages/page_me/1,,,00.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri; content:&quot;from=&quot;; nocase; http_uri; content:&quot;fromemail=&quot;; nocase; http_uri; content:&quot;body=&quot;; nocase; http_uri; pcre:&quot;/body\=\x7BIP\x3A[^\x7B\r\n]*\x7D\x7BOS\x3A[^\x7B\r\n]*\x7D\x7BSysuptime\x3A[^\x7B\r\n]*\x7D\x7BTrojan\x3A[^\x7B\r\n]*\x7D\x7BPort\x3A[^\x7B\r\n]*\x7D\x7BPassword\x3A[^\x7B\r\n]*\x7D\x7BUser\x3A/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7147</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 6667</filter1>
        <filter2>flow:to_server,established; content:&quot;{IP}&quot;; nocase; content:&quot;{OS}&quot;; distance:0; nocase; content:&quot;{Uptime}&quot;; distance:0; nocase; content:&quot;{Trojan}&quot;; distance:0; nocase; content:&quot;{PSW}&quot;; distance:0; nocase; content:&quot;{Port}&quot;; distance:0; nocase; content:&quot;{User}&quot;; nocase; pcre:&quot;/\x7BIP\x7D[^\x7D\r\n]*\x7BOS\x7D[^\x7D\r\n]*\x7BUptime\x7D[^\x7D\r\n]*\x7BTrojan\x7D[^\x7D\r\n]*\x7BPSW\x7D[^\x7D\r\n]*\x7BPort\x7D[^\x7D\r\n]*\x7BUser\x7D/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7150</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - irc notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 135</filter1>
        <filter2>flow:to_server; content:&quot;NUCLEAR-NOTIFY&quot;; nocase; content:&quot;IP|3A|&quot;; distance:0; nocase; content:&quot;OS|3A|&quot;; distance:0; nocase; content:&quot;Sysuptime|3A|&quot;; distance:0; nocase; content:&quot;Trojan|3A|&quot;; distance:0; nocase; content:&quot;Port|3A|&quot;; distance:0; nocase; content:&quot;Password|3A|&quot;; distance:0; nocase; content:&quot;User|3A|&quot;; distance:0; nocase; pcre:&quot;/IP\x3A\s+[^\r\n]*\x0d\x0aOS\x3A\s+[^\r\n]*\x0d\x0aSysuptime\x3A\s+[^\r\n]*\x0d\x0aTrojan\x3A\s+[^\r\n]*\x0d\x0aPort\x3A\s+[^\r\n]*\x0d\x0aPassword\x3A\s+[^\r\n]*\x0d\x0aUser\x3A\s+/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7151</id>
        <msg>SPYWARE-PUT Hacker-Tool sars notifier runtime detection - net send notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078294</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download/CnsMinM.ini&quot;; fast_pattern; nocase; http_uri; content:&quot;t=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7152</id>
        <msg>SPYWARE-PUT Hijacker cnsmin 3721 runtime detection - installation</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072511</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cns.dll&quot;; nocase; http_uri; content:&quot;coagent=&quot;; nocase; http_uri; content:&quot;3721cnsmin&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7153</id>
        <msg>SPYWARE-PUT Hijacker cnsmin 3721 runtime detection - hijacking</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072511</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Active&quot;; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; content:&quot;Home&quot;; distance:0; nocase; content:&quot;Report&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7154</id>
        <msg>SPYWARE-PUT Keylogger active keylogger home runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=1720</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sresult.aspx&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.emp3finder.com&quot;; nocase; http_header; content:&quot;txtSearch=&quot;; nocase; content:&quot;mp3s=&quot;; nocase; pcre:&quot;/^Host\x3A\s+www\x2Eemp3finder\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7155</id>
        <msg>SPYWARE-PUT Trickler jubster runtime detection</msg>
        <url>freeware4pc.com/multimedia/jubster.shtml</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;_ANSMTP_&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;LOG&quot;; distance:0; nocase; content:&quot;FILE&quot;; distance:0; nocase; content:&quot;Current&quot;; distance:0; nocase; content:&quot;User|3A|&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*_\d+_ANSMTP_\d+_.*Subject\x3A[^\r\n]*LOG\s+FILE\s+Current\s+User\x3A/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7156</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - email delivery</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10050</filter1>
        <filter2>flow:to_server,established; content:&quot;/CLUserName|18|Password|16|&quot;; depth:21; nocase; flowbits:set,winspy_conn_client-to-server; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7157</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - remote conn client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 10050 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,winspy_conn_client-to-server; content:&quot;/CK|16|&quot;; depth:4; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7158</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - remote conn server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10050</filter1>
        <filter2>flow:to_server,established; content:&quot;/CU&quot;; nocase; content:&quot;True&quot;; distance:0; nocase; pcre:&quot;/\x2FCU[^\r\n]*\x18\d+\x18True\x18\x16/smi&quot;; flowbits:set,winspy_upload_client-to-server; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7159</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - upload file client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 10050 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,winspy_upload_client-to-server; content:&quot;/CK|16|&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7160</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - upload file server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10050</filter1>
        <filter2>flow:to_server,established; content:&quot;/CD&quot;; fast_pattern:only; pcre:&quot;/\x2FCD[^\r\n]*\x18\x16/smi&quot;; flowbits:set,winspy_download_client-to-server; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7161</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - download file client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 10050 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,winspy_download_client-to-server; content:&quot;/CU&quot;; fast_pattern:only; pcre:&quot;/\x2FCU[^\r\n]*\x18\d+\x18\x16/smi&quot;; flowbits:unset,winspy_download_client-to-server; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7162</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - download file server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10050</filter1>
        <filter2>flow:to_server,established; content:&quot;/RF&quot;; fast_pattern:only; pcre:&quot;/\x2FRF[^\r\n]*\x16/smi&quot;; flowbits:set,winspy_execute_client-to-server; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7163</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - execute file client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 10050 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,winspy_execute_client-to-server; content:&quot;/RF|16|&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7164</id>
        <msg>SPYWARE-PUT Keylogger win-spy runtime detection - execute file server-to-client</msg>
        <url>www.spywareguide.com/product_show.php?id=715</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 868</filter1>
        <filter2>flow:to_server,established; content:&quot;Send me the logs, please&quot;; flowbits:set,ABSystemSpy_LogRetrieve; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7175</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - log retrieve</msg>
        <url>www.spywareguide.com/product_show.php?id=591</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 868 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,ABSystemSpy_LogRetrieve; content:&quot;FILEINFO|7C|&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7176</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - log retrieve</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076050</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;&lt;logs@dummyserver.com&gt;&quot;; distance:0; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Logs&quot;; distance:0; nocase; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Built-in Mail&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7177</id>
        <msg>SPYWARE-PUT Keylogger ab system spy runtime detection - info send through email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076050</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|FE FE FE FE|90|00 00|&quot;; depth:8; content:&quot;Private&quot;; distance:0; nocase; content:&quot;Server,&quot;; distance:0; nocase; content:&quot;Login&quot;; distance:0; nocase; content:&quot;Required&quot;; distance:0; nocase; flowbits:set,DesktopDetective_InitConnection1; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7178</id>
        <msg>SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,DesktopDetective_InitConnection1; content:&quot;|FE FE FE FE 00 00 00 00|&quot;; depth:8; content:&quot;DDController&quot;; distance:0; nocase; flowbits:set,DesktopDetective_InitConnection2; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7179</id>
        <msg>SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,DesktopDetective_InitConnection2; content:&quot;|FE FE FE FE|90|00 00|&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7180</id>
        <msg>SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060318</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Barok.... PSWRD Sender Trojan&quot;; distance:0; nocase; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Barok... email PSWRD sender--- by|3A| spyder&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7183</id>
        <msg>SPYWARE-PUT Snoopware barok runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075534</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;filename=&quot;; nocase; content:&quot;zip&quot;; distance:0; nocase; pcre:&quot;/filename\x3D\x22[^\r\n]*?\x2D\d+\x5F\d+\x5F\d+\x2D\d+\x5F\d+\x5F\d+\s+[AP]M\x2Ezip/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7186</id>
        <msg>SPYWARE-PUT Keylogger kgb Keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096494</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;SAH Agent&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\s*\x3A[^\r\n]*SAH Agent/miH&quot;; metadata:policy security-ips drop, service http; classtype:successful-recon-limited;</filter2>
        <id>7187</id>
        <msg>SPYWARE-PUT Trackware shopathome user-agent detected</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/frameset.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;MID=&quot;; nocase; http_uri; content:&quot;ruleID=&quot;; nocase; http_uri; content:&quot;popupID=&quot;; nocase; http_uri; content:&quot;doPopup=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;requested=&quot;; nocase; http_uri; content:&quot;CustomerID=&quot;; nocase; http_uri; content:&quot;owner=&quot;; nocase; http_uri; content:&quot;refer=&quot;; nocase; http_uri; content:&quot;LastPrefs=&quot;; http_uri; content:&quot;GUID=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7188</id>
        <msg>SPYWARE-PUT Hijacker shop at home select - merchant redirect in progress</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setcookie.asp?&quot;; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;discounts.shopathome.com/frameset.asp?&quot;; nocase; http_header; pcre:&quot;/^Referer\x3A[^\r\n]*http\x3A\x2F\x2Fdiscounts\x2Eshopathome\x2Ecom\x2Fframeset\x2Easp\?/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7189</id>
        <msg>SPYWARE-PUT Trackware shopathome runtime detection - setcookie request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?hostfile=&quot;; depth:20; nocase; http_uri; content:&quot;client=TFLS&quot;; fast_pattern; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;get=&quot;; nocase; http_uri;  metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>7190</id>
        <msg>SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - host retrieval</msg>
        <url>www.softpicks.net/software/TrustyFiles-Personal-File-Sharing-13308.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;/.&quot;; nocase; http_uri; content:&quot;urlfile=&quot;; nocase; http_uri; content:&quot;client=TFLS&quot;; fast_pattern; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;get=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7191</id>
        <msg>SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - url retrieval</msg>
        <url>www.softpicks.net/software/TrustyFiles-Personal-File-Sharing-13308.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;/rd/feed/XMLFeed.jsp&quot;; fast_pattern; nocase; http_uri; content:&quot;trackID=&quot;; nocase; http_uri; content:&quot;pID=&quot;; nocase; http_uri; content:&quot;cat=&quot;; nocase; http_uri; content:&quot;nl=&quot;; nocase; http_uri; content:&quot;page=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;excID=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7192</id>
        <msg>SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - sponsor selection</msg>
        <url>www.softpicks.net/software/TrustyFiles-Personal-File-Sharing-13308.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;/index-tfc.php&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;trustyfiles&quot;; nocase; http_header; content:&quot;com&quot;; nocase; http_header; pcre:&quot;/^Host|3A|[^\r\n]*trustyfiles\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7193</id>
        <msg>SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - startup access</msg>
        <url>www.softpicks.net/software/TrustyFiles-Personal-File-Sharing-13308.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cs/cs.aspx?&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;cs.shopperreports.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*cs\x2Eshopperreports\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7194</id>
        <msg>SPYWARE-PUT Hijacker shopprreports runtime detection - services requests</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_133312.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;shprrprt-cs-&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*shprrprt-cs-\d+\x2E\d+\x2E\d+/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7195</id>
        <msg>SPYWARE-PUT Hijacker shopprreports runtime detection - track/upgrade/report activities</msg>
        <url>vil.mcafeesecurity.com/vil/content/v_133312.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10607</filter1>
        <filter2>flow:to_server,established; content:&quot;Hello&quot;; depth:5; flowbits:set,coma.1; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7506</id>
        <msg>SPYWARE-PUT Hacker-Tool coma runtime detection - init connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 10607 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,coma.1; content:&quot;COMA Server Version&quot;; depth:19; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7507</id>
        <msg>SPYWARE-PUT Hacker-Tool coma runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090795</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 10607</filter1>
        <filter2>flow:to_server,established; content:&quot;Ping&quot;; depth:4; flowbits:set,coma.2; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7508</id>
        <msg>SPYWARE-PUT Hacker-Tool coma runtime detection - ping - flowbit set</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 10607 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,coma.2; content:&quot;Pong&quot;; depth:4; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7509</id>
        <msg>SPYWARE-PUT Hacker-Tool coma runtime detection - ping</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090795</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ver/ver.php&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;app=&quot;; nocase; http_uri; content:&quot;install_date=&quot;; nocase; http_uri; content:&quot;reg=&quot;; nocase; http_uri; content:&quot;sys=&quot;; nocase; http_uri; content:&quot;sver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;home.edonkey.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*home\x2Eedonkey\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7510</id>
        <msg>SPYWARE-PUT Trickler edonkey2000 runtime detection - version verification</msg>
        <url>www.fbmsoftware.com/spyware-net/Process/edonkey2000_exe/705/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/adscript4.php&quot;; fast_pattern; nocase; http_uri; content:&quot;country=&quot;; nocase; http_uri; content:&quot;dummy=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;sda.edonkey.com&quot;; nocase; http_header; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;ed2k&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*sda\x2Eedonkey\x2Ecom.*User-Agent\x3A[^\r\n]*ed2k/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7511</id>
        <msg>SPYWARE-PUT Trickler edonkey2000 runtime detection - get ads page</msg>
        <url>www.fbmsoftware.com/spyware-net/Process/edonkey2000_exe/705/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;N|3A|UC|3A|&quot;; fast_pattern:only; pcre:&quot;/^N\x3aUC\x3a\d+\x2c\d+\x2e\d+\x2e\d+\x2e\d+\x2c/smi&quot;; flowbits:set,WatchDog_Init_Connection; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7512</id>
        <msg>SPYWARE-PUT Keylogger watchdog runtime detection - init connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098060</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,WatchDog_Init_Connection; content:&quot;I|3A|NAME|3A|&quot;; fast_pattern:only; pcre:&quot;/^I\x3aNAME\x3a/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7513</id>
        <msg>SPYWARE-PUT Keylogger watchdog runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098060</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;S|3A|Users&quot;; fast_pattern:only; pcre:&quot;/^S\x3aUsers\x5c\d+\x2cSTATSTimeTotal/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7514</id>
        <msg>SPYWARE-PUT Keylogger watchdog runtime detection - send out info to server periodically</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098060</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Server|3A|&quot;; nocase; http_header; content:&quot;WatchDog&quot;; nocase; http_header; content:&quot;Server&quot;; nocase; http_header; pcre:&quot;/Server\x3a[^\r\n]*WatchDog[^\r\n]*Server/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7515</id>
        <msg>SPYWARE-PUT Keylogger watchdog runtime detection - remote monitoring</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098060</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;tool.world2.cn&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Toolbar.*Host\x3A[^\r\n]*tool\x2Eworld2\x2Ecn/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7516</id>
        <msg>SPYWARE-PUT Trickler hmtoolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096408</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ta/NEWS/&quot;; nocase; http_uri; content:&quot;/rss&quot;; nocase; http_uri; pcre:&quot;/\x2Fta\x2FNEWS\x2F[^\r\n]*\x2Frss/Ui&quot;; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;AsyncHTTP&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*AsyncHTTP/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7518</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - get up-to-date news info</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/track?&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;earthlink&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7519</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - track activity</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sw/ietb/3/0/rd103.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;d=error_earthlink&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7520</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - ie autosearch hijack</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sw/toolbar/4/2/rd601.html?&quot;; nocase; http_uri; content:&quot;area=earthlink-ws-altsearchbox&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7521</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - search toolbar request 1</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search?&quot;; nocase; http_uri; content:&quot;area=earthlink-ws-altsearchbox&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7522</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - search toolbar request 2</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/article/&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;enews.earthlink.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*enews\x2Eearthlink\x2Enet/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7523</id>
        <msg>SPYWARE-PUT Trackware earthlink toolbar runtime detection - click news button links</msg>
        <url>castlecops.com/startuplist-1068.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchapp/barad.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;searchkey=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;toolbar.hotblox.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*toolbar\x2Ehotblox\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7525</id>
        <msg>SPYWARE-PUT Trackware hotblox toolbar runtime detection - barad.asp request</msg>
        <url>sparkles.nu/spy/proceed-34.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/t.php?&quot;; nocase; http_uri; content:&quot;sc_project=&quot;; nocase; http_uri; content:&quot;resolution=&quot;; nocase; http_uri; content:&quot;camefrom=&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;toolbar.hotblox.com/searchapp/barad.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;t=barad&quot;; nocase; http_uri; content:&quot;java=&quot;; nocase; http_uri; content:&quot;security=&quot;; nocase; http_uri; content:&quot;sc_random=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7526</id>
        <msg>SPYWARE-PUT Trackware hotblox toolbar runtime detection - stat counter</msg>
        <url>sparkles.nu/spy/proceed-34.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/custom?&quot;; nocase; http_uri; content:&quot;sourceid=toolbar.hotblox.com&quot;; fast_pattern; nocase; http_uri; content:&quot;client=&quot;; nocase; http_uri; content:&quot;forid=&quot;; nocase; http_uri; content:&quot;ie=&quot;; nocase; http_uri; content:&quot;cof=&quot;; nocase; http_uri; content:&quot;hl=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7527</id>
        <msg>SPYWARE-PUT Trackware hotblox toolbar runtime detection - toolbar find function</msg>
        <url>sparkles.nu/spy/proceed-34.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dns/?url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;toolbar.hotblox.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*toolbar\x2Ehotblox\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7528</id>
        <msg>SPYWARE-PUT Trackware hotblox toolbar runtime detection - ie autosearch hijack</msg>
        <url>sparkles.nu/spy/proceed-34.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;from=HL-Jacker&quot;; nocase; http_uri; content:&quot;body=key&quot;; nocase; http_uri; content:&quot;fromemail=Jacked&quot;; fast_pattern; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7529</id>
        <msg>SPYWARE-PUT Snoopware halflife jacker runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077199</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gs_trickler&quot;; fast_pattern; nocase; http_uri; content:&quot;TRICKLER&quot;; nocase; pcre:&quot;/^TRICKLER\d+=[^\r\n]*MediaSeek*/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7530</id>
        <msg>SPYWARE-PUT Trickler mediaseek.pl client runtime detection - trickler</msg>
        <url>www.remove-spyware-now.net/MediaSeek-pl-Client.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; depth:3; nocase; content:&quot;/K?&quot;; distance:0; nocase; pcre:&quot;/^GET\s+\x2FK\x3F[^\r\n]*\x7C*\x7C*\x7C*\s+HTTP*/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7531</id>
        <msg>SPYWARE-PUT Trickler mediaseek.pl client runtime detection - login</msg>
        <url>www.remove-spyware-now.net/MediaSeek-pl-Client.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Microsoft&quot;; nocase; http_header; content:&quot;URL&quot;; nocase; http_header; content:&quot;Control&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.piolet.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Microsoft\s+URL\s+Control/smiH&quot;; pcre:&quot;/^Host\x3A[^\r\n]*www.piolet.com/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7532</id>
        <msg>SPYWARE-PUT Adware piolet runtime detection - user-agent</msg>
        <url>taxster.fateback.com/piolet.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ads/468x60&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.piolet.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www.piolet.com/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7533</id>
        <msg>SPYWARE-PUT Adware piolet runtime detection - ads request</msg>
        <url>taxster.fateback.com/piolet.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ie/?&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;addr=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| IEXPLORE.EXE&quot;; fast_pattern; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7534</id>
        <msg>SPYWARE-PUT Hijacker clearsearch variant runtime detection - ie hijacking</msg>
        <url>www.doxdesk.com/parasite/ClearSearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fast-cgi/bsc?&quot;; nocase; http_uri; content:&quot;mandant=clear&quot;; nocase; http_uri; content:&quot;synd=clear&quot;; nocase; http_uri; content:&quot;device=&quot;; nocase; http_uri; content:&quot;portalLanguage=&quot;; fast_pattern; nocase; http_uri; content:&quot;userLanguage=&quot;; nocase; http_uri; content:&quot;context=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7535</id>
        <msg>SPYWARE-PUT Hijacker clearsearch variant runtime detection - pass information</msg>
        <url>www.doxdesk.com/parasite/ClearSearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/popup/popup.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;cat=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;sc=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;clearsearch.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*clearsearch\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7536</id>
        <msg>SPYWARE-PUT Hijacker clearsearch variant runtime detection - popup</msg>
        <url>www.doxdesk.com/parasite/ClearSearch.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Arrow Search&quot;; fast_pattern; nocase; http_header;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7537</id>
        <msg>SPYWARE-PUT Trackware arrow search runtime detection</msg>
        <url>www.rt-software.co.uk/arrow_search/index.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Eye&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;Pro&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*Eye\s+Spy\s+Pro/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7539</id>
        <msg>SPYWARE-PUT Keylogger eye spy pro 1.0 runtime detection</msg>
        <url>www.softslist.com/download-9-50-20783.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;|22|StarLogger|22|&quot;; distance:0; nocase; content:&quot;Subject|3A| StarLogger information&quot;; distance:0; nocase; content:&quot;Please find attached the StarLogger log file named&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7541</id>
        <msg>SPYWARE-PUT Keylogger starlogger runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=922</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;OVN|01 00 01 00 1A 00 00 00|&quot;; depth:11; content:&quot;Mini&quot;; distance:0; content:&quot;Oblivion&quot;; distance:0; content:&quot;Ready&quot;; distance:0; pcre:&quot;/^OVN.*Mini\s+Oblivion.*Ready/&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7542</id>
        <msg>SPYWARE-PUT Hacker-Tool mini oblivion runtime detection - successful init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=26770</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/9894/search/search.html&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;pop.popuptoast.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*pop\x2Epopuptoast\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7543</id>
        <msg>SPYWARE-PUT Hijacker 2020search runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076971</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A| CSMTPConnection&quot;; depth:256; nocase; flowbits:set,PerfectKeylogger1; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7544</id>
        <msg>SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073333</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,PerfectKeylogger1; content:&quot;filename=|22|keystrokes.html|22|&quot;; depth:300; nocase; flowbits:set,PerfectKeylogger2; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7545</id>
        <msg>SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073333</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,PerfectKeylogger2; content:&quot;This is a Perfect Keylogger report&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7546</id>
        <msg>SPYWARE-PUT Keylogger PerfectKeylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073333</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 15164</filter1>
        <filter2>content:&quot;|00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:16;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7547</id>
        <msg>SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection - agent status monitoring</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=35592</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 15165</filter1>
        <filter2>content:&quot;|00 00 00 00 00 00 00 00|&quot;; depth:8;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7548</id>
        <msg>SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection - agent up notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=35592</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 15165</filter1>
        <filter2>content:&quot;|1D BA 0B FB|d|5C 86 E1 DA 83|BC|B6 04 E0|^|0A|@|C5 D4 00 00 00 00 00 00 00 00|&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7549</id>
        <msg>SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=35592</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;ADROAR&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*ADROAR/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7550</id>
        <msg>SPYWARE-PUT Adware adroar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077256</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ClientID=&quot;; nocase; http_uri; content:&quot;ServerTableID=&quot;; fast_pattern; nocase; http_uri; content:&quot;ClientData=&quot;; nocase; http_uri; content:&quot;AuxData=&quot;; nocase; http_uri; content:&quot;ReleaseID=&quot;; nocase; http_uri; content:&quot;ClientStats=&quot;; nocase; http_uri; content:&quot;StoreID=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;HXLogOnly&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]+HXLogOnly/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7553</id>
        <msg>SPYWARE-PUT Adware hxdl runtime detection - hxlogonly user-agent</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;HXDownload&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]+HXDownload/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7554</id>
        <msg>SPYWARE-PUT Adware hxdl runtime detection - hxdownload user-agent</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search_results.php&quot;; fast_pattern; nocase; http_uri; content:&quot;account_id=&quot;; nocase; http_uri; content:&quot;search_string=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.blazefind.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]+www\x2Eblazefind\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7556</id>
        <msg>SPYWARE-PUT Hijacker blazefind runtime detection - search bar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079063</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cs/pop4/&quot;; fast_pattern; nocase; http_uri; content:&quot;.html&quot;; nocase; http_uri; pcre:&quot;/\x2Fcs\x2Fpop4\x2F((frame_ver2)|(UI2))\x2Ehtml/Ui&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7557</id>
        <msg>SPYWARE-PUT Trackware purityscan runtime detection - start up</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/install/notify.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;module=&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;b=&quot;; nocase; http_uri; content:&quot;result=&quot;; nocase; http_uri; content:&quot;message=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7558</id>
        <msg>SPYWARE-PUT Trackware purityscan runtime detection - installation notify</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/count.cgi?clickspring&quot;; nocase; http_uri; content:&quot;www.clickspring.net/cs/pop4/frame_ver2.html&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7559</id>
        <msg>SPYWARE-PUT Trackware purityscan runtime detection - track user activity and status</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/query.php&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; content:&quot;b=&quot;; distance:0; nocase; content:&quot;vt=&quot;; distance:0; nocase; content:&quot;c=&quot;; distance:0; nocase; content:&quot;os=&quot;; distance:0; nocase; content:&quot;lang=&quot;; distance:0; nocase; content:&quot;pl=&quot;; distance:0; nocase; content:&quot;z=&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7560</id>
        <msg>SPYWARE-PUT Trackware purityscan runtime detection - self update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ps/ps_uninstaller.exe&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.purityscan.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Epurityscan\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7561</id>
        <msg>SPYWARE-PUT Trackware purityscan runtime detection - opt out of interstitial advertising</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rotation/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;downloads.morpheus.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*downloads\x2Emorpheus\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7562</id>
        <msg>SPYWARE-PUT Adware morpheus runtime detection - ad 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=54367</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;downloads.morpheus.com/rotation/&quot;; nocase; http_header; pcre:&quot;/^Referer\x3A[^\r\n]*downloads\x2Emorpheus\x2Ecom\x2Frotation/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7563</id>
        <msg>SPYWARE-PUT Adware morpheus runtime detection - ad 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=54367</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ieb/res/topres.xsl&quot;; fast_pattern; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7564</id>
        <msg>SPYWARE-PUT Hijacker startnow runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083036</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchbar/engine.php&quot;; fast_pattern; nocase; http_uri; content:&quot;cver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.searchexpert.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Esearchexpert\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7565</id>
        <msg>SPYWARE-PUT Hijacker adshooter.searchforit runtime detection - search engine</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079051</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/redirector.html&quot;; fast_pattern; nocase; http_uri; content:&quot;image_id=&quot;; nocase; http_uri; content:&quot;advertiser_id=&quot;; nocase; http_uri; content:&quot;keyword_id=&quot;; nocase; http_uri; content:&quot;bid=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7566</id>
        <msg>SPYWARE-PUT Hijacker adshooter.searchforit runtime detection - redirector</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079051</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; depth:4; nocase; content:&quot;X-AT|3A|&quot;; nocase; http_header; content:&quot;X-CI|3A|&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;webhancer.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*webhancer\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7568</id>
        <msg>SPYWARE-PUT Trackware webhancer runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=43482</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/home/lordofsearch&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\x5Chome\/lordofsearch[^\r\n]*\x2Ehtml/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7569</id>
        <msg>SPYWARE-PUT Adware lordofsearch runtime detection</msg>
        <url>www.spywareguide.com/product_list_category.php?category_id=12</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pagead/ads?&quot;; nocase; http_uri; content:&quot;www.linkspider.co.uk/cgi-bin/cgsearch/cgsearch.cgi&quot;; fast_pattern; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7570</id>
        <msg>SPYWARE-PUT Hijacker linkspider search bar runtime detection - ads</msg>
        <url>linkspider.co.uk</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/cgsearch/cgsearch.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;vid=&quot;; nocase; http_uri; content:&quot;category=&quot;; nocase; http_uri; content:&quot;lout=&quot;; nocase; http_uri; content:&quot;sel=&quot;; nocase; http_uri; content:&quot;refer=&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;match=&quot;; nocase; http_uri; content:&quot;where=&quot;; nocase; http_uri; content:&quot;sd=&quot;; nocase; http_uri; content:&quot;pp=&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7571</id>
        <msg>SPYWARE-PUT Hijacker linkspider search bar runtime detection - toolbar search</msg>
        <url>linkspider.co.uk</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data/startup.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;DigExt&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*DigExt/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7572</id>
        <msg>SPYWARE-PUT Trickler album galaxy runtime detection - startup data</msg>
        <url>codegravity.com/index.php/spyware</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/P2P/gnutella/cache/gerry.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;urlfile=&quot;; nocase; http_uri; content:&quot;client=GALA&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;get=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7573</id>
        <msg>SPYWARE-PUT Trickler album galaxy runtime detection - p2p gnutella</msg>
        <url>codegravity.com/index.php/spyware</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;HELO&quot;; nocase; content:&quot;ProAgent&quot;; distance:0; nocase; pcre:&quot;/^HELO\s+ProAgent/smi&quot;; content:&quot;From|3A|&quot;; nocase; content:&quot;ProAgent&quot;; distance:0; nocase; pcre:&quot;/^From\x3A\s+\x22ProAgent\s+v\d+\x2E\d+\x22/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7574</id>
        <msg>SPYWARE-PUT Keylogger proagent 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076925</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dp/weather?x=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;as.starware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*as\x2Estarware\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7575</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - weather request</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dp/search?x=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;as.starware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*as\x2Estarware\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7576</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - hijack ie browser</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/sr/?&quot;; nocase; http_uri; content:&quot;xargs=&quot;; nocase; http_uri; content:&quot;yargs=&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;as.starware.com/dp/search?x=&quot;; nocase; http_header; pcre:&quot;/^Referer\x3A[^\r\n]*as\x2Estarware\x2Ecom\x2Fdp\x2Fsearch\?x=/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7577</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - collect information</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dp/reference?x=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;as.starware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*as\x2Estarware\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7578</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - reference</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pl/shared/smileys/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;files-pl.starware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*files-pl\x2Estarware\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7579</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - smileys</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dp/simpleupdate?x=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;as.starware.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*as\x2Estarware\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7580</id>
        <msg>SPYWARE-PUT Hijacker starware toolbar runtime detection - update</msg>
        <url>www.spywareguide.com/product_show.php?id=2009</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Pcast Live&quot;; fast_pattern; nocase; http_header;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7582</id>
        <msg>SPYWARE-PUT Trickler pcast runtime detection - update checking</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098354</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4563</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,Clandestine_CTS1; content:&quot;big&quot;; depth:3; nocase; flowbits:set,Clandestine_CTS1; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7583</id>
        <msg>SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set big</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4563</filter1>
        <filter2>flow:to_server,established; flowbits:isnotset,Clandestine_CTS1; content:&quot;open&quot;; depth:4; nocase; flowbits:set,Clandestine_CTS1; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7584</id>
        <msg>SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set open</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 4563 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Clandestine_CTS1; content:&quot;&gt;&gt;IMAGE|FF D8 FF E0 00 10|JFIF&quot;; flowbits:set,Clandestine_STC1; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7585</id>
        <msg>SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set image</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 4563 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Clandestine_STC1; content:&quot;&lt;&lt;DONE&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7586</id>
        <msg>SPYWARE-PUT Hacker-Tool clandestine runtime detection - image transferred</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=1295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;URLBlaze&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*URLBlaze/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7587</id>
        <msg>SPYWARE-PUT Trickler urlblaze runtime detection - software information request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073195</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/phppbc.php&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.urlblaze.net&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.peer2mail.com&quot;; nocase; http_header; pcre:&quot;/^Referer\x3a[^\r\n]*www\x2eurlblaze\x2enet.*Host\x3A[^\r\n]*www\x2Epeer2mail\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7588</id>
        <msg>SPYWARE-PUT Trickler urlblaze runtime detection - files search or download</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073195</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 6667</filter1>
        <filter2>flow:to_server,established; content:&quot;NICK&quot;; depth:4; nocase; content:&quot;6633&quot;; distance:0; nocase; pcre:&quot;/^NICK\s+\x5E\d+\x5E\d+\x5E\d+\x5E\d+\x5E6633/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7589</id>
        <msg>SPYWARE-PUT Trickler urlblaze runtime detection - irc notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073195</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/swbartb0110.cfg&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.searchwords.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A\s+www\x2Esearchwords\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7590</id>
        <msg>SPYWARE-PUT Hijacker swbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077852</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;Keylogger-Pro&quot;; distance:0; nocase; pcre:&quot;/^From\x3a[^\r\n]*Keylogger-Pro/smi&quot;; flowbits:set,KeyloggerPro_SMTP; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7591</id>
        <msg>SPYWARE-PUT Keylogger keylogger pro runtime detection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,KeyloggerPro_SMTP; content:&quot;Keylogger&quot;; nocase; content:&quot;Pro&quot;; distance:0; nocase; content:&quot;Activity&quot;; distance:0; nocase; content:&quot;Logs&quot;; distance:0; pcre:&quot;/^Keylogger\s+Pro\s+Activity\s+Logs/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7592</id>
        <msg>SPYWARE-PUT Keylogger keylogger pro runtime detection</msg>
        <url>www.spyany.com/keylogger.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/add.txt?&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;url=http&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;rank.toolbarbrowser.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*rank\x2Etoolbarbrowser\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7593</id>
        <msg>SPYWARE-PUT Trackware trellian toolbarbrowser runtime detection</msg>
        <url>www.toolbarbrowser.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/advertisement/advertisement.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;systemTray=&quot;; nocase; http_uri; content:&quot;joke_category=&quot;; nocase; http_uri; content:&quot;joke_id=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7594</id>
        <msg>SPYWARE-PUT Adware comedy planet runtime detection - ads</msg>
        <url>labs.paretologic.com/spyware.aspx?remove=Comedy-Planet</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php?document=&quot;; fast_pattern:only; content:&quot;form-data|3B|&quot;; nocase; content:&quot;name=&quot;; distance:0; nocase; content:&quot;user_name&quot;; distance:0; nocase; content:&quot;user_email&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7595</id>
        <msg>SPYWARE-PUT Adware comedy planet runtime detection - collect user information</msg>
        <url>labs.paretologic.com/spyware.aspx?remove=Comedy-Planet</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Hello.&quot;; nocase; content:&quot;This&quot;; distance:0; nocase; content:&quot;letter&quot;; distance:0; nocase; content:&quot;contains&quot;; distance:0; nocase; content:&quot;logfile&quot;; distance:0; nocase; content:&quot;from&quot;; distance:0; nocase; pcre:&quot;/Hello\x2E\s+This\s+letter\s+contains\s+logfile\s+from/smi&quot;; flowbits:set,LanternKeylogger; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7596</id>
        <msg>SPYWARE-PUT Keylogger spy lantern keylogger runtime detection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083297</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,LanternKeylogger; content:&quot;filename=&quot;; nocase; content:&quot;.ltr&quot;; distance:0; nocase; pcre:&quot;/filename=\x22[^\r\n]*\x2Eltr\x22/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7597</id>
        <msg>SPYWARE-PUT Keylogger spy lantern keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083297</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.2-seek.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2E2-seek\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7598</id>
        <msg>SPYWARE-PUT Snoopware 2-seek runtime detection - search in toolbar</msg>
        <url>www.2-seek.com/toolbar.php</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/go.php?&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.2-seek.com/search/&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.2-seek.com&quot;; nocase; http_header; pcre:&quot;/^Referer\x3a[^\r\n]*www\x2e2-seek\x2ecom\x2fsearch/smiH&quot;; pcre:&quot;/^Host\x3A[^\r\n]*www\x2E2-seek\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7599</id>
        <msg>SPYWARE-PUT Snoopware 2-seek runtime detection - user info collection</msg>
        <url>www.2-seek.com/toolbar.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;EFError&quot;; nocase; http_header; content:&quot;Internet&quot;; nocase; http_header; content:&quot;Connection&quot;; nocase; http_header; content:&quot;Test&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*EFError\s+Internet\s+Connection\s+Test/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7600</id>
        <msg>SPYWARE-PUT Hijacker adtraffic runtime detection - notfound website search hijack and redirection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094115</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 7001</filter1>
        <filter2>flow:to_server,established; content:&quot;login&quot;; depth:5; nocase; content:&quot;~EOL!&quot;; distance:0; nocase; pcre:&quot;/^login\s+[^\r\n]*\x2A[^\r\n]*~EOL!/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7601</id>
        <msg>SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to keyserver</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=45916</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7000</filter1>
        <filter2>flow:to_server,established; content:&quot;HBand&quot;; depth:6; nocase; content:&quot;~EOL!&quot;; distance:0; nocase; pcre:&quot;/^HBand\d+,\d+,\d+,\d+,\d+,\d+~EOL!/smi&quot;; flowbits:set,snoopware.big.brother.3.5.1.conn.cts; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7602</id>
        <msg>SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to receiver - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=45916</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 7000 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,snoopware.big.brother.3.5.1.conn.cts; content:&quot;HBand&quot;; depth:6; nocase; content:&quot;ZBM&quot;; distance:0; nocase; pcre:&quot;/^HBand,[^\r\n]*,[^\r\n]*,\d+,\d+\x2A\xD5ZBM/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7603</id>
        <msg>SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to receiver</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=45916</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;10040&quot;; depth:5; flowbits:set,katux20.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7604</id>
        <msg>BACKDOOR katux 2.0 runtime detection - screen capture - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,katux20.2; content:&quot;000Ecran captur|E9|, transfert lanc|E9|...&quot;; depth:36; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7605</id>
        <msg>BACKDOOR katux 2.0 runtime detection - screen capture</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077310</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;001&quot;; depth:3; flowbits:set,katux20.3; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7606</id>
        <msg>BACKDOOR katux 2.0 runtime detection - get system info - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,katux20.3; content:&quot;001&quot;; depth:3; content:&quot;Version serveur|3A| Katux 2&quot;; distance:0; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7607</id>
        <msg>BACKDOOR katux 2.0 runtime detection - get system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077310</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;07415&quot;; depth:5; flowbits:set,katux20.4; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7608</id>
        <msg>BACKDOOR katux 2.0 runtime detection - chat - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,katux20.4; content:&quot;000Chat ouvert...&quot;; depth:17; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7609</id>
        <msg>BACKDOOR katux 2.0 runtime detection - chat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077310</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7424</filter1>
        <filter2>flow:to_server,established; content:&quot;|0C 00 18 00 01 02 03 04 05 06 07 08 01 02 03 04 05 06 07 08 01 02 03 04 05 06 07 08|&quot;; depth:28; flowbits:set,remote.control.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7620</id>
        <msg>BACKDOOR remote control 1.7 runtime detection - connection request flowbit 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7424 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,remote.control.1; content:&quot;|10 00|&quot;; depth:2; flowbits:set,remote.control.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7621</id>
        <msg>BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7424</filter1>
        <filter2>flow:to_server,established; flowbits:isset,remote.control.2; content:&quot;|1D 00 03 00|&quot;; depth:4; flowbits:set,remote.control.3; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7622</id>
        <msg>BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 3</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7424 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,remote.control.3; content:&quot;|03 00|&quot;; depth:2; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7623</id>
        <msg>BACKDOOR remote control 1.7 runtime detection - connection request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080063</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7425 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|19 00 C8 00 01 00|&quot;; depth:6;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7624</id>
        <msg>BACKDOOR remote control 1.7 runtime detection - data communication</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080063</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;*SPORT*&quot;; depth:7; flowbits:set,skyrat.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7625</id>
        <msg>BACKDOOR skyrat show runtime detection - initial connection - flowbit 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,skyrat.1; content:&quot;*PORT1*&quot;; depth:7; pcre:&quot;/^\x2APORT1\x2A\d+/&quot;; flowbits:set,skyrat.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7626</id>
        <msg>BACKDOOR skyrat show runtime detection - initial connection - flowbit 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,skyrat.2; content:&quot;*PORT2*&quot;; depth:7; pcre:&quot;/^\x2APORT2\x2A\d+/&quot;; flowbits:set,skyrat.3; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7627</id>
        <msg>BACKDOOR skyrat show runtime detection - initial connection - flowbit 3</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,skyrat.3; content:&quot;*PORT3*&quot;; depth:7; pcre:&quot;/^\x2APORT3\x2A\d+/&quot;; flowbits:set,skyrat.4; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7628</id>
        <msg>BACKDOOR skyrat show runtime detection - initial connection - flowbit 4</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,skyrat.4; content:&quot;*portok*&quot;; depth:8; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7629</id>
        <msg>BACKDOOR skyrat show runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453081105</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;100|8D|&quot;; depth:4; content:&quot;|8D|3.1|8D|1|8F|&quot;; distance:0; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7630</id>
        <msg>BACKDOOR helios 3.1 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074473</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;007r&quot;; depth:4; flowbits:set,hornet.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7631</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - fetch system info - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,hornet.2; content:&quot;007Server&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7632</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - fetch system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;006cb&quot;; depth:5; flowbits:set,hornet.3; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7633</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - irc connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,hornet.3; content:&quot;006cb&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7634</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - irc connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;008g&quot;; depth:4; flowbits:set,hornet.4; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7635</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - fetch process list - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,hornet.4; content:&quot;008&quot;; depth:3; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7636</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - fetch processes list</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/WWPMsg.dll&quot;; nocase; http_uri; content:&quot;from=Hornet+Server&quot;; nocase; content:&quot;fromemail=Hornet&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7637</id>
        <msg>BACKDOOR hornet 1.0 runtime detection - icq notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073228</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;xV4|12 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:24; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7638</id>
        <msg>BACKDOOR ncph runtime detection - initial connection</msg>
        <url>www.mmbest.com/Software/Catalog3/1477.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/air/notify/mail.php?&quot;; nocase; http_uri; content:&quot;controlport=&quot;; nocase; http_uri; content:&quot;webserverport=&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri; content:&quot;ip=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7640</id>
        <msg>BACKDOOR air runtime detection - webmail notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076794</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6116</filter1>
        <filter2>flow:to_server,established; pcre:&quot;/^\d+\x01/smi&quot;; flowbits:set,AM_Remote_Client; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7641</id>
        <msg>BACKDOOR am remote client runtime detection - client-to-server</msg>
        <url>www.megasecurity.org/trojans/a/amrc/Amrc1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6116 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AM_Remote_Client; pcre:&quot;/^\d+\x01/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7642</id>
        <msg>BACKDOOR am remote client runtime detection - server-to-client</msg>
        <url>www.megasecurity.org/trojans/a/amrc/Amrc1.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1981</filter1>
        <filter2>flow:to_server,established; content:&quot;L'esclave&quot;; nocase; pcre:&quot;/^\d+L\x27esclave\x09\d+\x09\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7644</id>
        <msg>BACKDOOR ullysse runtime detection - client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075739</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 666 -&gt; $HOME_NET 667</filter1>
        <filter2>flow:to_server,established; content:&quot;cmdping&quot;; depth:7; nocase; flowbits:set,snipernet; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7645</id>
        <msg>BACKDOOR snipernet 2.1 runtime detection - flowbit set</msg>
        <url>www.megasecurity.org/trojans/s/snipernet/Snipernet2.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 667 -&gt; $EXTERNAL_NET 666</filter1>
        <filter2>flow:from_server,established; flowbits:isset,snipernet; content:&quot;pingback&quot;; depth:8; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7646</id>
        <msg>BACKDOOR snipernet 2.1 runtime detection</msg>
        <url>www.megasecurity.org/trojans/s/snipernet/Snipernet2.1.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;|04 03 02 01|&quot;; depth:4; nocase; flowbits:set,MinicomLite; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7648</id>
        <msg>BACKDOOR minicom lite runtime detection - client-to-server</msg>
        <url>www.spywareguide.com/product_show.php?id=910</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;Pass-On&quot;; depth:7; nocase; flowbits:set,smalluploader_conn; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7650</id>
        <msg>BACKDOOR small uploader 1.01 runtime detection - initial connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7777 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;++Conectado a&quot;; depth:13; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7658</id>
        <msg>BACKDOOR jodeitor 1.1 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077303</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;pci&quot;; depth:3; content:&quot;|08 08 08 08 08 08 08 08|&quot;; distance:0; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7659</id>
        <msg>BACKDOOR lan filtrator 1.1 runtime detection - sin notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074827</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|B4 AF 29 AE|LANfiltrator|AE 28 AF|`&quot;; depth:20; flowbits:set,LanFiltrator_InitConnectionRequest; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7660</id>
        <msg>BACKDOOR lan filtrator 1.1 runtime detection - initial connection request - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,LanFiltrator_InitConnectionRequest; content:&quot;id_id&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7661</id>
        <msg>BACKDOOR lan filtrator 1.1 runtime detection - initial connection request</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074827</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1784</filter1>
        <filter2>flow:to_server,established; content:&quot;VER &quot;; depth:4; flowbits:set,Snid_X2_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7662</id>
        <msg>BACKDOOR snid x2 v1.2 runtime detection - initial connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1784 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Snid_X2_InitConnection; content:&quot;Snid X2 Server&quot;; depth:14; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7663</id>
        <msg>BACKDOOR snid x2 v1.2 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=5567</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2208</filter1>
        <filter2>flow:to_server,established; content:&quot;/&quot;; depth:1; content:&quot;R&quot;; depth:1; offset:2; nocase; pcre:&quot;/^\x2F[GL]R/smi&quot;; flowbits:set,ScreenControl_conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7664</id>
        <msg>BACKDOOR screen control 1.0 runtime detection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080930</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2208 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,ScreenControl_conn; content:&quot;/LO&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7665</id>
        <msg>BACKDOOR screen control 1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080930</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2208 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,ScreenControl_conn; content:&quot;/GR&quot;; nocase; pcre:&quot;/\x2FGR\d+\x3B\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7667</id>
        <msg>BACKDOOR screen control 1.0 runtime detection - capture on port 2208</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080930</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2213</filter1>
        <filter2>flow:to_server,established; content:&quot;a&quot;; flowbits:set,ScreenControl_capture2213; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7668</id>
        <msg>BACKDOOR screen control 1.0 runtime detection - capture on port 2213 - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080930</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2213 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,ScreenControl_capture2213; content:&quot;|00|2|00 00|x|9C ED|&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7669</id>
        <msg>BACKDOOR screen control 1.0 runtime detection - capture on port 2213</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080930</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 19850</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;password&gt;&quot;; depth:10; nocase; content:&quot;&lt;/password&gt;&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7670</id>
        <msg>BACKDOOR digital upload runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068131</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 19850 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;&lt;chat&gt;&quot;; nocase; content:&quot;&lt;/chat&gt;&quot;; nocase; pcre:&quot;/\x3Cchat\x3E[^\r\n]*\x3C\x2Fchat\x3E/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7671</id>
        <msg>BACKDOOR digital upload runtime detection - chat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068131</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 32222 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7672</id>
        <msg>BACKDOOR remoter runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=53155</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1001 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;CONN&quot;; depth:4; nocase; flowbits:set,RemoteHAVOC_conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7673</id>
        <msg>BACKDOOR remote havoc runtime detection - flowbit set 1</msg>
        <url>www.spywareguide.com/product_show.php?id=863</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1001</filter1>
        <filter2>flow:to_server,established; flowbits:isset,RemoteHAVOC_conn.1; content:&quot;REFR&quot;; depth:4; flowbits:set,RemoteHAVOC_conn.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7674</id>
        <msg>BACKDOOR remote havoc runtime detection - flowbit set 2</msg>
        <url>www.spywareguide.com/product_show.php?id=863</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1001 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,RemoteHAVOC_conn.2; content:&quot;LIST&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7675</id>
        <msg>BACKDOOR remote havoc runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=863</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|ENUMDRVS|7C|&quot;; depth:10; nocase; flowbits:set,CoolRemoteControl_conn; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7676</id>
        <msg>BACKDOOR cool remote control or crackdown runtime detection - initial connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CoolRemoteControl_conn; content:&quot;|7C|DRVS|7C|&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7677</id>
        <msg>BACKDOOR cool remote control or crackdown runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 11977</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|PUTFILE|7C|&quot;; nocase; flowbits:set,CoolRemoteControl_upload; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7678</id>
        <msg>BACKDOOR cool remote control 1.12 runtime detection - upload file - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 11977 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CoolRemoteControl_upload; content:&quot;|7C|COMPLETEPUTFILE|7C|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7679</id>
        <msg>BACKDOOR cool remote control 1.12 runtime detection - upload file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 11977</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|GETFILE|7C|&quot;; nocase; flowbits:set,CoolRemoteControl_Download.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7680</id>
        <msg>BACKDOOR cool remote control 1.12 runtime detection - download file - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 11977 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,CoolRemoteControl_Download.1; content:&quot;|7C|FILESIZE|7C|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7681</id>
        <msg>BACKDOOR cool remote control 1.12 runtime detection - download file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068314</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12345</filter1>
        <filter2>flow:to_server,established; content:&quot;TROJAN&quot;; depth:6; nocase; flowbits:set,acid_head_conn_step1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7682</id>
        <msg>BACKDOOR acid head 1.00 runtime detection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=71371</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 12345 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,acid_head_conn_step1; content:&quot;1.6&quot;; depth:3; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7683</id>
        <msg>BACKDOOR acid head 1.00 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=71371</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 567 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;hRat&quot;; depth:4; nocase; content:&quot;are&quot;; distance:0; nocase; content:&quot;ready&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;version&quot;; distance:0; nocase; pcre:&quot;/^hRat\s+are\s+ready\s+-\&gt;\s+Server\s+version/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7684</id>
        <msg>BACKDOOR hrat 1.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073815</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 5024</filter1>
        <filter2>flow:to_server,established; content:&quot;104&quot;; depth:3; flowbits:set,Illusion_Info; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7685</id>
        <msg>BACKDOOR illusion runtime detection - get remote info client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077268</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 5024 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Illusion_Info; content:&quot;023&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7686</id>
        <msg>BACKDOOR illusion runtime detection - get remote info server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077268</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 5024</filter1>
        <filter2>flow:to_server,established; content:&quot;[LOAD DRIVE DATA]&quot;; flowbits:set,Illusion_File; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7687</id>
        <msg>BACKDOOR illusion runtime detection - file browser client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077268</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 5024 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Illusion_File; content:&quot;[DRIVE&quot;; nocase; content:&quot;LIST]&quot;; nocase; pcre:&quot;/\x5BDRIVE\s+LIST\x5D/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7688</id>
        <msg>BACKDOOR illusion runtime detection - file browser server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077268</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;IDENTIFY&quot;; depth:8; pcre:&quot;/^IDENTIFY\s+\x23\s+\d+\x2E\d+\x2E\d+\x2E\d+\s+\x23\s+/&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7689</id>
        <msg>BACKDOOR evade runtime detection - initial connection</msg>
        <url>www.megasecurity.org/trojans/e/evade/Evade1.1b.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 9999</filter1>
        <filter2>flow:to_server,established; content:&quot;DRIVECHANGE +&quot;; flowbits:set,Evade_File_Manager1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7690</id>
        <msg>BACKDOOR evade runtime detection - file manager - flowbit set</msg>
        <url>www.megasecurity.org/trojans/e/evade/Evade1.1b.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 9999 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Evade_File_Manager1; content:&quot;FRESH +&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7691</id>
        <msg>BACKDOOR evade runtime detection - file manager</msg>
        <url>www.megasecurity.org/trojans/e/evade/Evade1.1b.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>flow:to_server,established; content:&quot;ip=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;id=Exception&quot;; nocase; http_uri; content:&quot;ver=Exception&quot;; nocase; http_uri; content:&quot;pass=&quot;; nocase; http_uri; content:&quot;os=&quot;; nocase; http_uri; content:&quot;conn=&quot;; nocase; http_uri; content:&quot;cpu=&quot;; nocase; http_uri; content:&quot;user=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7692</id>
        <msg>BACKDOOR exception 1.0 runtime detection - notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077099</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;spass|3A|&quot;; depth:6; nocase; flowbits:set,hanky_conn1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7695</id>
        <msg>BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077209</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,hanky_conn1; content:&quot;spas1|3A|&quot;; depth:6; nocase; flowbits:set,hanky_conn2; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7696</id>
        <msg>BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077209</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3100</filter1>
        <filter2>flow:to_server,established; content:&quot;APP&quot;; flowbits:set,BrAin_Wiper_LaunchApplication; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7698</id>
        <msg>BACKDOOR brain wiper runtime detection - launch application - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068367</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3100 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,BrAin_Wiper_LaunchApplication; content:&quot;Program Launched&quot;; depth:16; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7699</id>
        <msg>BACKDOOR brain wiper runtime detection - launch application</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068367</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3100</filter1>
        <filter2>flow:to_server,established; content:&quot;ChatCHA&quot;; depth:7; flowbits:set,BrAin_Wiper_Chat; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7700</id>
        <msg>BACKDOOR brain wiper runtime detection - chat - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068367</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 3100 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,BrAin_Wiper_Chat; content:&quot;Chat dialog opened&quot;; depth:18; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7701</id>
        <msg>BACKDOOR brain wiper runtime detection - chat</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068367</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1111</filter1>
        <filter2>flow:to_server,established; content:&quot;|A2 D0 D4 D6 DF C1 E1 D5 D6 DC BB DC CE D7|&quot;; depth:14; flowbits:set,Roach_RemoteControlActions; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7702</id>
        <msg>BACKDOOR roach 1.0 runtime detection - remote control actions - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1111 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Roach_RemoteControlActions; content:&quot;|A2 D0 D4 D6 DF C1 E1 D5 D6 DC BB DC CE D7|&quot;; depth:14; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7703</id>
        <msg>BACKDOOR roach 1.0 runtime detection - remote control actions</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075964</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/roach/mail.php&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;name=&quot;; nocase; http_uri; content:&quot;pw=&quot;; nocase; http_uri; content:&quot;lanby=&quot;; nocase; http_uri; content:&quot;to=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.kornputers.com&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7704</id>
        <msg>BACKDOOR roach 1.0 server installation notification - email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075964</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;Instant&quot;; nocase; content:&quot;Remote&quot;; distance:0; nocase; content:&quot;Control&quot;; distance:0; nocase; content:&quot;Service&quot;; distance:0; nocase; pcre:&quot;/Instant\s+Remote\s+Control\s+Service/smi&quot;; flowbits:set,Omniquad_IRC_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7705</id>
        <msg>BACKDOOR omniquad instant remote control runtime detection - initial connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 445 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Omniquad_IRC_InitConnection; content:&quot;|00 00 00|h|FF|SMB%|00 00 00|&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7706</id>
        <msg>BACKDOOR omniquad instant remote control runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080053</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;Welcome&quot;; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;the&quot;; distance:0; nocase; content:&quot;Omniquad&quot;; distance:0; nocase; content:&quot;File&quot;; distance:0; nocase; content:&quot;Transfer&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; pcre:&quot;/Welcome\s+to\s+the\s+Omniquad\s+File\s+Transfer\s+Server/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7707</id>
        <msg>BACKDOOR omniquad instant remote control runtime detection - file transfer setup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080053</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8811 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;connected&quot;; nocase; flowbits:set,Fear15_conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7708</id>
        <msg>BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8811</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Fear15_conn.1; content:&quot;listdrives&quot;; nocase; flowbits:set,Fear15_conn.2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7709</id>
        <msg>BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 8811 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Fear15_conn.2; content:&quot;Drive&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7710</id>
        <msg>BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077106</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 33229</filter1>
        <filter2>flow:to_server,established; content:&quot;[&quot;; depth:1; content:&quot;]&quot;; distance:0; pcre:&quot;/^\[[A-z]+\]/si&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7711</id>
        <msg>BACKDOOR amitis runtime command detection attacker to victim</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072405</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 33229 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;[&quot;; depth:1; content:&quot;]&quot;; distance:0; pcre:&quot;/^\[[A-z]+\]/si&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7712</id>
        <msg>BACKDOOR amitis runtime detection victim to attacker</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072405</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;Amitis&quot;; distance:0; content:&quot;1.3&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;information&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*Amitis\s+1\x2E3.*Subject\x3A[^\r\n]*Server\s+information/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7713</id>
        <msg>BACKDOOR amitis v1.3 runtime detection - email notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075097</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;passed&quot;; depth:6; nocase; flowbits:set,backdoor.NetDevil.conn.step1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7714</id>
        <msg>BACKDOOR netdevil runtime detection - flowbit set 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=27557</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,backdoor.NetDevil.conn.step1; content:&quot;version&quot;; depth:7; nocase; flowbits:set,backdoor.NetDevil.conn.step2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7715</id>
        <msg>BACKDOOR netdevil runtime detection - flowbit set 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=27557</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.NetDevil.conn.step2; content:&quot;ver&quot;; nocase; pcre:&quot;/^ver\d+\x2E\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7716</id>
        <msg>BACKDOOR netdevil runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=27557</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;The&quot;; depth:3; nocase; content:&quot;Snake&quot;; distance:0; nocase; content:&quot;Trojan&quot;; distance:0; nocase; pcre:&quot;/^The\s+Snake\s+Trojan/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7717</id>
        <msg>BACKDOOR snake trojan runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078423</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0|11 00 00|&quot;; depth:4; content:&quot;333333|13|@&quot;; offset:8; flowbits:set,DameWareMiniRemoteControl_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7718</id>
        <msg>BACKDOOR dameware mini remote control runtime detection - initial connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060041</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,DameWareMiniRemoteControl_InitConnection; content:&quot;0|11 00 00 00 00 00 00|333333|13|@|00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:30; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7719</id>
        <msg>BACKDOOR dameware mini remote control runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060041</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 5110 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Sifre_Korumasi&quot;; depth:14; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7721</id>
        <msg>BACKDOOR prorat 1.9 initial connection detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453082779</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;PORT=&quot;; depth:5; content:&quot;Victim=&quot;; distance:0; pcre:&quot;/^PORT\x3D\d+\x2AVictim\x3D/&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7724</id>
        <msg>BACKDOOR reversable ver1.0 runtime detection - initial connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;EXECUT&quot;; depth:6; flowbits:set,ReVerSaBle_ExecuteCommand; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7726</id>
        <msg>BACKDOOR reversable ver1.0 runtime detection - execute command - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,ReVerSaBle_ExecuteCommand; content:&quot;COMMENFile&quot;; depth:10; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7727</id>
        <msg>BACKDOOR reversable ver1.0 runtime detection - execute command</msg>
        <url>www.megasecurity.org/trojans/r/reversable/Reversable1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 00 00 00 01 00 00 00 08 08|&quot;; depth:10; flowbits:set,Radmin; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7728</id>
        <msg>BACKDOOR radmin runtime detection - client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Radmin; content:&quot;|01 00 00 00|%|00 00 01 10 08 01 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:46; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7729</id>
        <msg>BACKDOOR radmin runtime detection - server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453086368</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 5005</filter1>
        <filter2>flow:to_server,established; content:&quot;Sin&quot;; nocase; pcre:&quot;/^Sin[^\r\n]*\/[^\r\n]*\x0D\x0A\d+\x0D\x0A/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7730</id>
        <msg>BACKDOOR outbreak_0.2.7 runtime detection - reverse connection</msg>
        <url>www.megasecurity.org/trojans/o/outbreak/Outbreak0.2.7.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 5005 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;SINFO&quot;; nocase; pcre:&quot;/^SINFO\x3B\d+\x3B/smi&quot;; flowbits:set,outbreak_ring_stc; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7731</id>
        <msg>BACKDOOR outbreak_0.2.7 runtime detection - ring server-to-client</msg>
        <url>www.megasecurity.org/trojans/o/outbreak/Outbreak0.2.7.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 5005</filter1>
        <filter2>flow:to_server,established; flowbits:isset,outbreak_ring_stc; content:&quot;SINFO&quot;; nocase; content:&quot;PONG&quot;; distance:0; nocase; pcre:&quot;/^SINFO\x3B[^\r\n]{1,20}\x3BPONG\x3B/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7732</id>
        <msg>BACKDOOR outbreak_0.2.7 runtime detection - ring client-to-server</msg>
        <url>www.megasecurity.org/trojans/o/outbreak/Outbreak0.2.7.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 5005 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;CON&quot;; nocase; pcre:&quot;/^CON\w{1,10}\d+\xAE[^\r\n]{1,20}\x3B/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7733</id>
        <msg>BACKDOOR outbreak_0.2.7 runtime detection - initial connection</msg>
        <url>www.megasecurity.org/trojans/o/outbreak/Outbreak0.2.7.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|05 00 00 00|1|00 01 00 01 FD 12 00|&quot;; depth:12; flowbits:set,BioNet4_05_BE; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7734</id>
        <msg>BACKDOOR bionet 4.05 runtime detection - initial connection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072406</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 4444 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;accept|3A|&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7738</id>
        <msg>BACKDOOR alexmessomalex runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=45547</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4444</filter1>
        <filter2>flow:to_server,established; content:&quot;grab|3A|&quot;; depth:5; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7739</id>
        <msg>BACKDOOR alexmessomalex runtime detection - grab</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=45547</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Passed&quot;; depth:6; nocase; flowbits:set,nova_conn_1; flowbits:noalert; classtype:trojan-activity;</filter2>
        <id>7740</id>
        <msg>BACKDOOR nova 1.0 runtime detection - initial connection with pwd set - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073030</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7410 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;MSG00020&quot;; depth:8; flowbits:set,Phoenix_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7744</id>
        <msg>BACKDOOR phoenix 2.1 runtime detection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7410 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Phoenix_InitConnection; content:&quot;The Phoenix is ready&quot;; depth:20; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7745</id>
        <msg>BACKDOOR phoenix 2.1 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079790</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 4321 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Password|3A|&quot;; depth:9; flowbits:set,BoBo_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7746</id>
        <msg>BACKDOOR bobo 1.0 runtime detection - initial connection - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4321</filter1>
        <filter2>flow:to_server,established; flowbits:isset,BoBo_InitConnection; content:&quot;zdorovo&quot;; depth:7; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7747</id>
        <msg>BACKDOOR bobo 1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076842</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4321</filter1>
        <filter2>flow:to_server,established; content:&quot;Send Message&quot;; depth:12; flowbits:set,BoBo_SendMessages; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7748</id>
        <msg>BACKDOOR bobo 1.0 runtime detection - send message - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 4321 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BoBo_SendMessages; content:&quot;Message shown.|00|finish line|00|&quot;; depth:27; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7749</id>
        <msg>BACKDOOR bobo 1.0 runtime detection - send message</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076842</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;*PASS*&quot;; depth:6; flowbits:set,BuschTrommel_InitConnection1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7750</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,BuschTrommel_InitConnection1; content:&quot;ver&quot;; depth:3; flowbits:set,BuschTrommel_InitConnection2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7751</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BuschTrommel_InitConnection2; content:&quot;*VER1.22|28|REI|29|&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7752</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=20757</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;GETIT&quot;; depth:5; flowbits:set,BuschTrommel_SpyFunction1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7753</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BuschTrommel_SpyFunction1; content:&quot;{PLTS}&quot;; depth:6; flowbits:set,BuschTrommel_SpyFunction2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7754</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BuschTrommel_SpyFunction2; content:&quot;{FTPL}&quot;; depth:6; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7755</id>
        <msg>BACKDOOR buschtrommel 1.22 runtime detection - spy function</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=20757</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|F5 CB C9 CF C6 F5 C8 C8 CE C7 F5|&quot;; depth:11; content:&quot;|F5 D5 D1 D5 F5|&quot;; distance:0;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7758</id>
        <msg>BACKDOOR glacier runtime detection - initial connection and directory browse</msg>
        <url>www.symantec.com/avcenter/attack_sigs/s20302.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|F5 CA C7 C7 C6 F5 C8 C8 CE C7 F5|&quot;; depth:11;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7759</id>
        <msg>BACKDOOR glacier runtime detection - screen capture</msg>
        <url>www.symantec.com/avcenter/attack_sigs/s20302.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>content:&quot;|00 00 00 00 00 00 00 82|&quot;; depth:8; offset:17;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7760</id>
        <msg>BACKDOOR netthief runtime detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=16078</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6767</filter1>
        <filter2>flow:to_server,established; content:&quot;|3B|ServicesStatus&quot;; nocase; pcre:&quot;/^\x3BServicesStatus\x3B(All|Active|Inactive)Services/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7763</id>
        <msg>BACKDOOR nt remote controller 2000 runtime detection - services client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075691</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6767</filter1>
        <filter2>flow:to_server,established; content:&quot;|3B|SystemInfo&quot;; nocase; flowbits:set,NT_Remote_Controller_2000_Sysinfo1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7764</id>
        <msg>BACKDOOR nt remote controller 2000 runtime detection - sysinfo client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075691</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6767 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NT_Remote_Controller_2000_Sysinfo1; content:&quot;SystemInfo|3B|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7765</id>
        <msg>BACKDOOR nt remote controller 2000 runtime detection - sysinfo server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075691</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6767</filter1>
        <filter2>flow:to_server,established; content:&quot;|3B|FolderMonitor&quot;; nocase; flowbits:set,NT_Remote_Controller_2000_FolderMonitor; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7766</id>
        <msg>BACKDOOR nt remote controller 2000 runtime detection - foldermonitor client-to-server</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075691</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6767 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NT_Remote_Controller_2000_FolderMonitor; content:&quot;FolderMonitor|3B|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7767</id>
        <msg>BACKDOOR nt remote controller 2000 runtime detection - foldermonitor server-to-client</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075691</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 877 -&gt; $HOME_NET 876</filter1>
        <filter2>flow:established; content:&quot;getserverinfo|7C|&quot;; depth:14; flowbits:set,Messiah_GetServerInfoA; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7770</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - get server info - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 876 -&gt; $EXTERNAL_NET 877</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Messiah_GetServerInfoA; content:&quot;serverinformation|7C|&quot;; depth:18; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7771</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - get server info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077400</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 877 -&gt; $HOME_NET 876</filter1>
        <filter2>flow:established; content:&quot;enablekey|7C|&quot;; depth:10; flowbits:set,Messiah_EnableKeyloggerA; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7772</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - enable keylogger - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 876 -&gt; $EXTERNAL_NET 877</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Messiah_EnableKeyloggerA; content:&quot;kcaption|7C|&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7773</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - enable keylogger</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077400</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 877 -&gt; $HOME_NET 876</filter1>
        <filter2>flow:established; content:&quot;getscreen|7C|&quot;; depth:10; flowbits:set,Messiah_ScreenCaptureA; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7774</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - screen capture - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 876 -&gt; $EXTERNAL_NET 877</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Messiah_ScreenCaptureA; content:&quot;Downloadscreen|7C|&quot;; depth:15; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7775</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - screen capture</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077400</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7080</filter1>
        <filter2>flow:from_client,established; content:&quot;GET///Drives**&quot;; depth:14; flowbits:set,Messiah_GetDrives; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7776</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - get drives - flowbit set</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 7080 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Messiah_GetDrives; content:&quot;GET///Drives&quot;; depth:12; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7777</id>
        <msg>BACKDOOR messiah 4.0 runtime detection - get drives</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077400</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|01|elfRAT|04|&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7778</id>
        <msg>BACKDOOR elfrat runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=55224</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;get_drives&quot;; nocase; flowbits:set,NetDevil_FileManager; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7782</id>
        <msg>BACKDOOR netdevil runtime detection - file manager - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453087652</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetDevil_FileManager; content:&quot;get_drives_done&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7783</id>
        <msg>BACKDOOR netdevil runtime detection - file manager</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453087652</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>content:&quot;RA Broadcast|00|&quot;; depth:13; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7791</id>
        <msg>BACKDOOR remote anything 5.11.22 runtime detection - victim response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076440</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;RA Chat|00 00|&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7792</id>
        <msg>BACKDOOR remote anything 5.11.22 runtime detection - chat with victim</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076440</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>content:&quot;RA Chat|00 00|&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7793</id>
        <msg>BACKDOOR remote anything 5.11.22 runtime detection - chat with attacker</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076440</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;updateinfo&quot;; depth:10; nocase; flowbits:set,backdoor.fraggle.rock.2.0.lite.pc.info; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7794</id>
        <msg>BACKDOOR fraggle rock 2.0 lite runtime detection - pc info - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077120</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;ACS &quot;; depth:4; flowbits:set,InCommand_17_InitConnection; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7795</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,InCommand_17_InitConnection; content:&quot;PASSOK&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7796</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 148</filter1>
        <filter2>flow:to_server,established; content:&quot;USER inc&quot;; depth:8; flowbits:set,InCommand_17_FileManager_1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7797</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - file manage 1</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 148</filter1>
        <filter2>flow:to_server,established; flowbits:isset,InCommand_17_FileManager_1; content:&quot;PASS InClientMainPassword&quot;; depth:25; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7798</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - file manage 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9401</filter1>
        <filter2>flow:to_server,established; content:&quot;USER inc&quot;; depth:8; flowbits:set,InCommand_17_FileManager_2; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7799</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - file manage 2</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 9401</filter1>
        <filter2>flow:to_server,established; flowbits:isset,InCommand_17_FileManager_2; content:&quot;PASS InClientMainPassword&quot;; depth:25; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7800</id>
        <msg>BACKDOOR incommand 1.7 runtime detection - file manage 2</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=44730</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $EXTERNAL_NET 10220 -&gt; $HOME_NET 10167</filter1>
        <filter2>flow:to_server; content:&quot;pod&quot;; depth:3; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7801</id>
        <msg>BACKDOOR portal of doom runtime detection - udp cts</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4684</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>udp $HOME_NET 10167 -&gt; $EXTERNAL_NET 10220</filter1>
        <filter2>flow:to_client; content:&quot;KeepAlive&quot;; depth:9; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7802</id>
        <msg>BACKDOOR portal of doom runtime detection - udp stc</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=4684</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4201</filter1>
        <filter2>flow:to_server,established; content:&quot;text|3A|&quot;; depth:5; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7803</id>
        <msg>BACKDOOR war trojan ver1.0 runtime detection - send messages</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075746</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4201</filter1>
        <filter2>flow:to_server,established; content:&quot;disablectrlaltdel&quot;; depth:17; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7804</id>
        <msg>BACKDOOR war trojan ver1.0 runtime detection - disable ctrl+alt+del</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075746</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/top100&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;webfringe&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7805</id>
        <msg>BACKDOOR war trojan ver1.0 runtime detection - ie hijacker</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075746</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;00000&quot;; nocase; content:&quot;-~-&quot;; distance:0; nocase; pcre:&quot;/^00000\s+-~-\s+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7806</id>
        <msg>BACKDOOR fatal wound 1.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077104</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6666</filter1>
        <filter2>flow:to_server,established; content:&quot;Execute -~-&quot;; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7807</id>
        <msg>BACKDOOR fatal wound 1.0 runtime detection - execute file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077104</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6666</filter1>
        <filter2>flow:to_server,established; content:&quot;File Name -~-&quot;; nocase; flowbits:set,fatalwound_upload; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7808</id>
        <msg>BACKDOOR fatal wound 1.0 runtime detection - upload</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077104</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,fatalwound_upload; content:&quot;Send File -~-&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7809</id>
        <msg>BACKDOOR fatal wound 1.0 runtime detection - upload</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453077104</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot; |0D 0A|Vous etes connecte a|3A 0D 0A 0D 0A 00|&quot;; flowbits:set,Abacab; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7811</id>
        <msg>BACKDOOR abacab runtime detection - telnet initial</msg>
        <url>megasecurity.org/trojans/a/abacab/Abacab0.9beta.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 23 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Abacab; content:&quot;|00|  |23 23 23|    |23 23 23|         |23|   __...--''     ___...--_..'  .|3B|.' |3B 0D 0A|&quot;; nocase; content:&quot;CONNECTION|3A 0D 0A| |0D 0A|Veuillez entrer le mot de passe|0D 0A 00|&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7812</id>
        <msg>BACKDOOR abacab runtime detection - banner</msg>
        <url>megasecurity.org/trojans/a/abacab/Abacab0.9beta.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|55|7C|0|7C|0|7C 7C|&quot;; depth:9; flowbits:set,darkmoon_initial_cts; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7813</id>
        <msg>BACKDOOR darkmoon initial connection detection - cts</msg>
        <url>securityresponse.symantec.com/avcenter/venc/auto/index/indexD.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,darkmoon_initial_cts; content:&quot;|7C|Connected&quot;; depth:10; nocase; content:&quot;with|3A|&quot;; distance:0; nocase; pcre:&quot;/^\x7CConnected with\x3A\s+\d+\x2E\d+.\d+.\d+/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7814</id>
        <msg>BACKDOOR darkmoon initial connection detection - stc</msg>
        <url>securityresponse.symantec.com/avcenter/venc/auto/index/indexD.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;0^0^0^&quot;; depth:6; flowbits:set,darkmoon_reverse_stc; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7815</id>
        <msg>BACKDOOR darkmoon reverse connection detection - stc</msg>
        <url>securityresponse.symantec.com/avcenter/venc/auto/index/indexD.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,darkmoon_reverse_stc; content:&quot;DmInf&quot;; depth:5; nocase; pcre:&quot;/^DmInf\x5E[^\r\n]*\d+\x2E\d+\x2E\d+\x2E\d+\x5E/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7816</id>
        <msg>BACKDOOR darkmoon reverse connection detection - cts</msg>
        <url>securityresponse.symantec.com/avcenter/venc/auto/index/indexD.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 146</filter1>
        <filter2>flow:to_server,established; content:&quot;FC &quot;; depth:3; nocase; flowbits:set,back.infector.v1.0.conn.1; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7817</id>
        <msg>BACKDOOR infector v1.0 runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075657</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 146 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,back.infector.v1.0.conn.1; content:&quot;FC'S TROJAN&quot;; depth:11; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7818</id>
        <msg>BACKDOOR infector v1.0 runtime detection - init conn</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075657</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1111</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|&quot;; depth:1; offset:3; pcre:&quot;/^(?=[abchimoprswx])(acs|bin|c(ap|ls)|h(di|ms|tb)|iex|m(oo|tx|ws)|opn|pwr|rst|s(h[di]|ms|tb|wm)|wrd|xls)\x7C/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>7822</id>
        <msg>BACKDOOR xbkdr runtime detection</msg>
        <url>www.megasecurity.org/trojans/x/x-bkdr/X-bkdr1.4.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/DataChunksGZ&quot;; fast_pattern; nocase; http_uri; content:&quot;update=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7823</id>
        <msg>SPYWARE-PUT Adware whenu runtime detection - datachunksgz</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076030</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ClockDB&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;whenu.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*whenu\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7824</id>
        <msg>SPYWARE-PUT Trickler whenu.clocksync runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076030</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/heartbeat?&quot;; nocase; http_uri; content:&quot;program=savenow&quot;; fast_pattern; nocase; http_uri; content:&quot;partner=&quot;; nocase; http_uri; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7825</id>
        <msg>SPYWARE-PUT Adware whenu.savenow runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075520</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WthrPrefs&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;whenu.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*whenu\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7826</id>
        <msg>SPYWARE-PUT Trickler whenu.weathercast runtime detection - check</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074634</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SearchBar?&quot;; fast_pattern; nocase; http_uri; content:&quot;templ=&quot;; nocase; http_uri; content:&quot;num=&quot;; nocase; http_uri; content:&quot;app=desktop&quot;; nocase; http_uri; content:&quot;uiv=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;ctr=&quot;; nocase; http_uri; content:&quot;cc=&quot;; nocase; http_uri; content:&quot;rgn=&quot;; nocase; http_uri; content:&quot;sgp=&quot;; nocase; http_uri; content:&quot;stp=&quot;; nocase; http_uri; content:&quot;cnt=&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7827</id>
        <msg>SPYWARE-PUT Adware whenu runtime detection - search request 1</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079971</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchb?&quot;; nocase; http_uri; content:&quot;datatype=&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;partner=&quot;; nocase; http_uri; content:&quot;app=desktop&quot;; fast_pattern; nocase; http_uri; content:&quot;ui=&quot;; nocase; http_uri; content:&quot;srchtrig=&quot;; nocase; http_uri; content:&quot;pat=&quot;; nocase; http_uri; content:&quot;cc=&quot;; nocase; http_uri; content:&quot;rgn=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7828</id>
        <msg>SPYWARE-PUT Adware whenu runtime detection - search request 2</msg>
        <url>www.spywareguide.com/product_show.php?id=2485</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| Gator&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7829</id>
        <msg>SPYWARE-PUT Adware gator user-agent detected</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094092</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1174 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;lasd|0A|&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>7830</id>
        <msg>SPYWARE-PUT Botnet dacryptic runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=26162</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;affid=&quot;; nocase; http_uri; content:&quot;update=&quot;; nocase; http_uri; content:&quot;brand=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Message Center&quot;; fast_pattern; nocase; http_header; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7831</id>
        <msg>SPYWARE-PUT Adware downloadplus runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076008</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/NetTracker/&quot;; fast_pattern; nocase; http_uri; flowbits:set,NetTrack_Spy_ReportBrowsing; flowbits:noalert; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7834</id>
        <msg>SPYWARE-PUT Hacker-Tool nettracker runtime detection - report browsing</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,NetTrack_Spy_ReportBrowsing; content:&quot;NetTracker&quot;; nocase; content:&quot;Sane Solutions&quot;; distance:0; nocase;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7835</id>
        <msg>SPYWARE-PUT Hacker-Tool nettracker runtime detection - report browsing</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080821</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;NetTracker&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3A[^\r\n]*NetTracker/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7836</id>
        <msg>SPYWARE-PUT Hacker-Tool nettracker runtime detection - report send through email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453080821</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;SpyOuTSiDe@CurrenTChaoS.Tk&quot;; distance:0; nocase; pcre:&quot;/^From\x3A\s+SpyOuTSiDe\x40CurrenTChaoS\x2ETk/smi&quot;; content:&quot;Subject|3A|&quot;; nocase; content:&quot;SpYOuTSiDe&quot;; distance:0; nocase; content:&quot;transmission&quot;; distance:0; nocase; content:&quot;with&quot;; distance:0; nocase; content:&quot;log&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3A\s+\x5B\d+\x5D\x2D\s+SpYOuTSiDe\s+transmission\s+with\s+log\s+\x2D/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>7837</id>
        <msg>SPYWARE-PUT Keylogger spyoutside runtime detection - email delivery</msg>
        <url>securityresponse.symantec.com/avcenter/venc/data/spyware.spyoutside.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/iframe.html&quot;; nocase; http_uri; content:&quot;bisFWB=&quot;; nocase; http_uri; content:&quot;sPartnerID=&quot;; nocase; http_uri; content:&quot;UID=&quot;; nocase; http_uri; content:&quot;rand=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.smileycentral.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A\s+www\x2Esmileycentral\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7838</id>
        <msg>SPYWARE-PUT Adware smiley central runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2181</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;RX Bar&quot;; fast_pattern; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*RX Bar\s+(ver=)?/miH&quot;;  metadata:policy security-ips alert, service http; classtype:misc-activity;</filter2>
        <id>7839</id>
        <msg>SPYWARE-PUT Hijacker rx toolbar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094367</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/404/update/instafinktb0302.cfg&quot;; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Visicom&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*Visicom\s+Toolbar/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7840</id>
        <msg>SPYWARE-PUT Hijacker instafinder initial configuration detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090786</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/error2.asp&quot;; http_uri; content:&quot;err=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; pcre:&quot;/^Host\x3A\s+www\x2Einstafinder\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7841</id>
        <msg>SPYWARE-PUT Hijacker instafinder error redirect detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090786</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;dialup_vpn@hermangroup.org&quot;; distance:0; nocase; content:&quot;Subject|3A|&quot;; nocase; content:&quot;dialupvpn_pwd&quot;; distance:0; nocase; content:&quot;name=&quot;; nocase; content:&quot;reaction.txt&quot;; distance:0; nocase; pcre:&quot;/^From\x3a[^\r\n]*dialup\x5fvpn\x40hermangroup\x2Eorg.*Subject\x3a[^\r\n]*dialupvpn\x5fpwd.*name\x3d[^\r\n]*\x22reaction\x2Etxt\x22/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7842</id>
        <msg>SPYWARE-PUT Hacker-Tool davps runtime detection</msg>
        <url>www.megasecurity.org/trojans/d/davps/Davps1.0.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchresult/&quot;; fast_pattern; nocase; http_uri; content:&quot;lt=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;cls=&quot;; nocase; http_uri; content:&quot;rid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.yoogee.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Eyoogee\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7843</id>
        <msg>SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection - search engine hijack</msg>
        <url>www.itsecurity.com/security.htm?s=9473&amp;sid=875854b6006d07f08dae34f1b78a4600</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/conf/xml/&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; content:&quot;rid=&quot;; nocase; content:&quot;cls=&quot;; nocase; content:&quot;ser=&quot;; nocase; content:&quot;signint=&quot;; nocase; content:&quot;installt=&quot;; nocase; content:&quot;rmods=&quot;; nocase; content:&quot;mods=&quot;; nocase; content:&quot;iea=&quot;; nocase; content:&quot;speed=&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.internet-optimizer.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Einternet-optimizer\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7844</id>
        <msg>SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection - post data</msg>
        <url>www.itsecurity.com/security.htm?s=9473&amp;sid=875854b6006d07f08dae34f1b78a4600</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Keylogger&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*Keylogger/smi&quot;; flowbits:set,Clogger_SendLogOut1; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7845</id>
        <msg>SPYWARE-PUT Keylogger clogger 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Clogger_SendLogOut1; content:&quot;|23 23 23 23|&quot;; nocase; content:&quot;Fen|EA|tre |3A|&quot;; distance:0; nocase; content:&quot;|23 23 23 23|&quot;; distance:0; nocase; pcre:&quot;/\x23\x23\x23\x23\s+Fen\xeatre\s+\x3a[^\r\n]*\x23\x23\x23\x23/smi&quot;; flowbits:set,Clogger_SendLogOut2; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7846</id>
        <msg>SPYWARE-PUT Keylogger clogger 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Clogger_SendLogOut2; content:&quot;&lt;----------- Fin du Fichier ----------- &gt;&quot;; fast_pattern:only; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7847</id>
        <msg>SPYWARE-PUT Keylogger clogger 1.0 runtime detection - send log through email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453068235</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.cfm&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;pc=&quot;; nocase; http_uri; content:&quot;Keywords=&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;netguide.grip.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*netguide\x2Egrip\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>7848</id>
        <msg>SPYWARE-PUT Hijacker netguide runtime detection</msg>
        <url>castlecops.com/tk17754-CursorZone_Grip_Toolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar.exe&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;tb.freeprod.com&quot;; nocase; http_header; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;NSIS_DOWNLOAD&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*NSIS_DOWNLOAD.*Host\x3A[^\r\n]*tb\x2Efreeprod\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7849</id>
        <msg>SPYWARE-PUT Trickler maxsearch runtime detection - toolbar download</msg>
        <url>www.spywareguide.com/product_show.php?id=2248</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/director/wtd.php&quot;; fast_pattern; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;nocache=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.maxifiles.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Emaxifiles\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7850</id>
        <msg>SPYWARE-PUT Trickler maxsearch runtime detection - retrieve command</msg>
        <url>www.spywareguide.com/product_show.php?id=2248</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/director/ack.php&quot;; fast_pattern; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;actionname=&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;success=&quot;; nocase; http_uri; content:&quot;debug=&quot;; nocase; http_uri; content:&quot;nocache=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.maxifiles.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Emaxifiles\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7851</id>
        <msg>SPYWARE-PUT Trickler maxsearch runtime detection - ack</msg>
        <url>www.spywareguide.com/product_show.php?id=2248</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pan/adlogbundle.php&quot;; fast_pattern; nocase; http_uri; content:&quot;bannerid=&quot;; nocase; http_uri; content:&quot;zoneid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.adoptim.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Eadoptim\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7852</id>
        <msg>SPYWARE-PUT Trickler maxsearch runtime detection - advertisement</msg>
        <url>www.spywareguide.com/product_show.php?id=2248</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cp.php&quot;; nocase; http_uri; content:&quot;QoolShown-Popups|3A|&quot;; nocase; content:&quot;QoolShown-Popups-nt|3A|&quot;; fast_pattern:only; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;stech.web-nexus.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*stech\x2Eweb-nexus\x2Enet/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7853</id>
        <msg>SPYWARE-PUT Adware web-nexus runtime detection - ad url 1</msg>
        <url>www.spywareguide.com/product_show.php?id=381</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cconfig.php&quot;; nocase; http_uri; content:&quot;Qool-Uptime|3A|&quot;; nocase; http_header; content:&quot;Win-Version|3A|&quot;; nocase; http_header; content:&quot;QoolIE-Version|3A|&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dl.web-nexus.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*dl\x2Eweb-nexus\x2Enet/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7854</id>
        <msg>SPYWARE-PUT Adware web-nexus runtime detection - config retrieval</msg>
        <url>www.spywareguide.com/product_show.php?id=381</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exclurls.php&quot;; nocase; http_uri; content:&quot;loc=&quot;; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; content:&quot;eus=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dl.web-nexus.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*dl\x2Eweb-nexus\x2Enet/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>7855</id>
        <msg>SPYWARE-PUT Adware web-nexus runtime detection - ad url 2</msg>
        <url>www.spywareguide.com/product_show.php?id=381</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;&lt;logs@logs.com&gt;&quot;; distance:0; nocase; pcre:&quot;/^From\x3A[^\r\n]*\x3Clogs\x40logs\x2Ecom\x3E/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>7857</id>
        <msg>SPYWARE-PUT Keylogger EliteKeylogger runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=814</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-3122</cve>
        <filter1>udp $HOME_NET any -&gt; $HOME_NET 67</filter1>
        <filter2>flow:to_server; content:&quot;c|82|Sc&quot;; content:&quot;= &quot;; distance:0; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>8056</id>
        <msg>DOS ISC DHCP server 2 client_id length denial of service attempt</msg>
        <url>www.debian.org/security/2006/dsa-1143</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.asp&quot;; nocase; http_uri; content:&quot;group=autosearch&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;searches.worldtostart.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*searches\x2Eworldtostart\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8071</id>
        <msg>SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection - search hijack</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098705</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/1.asp&quot;; nocase; http_uri; content:&quot;r_t=&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.internetadvertisingcompany.biz&quot;; nocase; http_header; content:&quot;keyword=&quot;; nocase; content:&quot;url=&quot;; distance:0; nocase; content:&quot;www%2efindthewebsiteyouneed%2ecom&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Einternetadvertisingcompany\x2Ebiz/smiH&quot;; pcre:&quot;/keyword\x3d[^\r\n]*url\x3d[^\r\n]*www\x252efindthewebsiteyouneed\x252ecom/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8072</id>
        <msg>SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection - surf monitor</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098705</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/smartoffers/so.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;svc=&quot;; nocase; http_uri; content:&quot;opener=rm_zango&quot;; nocase; http_uri; content:&quot;kw=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;resultsmaster.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*resultsmaster\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8073</id>
        <msg>SPYWARE-PUT Adware zango toolbar runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2298</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1327 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|CE DE B7 A8 B4 F2 BF AA B5 BD D6 F7 BB FA B5 C4 C1 AC BD D3| |D4 DA B6 CB BF DA| 1327 |3A| |C1 AC BD D3 CA A7 B0 DC|&quot;; depth:43; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8074</id>
        <msg>BACKDOOR mithril runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/m/mithril/Mithril1.45.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1327</filter1>
        <filter2>flow:to_server,established; content:&quot;sysinfo|0A|&quot;; depth:8; nocase; flowbits:set,Mithril_GetSystemInformation; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8075</id>
        <msg>BACKDOOR mithril runtime detection - get system information</msg>
        <url>www.megasecurity.org/trojans/m/mithril/Mithril1.45.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1327 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Mithril_GetSystemInformation; content:&quot;|BC C6 CB E3 BB FA C3 FB A3 BA|&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8076</id>
        <msg>BACKDOOR mithril runtime detection - get system information</msg>
        <url>www.megasecurity.org/trojans/m/mithril/Mithril1.45.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1327</filter1>
        <filter2>flow:to_server,established; content:&quot;pslist|0A|&quot;; depth:7; nocase; flowbits:set,Mithril_GetProcessList; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8077</id>
        <msg>BACKDOOR mithril runtime detection - get process list</msg>
        <url>www.megasecurity.org/trojans/m/mithril/Mithril1.45.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1327 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Mithril_GetProcessList; content:&quot;|BD F8 B3 CC|ID|BA C5 A3 BA|          &quot;; depth:20; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8078</id>
        <msg>BACKDOOR mithril runtime detection - get process list</msg>
        <url>www.megasecurity.org/trojans/m/mithril/Mithril1.45.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 2421 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;connected&quot;; depth:9; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8079</id>
        <msg>BACKDOOR x2a runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084136</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/app.txt&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;x-2.gq.nu&quot;; nocase; http_header; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8080</id>
        <msg>BACKDOOR x2a runtime detection - client update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453084136</url>
      </rule>
      <rule>
        <bugtraq>19951</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2006-0001</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;CHNKINK &quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8350</id>
        <msg>WEB-CLIENT pub file download</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-054.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rep/pop/pop_&quot;; nocase; http_uri; content:&quot;ad_soft_type=&quot;; nocase; http_uri; content:&quot;ad_mid=&quot;; nocase; http_uri; content:&quot;ad_type=&quot;; nocase; http_uri; content:&quot;dm_source=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;corep.dmcast.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*corep\x2Edmcast\x2Ecom/smiH&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8352</id>
        <msg>SPYWARE-PUT Adware desktopmedia runtime detection - ads popup</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/script/update.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;ownerversion=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dcww.dmcast.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*dcww\x2Edmcast\x2Ecom/smiH&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8353</id>
        <msg>SPYWARE-PUT Adware desktopmedia runtime detection - auto update</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/script/judge/judge.html&quot;; fast_pattern; nocase; http_uri; content:&quot;mid=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;cojud.dmcast.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*cojud\x2Edmcast\x2Ecom/smiH&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8354</id>
        <msg>SPYWARE-PUT Adware desktopmedia runtime detection - surf monitoring</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;SpyBuddy&quot;; distance:0; nocase; pcre:&quot;/^From\x3a[^\r\n]*SpyBuddy/smi&quot;; flowbits:set,SpyBuddy_SMTP; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8355</id>
        <msg>SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,SpyBuddy_SMTP; content:&quot;SpyBuddy&quot;; nocase; content:&quot;Activity&quot;; distance:0; nocase; content:&quot;Logs&quot;; distance:0; pcre:&quot;/^SpyBuddy\s+Activity\s+Logs/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8356</id>
        <msg>SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send log out through email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097719</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,SpyBuddy_SMTP; content:&quot;SpyBuddy&quot;; nocase; content:&quot;Alert&quot;; distance:0; nocase; pcre:&quot;/^SpyBuddy\s+Alert/smi&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8357</id>
        <msg>SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send alert out through email</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097719</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/related_bottom_v2.php&quot;; fast_pattern; nocase; http_uri; content:&quot;key=&quot;; nocase; http_uri; content:&quot;No=&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; content:&quot;related.yok.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*related\x2Eyok\x2Ecom/smi&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8359</id>
        <msg>SPYWARE-PUT Hijacker yok supersearch runtime detection - target website display</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Yok.SuperSearch&amp;threatid=44407</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stat.htm&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;repeatip=&quot;; nocase; http_uri; content:&quot;Host|3A| count.yok.com&quot;; fast_pattern:only;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8360</id>
        <msg>SPYWARE-PUT Hijacker yok supersearch runtime detection - search info collect</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Yok.SuperSearch&amp;threatid=44407</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; dsize:&lt;50; content:&quot;0^0^0^&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8361</id>
        <msg>BACKDOOR black curse 4.0 runtime detection - inverse init connection</msg>
        <url>www.megasecurity.org/trojans/b/blackcurse/Blackcurse4.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; dsize:&lt;50; content:&quot;|7C|48|7C|0|7C|0|7C|&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8362</id>
        <msg>BACKDOOR black curse 4.0 runtime detection - normal init connection</msg>
        <url>www.megasecurity.org/trojans/b/blackcurse/Blackcurse4.0.html</url>
      </rule>
      <rule>
        <bugtraq>20096</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-4868</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|3A|fill&quot;; nocase; content:&quot;method&quot;; distance:0; nocase; pcre:&quot;/&lt;\w+\x3afill\s[^&gt;]*method\s*=\s*(\x27[^\x27]{32}|\x22[^\x22]{32}|[^\s&gt;]{32})/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>8416</id>
        <msg>WEB-CLIENT VML fill method overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-055.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2006-4692</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;{|5C|rtf&quot;; nocase; content:&quot;{|5C|object|5C|objemb{|5C|*|5C|objclass Package}&quot;; distance:0; nocase; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8445</id>
        <msg>WEB-CLIENT RTF file with embedded object package download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-065.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ddd2/report_userinfo.asp&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ddduser.dudu.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ddduser\x2Edudu\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8461</id>
        <msg>SPYWARE-PUT Trackware duduaccelerator runtime detection - send userinfo</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rep/dlinfo.html&quot;; fast_pattern; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;page=&quot;; nocase; http_uri; content:&quot;product=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dddrep.dudu.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*dddrep\x2Edudu\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8462</id>
        <msg>SPYWARE-PUT Trackware duduaccelerator runtime detection - trace info downloaded</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login_cn.html&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;mid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dddlogin.dudu.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*dddlogin\x2Edudu\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8463</id>
        <msg>SPYWARE-PUT Trackware duduaccelerator runtime detection - trace login info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hap/adserver.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; content:&quot;distributorid=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;AD&quot;; nocase; http_header; content:&quot;Request&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;wwws.henbang.net&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*AD[^\r\n]*Request/smiH&quot;; pcre:&quot;/^Host\x3a[^\r\n]*wwws\x2Ehenbang\x2Enet/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8464</id>
        <msg>SPYWARE-PUT Adware henbang runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094312</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;NETObserve&quot;; distance:0; nocase; pcre:&quot;/^From\x3a[^\r\n]*NETObserve/smi&quot;; flowbits:set,NETObserve_SMTP; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8465</id>
        <msg>SPYWARE-PUT Keylogger netobserve runtime detection - email notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073490</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,NETObserve_SMTP; content:&quot;NETObserve&quot;; nocase; content:&quot;Requested&quot;; distance:0; nocase; content:&quot;Information&quot;; distance:0; nocase; pcre:&quot;/^NETObserve\s+Requested\s+Information/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8466</id>
        <msg>SPYWARE-PUT Keylogger netobserve runtime detection - email notification</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073490</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;Server|3A|&quot;; nocase; http_header; content:&quot;NETObserve&quot;; nocase; http_header; pcre:&quot;/^Server\x3a[^\r\n]*NETObserve/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>8467</id>
        <msg>SPYWARE-PUT Keylogger netobserve runtime detection - remote login response</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453073490</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/soap&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.accoona.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eaccoona\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8468</id>
        <msg>SPYWARE-PUT Hijacker accoona runtime detection - collect info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096478</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search_assistant/accoona_search_assistant.jsp&quot;; http_uri; content:&quot;utm_id=&quot;; nocase; http_uri; content:&quot;utm_content=&quot;; nocase; http_uri; content:&quot;utm_source=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.accoona.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eaccoona\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8469</id>
        <msg>SPYWARE-PUT Hijacker accoona runtime detection - open sidebar search url</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096478</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/requestimpression.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;host=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;media.dxcdirect.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*media\x2Edxcdirect\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>8542</id>
        <msg>SPYWARE-PUT Trackware deluxecommunications runtime detection - collect info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453099974</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ip&quot;; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;pck_id=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;info=&quot;; nocase; http_uri; content:&quot;link=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;media.dxcdirect.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*media\x2Edxcdirect\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>8543</id>
        <msg>SPYWARE-PUT Trackware deluxecommunications runtime detection - display popup ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453099974</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|7C|roogoo|7C|&quot;; fast_pattern:only; pcre:&quot;/^\x23\d+\x7c([0-9A-E]{2}\x2d){5}[0-9A-E]{2}\x7croogoo\x7c/smi&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>8545</id>
        <msg>SPYWARE-PUT Adware roogoo runtime detection - surfing monitor</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/show/&quot;; nocase; http_uri; content:&quot;VER=&quot;; nocase; http_uri; content:&quot;AdID=&quot;; nocase; http_uri; content:&quot;UID=&quot;; nocase; http_uri; content:&quot;SURL=&quot;; nocase; http_uri; content:&quot;Host=&quot;; nocase; http_uri; content:&quot;ConditionID=&quot;; nocase; http_uri; content:&quot;HostJ&quot;; nocase; content:&quot;show.roogoo.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*show\x2Eroogoo\x2Ecom/smi&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>8546</id>
        <msg>SPYWARE-PUT Adware roogoo runtime detection - show ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 4000 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Connected&quot;; depth:9; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;at&quot;; distance:0; nocase; pcre:&quot;/^Connected\s+to\s+Server\s+at\x3a/smi&quot;; flowbits:set,Backdoor.ZZMM.InitConnect; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8547</id>
        <msg>BACKDOOR zzmm 2.0 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 4000 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Backdoor.ZZMM.InitConnect; content:&quot;Attached&quot;; nocase; content:&quot;through&quot;; distance:0; nocase; content:&quot;port&quot;; distance:0; nocase; pcre:&quot;/^Attached\s+through\s+port\x3a/smi&quot;; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>8548</id>
        <msg>BACKDOOR zzmm 2.0 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453054345</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;[zxconfig]&quot;; nocase; content:&quot;MyIP=&quot;; nocase; content:&quot;Port=&quot;; nocase; content:&quot;Password=&quot;; nocase; content:&quot;Banner=&quot;; nocase; content:&quot;BackConnect=&quot;; nocase; content:&quot;ServerID=&quot;; nocase; content:&quot;LocalPort=&quot;; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>8549</id>
        <msg>BACKDOOR zxshell runtime detection - setting information retrieve</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453081617</url>
      </rule>
      <rule>
        <bugtraq>870</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2001-0752</cve>
        <filter1>icmp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>ipopts:rr; icode:0; itype:8; metadata:policy security-ips drop; classtype:attempted-dos;</filter2>
        <id>8730</id>
        <msg>DOS record route rr denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;MZ|90 00|&quot;; byte_jump:4,56,relative,little; content:&quot;PE|00 00|&quot;; within:4; distance:-64; flowbits:set,exe.download; flowbits:noalert; metadata:service http; classtype:misc-activity;</filter2>
        <id>915306</id>
        <msg>WEB-CLIENT Portable Executable binary file transfer</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;JVBERi0x&quot;; flowbits:set,email.pdf; flowbits:noalert; metadata:service smtp; classtype:policy-violation;</filter2>
        <id>915361</id>
        <msg>POLICY pdf file sent via email</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A 08|P|D8|{|18|0|D8 D8 18|Py80|D8|P|18 0A 08|P|D8|{@0@0y8P|18|0|B8 0A|`|00 10 0A|8 {hP|D8|y8P|18|0&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9339</id>
        <msg>SPECIFIC-THREATS klez.g web propagation detection</msg>
        <url>www.sophos.com/virusinfo/analyses/w32klezg.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;E|5C 05|]d|9E|Z&lt;s-d1`/d0j3d3q4k2ank-v.k/`.k.f5kn7.d+r4v&gt;d3cpv|29|cpu/e|E6|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9340</id>
        <msg>SPECIFIC-THREATS klez.i web propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=11837</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;lwlw@21fd.fgs|00|lgsr@21fd.fgs|00|Wtzmkyj1978@21fd.fgs|00|wtzmkyj@bdswma.fgs|00|owfp@bdswma.fgs|00|lgs@bdswma.fgs|00|rywelb@bdswma.fgs|00|gebwduff@21fd&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9346</id>
        <msg>SPECIFIC-THREATS klez.b web propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-011716-2500-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;lwlw@21fd.fgs|00|lgsr@21fd.fgs|00|Wtzmkyj1978@21fd.fgs|00|wtzmkyj@bdswma.fgs|00|owfp@bdswma.fgs|00|lgs@bdswma.fgs|00|rywelb@bdswma.fgs|00|gebwduff@21fd&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9347</id>
        <msg>SPECIFIC-THREATS klez.b netshare propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-011716-2500-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;M|D5 15 80 85 D9 1C 92|zE|3B|iy|C7|2|97|8|14|/8q|1B DA|^R|DA 15|- A|80|T|BC|EJ|A3 C1 AD 8F|+ya|D9 1B|e|A3|B5|29 BB EE EE C3 D9 15 B3|U|B7 B4|os|3A AF|?|87|s|05 CE E7|rC/{|80|^r|F6|@yY|05 BC|f|83 F8 90 AF 17|d|15 24 83|i|9B 06 A6|H&lt;|A6|H|15 99 22 DA E6 C0 E5|2E|E5|2A|B5 C2|+|5C 90|Za|F8|[|92|@L |FE|0|90|W|01 FC E5|^|DE BF FF FF E9 F7 CF|&lt;|F9 F3 EF|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9351</id>
        <msg>SPECIFIC-THREATS lovgate.a netshare propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=31576</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;0@|00 0A 00 00 00|SV|8B|5|A8| @|00|W|8D|E|F0|j|0A|P|FF|5|28|0@|00 FF D6 8B|]|08 8D|E|F0|PS|E8 9D 08 00 00 BF|L0@|00|WS|E8 8B 08 00 00 8D|E|F0|j|0A|P|FF|5|D0|2@|00 FF D6 8D|E|F0|PS|E8|s|08 00 00|WS|E8|l|08 00 00 8D|E|F0|j|0A|P|FF|5|D4|2@|00 FF D6 83 C4|D|8D|E|F0|PS|E8|Q|08 00 00|WS|E8|J|08 00 00 8D|E|F0|j|0A|P|FF|5&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9353</id>
        <msg>SPECIFIC-THREATS deborm.x netshare propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DEBORM.X</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|B7 D6 B6 3B|?X4|00|h|94|[h|8F B3 B3|u@|80|*|0C|F|05 29 B3|=|CE|J|19|8V|EF 1E 10|n|90 9A|1|08 08|^X|A0 3A B6 D7|Kn^d|FE 85|h|9D|%|18|d|B7 E0|n|83 BD|x|0C|Lw|9E|`|FD|%Yr+?4|FC|y|24 07 F6 A3|Y|A4 C4|`|FD B6 06 C9 03|d|FE F3|d|8E 91 C6 DE|O|9C|jP[|90 AF 91|j|BA|{|C6|p|13 C4 8A 80 10 8B|@|0C|w|AB D5|P|FF 96|w|C2 10 04|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9354</id>
        <msg>SPECIFIC-THREATS deborm.y netshare propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DEBORM.Y</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|A3|Hp@|00 81|=Hp@|00 F0 00 00 00|~|0A C7 05|Hp@|00 0A 00 00 00|j|0A 8D|M|F0|Q|8B 15|Hp@|00|R|E8 E1|L|00 00 83 C4 0C 8D|E|F0|P|8B|M|08|Q|E8 DB 0D 00 00 83 C4 08|hlp@|00 8B|U|08|R|E8 DA 0D 00 00 83 C4 08|j|0A 8D|E|F0|P|8B 0D 90|{@|00|Q|E8 AB|L|00 00 83 C4 0C 8D|U|F0|R|8B|E|08|P|E8 B5 0D 00 00 83 C4 08|hpp@|00 8B|M|08|Q|E8|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9355</id>
        <msg>SPECIFIC-THREATS deborm.u netshare propagation detection</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DEBORM.U</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;|AB B4|+|F6 04 19 B8 9F CB|t|24|HpR|04 A6 8E|R|17 B1 7F 8A 1E|z|12 8C B8 0C|aVM|81 7C|0|AC|8|BA B5 EE 1A|B|9B|a*xe@|D1|q8|22|T|B7|.`|11 E0|iQ}|C7 CA C1 81 D9|i|B7 A4|C|BE|0|23|2X|9A DF 5C 3B|v|12 CC| |80 AD 7C|cT|19|.|AE|!|8E F8 84|R|F5|1n|D7 1B|8|E8 B0|&lt;U1F|BE B7 16 8B 89 17|Z2|B0 ED|%ED|C4 07 8B B6 CF 92 B2 22|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9356</id>
        <msg>SPECIFIC-THREATS deborm.q netshare propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32debormq.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;=X|A2|/|EF D1 BD C2 EB|0|5C 98|U|1A 08|c|AE|0|F1 06 C4 0B|m|D2 84|W|08|Z/|AD 02 0D|t|12|/|DA D7|&gt;|C6|&lt;|B2 DD 85 18 CF|,1j|8A F0 CF|Z|A4|`|87 D4|NP|89|@|F2 14 23 B8|R9|BF 0C B6 84|f|29 BA 02 0D F0 1D F6 B6|5C|04|n|99 10 BE 1D|j|0A DF 9A|P|BC CE DC C0|R9FlPT|BD CF|f|D4 CF F7|b|99 DD 8A 00 F0 E9 14|~b|9B EF C4 0C 24 96|,|14 89 D7|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9357</id>
        <msg>SPECIFIC-THREATS deborm.r netshare propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32debormr.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;agzyrywelb@igdupgdu.fgs|00|klgfp@yswma.fgs.fd|00|pyaab@igdupgdu.fgs|00|rywelb@163.fgs|00|bwdbwd@yswma.fgs.fd|00|ca1980@163.fgs|00|lmlm@igdupgdu.fgs|00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9363</id>
        <msg>SPECIFIC-THREATS klez.d web propagation detection</msg>
        <url>www.sophos.com/security/analyses/w32klezd.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;|F2 99 00 00 03|+|16|-|A8 90 BA 8A 9A 29|0PH|80|@8` Z|00 08 80|+|A0 80 00 00|X|29|h|00|H`|E8|Z0P@Zhp+|E0| |E0| |29 90 18|0Z0P@Z|88 90|+ |88|P|F8 29 BA E2 A2 A2|ZX|00 88|+ X|88|`|29|h|00|H`|E8|Z0P@Zhp+|10 B8| |A8|h|29|h|00|H`|E8|Z0P@Zhp+|B0 88 B8 00 00 88 29 98 00 B8|`|F8|PXZ&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9364</id>
        <msg>SPECIFIC-THREATS klez.e web propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2002-011716-2500-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;1|03|3-|3B|+|B5 23|!|03 E9 0B 03 23 23|5i9|23|1|3B 19 B5|/73|B5|9?|E9 1B|+|1B|+i|07|%/|B5|/73|B5 01 07 E9|+|01|7|1D|i|8D 9B 8B 8B B5|5|23 01 E9|+5|01 3B|i9|23|1|3B 19 B5|/73|B5|9?|E9|'|0D|+|09|9i9|23|1|3B 19 B5|/73|B5|9?|E9 0F 01 0D 23 23 01|i|05 23 0D 3B 1D|75|B5|5|23 01 E9 0F|+5|3B|i|8D 9B 8B 8B B5|5|23 01 E9|=+?|1B|i|01 23 0D 0D|+|B5 23 0F E9|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9387</id>
        <msg>SPECIFIC-THREATS klez.j web propagation detection</msg>
        <url>www.spywareguide.com/product_show.php?id=376</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;E|F4 00 00 00 00 8B 8D E8 FB FF FF 89|M|F0 EB 09 FF 15|dsB|00 89|E|F4 83|}|F0 00|uy|83|}|F4 00|t,|83|}|F4 05|u|15 C7 05|DVB|00 09 00 00 00 8B|U|F4 89 15|HVB|00 EB 0C 8B|E|F4|P|E8|*I|00 00 83 C4 04 83 C8 FF EB|P|8B|M|08 C1 F9 05 8B|U|08 83 E2 1F 8B 04 8D|@nB|00 0F BE|L|D0 04 83 E1|@|85 C9|t|0F 8B|U|0C 0F BE 02 83 F8 1A|u|04|3|C0 EB 22 C7 05|DVB|00 1C 00 00 00 C7 05|HVB|00 00 00 00 00 83 C8 FF EB 09 8B|E|F0|+|85 E0 FB|&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9390</id>
        <msg>SPECIFIC-THREATS deborm.d netshare propagation detection</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=30322</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;@|00|@|3B C7|v|F5|AA|80|9|00|u|D4 FF|E|FC 83 C3 08 83|}|FC 04|r|C1 8B|E|08 C7 05 5C|}@|00 01 00 00 00|P|A3|L}@|00 E8 C6 00 00 00 8D B6 EC|x@|00 BF|P}@|00 A5 A5|Y|A3|d|7F|@|00 A5 EB|UAA|80|y|FF 00 0F 85|H|FF FF FF|j|01|X|80 88|a~@|00 08|@=|FF 00 00 00|r|F1|V|E8 8C 00 00 00|Y|A3|d|7F|@|00 C7 05 5C|}@|00 01 00 00 00 EB 06 89 1D 5C|}@|00|3|C0 BF|P}@|00 AB AB AB EB 0D|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9395</id>
        <msg>SPECIFIC-THREATS deborm.j netshare propagation detection</msg>
        <url>www3.cai.com/securityadvisor/virusinfo/virus.aspx?ID=30328</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 445</filter1>
        <filter2>flow:to_server,established; content:&quot;C|80 EA 01 A1 EC|GB|00 8B|H|10 88|QC|8B 15 EC|GB|00 8B|B|10 0F BE|HC|85 C9|u|14 8B 15 EC|GB|00 8B|B|04 24 FE 8B 0D EC|GB|00 89|A|04 8B 15 EC|GB|00 83|z|08 FF 0F 85 92 00 00 00|h|00 80 00 00|j|00 A1 EC|GB|00 8B|H|0C|Q|FF 15 1C|cB|00 8B 15 EC|GB|00 8B|B|10|Pj|00 8B 0D E4|]B|00|Q|FF 15|4cB|00 8B 15 F0|GB|00|k|D2 14 A1 F4|GB|00 03 C2 8B 0D EC|GB|00 83 C1 14|+|C1|P|8B 15 EC|GB|00 83 C2 14|R|A1 EC|GB|00|P|E8|Z%|00 00 83 C4 0C 8B 0D F0|GB|00 83 E9 01 89 0D F0|GB|00 8B|U|08 3B 15 EC|GB|00|v&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9396</id>
        <msg>SPECIFIC-THREATS deborm.t netshare propagation detection</msg>
        <url>www.viruslist.com/en/viruses/encyclopedia?virusid=24669</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|0B|Bp|D6|p|00 C2 91 C5 83 DE 3B 08 C9| Ll|F8|l|18 F0 80|K!|89|.*|B0 AC 0C C8 08 88 93 E4|d1%7|DF BA 84 3A 3B|,|02 0C E7|,,8|80 D1 24 B1|j|10 D4 E0 E8|&gt;B|C1 29 D3|I|F7 D8 1B C0 05 96 A4 D6 03 01 AE 7C 91 0F 9D A5 BA 95|F|8D 02|'n|99 8F E0 15 98 A0|j|FF FD BE|G|BE B3 EC A3 E1 17 C4|h|DC 3A|f|B8 02 F9 0E 81 CE E2 1B E4 10 13 C8 E7 E3 0C 3B E4 0C C6 01|`6h|D3|h|C0 98 99 87 8C 3B|V|D3|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9401</id>
        <msg>SPECIFIC-THREATS gokar http propagation detectiot</msg>
        <url>www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=10606</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 139</filter1>
        <filter2>flow:to_server,established; content:&quot;|F7|F|DA C4|D|22|A|AB E6 0D AA 10 17 A5 9F|=|90 B6|D7|AD F6 EE|UN|E5 17|rx|B7|v|E1 94 C7 8C|Q9y|A1 D9 C9|wL|E2 94|Q|7C 0F|6QA6|02|Y|D4 D2 B0 C9|k|C5|r|B9|m|81 DE|'|08 D8 DB 1B A4 99 AC EB 08 BD A7 24|G|8C BC 07 0D E5 06 7F|3|80 0A|T3|90|B|7F 0F|V|95|m|0D 16|g|0A|Y|CB CF 18 FF CB CA|Z|01|_|DE|Z52|0C|Y|CE|Y|1F|&amp;|8C|W|B0 14|u|5C 88 B1 B0 EB C3|&lt;|84 B4|h|D4|&gt;|B8 1E 0F A6|~&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9407</id>
        <msg>SPECIFIC-THREATS lovgate.b netshare propagation detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2003-021922-4852-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1863</filter1>
        <filter2>flow:to_server,established; content:&quot;Application-File|3A| smb.exe&quot;; nocase; content:&quot;Application-FileSize|3A| 163840&quot;; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9412</id>
        <msg>SPECIFIC-THREATS sinmsn.b msn propagation detection</msg>
        <url>www.viruslist.com/en/viruses/encyclopedia?virusid=23776</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/1.php?p=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;beagle_beagle&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*beagle_beagle/smiH&quot;;  metadata:impact_flag red, policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9418</id>
        <msg>BOTNET-CNC bagle.a http notification detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-011815-3332-99&amp;tabid=2</url>
      </rule>
      <rule>
        <bugtraq>10108</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2003-0533</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; dce_iface:3919286a-b10c-11d0-9ba8-00c04fd92ef5; dce_opnum:9; dce_stub_data; content:&quot;|EC 03 00 00|&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9419</id>
        <msg>SPECIFIC-THREATS sasser attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>10108</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2003-0533</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; dce_iface:3919286a-b10c-11d0-9ba8-00c04fd92ef5; dce_opnum:9; dce_stub_data; content:&quot;|AD 0D 00 00|&quot;; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9420</id>
        <msg>SPECIFIC-THREATS korgo attempt</msg>
        <nessus>12205</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-011.mspx</url>
      </rule>
      <rule>
        <bugtraq>14513</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2005-1983</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; dce_iface:8d9f4e40-a03d-11ce-8f69-08003e30051b; dce_opnum:54; dce_stub_data; content:&quot;|C0 07 00 00 00 00 00 00|&quot;; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9421</id>
        <msg>SPECIFIC-THREATS zotob attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2003-0352</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:established,to_server; dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:4; dce_stub_data; content:&quot;F|00|X|00|N|00|B|00|F|00|X|00|F|00|X|00|N|00|B|00|F|00|X|00|F|00|X|00|F|00|X|00|F|00|X|00|&quot;; content:&quot;|9D 13 00 01|&quot;; within:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9422</id>
        <msg>SPECIFIC-THREATS msblast attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-026.asp</url>
      </rule>
      <rule>
        <bugtraq>8205</bugtraq>
        <classtype>trojan-activity</classtype>
        <cve>2003-0352</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:established,to_server; dce_iface:000001a0-0000-0000-c000-000000000046; dce_opnum:4; dce_stub_data; content:&quot;F|00|X|00|N|00|B|00|F|00|X|00|F|00|X|00|N|00|B|00|F|00|X|00|F|00|X|00|F|00|X|00|F|00|X|00|&quot;; content:&quot;|9F|u|18 00|&quot;; within:4; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9423</id>
        <msg>SPECIFIC-THREATS lovegate attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS03-026.asp</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 139</filter1>
        <filter2>flow:established,to_server; content:&quot;|00|&quot;; depth:1; content:&quot;|FF|SMB|A2|&quot;; within:5; distance:3; byte_test:1,&amp;,128,6,relative; pcre:&quot;/^.{27}/sR&quot;; byte_test:4,&amp;,2,28,little,relative; content:&quot;|5C 00|w|00|i|00|n|00|n|00|t|00 5C 00|e|00|x|00|p|00|l|00|o|00|r|00|e|00|r|00|.|00|e|00|x|00|e|00 00 00|&quot;; within:41; distance:51; nocase; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9424</id>
        <msg>SPECIFIC-THREATS /winnt/explorer.exe unicode klez infection attempt attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Disposition|3A|&quot;; nocase; content:&quot;OsrkDtNPNg9Xj38hSOB7pKSR+RzaaUnt5GIvg8wXTYQPiLhBPWmLUXYLSN2KDpF0AWHCd8Po&quot;;  metadata:policy balanced-ips alert, policy connectivity-ips alert, policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9425</id>
        <msg>SPECIFIC-THREATS netsky attachment</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Disposition|3A|&quot;; nocase; content:&quot;Received message is available at&quot;; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9426</id>
        <msg>SPECIFIC-THREATS mydoom.ap attachment</msg>
      </rule>
      <rule>
        <bugtraq>20744</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5567</cve>
        <filter1>tcp $EXTERNAL_NET [80,5190,8090] -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Ultravox-Max-Msg|3A|&quot;; nocase; byte_test:10,&gt;,65535,0,relative,string; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9434</id>
        <msg>WEB-CLIENT Ultravox-Max-Msg header integer overflow attempt</msg>
        <url>www.winamp.com/player/version_history.php</url>
      </rule>
      <rule>
        <bugtraq>20978</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5864</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;%%DocumentMedia|3A|&quot;; nocase; isdataat:257,relative; content:!&quot;|0A|&quot;; within:257; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9619</id>
        <msg>WEB-CLIENT Gnu gv buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2006-2386</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|9C CB CB 8D 13|u|D2 11 91|X|00 C0|OyV|A4|&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9639</id>
        <msg>WEB-CLIENT Windows Address Book download attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-076.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bho/ibho.php&quot;; fast_pattern; nocase; http_uri; content:&quot;add=&quot;; nocase; http_uri; content:&quot;hdid=&quot;; nocase; http_uri; content:&quot;os=&quot;; nocase; http_uri; content:&quot;ie=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;modid=&quot;; nocase; http_uri;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>9644</id>
        <msg>SPYWARE-PUT Adware imnames runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453100875</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/web&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.sogou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Esogou\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>9646</id>
        <msg>SPYWARE-PUT Hijacker sogou runtime detection - search through sogou toolbar</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098380</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;System&quot;; distance:0; nocase; content:&quot;Surveillance&quot;; distance:0; nocase; content:&quot;Log&quot;; distance:0; nocase; content:&quot;Open&quot;; nocase; content:&quot;log&quot;; distance:0; nocase; content:&quot;file&quot;; distance:0; nocase; content:&quot;import&quot;; distance:0; nocase; pcre:&quot;/^Subject\x3a[^\r\n]*System\s+Surveillance\s+Log/smi&quot;; pcre:&quot;/^Open\s+log\s+file\s+to\s+import/smi&quot;; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>9647</id>
        <msg>SPYWARE-PUT Keylogger system surveillance pro runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098658</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-FILTERED-BY-GHOST|3A|&quot;; fast_pattern:only; content:&quot;1&quot;; pcre:&quot;/^X-FILTERED-BY-GHOST\x3a[^\r\n]*1/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>9648</id>
        <msg>SPYWARE-PUT Keylogger emailspypro runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453083347</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;|23|&quot;; nocase; content:&quot;Ghost&quot;; distance:0; nocase; content:&quot;keylogger&quot;; distance:0; nocase; content:&quot;has&quot;; distance:0; nocase; content:&quot;started&quot;; distance:0; nocase; pcre:&quot;/^\x23\s+Ghost\s+Keylogger\s+has\s+started\x2E/smi&quot;; flowbits:set,ghost_keylogger_start; flowbits:noalert; metadata:policy security-ips drop; classtype:successful-recon-limited;</filter2>
        <id>9649</id>
        <msg>SPYWARE-PUT Keylogger ghost Keylogger runtime detection - flowbit set</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=70892</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,ghost_keylogger_start; content:&quot;[Static&quot;; nocase; content:&quot;Text]&quot;; distance:0; nocase; pcre:&quot;/^\s*\x5BStatic\s+Text\x5D/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>9650</id>
        <msg>SPYWARE-PUT Keylogger ghost Keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=70892</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/banner/banner.asp&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.ricercadoppia.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Ericercadoppia\x2Ecom/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>9651</id>
        <msg>SPYWARE-PUT Hijacker ricercadoppia runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098730</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/bar/&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; content:&quot;app=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.oemji.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eoemji\x2Ecom/smiH&quot;;  metadata:policy security-ips alert; classtype:misc-activity;</filter2>
        <id>9652</id>
        <msg>SPYWARE-PUT Hijacker oemji bar runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094187</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;?&amp;sesion=&quot;; nocase; flowbits:set,Backdoor.Apofis.Remotecontrol; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9654</id>
        <msg>BACKDOOR apofis 1.0 runtime detection - remote controlling</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Backdoor.Apofis.Remotecontrol; content:&quot;Troyano&quot;; nocase; content:&quot;Apofis&quot;; distance:0; nocase; pcre:&quot;/Troyano\s+Apofis\s+1\x2E0/smi&quot;;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9655</id>
        <msg>BACKDOOR apofis 1.0 runtime detection - remote controlling</msg>
        <url>www.megasecurity.org/trojans/a/apofis/Apofis1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|24|[version]&quot;; depth:10; nocase; flowbits:set,Backdoor.Bersek.Init; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9656</id>
        <msg>BACKDOOR bersek 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Backdoor.Bersek.Init; content:&quot;|23|[version]1.0&quot;; depth:13; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9657</id>
        <msg>BACKDOOR bersek 1.0 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/b/bersek/Bersek1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|24|[showuni]&quot;; depth:10; nocase; flowbits:set,Backdoor.Bersek.Filemanager; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9658</id>
        <msg>BACKDOOR bersek 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Backdoor.Bersek.Filemanager; content:&quot;|23|[showuni]&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9659</id>
        <msg>BACKDOOR bersek 1.0 runtime detection - file manage</msg>
        <url>www.megasecurity.org/trojans/b/bersek/Bersek1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|24|[proclst]&quot;; depth:10; nocase; flowbits:set,Backdoor.Bersek.Showprocesses; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9660</id>
        <msg>BACKDOOR bersek 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Backdoor.Bersek.Showprocesses; content:&quot;|23|[shwproc]&quot;; depth:10; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9661</id>
        <msg>BACKDOOR bersek 1.0 runtime detection - show processes</msg>
        <url>www.megasecurity.org/trojans/b/bersek/Bersek1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|24|[shellgo]&quot;; depth:10; nocase; flowbits:set,Backdoor.Bersek.Remoteshell; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9662</id>
        <msg>BACKDOOR bersek 1.0 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Backdoor.Bersek.Remoteshell; content:&quot;|23|[shellrs]&quot;; depth:10; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9663</id>
        <msg>BACKDOOR bersek 1.0 runtime detection - start remote shell</msg>
        <url>www.megasecurity.org/trojans/b/bersek/Bersek1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;SrvDtl&quot;; depth:6; nocase; flowbits:set,Backdoor.Crossbow.Init; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9664</id>
        <msg>BACKDOOR crossbow 1.12 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Backdoor.Crossbow.Init; content:&quot;SrvDtl|7C|&quot;; depth:7; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9665</id>
        <msg>BACKDOOR crossbow 1.12 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/c/crossbow/Crossbow1.12.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 16454 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;{|05 00 00|&quot;; depth:4; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9666</id>
        <msg>BACKDOOR superra runtime detection - success init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 16454</filter1>
        <filter2>flow:to_server,established; content:&quot;|05 00 00|&quot;; depth:3; offset:1;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9667</id>
        <msg>BACKDOOR superra runtime detection - issue remote control command</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Supreme&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*Supreme\s+Spy/smi&quot;;  metadata:policy security-ips alert; classtype:successful-recon-limited;</filter2>
        <id>9830</id>
        <msg>SPYWARE-PUT Keylogger supreme spy runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097729</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;friendlink=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.u88.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eu88\x2Ecn/smiH&quot;; metadata:policy security-ips drop; classtype:misc-activity;</filter2>
        <id>9831</id>
        <msg>SPYWARE-PUT Adware u88 runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Adware.U88&amp;threatid=46383</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1254</filter1>
        <filter2>flow:to_server,established; content:&quot;ASKGAY&quot;; depth:6; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9832</id>
        <msg>BACKDOOR ieva 1.0 runtime detection - send message</msg>
        <url>www.www.megasecurity.org/trojans/i/ieva/Ieva1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1254</filter1>
        <filter2>flow:to_server,established; content:&quot;DELEHARD&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9833</id>
        <msg>BACKDOOR ieva 1.0 runtime detection - fake delete harddisk message</msg>
        <url>www.www.megasecurity.org/trojans/i/ieva/Ieva1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1254</filter1>
        <filter2>flow:to_server,established; content:&quot;BLACK&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9834</id>
        <msg>BACKDOOR ieva 1.0 runtime detection - black screen</msg>
        <url>www.www.megasecurity.org/trojans/i/ieva/Ieva1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1254</filter1>
        <filter2>flow:to_server,established; content:&quot;OTHER&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9835</id>
        <msg>BACKDOOR ieva 1.0 runtime detection - swap mouse</msg>
        <url>www.www.megasecurity.org/trojans/i/ieva/Ieva1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1254</filter1>
        <filter2>flow:to_server,established; content:&quot;MOUSE&quot;; depth:5; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9836</id>
        <msg>BACKDOOR ieva 1.0 runtime detection - crazy mouse</msg>
        <url>www.www.megasecurity.org/trojans/i/ieva/Ieva1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF 01 01 01 80 00 00 00|&quot;; depth:8; nocase; flowbits:set,Backdoor.SunShadow.Init; flowbits:noalert; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9837</id>
        <msg>BACKDOOR sun shadow 1.70 runtime detection - init connection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Backdoor.SunShadow.Init; content:&quot;|FF 01 01 03 00 00 00 00|&quot;; depth:8; nocase; metadata:policy security-ips drop; classtype:trojan-activity;</filter2>
        <id>9838</id>
        <msg>BACKDOOR sun shadow 1.70 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/s/sunshadow/Sunshadow1.7.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF 01 03 03 00 00 00 00|&quot;; depth:8; nocase;  metadata:policy security-ips alert; classtype:trojan-activity;</filter2>
        <id>9839</id>
        <msg>BACKDOOR sun shadow 1.70 runtime detection - keep alive</msg>
        <url>www.megasecurity.org/trojans/s/sunshadow/Sunshadow1.7.0.html</url>
      </rule>
      <rule>
        <bugtraq>21852</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|23|EXTM3U&quot;; content:&quot;udp|3A|//&quot;; distance:0; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/\x23EXTM3U.*?udp\x3A\x2F\x2F[^\r\n]*%/smi&quot;; metadata:policy connectivity-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9844</id>
        <msg>WEB-CLIENT VLC Media Player udp URI format string attempt - single packet</msg>
        <url>projects.info-pull.com/moab/MOAB-02-01-2007.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|23|EXTM3U&quot;; flowbits:set,http.m3u.download; flowbits:noalert; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy security-ips drop; classtype:misc-activity;</filter2>
        <id>9845</id>
        <msg>WEB-CLIENT M3U File Download Detected</msg>
      </rule>
      <rule>
        <bugtraq>21852</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0017</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.m3u.download; content:&quot;udp|3A|//&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/\x23EXTM3U.*?udp\x3A\x2F\x2F[^\r\n]*%/smi&quot;; metadata:policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9846</id>
        <msg>WEB-CLIENT VLC Media Player udp URI format string attempt - multipacket</msg>
        <url>projects.info-pull.com/moab/MOAB-02-01-2007.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0024</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;recolorinfo&quot;; content:&quot;numfills&quot;; pcre:&quot;/recolorinfo[^&gt;]*numfills\s*=\s*\x22/si&quot;; byte_test:10,&gt;,24403223,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9848</id>
        <msg>WEB-CLIENT Vector Markup Language recolorinfo tag numfills parameter buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-004.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-0024</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;recolorinfo&quot;; content:&quot;numcolors&quot;; pcre:&quot;/recolorinfo[^&gt;]*numcolors\s*=\s*\x22/si&quot;; byte_test:10,&gt;,24403223,0,relative,string; metadata:policy balanced-ips drop, policy security-ips drop; classtype:attempted-user;</filter2>
        <id>9849</id>
        <msg>WEB-CLIENT Vector Markup Language recolorinfo tag numcolors parameter buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-004.mspx</url>
      </rule>
    </attacks>
    <groupid>500</groupid>
    <groupname>Malware</groupname>
    <warnings>
      <rule>
        <bugtraq>17040</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-1148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7144</filter1>
        <filter2>flow:established,to_server; content:&quot;/stream/?&quot;; isdataat:800; pcre:&quot;/GET\s+\x2fstream\x2f\x3f[^\x0a\x0d\x00\x20\x2f\x3d\x3b]{800}/smi&quot;; classtype:attempted-user;</filter2>
        <id>10064</id>
        <msg>EXPLOIT Peercast URL Parameter overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST /g&quot;; depth:7; nocase; content:&quot;back=++Back++|0D 0A 0D 0A|&quot;; distance:0; nocase;  classtype:attempted-admin;</filter2>
        <id>10124</id>
        <msg>SPECIFIC-THREATS PA168 chipset based IP phone authentication bypass</msg>
        <url>www.procheckup.com/Vulner_PR0614.php</url>
      </rule>
      <rule>
        <bugtraq>16697</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0460</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 11000</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 00 00|8|03|A&quot;; depth:7; isdataat:764; classtype:attempted-user;</filter2>
        <id>10125</id>
        <msg>MISC bomberclone buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 20</filter1>
        <filter2>flow:from_server,established; content:&quot;&lt;title&gt;New Page 1&lt;/title&gt;&quot;; nocase; content:&quot;Log Started |3A|&quot;; distance:0; fast_pattern; nocase; classtype:successful-recon-limited;</filter2>
        <id>10167</id>
        <msg>SPYWARE-PUT Keylogger radar spy 1.0 runtime detection - send html log</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453079942</url>
      </rule>
      <rule>
        <bugtraq>22530</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-0927</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;d8|3A|announce&quot;; nocase; pcre:&quot;/^(\d{5,}|390[1-9]|39[1-9][0-9]|[4-9][0-9]{3})\x3A/R&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>10172</id>
        <msg>WEB-MISC uTorrent announce buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-1260</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;Content-Length|3A|&quot;; nocase; http_header; isdataat:100,relative; pcre:&quot;/^Content-Length\x3A\s*[^\r\n]{100}/smiH&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>10195</id>
        <msg>WEB-MISC Content-Length buffer overflow attempt</msg>
        <url>djeyl.net/w.php</url>
      </rule>
      <rule>
        <bugtraq>2294</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0251</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;REVLOG / &quot;; depth:9; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1047</id>
        <msg>WEB-MISC Netscape Enterprise DOS</msg>
      </rule>
      <rule>
        <bugtraq>2285</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0250</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;INDEX &quot;; depth:6; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1048</id>
        <msg>WEB-MISC Netscape Enterprise directory listing attempt</msg>
        <nessus>10691</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2004-0297</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|10480;</filter2>
        <id>10480</id>
        <msg>EXPLOIT imail ldap buffer overflow exploit attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=74</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2004-0541</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|10481;</filter2>
        <id>10481</id>
        <msg>EXPLOIT squid NTLM Authorization buffer overflow exploit attempt</msg>
        <url>www.idefense.com/application/poi/display?id=107</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 2589 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;2|00 00 00 06 00 00 00|Drives|24 00|&quot;; depth:16; classtype:misc-activity;</filter2>
        <id>105</id>
        <msg>BACKDOOR - Dagger_1.4.0</msg>
      </rule>
      <rule>
        <bugtraq>2732</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0746</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GETPROPERTIES&quot;; depth:13; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1050</id>
        <msg>WEB-MISC iPlanet GETPROPERTIES attempt</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;unescape&quot;; fast_pattern:only; pcre:&quot;/(spray|return_address|payloadcode|shellcode|retaddr|retaddress|block|payload|agent|hspt)/smi&quot;; pcre:&quot;/unescape\s*\x28(\x22|\x27|\x26quot\x3B|\x5c\x22)[\x25\x5c]u[0-9a-f]{4}(\x22\s*\x2B\s*\x22)?[\x25\x5c]u[0-9a-f]{4}/smi&quot;; classtype:shellcode-detect;</filter2>
        <id>10504</id>
        <msg>SHELLCODE unescape encoded shellcode</msg>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;unescape&quot;; fast_pattern:only; pcre:&quot;/(spray|return_address|payloadcode|shellcode|retaddr|retaddress|block|payload|agent|hspt)/smi&quot;; pcre:&quot;/unescape\s*\x28(\x22|\x27|\x26quot\x3B|\x5c\x22)[\x25\x5c][0-9a-f]{2}[\x25\x5c][0-9a-f]{2}/smi&quot;; classtype:shellcode-detect;</filter2>
        <id>10505</id>
        <msg>SHELLCODE unescape encoded shellcode</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;nc.exe&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1062</id>
        <msg>WEB-MISC nc.exe attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;wsh.exe&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1064</id>
        <msg>WEB-MISC wsh attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;rcmd.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1065</id>
        <msg>WEB-MISC rcmd attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;telnet.exe&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1066</id>
        <msg>WEB-MISC telnet attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;net.exe&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1067</id>
        <msg>WEB-MISC net attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htpasswd&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1071</id>
        <msg>WEB-MISC .htpasswd access</msg>
      </rule>
      <rule>
        <bugtraq>950</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0097</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/samples/search/webhits.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1073</id>
        <msg>WEB-MISC webhits.exe access</msg>
      </rule>
      <rule>
        <bugtraq>1656</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2003-0718</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;propfind&quot;; nocase; pcre:&quot;/&lt;a\x3a\s*propfind.*?xmlns\x3a\s*a=[\x21\x22]?DAV[\x21\x22]?/iR&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1079</id>
        <msg>WEB-MISC WebDAV propfind access</msg>
        <nessus>10505</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS04-030.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7597</filter1>
        <filter2>flow:to_server,established; content:&quot;qazwsx.hsq&quot;; classtype:misc-activity;</filter2>
        <id>108</id>
        <msg>BACKDOOR QAZ Worm Client Login access</msg>
      </rule>
      <rule>
        <bugtraq>1876</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1025</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/servlet/com.unify.servletexec.UploadServlet&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1080</id>
        <msg>WEB-MISC unify eWave ServletExec upload</msg>
        <nessus>10570</nessus>
      </rule>
      <rule>
        <bugtraq>1868</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1025</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dsgw/bin/search?context=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1081</id>
        <msg>WEB-MISC Netscape Servers suite DOS</msg>
      </rule>
      <rule>
        <bugtraq>1194</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0439</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ref%3Cscript%20language%3D%22Javascript&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1082</id>
        <msg>WEB-MISC amazon 1-click cookie theft</msg>
      </rule>
      <rule>
        <bugtraq>1868</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1025</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/servlet/ServletExec&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1083</id>
        <msg>WEB-MISC unify eWave ServletExec DOS</msg>
      </rule>
      <rule>
        <bugtraq>2337</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1049</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;servlet/.......&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1084</id>
        <msg>WEB-MISC Allaire JRUN DOS attempt</msg>
      </rule>
      <rule>
        <bugtraq>1463</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1078</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;??????????&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1091</id>
        <msg>WEB-MISC ICQ Webfront HTTP DOS</msg>
      </rule>
      <rule>
        <bugtraq>1722</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus.exe?script=test.wml&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1095</id>
        <msg>WEB-MISC Talentsoft Web+ Source Code view access</msg>
        <url>archives.neohapsis.com/archives/ntbugtraq/2000-q3/0168.html</url>
      </rule>
      <rule>
        <bugtraq>1720</bugtraq>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus.exe?about&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1096</id>
        <msg>WEB-MISC Talentsoft Web+ internal IP Address access</msg>
        <url>archives.neohapsis.com/archives/ntbugtraq/2000-q3/0168.html</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cybercop&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1099</id>
        <msg>WEB-MISC cybercop scan</msg>
      </rule>
      <rule>
        <bugtraq>5847</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0840</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ONERROR=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>10990</id>
        <msg>WEB-MISC encoded cross site scripting HTML Image tag attempt</msg>
      </rule>
      <rule>
        <bugtraq>5362</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0656</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 443</filter1>
        <filter2>flow:to_server,established; flowbits:isset,sslv2.server_hello.request; content:&quot;|02|&quot;; depth:1; offset:2; byte_test:2,&gt;,8,10; flowbits:unset,sslv2.server_hello.request; metadata:service http; classtype:misc-attack;</filter2>
        <id>10997</id>
        <msg>WEB-MISC SSLv2 OpenSSl KEY_ARG buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12345:12346</filter1>
        <filter2>flow:to_server,established; content:&quot;GetInfo|0D|&quot;; classtype:trojan-activity;</filter2>
        <id>110</id>
        <msg>BACKDOOR netbus getinfo</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Java1.2.1|0D 0A|&quot;; http_header; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1100</id>
        <msg>WEB-MISC L3retriever HTTP Probe</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| Webtrends Security Analyzer|0D 0A|&quot;; http_header; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1101</id>
        <msg>WEB-MISC Webtrends HTTP probe</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/nessus_is_probing_you_&quot;; depth:32; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1102</id>
        <msg>WEB-MISC nessus 1.X 404 probe</msg>
      </rule>
      <rule>
        <bugtraq>1579</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin-serv/config/admpw&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1103</id>
        <msg>WEB-MISC Netscape admin passwd</msg>
        <nessus>10468</nessus>
      </rule>
      <rule>
        <bugtraq>1455</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0638</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bb-hostsvc.sh?HOSTSVC&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1105</id>
        <msg>WEB-MISC BigBrother access</msg>
        <nessus>10460</nessus>
      </rule>
      <rule>
        <bugtraq>1510</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0671</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/%00&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1109</id>
        <msg>WEB-MISC ROXEN directory list attempt</msg>
        <nessus>10479</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?DeleteDocument&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1116</id>
        <msg>WEB-MISC Lotus DelDoc attempt</msg>
      </rule>
      <rule>
        <bugtraq>23532</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2126</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;dbms_cdc_ipublish.chgtab_cache&quot;; nocase; pcre:&quot;/((\w+)[\r\n\s]*\x3a=[\r\n\s]*(\x27[^\x27]{30,}\x27|\x22[^\x22]{30,}\x22)[\r\n\s]*\x3b.*change_table_name[\r\n\s]*=&gt;[\r\n\s]*\2|change_table_name\s*=&gt;\s*(\x27[^\x27]{30,}|\x22[^\x22]{30,})|\(\s*((\x27[^\x27]*\x27|\x22[^\x22]*\x22)\s*,\s*){2}(\x27[^\x27]{30,}|\x22[^\x22]{30,}))/si&quot;; classtype:attempted-user;</filter2>
        <id>11175</id>
        <msg>ORACLE dbms_cdc_ipublish.chgtab_cache buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ls%20-l&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1118</id>
        <msg>WEB-MISC ls%20-l</msg>
      </rule>
      <rule>
        <bugtraq>713</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0346</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mlog.phtml&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1119</id>
        <msg>WEB-MISC mlog.phtml access</msg>
      </rule>
      <rule>
        <bugtraq>713</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0346</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mylog.phtml&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1120</id>
        <msg>WEB-MISC mylog.phtml access</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;sys.dbms_apply_user_agent.set_registration_handler&quot;; nocase; classtype:attempted-user;</filter2>
        <id>11203</id>
        <msg>ORACLE sys.dbms_apply_user_agent.set_registration_handler access attempt</msg>
        <url>www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;sys.dbms_upgrade_internal&quot;; nocase; classtype:attempted-user;</filter2>
        <id>11205</id>
        <msg>ORACLE sys.dbms_upgrade_internal access attempt</msg>
        <url>www.red-database-security.com/advisory/oracle_sql_injection_dbms_upgrade_internal.html</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/etc/passwd&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1122</id>
        <msg>WEB-MISC /etc/passwd</msg>
      </rule>
      <rule>
        <bugtraq>15509</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-3757</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;proxystylesheet&quot;; http_uri; content:&quot;/search&quot;; http_uri; pcre:&quot;/proxystylesheet=[-a-z0-9_\.]*[^-a-z0-9_\.&amp;\s]/sUmi&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>11223</id>
        <msg>WEB-MISC google proxystylesheet arbitrary command execution attempt</msg>
        <url>metasploit.com/research/vulns/google_proxystylesheet/</url>
      </rule>
      <rule>
        <bugtraq>7621</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0269</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?PageServices&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1123</id>
        <msg>WEB-MISC ?PageServices access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config/check.txt&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1124</id>
        <msg>WEB-MISC Ecommerce check.txt access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-0610</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webcart/&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1125</id>
        <msg>WEB-MISC webcart access</msg>
        <nessus>10298</nessus>
      </rule>
      <rule>
        <bugtraq>2110</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0407</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;_AuthChangeUrl?&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1126</id>
        <msg>WEB-MISC AuthChangeUrl access</msg>
      </rule>
      <rule>
        <bugtraq>12742</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-0353</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5093</filter1>
        <filter2>flow:to_server; dsize:&gt;836; classtype:attempted-admin;</filter2>
        <id>11265</id>
        <msg>EXPLOIT Sentinel license manager buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>7180</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0220</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 44334</filter1>
        <filter2>flow:to_server,established; isdataat:1000; pcre:&quot;/^[^\x00]{1000}/m&quot;; classtype:attempted-admin;</filter2>
        <id>11266</id>
        <msg>EXPLOIT Kerio Personal Firewall authentication buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>2025</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0175</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/convert.bas&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1127</id>
        <msg>WEB-MISC convert.bas access</msg>
      </rule>
      <rule>
        <bugtraq>4002</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0360</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/cpshost.dll&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1128</id>
        <msg>WEB-MISC cpshost.dll access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htaccess&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1129</id>
        <msg>WEB-MISC .htaccess access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.wwwacl&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1130</id>
        <msg>WEB-MISC .wwwacl access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.www_acl&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1131</id>
        <msg>WEB-MISC .wwwacl access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:stateless; ack:0; flags:SFP; content:&quot;AAAAAAAAAAAAAAAA&quot;; depth:16; classtype:attempted-recon;</filter2>
        <id>1133</id>
        <msg>SCAN cybercop os probe</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cd..&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1136</id>
        <msg>WEB-MISC cd..</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;HEAD/./&quot;; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1139</id>
        <msg>WEB-MISC whisker HEAD/./</msg>
        <url>www.wiretrip.net/rfp/pages/whitepapers/whiskerids.html</url>
      </rule>
      <rule>
        <bugtraq>776</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-1053</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/guestbook.pl&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1140</id>
        <msg>WEB-MISC guestbook.pl access</msg>
        <nessus>10099</nessus>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/~root&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1145</id>
        <msg>WEB-MISC /~root access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config/import.txt&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1146</id>
        <msg>WEB-MISC Ecommerce import.txt access</msg>
      </rule>
      <rule>
        <bugtraq>374</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0039</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;cat &quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1147</id>
        <msg>WEB-MISC cat%20 access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/orders/import.txt&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1148</id>
        <msg>WEB-MISC Ecommerce import.txt access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 20034 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,backdoor.netbus_2.connect; content:&quot;BN|10 00 02 00|&quot;; depth:6; content:&quot;|05 00|&quot;; depth:2; offset:8; classtype:trojan-activity;</filter2>
        <id>115</id>
        <msg>BACKDOOR NetBus Pro 2.0 connection established</msg>
      </rule>
      <rule>
        <bugtraq>2281</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/orders/checks.txt&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1155</id>
        <msg>WEB-MISC Ecommerce checks.txt access</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-1196</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/PSUser/PSCOErrPage.htm&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1157</id>
        <msg>WEB-MISC Netscape PublishingXpert access</msg>
        <nessus>10364</nessus>
      </rule>
      <rule>
        <bugtraq>1073</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0242</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/windmail.exe&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1158</id>
        <msg>WEB-MISC windmail.exe access</msg>
        <nessus>10365</nessus>
      </rule>
      <rule>
        <bugtraq>1725</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-1005</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webplus?script&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1159</id>
        <msg>WEB-MISC webplus access</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1160</id>
        <msg>WEB-MISC Netscape dir index wp</msg>
        <nessus>10352</nessus>
      </rule>
      <rule>
        <bugtraq>1153</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0429</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/c32web.exe/ChangeAdminPassword&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1162</id>
        <msg>WEB-MISC cart 32 AdminPwd access</msg>
      </rule>
      <rule>
        <bugtraq>2049</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-1188</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/quikstore.cfg&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1164</id>
        <msg>WEB-MISC shopping cart access</msg>
      </rule>
      <rule>
        <bugtraq>1036</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0192</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rpm_query&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1167</id>
        <msg>WEB-MISC rpm_query access</msg>
        <nessus>10340</nessus>
      </rule>
      <rule>
        <bugtraq>2266</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0606</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mall_log_files/order.log&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1168</id>
        <msg>WEB-MISC mall log order access</msg>
      </rule>
      <rule>
        <bugtraq>11032</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2001-0311</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5555</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00|.2|00| a|00| 0|00| 0|00| 0|00| A|00| 28|00|&quot;; depth:25; pcre:&quot;/^[^\x00]*\x2e\x2e/R&quot;; classtype:attempted-admin;</filter2>
        <id>11681</id>
        <msg>EXPLOIT Openview Omni II command bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>8968</bugtraq>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;|EB|3&quot;; depth:2; isdataat:53; content:&quot;6B@|00|&quot;; depth:4; offset:49; classtype:attempted-admin;</filter2>
        <id>11682</id>
        <msg>SPECIFIC-THREATS Metasploit niprint_lpd module attack attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>1999-0660</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;WHATISIT&quot;; classtype:misc-activity;</filter2>
        <id>117</id>
        <msg>BACKDOOR Infector.1.x</msg>
        <nessus>11157</nessus>
      </rule>
      <rule>
        <bugtraq>2248</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0279</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ews/architext_query.pl&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1173</id>
        <msg>WEB-MISC architext_query.pl access</msg>
        <nessus>10064</nessus>
        <url>www2.fedcirc.gov/alerts/advisories/1998/txt/fedcirc.98.03.txt</url>
      </rule>
      <rule>
        <bugtraq>649</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0954</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwwboard.pl&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1175</id>
        <msg>WEB-MISC wwwboard.pl access</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-verify-link&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1177</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 666 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Remote|3A| &quot;; depth:11; nocase; content:&quot;You are connected to me.|0D 0A|Remote|3A| Ready for commands&quot;; distance:0; nocase; classtype:trojan-activity;</filter2>
        <id>118</id>
        <msg>BACKDOOR SatansBackdoor.2.0.Beta</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=5260</url>
      </rule>
      <rule>
        <bugtraq>770</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>1999-0885</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get32.exe&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1180</id>
        <msg>WEB-MISC get32.exe access</msg>
        <nessus>10011</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>1999-1070</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ping?query=&quot;; http_uri; metadata:service http; classtype:attempted-dos;</filter2>
        <id>1181</id>
        <msg>WEB-MISC Annex Terminal DOS attempt</msg>
        <nessus>10017</nessus>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-cs-dump&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1183</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
        <nessus>10352</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2219</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;res|3A|//&quot;; pcre:&quot;/\x2Edll[\x2F\x5C][^\x3E\x00\s\x2F\x5C]*[\x2F\x5C](\x23|%23)(\d{6}|[7-9]\d{4}|6[6-9]\d{3}|65[6-9]\d{2}|655[4-9]\d|6553[6-9])/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>11838</id>
        <msg>WEB-MISC Win32 API res buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-035.mspx</url>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-ver-info&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1184</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-ver-diff&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1186</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>1089</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0289</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/slxweb.dll/admin?command=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1187</id>
        <msg>WEB-MISC SalesLogix Eviewer web command attempt</msg>
        <nessus>10361</nessus>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-start-ver&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1188</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-stop-ver&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1189</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 6789 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;Wtzup Use&quot;; depth:32; classtype:misc-activity;</filter2>
        <id>119</id>
        <msg>BACKDOOR Doly 2.0 access</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-uncheckout&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1190</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-html-rend&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1191</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>1053</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0169</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ows-bin/&quot;; nocase; http_uri; content:&quot;?&amp;&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1193</id>
        <msg>WEB-MISC oracle web arbitrary command execution attempt</msg>
        <nessus>10348</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-2218</cve>
        <filter1>tcp $EXTERNAL_NET 443 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established, to_client; ssl_state:server_hello; content:&quot;|16 03 00|&quot;; content:&quot;|0C|&quot;; within:1; distance:2; byte_jump:2,3,relative,big; byte_jump:2,0,relative,big; content:&quot;|00 00|&quot;; within:2; classtype:attempted-user;</filter2>
        <id>11947</id>
        <msg>WEB-CLIENT Windows schannel security package</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-031.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Cookie|3A|&quot;; nocase; http_header; content:&quot;www.snap.com&quot;; nocase; http_header; content:&quot;toolbar_domain_redirect&quot;; nocase; http_header; pcre:&quot;/^Cookie\x3a[^\r\n]*www\x2Esnap\x2Ecom[^\r\n]*toolbar_domain_redirect/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>11948</id>
        <msg>SPYWARE-PUT Hijacker snap toolbar runtime detection - cookie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094831</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7896</filter1>
        <filter2>flow:established; content:&quot;MESSAGE + &quot;; depth:10; nocase; content:&quot; + windows&quot;; distance:0; nocase; classtype:trojan-activity;</filter2>
        <id>11949</id>
        <msg>BACKDOOR lame rat v1.0 runtime detection</msg>
        <url>www.megasecurity.org/trojans/l/lamerat/Lamerat1.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 1339 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Server|3A|&quot;; nocase; content:&quot;Root&quot;; distance:0; nocase; content:&quot;kit&quot;; distance:0; nocase; content:&quot;scaner&quot;; distance:0; nocase; pcre:&quot;/^Server\x3a[^\r\n]*Root[^\r\n]*kit[^\r\n]*Scaner/smi&quot;;  classtype:trojan-activity;</filter2>
        <id>11950</id>
        <msg>BACKDOOR killav_gj</msg>
        <url>karus-software.at/portal/modules.php?name=Virenlexikon&amp;suche=t&amp;submit=suche&amp;show=Trojan.Win32.KillAV.GJ</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 610</filter1>
        <filter2>flow:to_server,established; flowbits:isset,SupervisorPlus_detection; content:&quot;&lt;A &quot;; depth:3; nocase; pcre:&quot;/^\x3c\x41\x20.*\x3b\x5c\x5c.*\x5cSV\x24\x5c\x3e\x3c/smi&quot;;  classtype:trojan-activity;</filter2>
        <id>11954</id>
        <msg>BACKDOOR supervisor plus runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453109596</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;INVITE&quot;; depth:6; nocase; content:&quot;SIP/2.0&quot;; distance:0; nocase; pcre:&quot;/^INVITE\s+(sips?|tel|https?)\x3A[\w-'&quot;]+\x40[\w-'&quot;\x2E]+\s+/smi&quot;; classtype:protocol-command-decode;</filter2>
        <id>11968</id>
        <msg>VOIP-SIP inbound INVITE message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 401 Unauthorized&quot;; depth:24; nocase; classtype:protocol-command-decode;</filter2>
        <id>11969</id>
        <msg>VOIP-SIP inbound 401 unauthorized message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>18906</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-4050</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060:5061</filter1>
        <filter2>content:&quot;CSeq|3A|&quot;; nocase; isdataat:25,relative; content:!&quot;|0A|&quot;; within:25; classtype:attempted-dos;</filter2>
        <id>11971</id>
        <msg>VOIP-SIP CSeq buffer overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Max-Forwards|3A|&quot;; fast_pattern:only; pcre:&quot;/^Max-Forwards\x3A\s+(\d{3,}|[89]\d|7[1-9])/smi&quot;; classtype:misc-activity;</filter2>
        <id>11972</id>
        <msg>VOIP-SIP Max-Forwards value over 70</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>24542</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3369</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Via|3A|&quot;; fast_pattern:only; nocase; pcre:&quot;/^Via\x3A\s+SIP\x2F2\x2E0\x2F(TCP|UDP)\s+[^\x3B\r\n]{63}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11973</id>
        <msg>VOIP-SIP Via header hostname buffer overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>dsize:&lt;11; classtype:misc-activity;</filter2>
        <id>11974</id>
        <msg>VOIP-SIP response too small</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Via|3A|&quot;; fast_pattern:only; pcre:&quot;/^Via\x3A\s+(?!SIP\x2F2\x2E0)/smi&quot;; classtype:misc-activity;</filter2>
        <id>11975</id>
        <msg>VOIP-SIP Via header missing SIP field</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;&lt;sip&quot;; fast_pattern:only; pcre:&quot;/&lt;sips?[^\x3A]{6}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11976</id>
        <msg>VOIP-SIP overflow in URI type - SIP</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;&lt;tel&quot;; fast_pattern:only; pcre:&quot;/&lt;tel[^\x3A]{6}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11977</id>
        <msg>VOIP-SIP overflow in URI type - Tel</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;From|3A|&quot;; fast_pattern:only; nocase; pcre:&quot;/^From\x3A\s+[^\r\n]{256}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11978</id>
        <msg>VOIP-SIP from header field buffer overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;m=&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^m=[A-Z]{1,20}\s(\d{6,}|[7-9]\d{5,}|6[6-9]\d{3,}|65[6-9]\d{2,}|655[4-9]\d+|6553[6-9])/smi&quot;; classtype:attempted-user;</filter2>
        <id>11979</id>
        <msg>VOIP-SIP oversized SDP media port</msg>
        <url>www.ietf.org/rfc/rfc4566.txt</url>
      </rule>
      <rule>
        <bugtraq>1063</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0236</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;?wp-usr-prop&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1198</id>
        <msg>WEB-MISC Netscape Enterprise Server directory view</msg>
      </rule>
      <rule>
        <bugtraq>16213</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0189</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;a=&quot;; distance:0; nocase; isdataat:257,relative; content:!&quot;|0A|&quot;; within:257; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^a=[^\r\n]{256}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11980</id>
        <msg>VOIP-SIP SDP attribute buffer overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc4566.txt</url>
      </rule>
      <rule>
        <bugtraq>15711</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-4050</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;INVITE&quot;; depth:6; nocase; pcre:&quot;/^INVITE\s[^\s\r\n]{60}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11981</id>
        <msg>VOIP-SIP MultiTech INVITE field buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;To|3A|&quot;; nocase; content:&quot;%25%32%35%25%33%32%25%33%35%25%32%35%25%33%33&quot;; fast_pattern:only; pcre:&quot;/^To\x3A\s+%25%32%35%25%33%32%25%33%35%25%32%35%25%33%33/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11982</id>
        <msg>VOIP-SIP recursive URL-encoded data in To header</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;t=&quot;; distance:0; nocase; content:&quot;-&quot;; distance:0; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^t=(-|\d{1,6}\s-)/smi&quot;; classtype:attempted-user;</filter2>
        <id>11983</id>
        <msg>VOIP-SIP SDP negative time value</msg>
        <url>www.ietf.org/rfc/rfc4566.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;t=&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^t=(\d{7,}|\d{1,6}\s\d{7,})/smi&quot;; classtype:attempted-user;</filter2>
        <id>11984</id>
        <msg>VOIP-SIP SDP oversized time value</msg>
        <url>www.ietf.org/rfc/rfc4566.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Expires|3A|&quot;; fast_pattern:only; pcre:&quot;/^Expires\x3A\s+\d{11}/smi&quot;; classtype:attempted-user;</filter2>
        <id>11985</id>
        <msg>VOIP-SIP Expires header overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Authorization|3A|&quot;; nocase; content:&quot;response=&quot;; distance:0; nocase; pcre:&quot;/^Authorization\x3A[^\r\n]+?response=[\x00-\x09\x0B\x0C\x0E-\x7F]*[\x80-\xFF]/smi&quot;; classtype:attempted-user;</filter2>
        <id>11986</id>
        <msg>VOIP-SIP invalid characters in authorization response parameter</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Via|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^Via\x3A\s*SIP\x2F2\x2E0\x2F(TC|UD)P\s+[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11987</id>
        <msg>VOIP-SIP Via header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;From|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^From\x3A\s*[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11988</id>
        <msg>VOIP-SIP From header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Call-ID|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^Call-ID\x3A\s*[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11989</id>
        <msg>VOIP-SIP Call-ID header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>282</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0771</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2301</filter1>
        <filter2>flow:to_server,established; content:&quot;../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1199</id>
        <msg>WEB-MISC Compaq Insight directory traversal</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Contact|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^Contact\x3A\s*[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11990</id>
        <msg>VOIP-SIP Contact header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;CSeq|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^CSeq\x3A\s*[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11991</id>
        <msg>VOIP-SIP CSeq header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;%&quot;; distance:0; pcre:&quot;/^Content-Type\x3A\s*[^\r\n%]*%/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11992</id>
        <msg>VOIP-SIP Content-Type header format string attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Call-ID|3A|&quot;; fast_pattern:only; pcre:&quot;/^Call-ID\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11993</id>
        <msg>VOIP-SIP Call-ID header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Contact|3A|&quot;; fast_pattern:only; pcre:&quot;/^Contact\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11994</id>
        <msg>VOIP-SIP Contact header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; fast_pattern:only; pcre:&quot;/^Content-Type[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11995</id>
        <msg>VOIP-SIP Content-Type header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;CSeq|3A|&quot;; fast_pattern:only; pcre:&quot;/^CSeq\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11996</id>
        <msg>VOIP-SIP CSeq header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;From|3A|&quot;; fast_pattern:only; pcre:&quot;/^From\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11997</id>
        <msg>VOIP-SIP From header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;To|3A|&quot;; fast_pattern:only; pcre:&quot;/^To\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11998</id>
        <msg>VOIP-SIP To header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Via|3A|&quot;; fast_pattern:only; pcre:&quot;/^Via\x3A[^\r\n]+[\x01-\x08\x0B\x0C\x0E-\x1F\x80-\xFF]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>11999</id>
        <msg>VOIP-SIP Via header invalid characters detected</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;INVITE&quot;; nocase; content:&quot;sip&quot;; distance:0; nocase; pcre:&quot;/^INVITE\s+sip\x3A[^\r\n\x40]+\x40((192\.0\.[02]\.\d{1,3})|(127\.\d{1,3}\.\d{1,3}\.\d{1,3})|(128\.0\.\d{1,3}\.\d{1,3})|(191\.255\.\d{1,3}\.\d{1,3})|(223\.255\.255\.\d{1,3})|(2(2[4-9]|[34][0-9]|5[0-5])\.\d{1,3}\.\d{1,3}\.\d{1,3}))/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12000</id>
        <msg>VOIP-SIP INVITE invalid IP address</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;v=&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^v=(-|(\d{6,}|[7-9]\d{5,}|6[6-9]\d{3,}|65[6-9]\d{2,}|655[4-9]\d+|6553[6-9]))/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12001</id>
        <msg>VOIP-SIP SDP version overflow attempt</msg>
        <url>www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;BYE&quot;; depth:3; nocase; content:&quot;sip|3A|&quot;; distance:0; nocase; content:&quot;SIP/2.0&quot;; distance:0; nocase; pcre:&quot;/^BYE\s+sip\x3A[^\r\n\s]+\x40[^\r\n\s]+\s+SIP\x2F2\x2E0/smi&quot;;  classtype:attempted-dos;</filter2>
        <id>12002</id>
        <msg>VOIP-SIP BYE flood</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;CANCEL&quot;; depth:6; nocase; content:&quot;sip|3A|&quot;; distance:0; nocase; content:&quot;SIP/2.0&quot;; distance:0; nocase; pcre:&quot;/^CANCEL\s+sip\x3A[^\r\n\s]+\x40[^\r\n\s]+\s+SIP\x2F2\x2E0/smi&quot;;  classtype:attempted-dos;</filter2>
        <id>12003</id>
        <msg>VOIP-SIP CANCEL flood</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;INVITE&quot;; depth:6; nocase; content:&quot;sip|3A|&quot;; distance:0; nocase; content:&quot;SIP/2.0&quot;; distance:0; nocase; content:&quot;Content-Length|3A|&quot;; distance:0; nocase; content:&quot;0&quot;; distance:0; pcre:&quot;/^INVITE\s+sip\x3A[^\r\n\s]+\x40[^\r\n\s]+\s+SIP\x2F2\x2E0/smi&quot;; pcre:&quot;/^Content-Length\x3A\s+0[\r\n]/smi&quot;;  classtype:attempted-dos;</filter2>
        <id>12004</id>
        <msg>VOIP-SIP INVITE message invalid Content-Length size of zero</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;c=&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^c=([^I]|I[^N]|IN[^\s]|IN\s+[^I]|IN\s+I[^P]|IN\s+IP[^46])/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12005</id>
        <msg>VOIP-SIP invalid SDP connection value</msg>
        <url>www.ietf.org/rfc/rfc4566.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $HOME_NET 5060 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>content:&quot;INVITE&quot;; depth:6; nocase; content:&quot;SIP/2.0&quot;; distance:0; nocase; pcre:&quot;/^INVITE\s+(sips?|tel|https?)\x3A[\w-'&quot;]+\x40[\w-'&quot;\x2E]+\s+/smi&quot;; classtype:protocol-command-decode;</filter2>
        <id>12006</id>
        <msg>VOIP-SIP outbound INVITE message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $HOME_NET 5060 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 401 Unauthorized&quot;; depth:24; nocase; classtype:protocol-command-decode;</filter2>
        <id>12007</id>
        <msg>VOIP-SIP outbound 401 Unauthorized message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>162</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.vts&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1202</id>
        <msg>WEB-MISC search.vts access</msg>
      </rule>
      <rule>
        <bugtraq>5902</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-0386</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4000</filter1>
        <filter2>flow:to_server,established; content:&quot;Transfer-Encoding|3A|&quot;; nocase; pcre:&quot;/Transfer-Encoding\x3a\s*chunked.*\n\r?\n/smi&quot;; pcre:!&quot;/\n\r?\n[0-9a-f]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12044</id>
        <msg>ORACLE Oracle Web Cache denial of service attempt</msg>
        <url>www.cgisecurity.com/archive/database/oracle-9iAS-web-cache-dos.txt</url>
      </rule>
      <rule>
        <bugtraq>5902</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-0386</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4000</filter1>
        <filter2>flow:to_server,established; content:&quot;GET&quot;; nocase; content:&quot;..&quot;; pcre:&quot;/GET[^\n]*\.\.[\/\\]/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12045</id>
        <msg>ORACLE Oracle Web Cache denial of service attempt</msg>
        <url>www.cgisecurity.com/archive/database/oracle-9iAS-web-cache-dos.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ad.asmx&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;yayad.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*yayad\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12047</id>
        <msg>SPYWARE-PUT Adware yayad runtime detection</msg>
        <url>www.360safe.com/elist.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;ComputerKeylogger.com&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*ComputerKeylogger\x2Ecom/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>12048</id>
        <msg>SPYWARE-PUT Keylogger computer Keylogger runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453098303</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;A-Spy&quot;; distance:0; nocase; content:&quot;Server&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*A-Spy[^\r\n]*Server/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>12049</id>
        <msg>SPYWARE-PUT Keylogger apophis spy 1.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453072636</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/ezg_serverside.xml&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.ez-greets.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eez-greets\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12050</id>
        <msg>SPYWARE-PUT Hijacker ez-greets toolbar runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=EZ-Greets%20Toolbar&amp;threatid=47475</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|01 00 00 02|WordUP&quot;; depth:10; nocase; classtype:trojan-activity;</filter2>
        <id>12051</id>
        <msg>BACKDOOR ultimate rat 2.1 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453060550</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;000The[X]Server&quot;; depth:15; nocase;  classtype:trojan-activity;</filter2>
        <id>12052</id>
        <msg>BACKDOOR the[x] 1.2 runtime detection - execute command</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453074872</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; content:&quot;_Get_Sys_Info_&quot;; depth:14; nocase; classtype:trojan-activity;</filter2>
        <id>12053</id>
        <msg>BACKDOOR trail of destruction 2.0 runtime detection - get system info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076564</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 58008 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Tron_Initconnection; content:&quot;&lt;THETIMEIS&gt;&quot;; depth:11; nocase; classtype:trojan-activity;</filter2>
        <id>12055</id>
        <msg>BACKDOOR tron runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/t/tron/Tron.html</url>
      </rule>
      <rule>
        <bugtraq>24359</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2007-2297</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0&quot;; nocase; content:&quot;0&quot;; distance:0; nocase; pcre:&quot;/^SIP\/2\.0\s+0\s*$/smi&quot;; classtype:attempted-dos;</filter2>
        <id>12061</id>
        <msg>SIP request line equal To zero</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-0832</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htgrep&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1207</id>
        <msg>WEB-MISC htgrep access</msg>
        <nessus>10495</nessus>
      </rule>
      <rule>
        <bugtraq>23093</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1594</cve>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 &quot;; depth:8; nocase; pcre:&quot;/^SIP\/2\.0\s+(?!\d{3})/smi&quot;; classtype:attempted-admin;</filter2>
        <id>12072</id>
        <msg>VOIP-SIP response code not three digits</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 100 Trying&quot;; depth:18; nocase;  classtype:protocol-command-decode;</filter2>
        <id>12073</id>
        <msg>VOIP-SIP inbound 100 Trying message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 100 Trying&quot;; depth:18; nocase;  classtype:protocol-command-decode;</filter2>
        <id>12074</id>
        <msg>VOIP-SIP outbound 100 Trying message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>22342</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0449</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:to_server,established; byte_test:10,&gt;,284,0,big,dec,string; pcre:!&quot;/(\x7e\x7e){284}/&quot;; isdataat:294; classtype:attempted-admin;</filter2>
        <id>12079</id>
        <msg>EXPLOIT CA BrightStor LGServer Stack buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>12967</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-1009</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20031</filter1>
        <filter2>flow:to_server,established; byte_test:4,&gt;,1000,0,little; isdataat:1000; classtype:attempted-admin;</filter2>
        <id>12081</id>
        <msg>EXPLOIT BakBone NetVault heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>4391</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-0509</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1521</filter1>
        <filter2>flow:to_server,established; content:&quot;|00|&quot;; depth:1; dsize:1; classtype:attempted-dos;</filter2>
        <id>12082</id>
        <msg>ORACLE Oracle 9i TNS denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>1999-0660</cve>
        <filter1>tcp $EXTERNAL_NET 1000:1300 -&gt; $HOME_NET 146</filter1>
        <filter2>flow:to_server,established; content:&quot;FC &quot;; classtype:misc-activity;</filter2>
        <id>121</id>
        <msg>BACKDOOR Infector 1.6 Client to Server Connection Request</msg>
        <nessus>11157</nessus>
      </rule>
      <rule>
        <classtype>network-scan</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;From|3A|&quot;; nocase; content:&quot;sivus_voip_scanner&quot;; distance:0; nocase; pcre:&quot;/^From\x3A\s*sivus_voip_scanner/smi&quot;; classtype:network-scan;</filter2>
        <id>12112</id>
        <msg>VOIP-SIP Sivus scanner detected</msg>
        <url>www.vopsecurity.org/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot; sip|3A|&quot;; fast_pattern:only; pcre:&quot;/^[A-Z]+\s+sip\x3A[^\r\n\x40]{256}/smi&quot;; classtype:misc-activity;</filter2>
        <id>12113</id>
        <msg>VOIP-SIP SIP URI overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/admin_files&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1212</id>
        <msg>WEB-MISC Admin_files access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/NewVerInfo.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;down.pprich.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*down\x2Epprich\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12120</id>
        <msg>SPYWARE-PUT Adware pprich runtime detection - version check</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453100047</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $HOME_NET 6600 -&gt; $EXTERNAL_NET 30000</filter1>
        <filter2>flow:to_server; content:&quot;adf`%|24|%^pk*|94|&quot;; depth:12; offset:8;  classtype:misc-activity;</filter2>
        <id>12121</id>
        <msg>SPYWARE-PUT Adware pprich runtime detection - udp info sent out</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453100047</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Spynova&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Spynova[^\r\n]*Toolbar/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12122</id>
        <msg>SPYWARE-PUT Trackware spynova runtime detection</msg>
        <url>www.symantec.com/en/aa/enterprise/security_response/writeup.jsp?docid=2007-041614-3222-99</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?keywords=&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.lookquick.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Elookquick\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12123</id>
        <msg>SPYWARE-PUT Hijacker lookquick runtime detection - hijack ie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079050</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r.look?plq=&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12124</id>
        <msg>SPYWARE-PUT Hijacker lookquick runtime detection - monitor and collect user info</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079050</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/web/search.php&quot;; nocase; content:&quot;keywords=&quot;; distance:0; nocase; content:&quot;username=&quot;; distance:0; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.lookster.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Elookster\x2Enet/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>12125</id>
        <msg>SPYWARE-PUT Trackware lookster toolbar runtime detection - hijack ie search assistant</msg>
        <url>www.pestpatrol.com/spywarecenter/pest.aspx?id=453105797</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/googlerank/get_googlerank.php&quot;; fast_pattern; nocase; http_uri; content:&quot;URL=&quot;; nocase; http_uri; content:&quot;act=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12126</id>
        <msg>SPYWARE-PUT Trackware lookster toolbar runtime detection - collect user information</msg>
        <url>www.pestpatrol.com/spywarecenter/pest.aspx?id=453105797</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pagead/ads?&quot;; nocase; http_uri; content:&quot;client=&quot;; nocase; http_uri; content:&quot;dt=&quot;; nocase; http_uri; content:&quot;lmt=&quot;; nocase; http_uri; content:&quot;format=&quot;; nocase; http_uri; content:&quot;output=&quot;; nocase; http_uri; content:&quot;correlator=&quot;; nocase; http_uri; content:&quot;url=http&quot;; nocase; http_uri; content:&quot;www.lookster.net&quot;; fast_pattern; nocase; http_uri;  classtype:successful-recon-limited;</filter2>
        <id>12127</id>
        <msg>SPYWARE-PUT Trackware lookster toolbar runtime detection - ads</msg>
        <url>www.pestpatrol.com/spywarecenter/pest.aspx?id=453105797</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;WNDkServer&quot;; depth:10; classtype:successful-recon-limited;</filter2>
        <id>12128</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - init connection</msg>
        <url>www.downloadtopc.com/spywareadware/993/3560/Win32RemoteKeyLogb.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,RemoteKeyLog.b.Info_detection; content:&quot;Product Name&quot;; depth:12; classtype:successful-recon-limited;</filter2>
        <id>12130</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - get sys info</msg>
        <url>www.downloadtopc.com/spywareadware/993/3560/Win32RemoteKeyLogb.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,RemoteKeyLog.b.Keylogging_detection; content:&quot;KEY&quot;; depth:3;  classtype:successful-recon-limited;</filter2>
        <id>12132</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - keylogging</msg>
        <url>www.downloadtopc.com/spywareadware/993/3560/Win32RemoteKeyLogb.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,RemoteKeyLog.b.Url_detection; content:&quot;WND&quot;; depth:3;  classtype:successful-recon-limited;</filter2>
        <id>12134</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - open url</msg>
        <url>www.downloadtopc.com/spywareadware/993/3560/Win32RemoteKeyLogb.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET 456 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,RemoteKeyLog.b.Fun_detection; content:&quot;WND&quot;; depth:3; classtype:successful-recon-limited;</filter2>
        <id>12136</id>
        <msg>SPYWARE-PUT Keylogger remotekeylog.b runtime detection - fun</msg>
        <url>www.downloadtopc.com/spywareadware/993/3560/Win32RemoteKeyLogb.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;TIT=|0D 0A|LE&gt;|0D 0A|King log|0D 0A|&lt;/TITLE&gt;|0D 0A|&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>12137</id>
        <msg>SPYWARE-PUT Keylogger Keylogger king home 2.3 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097591</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Set-Cookie|3A|&quot;; nocase; http_header; content:&quot;LastURL=http|3A|//www.680180.net|3A|80/ads/&quot;; nocase; http_header; pcre:&quot;/^Set-Cookie\x3a[^\r\n]*LastURL\x3dhttp\x3a\x2f\x2fwww\x2e680180\x2enet\x3a80\x2fads\x2f/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>12138</id>
        <msg>SPYWARE-PUT Adware zamingo runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453088136</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Email Reports from Stealth Website Logger&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12139</id>
        <msg>SPYWARE-PUT Trackware stealth website logger 3.4 runtime detection</msg>
        <url>www.programurl.com/stealth-website-logger.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cn.dll?&quot;; fast_pattern; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;met=&quot;; nocase; http_uri; content:&quot;charset=&quot;; nocase; http_uri; content:&quot;name=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12140</id>
        <msg>SPYWARE-PUT Hijacker cnnic update runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097703</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Logger Results&quot;; nocase; content:&quot;|0D 0A 0D 0A|&lt;|7C|&quot;; distance:0; content:&quot;|7C|&gt;|0D 0A 0D 0A|&quot;; distance:0; classtype:successful-recon-limited;</filter2>
        <id>12141</id>
        <msg>SPYWARE-PUT Keylogger logit v1.0 runtime detection</msg>
        <url>www.trojanfrance.com/index.php?dir=KeyLoggers/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AccessRemotePC_detection; content:&quot;|99 F3 00 00 00 00 00 00 FF FF FF FF|&quot;; depth:12; classtype:trojan-activity;</filter2>
        <id>12143</id>
        <msg>BACKDOOR access remote pc runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Access%20Remote%20PC&amp;threatid=29373</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BlueEye1.0b_detection; dsize:3; content:&quot;SUC&quot;; classtype:trojan-activity;</filter2>
        <id>12147</id>
        <msg>BACKDOOR blue eye 1.0b runtime detection - init connection</msg>
        <url>www.spywareguide.com/spydet_816_blue_eye_1_0b.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 54320 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,BackOrifice2006_1.1.5_detection; content:&quot;|00 00 00|&quot;; depth:3; content:&quot;|CD C3 13|7|04|&quot;; within:5; distance:1;  classtype:trojan-activity;</filter2>
        <id>12149</id>
        <msg>BACKDOOR back orifice 2006 - v1.1.5 runtime detection - init connection</msg>
        <url>www.spywareguide.com/product_show.php?id=1945</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,CAFEiNi_detection; content:&quot;INIPACK&quot;; depth:7; nocase;  classtype:trojan-activity;</filter2>
        <id>12151</id>
        <msg>BACKDOOR cafeini 1.0 runtime detection</msg>
        <url>www.spywareguide.com/spydet_904_cafeini.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;001|AC|Optix&quot;; depth:9; nocase; content:&quot;Pro&quot;; distance:0; nocase; content:&quot;v1.32&quot;; distance:0; nocase; content:&quot;Connected&quot;; distance:0; nocase; content:&quot;Successfully!|0D 0A|&quot;; distance:0; nocase; classtype:trojan-activity;</filter2>
        <id>12152</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - init connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076768</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 500 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Download_detection2; content:&quot;+OK RCVD|0D 0A|&quot;; depth:10; classtype:trojan-activity;</filter2>
        <id>12155</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - download file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076768</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 501 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Upload_detection2; content:&quot;FileSizeIs|AC|&quot;; depth:11; classtype:trojan-activity;</filter2>
        <id>12158</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - upload file</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076768</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 502 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;inc|AC|&quot;; depth:4;  classtype:trojan-activity;</filter2>
        <id>12159</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - keylogging</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076768</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <cve>1999-1155</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/filemail&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1216</id>
        <msg>WEB-MISC filemail access</msg>
        <url>www.securityfocus.com/archive/1/11175</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 503 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,OptixPROv1.32Screencapture_detection2; content:&quot;SizeIs|AC|&quot;; depth:11;  classtype:trojan-activity;</filter2>
        <id>12162</id>
        <msg>BACKDOOR optix pro v1.32 runtime detection - screen capturing</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453076768</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1357</filter1>
        <filter2>flow:to_server,established; flowbits:isset,CobraUploader1.0_detection; content:&quot;filebhejdai|7C|&quot;; depth:12; classtype:trojan-activity;</filter2>
        <id>12164</id>
        <msg>BACKDOOR cobra uploader 1.0 runtime detection</msg>
        <url>www.megasecurity.org/trojans/b/blackcobra/Blackcobra_uploader1.0.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot; sip|3A|&quot;; fast_pattern:only; pcre:&quot;/^[A-Z]+\s+sip\x3A[^\r\n\x40]+\x40{2}/smi&quot;; classtype:misc-activity;</filter2>
        <id>12167</id>
        <msg>VOIP-SIP multiple at signs in SIP URI</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>2653</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2000-0074</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/plusmail&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1217</id>
        <msg>WEB-MISC plusmail access</msg>
        <nessus>10181</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 408 Request Timeout&quot;; depth:27; nocase; classtype:protocol-command-decode;</filter2>
        <id>12170</id>
        <msg>VOIP-SIP inbound 408 Request Timeout message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 408 Request Timeout&quot;; depth:27; nocase; classtype:protocol-command-decode;</filter2>
        <id>12171</id>
        <msg>VOIP-SIP outbound 408 Request Timeout message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 501 Not Implemented&quot;; depth:27; nocase; classtype:protocol-command-decode;</filter2>
        <id>12172</id>
        <msg>VOIP-SIP inbound 501 Not Implemented message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 501 Not Implemented&quot;; depth:27; nocase; classtype:protocol-command-decode;</filter2>
        <id>12173</id>
        <msg>VOIP-SIP outbound 501 Not Implemented message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 604 Does Not Exist Anywhere&quot;; depth:35; nocase; classtype:protocol-command-decode;</filter2>
        <id>12174</id>
        <msg>VOIP-SIP inbound 604 Does Not Exist Anywhere message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 604 Does Not Exist Anywhere&quot;; depth:35; nocase; classtype:protocol-command-decode;</filter2>
        <id>12175</id>
        <msg>VOIP-SIP outbound 604 Does Not Exist Anywhere message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 415 Unsupported Media Type&quot;; depth:34; nocase; classtype:protocol-command-decode;</filter2>
        <id>12176</id>
        <msg>VOIP-SIP inbound 415 Unsupported Media Type message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 415 Unsupported Media Type&quot;; depth:34; nocase; classtype:protocol-command-decode;</filter2>
        <id>12177</id>
        <msg>VOIP-SIP outbound 415 Unsupported Media Type message</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 481 Call/Leg Transaction Does Not Exist&quot;; depth:47; nocase; classtype:protocol-command-decode;</filter2>
        <id>12178</id>
        <msg>VOIP-SIP inbound 481 Call/Leg Transaction Does Not Exist</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 481 Call/Leg Transaction Does Not Exist&quot;; depth:47; nocase; classtype:protocol-command-decode;</filter2>
        <id>12179</id>
        <msg>VOIP-SIP outbound 481 Call/Leg Transaction Does Not Exist</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;SIP/2.0 404 Not Found&quot;; depth:21; nocase; classtype:protocol-command-decode;</filter2>
        <id>12180</id>
        <msg>VOIP-SIP inbound 404 Not Found</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET 5060 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;SIP/2.0 404 Not Found&quot;; depth:21; nocase; classtype:protocol-command-decode;</filter2>
        <id>12181</id>
        <msg>VOIP-SIP outbound 404 Not Found</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>25051</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-0060</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3104</filter1>
        <filter2>flow:established,to_server; pcre:&quot;/^[^\d]|\d[^\d]/sm&quot;; classtype:attempted-admin;</filter2>
        <id>12197</id>
        <msg>EXPLOIT CA message queuing server buffer overflow attempt</msg>
        <url>supportconnectw.ca.com/public/dto_transport/infodocs/camsgguevul-secnot.asp</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2006-5583</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>flow:to_server; content:&quot;0&quot;; depth:1; byte_test:1,!&amp;,128,0,relative; content:&quot;|02 01 01 04|&quot;; within:4; distance:1; byte_test:1,!&amp;,128,0,relative; byte_jump:1,0, relative; content:&quot;|A5|&quot;; within:1; metadata:service snmp; classtype:attempted-admin;</filter2>
        <id>12198</id>
        <msg>SNMP MS Windows getbulk request</msg>
      </rule>
      <rule>
        <bugtraq>16100</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2005-2342</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3101</filter1>
        <filter2>flow:to_server,established; content:&quot;S|FF FF FF|&quot;; classtype:attempted-dos;</filter2>
        <id>12199</id>
        <msg>DOS RIM BlackBerry SRP negative string size</msg>
      </rule>
      <rule>
        <bugtraq>1175</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ultraboard&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1220</id>
        <msg>WEB-MISC ultraboard access</msg>
        <nessus>11748</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3334</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21064</filter1>
        <filter2>flow:to_server,established; isdataat:1169; byte_test:2,&gt;,1168,0,little; classtype:attempted-admin;</filter2>
        <id>12202</id>
        <msg>SPECIFIC-THREATS Ingres long message heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25048</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3566</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 14|&quot;; depth:4; isdataat:1032; content:!&quot;|00|&quot;; within:1024; distance:8; classtype:attempted-admin;</filter2>
        <id>12216</id>
        <msg>EXPLOIT Borland interbase Create Request opcode string length buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25048</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3566</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 13|&quot;; depth:4; isdataat:1032; content:!&quot;|00|&quot;; within:1024; distance:8; classtype:attempted-admin;</filter2>
        <id>12217</id>
        <msg>EXPLOIT Borland interbase string length buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25048</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3566</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00|R&quot;; depth:4; isdataat:1032; content:!&quot;|00|&quot;; within:1024; distance:8; classtype:attempted-admin;</filter2>
        <id>12218</id>
        <msg>EXPLOIT Borland interbase string length buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>19264</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-3854</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [1526,1625]</filter1>
        <filter2>flow:to_server,established; content:&quot;sqlexec &quot;; depth:20; content:!&quot; &quot;; within:127; classtype:attempted-admin;</filter2>
        <id>12220</id>
        <msg>EXPLOIT IBM Informix Dynamic Server long username</msg>
      </rule>
      <rule>
        <bugtraq>12432</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0211</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 2048</filter1>
        <filter2>flow:to_server; dsize:&gt;1428; classtype:attempted-user;</filter2>
        <id>12222</id>
        <msg>EXPLOIT Squid proxy long WCCP packet</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mbop/index.php3?&quot;; nocase; content:&quot;UID=&quot;; distance:0; nocase; content:&quot;DIST=&quot;; distance:0; nocase; content:&quot;VER=&quot;; distance:0; nocase; content:&quot;Host|3A| www.digink.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12224</id>
        <msg>SPYWARE-PUT Adware enbrowser snackman runtime detection</msg>
        <url>www.spywareguide.com/spydet_2334_enbrowser.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/smartoffers/SmartOffers.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;HBHintSVC=&quot;; nocase; http_uri; content:&quot;SG=&quot;; nocase; http_uri; content:&quot;COUNTRY=&quot;; nocase; http_uri; content:&quot;Version=&quot;; nocase; http_uri; content:&quot;partner=zango&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12225</id>
        <msg>SPYWARE-PUT Adware zango2007 toolbar runtime detection</msg>
        <url>www.spywareguide.com/spydet_2298_zango_toolbar.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| OverSpy Surveillance Data&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12226</id>
        <msg>SPYWARE-PUT Keylogger overspy runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2006-021412-4303-99</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php&quot;; nocase; http_uri; content:&quot;source=ultrasearch136&quot;; fast_pattern; nocase; http_uri; content:&quot;campaign=snap&quot;; nocase; http_uri; classtype:successful-recon-limited;</filter2>
        <id>12227</id>
        <msg>SPYWARE-PUT Trackware snap ultrasearch/desktop toolbar runtime detection - search</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094831</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;Cookie|3A|&quot;; nocase; http_header; content:&quot;source%3Dultrasearch136%26campaign%3Dsnap&quot;; nocase; http_header; pcre:&quot;/^Cookie\x3a[^\r\n]*source%3Dultrasearch136%26campaign%3Dsnap/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12228</id>
        <msg>SPYWARE-PUT Trackware snap ultrasearch/desktop toolbar runtime detection - cookie</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094831</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/v30/pop.fcgi&quot;; nocase; http_uri; content:&quot;cat=&quot;; nocase; http_uri; content:&quot;Host|3A| gpstool.globaladserver.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12229</id>
        <msg>SPYWARE-PUT Adware vroomsearch runtime detection</msg>
        <url>www.spywareguide.com/spydet_1274_vroomsearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wwp/msg/1,,,00.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;Uin=&quot;; nocase; http_uri; content:&quot;Name=&quot;; nocase; http_uri; content:&quot;Send=yes&quot;; nocase; http_uri; pcre:&quot;/Uin=\d+\x26Name=.*?IP-.*?USER-.*?TROJAN-.*?PORT-.*?PASSWORD-.*?OS-.*?WEBCAM-/smi&quot;; classtype:misc-activity;</filter2>
        <id>12230</id>
        <msg>SPYWARE-PUT Hacker-Tool hippynotify 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453078296</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/v30/pop.fcgi&quot;; nocase; http_uri; content:&quot;cat=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;gpstool.globaladserver.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*gpstool\x2eglobaladserver\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12231</id>
        <msg>SPYWARE-PUT Adware vroomsearch runtime detection</msg>
        <url>www.spywareguide.com/spydet_1274_vroomsearch.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pages/scanner/order.php&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;affid=&quot;; nocase; http_uri; content:&quot;nid=&quot;; nocase; http_uri; content:&quot;err=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12232</id>
        <msg>SPYWARE-PUT Adware errorsafe runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2006-012017-0346-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET $HTTP_PORTS -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;Web Center|3A|&quot;; nocase; http_header; content:&quot;Nom de l ordinateur|3A|&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>12239</id>
        <msg>BACKDOOR webcenter v1.0 Backdoor - init connection</msg>
        <url>www.megasecurity.org/trojans/w/webcenter/Webcenter1.0.html</url>
      </rule>
      <rule>
        <bugtraq>2371</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0215</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ROADS/cgi-bin/search.pl&quot;; http_uri; content:&quot;form=&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1224</id>
        <msg>WEB-MISC ROADS search.pl attempt</msg>
        <nessus>10627</nessus>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,Genie1.7_detection; content:&quot;|1B|[2J|0D 0A| &quot;; depth:7; content:&quot;Genie&quot;; distance:0; nocase; content:&quot;v1.7&quot;; distance:0; nocase; classtype:trojan-activity;</filter2>
        <id>12241</id>
        <msg>BACKDOOR genie 1.7 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/g/genie/Genie1.7.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,HotmailHackerLogEdition5.0_detection; content:&quot;|C0|STATUS|C0|Server&quot;; depth:14; nocase; content:&quot;Keylogging&quot;; distance:0; nocase; content:&quot;Started!&quot;; distance:0; nocase; pcre:&quot;/^\xc0STATUS\xc0Server\s\x3A\sKeylogging\sStarted\!$/smi&quot;; classtype:trojan-activity;</filter2>
        <id>12243</id>
        <msg>BACKDOOR hotmail hacker log edition 5.0 runtime detection - init connection</msg>
        <url>www.spywareguide.com/spydet_935_hotmail_hacker_x_edition.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|0D 0A|&lt;title&gt;ItAdEm Trojan Server&lt;/title&gt;|0D 0A|&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>12244</id>
        <msg>BACKDOOR itadem trojan 3.0 runtime detection</msg>
        <url>www.megasecurity.org/trojans/i/itadem/Itadem3.0.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|03 00 1C 00 00 00 00 00 01|Furax&quot;; depth:14; nocase; content:&quot;1.0b3&quot;; distance:0; nocase; content:&quot;Server|00|&quot;; distance:0; nocase; pcre:&quot;/^\x03\x00\x1c\x00\x00\x00\x00\x00\x01Furax\s+1\x2E0b3\s+Server\x00/smi&quot;; classtype:trojan-activity;</filter2>
        <id>12245</id>
        <msg>BACKDOOR furax 1.0 b3 runtime detection</msg>
        <url>www.megasecurity.org/trojans/f/furax/Furax1.0b3.html</url>
      </rule>
      <rule>
        <bugtraq>25310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1749</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;imagedata&quot;; nocase; pcre:&quot;/&lt;(?P&lt;t&gt;[A-Z]+\x3A)\s*[^&gt;]+&gt;.*&lt;[A-Z]+\x3A\s*imagedata\s+[^&gt;]*src\s*=\s*(?P&lt;q&gt;\x22|\x27|)[\w\x25\x2D\x2E]+(?P=q)[^&gt;]*&gt;.*?&lt;\x2F/smi&quot;; classtype:attempted-user;</filter2>
        <id>12280</id>
        <msg>WEB-CLIENT VML source file memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-050.mspx</url>
      </rule>
      <rule>
        <bugtraq>25310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1749</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;stroke&quot;; nocase; pcre:&quot;/&lt;(?P&lt;t&gt;[A-Z]+\x3A)\s*[^&gt;]+&gt;.*&lt;[A-Z]+\x3A\s*stroke\s+[^&gt;]*src\s*=\s*(?P&lt;q&gt;\x22|\x27|)[\w\x25\x2D\x2E]+(?P=q)[^&gt;]*&gt;.*?&lt;\x2F/smi&quot;; classtype:attempted-user;</filter2>
        <id>12281</id>
        <msg>WEB-CLIENT VML source file memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-050.mspx</url>
      </rule>
      <rule>
        <bugtraq>25310</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1749</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;vmlframe&quot;; nocase; pcre:&quot;/&lt;(?P&lt;t&gt;[A-Z]+\x3A)\s*[^&gt;]+&gt;.*&lt;[A-Z]+\x3A\s*vmlframe\s+[^&gt;]*src\s*=\s*(?P&lt;q&gt;\x22|\x27|)[\w\x25\x2D\x2E]+(?P=q)[^&gt;]*&gt;.*?&lt;\x2F/smi&quot;; classtype:attempted-user;</filter2>
        <id>12282</id>
        <msg>WEB-CLIENT VML source file memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-050.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ebrss.aspx?&quot;; nocase; http_uri; content:&quot;eb_ct_id=&quot;; nocase; http_uri; content:&quot;eb_rss_index=&quot;; fast_pattern; nocase; http_uri; content:&quot;eb_preview=&quot;; nocase; http_uri; content:&quot;eb_color=&quot;; nocase; http_uri; content:&quot;eb_forecolor=&quot;; nocase; http_uri; content:&quot;eb_speed=&quot;; nocase; http_uri; content:&quot;eb_random=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12287</id>
        <msg>SPYWARE-PUT Hijacker scn toolbar runtime detection - ebrss request</msg>
        <url>www.spywareguide.com/spydet_1830_scn_toolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ResultsExt.aspx?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;ctid=&quot;; nocase; http_uri; content:&quot;SearchSource=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;search.conduit.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*search\x2econduit\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12288</id>
        <msg>SPYWARE-PUT Hijacker scn toolbar runtime detection - hijack ie searches</msg>
        <url>www.spywareguide.com/spydet_1830_scn_toolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/update.xml&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;scn.mystoretoolbar.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*scn\x2emystoretoolbar\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12289</id>
        <msg>SPYWARE-PUT Hijacker scn toolbar runtime detection - get updates</msg>
        <url>www.spywareguide.com/spydet_1830_scn_toolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/apps/eps/eps.cgi?&quot;; fast_pattern; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; content:&quot;dp_lp=&quot;; nocase; http_uri; content:&quot;dp_p4pid=&quot;; nocase; http_uri; content:&quot;dp_format=&quot;; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;nnreq=&quot;; nocase; http_uri; content:&quot;prt=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12290</id>
        <msg>SPYWARE-PUT Hijacker newdotnet quick! search runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data?&quot;; nocase; http_uri; content:&quot;cli=&quot;; nocase; http_uri; content:&quot;ver=visicom-vmntoolbar&quot;; fast_pattern; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri;  classtype:successful-recon-limited;</filter2>
        <id>12291</id>
        <msg>SPYWARE-PUT Trackware vmn toolbar runtime detection</msg>
        <url>www.download.com/3000-12777_4-10693292.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jsp/AJmain.jsp?&quot;; fast_pattern; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;ptnrs=&quot;; nocase; http_uri; content:&quot;PG=&quot;; nocase; http_uri; content:&quot;SEC=&quot;; nocase; http_uri; content:&quot;searchfor=&quot;; nocase; http_uri; pcre:&quot;/st=(kwd|dns)/Ui&quot;; classtype:misc-activity;</filter2>
        <id>12292</id>
        <msg>SPYWARE-PUT Hijacker morpheus toolbar runtime detection - hijack/search</msg>
        <url>www.sophos.com/security/analyses/morpheustoolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/counter.php?&quot;; nocase; http_uri; content:&quot;tbid=&quot;; nocase; http_uri; content:&quot;do=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Toolbar&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12294</id>
        <msg>SPYWARE-PUT Hijacker 3search runtime detection - counter</msg>
        <url>www.softwarerevenue.org</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?q=&quot;; nocase; http_uri; content:&quot;Host|3A| downloadfile.org&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12295</id>
        <msg>SPYWARE-PUT Hijacker 3search runtime detection - hijacking</msg>
        <url>www.softwarerevenue.org</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/cab/version.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12296</id>
        <msg>SPYWARE-PUT Hijacker 3search runtime detection - update</msg>
        <url>www.softwarerevenue.org</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Bifrost_v1.2.1_detection; content:&quot;|00 00 00 9B|O|B0|h|FE|j|9A 1C|&quot;; depth:11; offset:1; classtype:trojan-activity;</filter2>
        <id>12298</id>
        <msg>BACKDOOR bifrost v1.2.1 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453114444</url>
      </rule>
      <rule>
        <bugtraq>2808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/catinfo&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1231</id>
        <msg>WEB-MISC VirusWall catinfo access</msg>
        <nessus>10650</nessus>
      </rule>
      <rule>
        <bugtraq>2808</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-0432</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1812</filter1>
        <filter2>flow:to_server,established; content:&quot;/catinfo&quot;; nocase; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1232</id>
        <msg>WEB-MISC VirusWall catinfo access</msg>
        <nessus>10650</nessus>
      </rule>
      <rule>
        <bugtraq>25440</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4561</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;require|3A|&quot;; nocase; content:&quot;|0A|require|3A|&quot;; distance:0; nocase; classtype:attempted-admin;</filter2>
        <id>12358</id>
        <msg>EXPLOIT Helix DNA Server RTSP require tag heap overflow</msg>
      </rule>
      <rule>
        <bugtraq>20617</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-5444</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2000</filter1>
        <filter2>flow:established,to_server; dsize:&gt;992; byte_test:4,&gt;,992,0,little; classtype:attempted-user;</filter2>
        <id>12359</id>
        <msg>VOIP-SIP Asterisk data length field overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;grabv2.php&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12361</id>
        <msg>SPYWARE-PUT Infostealer.Monstres runtime detection</msg>
        <url>www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-081617-4608-99</url>
      </rule>
      <rule>
        <bugtraq>10500</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2004-0541</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3128</filter1>
        <filter2>flow:established,to_server; content:&quot;Proxy-Authorization|3A| NTLM TlRMTVNTUAADA&quot;; http_header; content:!&quot;AAAGAAYA&quot;; http_header; classtype:attempted-user;</filter2>
        <id>12362</id>
        <msg>EXPLOIT Squid HTTP Proxy-Authorization overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;d=&quot;; nocase; http_uri; content:&quot;vs=&quot;; nocase; http_uri; content:&quot;Host|3A| www.malware-stopper.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12363</id>
        <msg>SPYWARE-PUT Other-Technologies malware-stopper runtime detection</msg>
        <url>www.spywareguide.com/spydet_3513_malware_stopper.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbaradmin/simt32.shq&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12364</id>
        <msg>SPYWARE-PUT Hijacker proventactics 3.5 runtime detection - get cfg information</msg>
        <url>www.spywareguide.com/spydet_1826_proventactics.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search/index.php?&quot;; nocase; http_uri; content:&quot;query_string=&quot;; nocase; http_uri; content:&quot;Host|3A| www.proventactics.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12365</id>
        <msg>SPYWARE-PUT Hijacker proventactics 3.5 runtime detection - redirect searches</msg>
        <url>www.spywareguide.com/spydet_1826_proventactics.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; nocase; http_uri; content:&quot;s=&quot;; nocase; http_uri; content:&quot;Host|3A| www.proventactics.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12366</id>
        <msg>SPYWARE-PUT Hijacker proventactics 3.5 runtime detection - toolbar search function</msg>
        <url>www.spywareguide.com/spydet_1826_proventactics.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/webResults.html?&quot;; nocase; http_uri; content:&quot;src=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| search.imesh.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12367</id>
        <msg>SPYWARE-PUT Hijacker imesh mediabar runtime detection - hijack ie searches</msg>
        <url>www.spywaredata.com/spyware/malware/mediabar.dll.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sidebar.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;src=ssb&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>12368</id>
        <msg>SPYWARE-PUT Hijacker imesh mediabar runtime detection - hijack ie side search</msg>
        <url>www.spywaredata.com/spyware/malware/mediabar.dll.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;__utm.gif?&quot;; nocase; http_uri; content:&quot;utmwv=&quot;; nocase; http_uri; content:&quot;utmn=&quot;; nocase; http_uri; content:&quot;utmcs=&quot;; nocase; http_uri; content:&quot;utmsr=&quot;; nocase; http_uri; content:&quot;utmhn=search.imesh.com&quot;; fast_pattern; nocase; http_uri; content:&quot;utmp=&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>12369</id>
        <msg>SPYWARE-PUT Hijacker imesh mediabar runtime detection - collect user information</msg>
        <url>www.spywaredata.com/spyware/malware/mediabar.dll.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/autoupdate/version.txt&quot;; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12370</id>
        <msg>SPYWARE-PUT Hijacker imesh mediabar runtime detection - auto update</msg>
        <url>www.spywaredata.com/spyware/malware/mediabar.dll.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| SpamBlockerUtility 4.8.4&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12371</id>
        <msg>SPYWARE-PUT Hijacker sbu hotbar 4.8.4 runtime detection - user-agent string</msg>
        <url>www.spywareguide.com/product_show.php?id=481</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;Mailer&quot;; distance:0; nocase; pcre:&quot;/^X-Mailer\x3a[^\r\n]*Mailer/smi&quot;; content:&quot;+++ MG-Shadow 2.0&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12372</id>
        <msg>SPYWARE-PUT Keylogger mg-shadow 2.0 runtime detection</msg>
        <url>www.softpedia.com/progDownload/MGShadow-Download-44651.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Radmin3.0_conn_detection; content:&quot;|01 00 00 00|%|00 00 02 12 08 02 00 00 0A 00 00|&quot;; depth:16; classtype:trojan-activity;</filter2>
        <id>12374</id>
        <msg>BACKDOOR radmin 3.0 runtime detection - initial connection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096740</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Radmin3.0_login_detection; content:&quot;|01 00 00 00 05 00 00 00|''|00 00 00 00|&quot;; depth:14; classtype:trojan-activity;</filter2>
        <id>12376</id>
        <msg>BACKDOOR radmin 3.0 runtime detection - login &amp; remote control</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453096740</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,sharK_2.3.2_detection; content:&quot;F|15 1D|K|80|?|03 00 01 09|5&quot;; depth:11;  classtype:trojan-activity;</filter2>
        <id>12378</id>
        <msg>BACKDOOR shark 2.3.2 runtime detection</msg>
        <url>www.spywaredb.com/remove-shark-trojan/</url>
      </rule>
      <rule>
        <bugtraq>1252</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0446</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2224</filter1>
        <filter2>flow:to_server,established; content:&quot;|01|1|DB CD 80 E8|[|FF FF FF|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>1240</id>
        <msg>EXPLOIT MDBMS overflow</msg>
        <nessus>10422</nessus>
      </rule>
      <rule>
        <bugtraq>2868</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2001-0555</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SWEditServlet&quot;; http_uri; content:&quot;template=../../../&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>1241</id>
        <msg>WEB-MISC SWEditServlet directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>6454</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-1643</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SETUP&quot;; depth:5; nocase; content:&quot;Transport|3A|&quot;; nocase; isdataat:256,relative; content:!&quot;|0A|&quot;; within:256; metadata:service rtsp; classtype:attempted-user;</filter2>
        <id>12421</id>
        <msg>EXPLOIT RealNetworks Helix RTSP long transport header</msg>
      </rule>
      <rule>
        <bugtraq>6454</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-1643</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:established,to_server; content:&quot;DESCRIBE&quot;; depth:8; nocase; isdataat:200; content:!&quot;|0A|&quot;; depth:200; classtype:attempted-user;</filter2>
        <id>12422</id>
        <msg>EXPLOIT RealNetworks Helix RTSP long describe request exploit attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <cve>2007-3040</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;HTTP&quot;; depth:4; content:&quot;|0D 0A 0D 0A C4 AB CD AB|&quot;; within:768; classtype:misc-activity;</filter2>
        <id>12454</id>
        <msg>MISC asf file download</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-051.mspx</url>
      </rule>
      <rule>
        <bugtraq>21261</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6133</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|FE FF|&quot;; content:&quot;|E0 85 9F F2 F9|Oh|10 AB 91 08 00|+'|B3 D9|&quot;; within:16; distance:26; content:!&quot;|01 00 00 00|&quot;; within:4; distance:-20; classtype:attempted-user;</filter2>
        <id>12463</id>
        <msg>EXPLOIT Crystal Reports RPT file handling buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS07-052.mspx</url>
      </rule>
      <rule>
        <bugtraq>9382</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0045</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 119</filter1>
        <filter2>flow:to_server,established; content:&quot;cancel&quot;; fast_pattern:only; pcre:&quot;/^cancel\x3a[^\n]{32}/smi&quot;; metadata:service nntp; classtype:attempted-admin;</filter2>
        <id>12464</id>
        <msg>NNTP cancel overflow attempt</msg>
        <nessus>11984</nessus>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/code/engine.cgi?&quot;; nocase; http_uri; content:&quot;toolbar_id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Toolbar&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12481</id>
        <msg>SPYWARE-PUT Hijacker 411web toolbar runtime detection</msg>
        <url>www.onetwo.ca/spyware.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| ZOMBIES_HTTP_GET&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12482</id>
        <msg>SPYWARE-PUT Trickler pseudorat 0.1b runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453079890</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy_online.php?&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;Host|3A| www.virusprotectpro.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12483</id>
        <msg>SPYWARE-PUT Other-Technologies virusprotectpro 3.7 runtime detection</msg>
        <url>www.xp-vista.com/spyware-removal/virusprotectpro-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/members.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;username=&quot;; nocase; http_uri; content:&quot;auth=&quot;; nocase; http_uri; content:&quot;page=&quot;; nocase; http_uri; pcre:&quot;/page=(messages|community)/Ui&quot;; classtype:misc-activity;</filter2>
        <id>12484</id>
        <msg>SPYWARE-PUT Adware instant buzz runtime detection - ads for members</msg>
        <url>www.spywareremove.com/removeInstantBuzz.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/click.php?&quot;; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| www2.instantbuzz.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12485</id>
        <msg>SPYWARE-PUT Adware instant buzz runtime detection - random text ads</msg>
        <url>www.spywareremove.com/removeInstantBuzz.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A| TencentTraveler&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12486</id>
        <msg>SPYWARE-PUT Hijacker soso toolbar runtime detection - get weather information</msg>
        <url>www.xblock.com/product_show.php?id=3333</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/q?&quot;; http_uri; content:&quot;w=&quot;; nocase; http_uri; content:&quot;sc=&quot;; nocase; http_uri; content:&quot;cin=&quot;; fast_pattern; nocase; http_uri; content:&quot;cid=&quot;; nocase; http_uri; pcre:&quot;/cid=tb\x2e(addr|sb)/Ui&quot;;  classtype:misc-activity;</filter2>
        <id>12487</id>
        <msg>SPYWARE-PUT Hijacker soso toolbar runtime detection - hijack ie auto searches / soso toolbar searches requests</msg>
        <url>www.xblock.com/product_show.php?id=3333</url>
      </rule>
      <rule>
        <bugtraq>2010</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>1999-0153</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135:139</filter1>
        <filter2>flow:stateless; flags:U+; classtype:attempted-dos;</filter2>
        <id>1257</id>
        <msg>DOS Winnuke attack</msg>
      </rule>
      <rule>
        <bugtraq>2845</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2001-0552</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/OvCgi/OpenView5.exe?Context=Snmp&amp;Action=Snmp&amp;Host=&amp;Oid=&quot;; nocase; http_uri; metadata:service http; classtype:misc-activity;</filter2>
        <id>1258</id>
        <msg>WEB-MISC HP OpenView Manager DOS</msg>
      </rule>
      <rule>
        <bugtraq>2868</bugtraq>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SWEditServlet&quot;; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1259</id>
        <msg>WEB-MISC SWEditServlet access</msg>
      </rule>
      <rule>
        <bugtraq>5678</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2002-1118</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;COMMAND=SERVICE_CURLOAD&quot;; fast_pattern:only; classtype:attempted-dos;</filter2>
        <id>12594</id>
        <msg>DOS Oracle TNS Service_CurLoad command</msg>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5003</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:established,to_server; content:&quot;rxrLogin&quot;; nocase; isdataat:281,relative; content:!&quot;~~&quot;; within:279; distance:2; classtype:attempted-admin;</filter2>
        <id>12596</id>
        <msg>EXPLOIT CA BrightStor LGServer username buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15408</bugtraq>
        <classtype>suspicious-filename-detect</classtype>
        <cve>2005-3573</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;filename*=utf-8&quot;; fast_pattern:only; classtype:suspicious-filename-detect;</filter2>
        <id>12597</id>
        <msg>DOS utf8 filename transfer attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/site_drivecleaner/ad_keyin/link_keyin/aff_keyin&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| stats.drivecleaner.com&quot;; nocase; classtype:misc-activity;</filter2>
        <id>12620</id>
        <msg>SPYWARE-PUT Adware drive cleaner 1.0.111 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=3150</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbarinfo.php?&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A| www.onlinecasinoextra.com&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12621</id>
        <msg>SPYWARE-PUT Trackware extra toolbar 1.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453117295</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/_vti_bin/owssvr.dll&quot;; nocase; http_uri; content:&quot;Host|3A| www.onlinecasinoextra.com&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12622</id>
        <msg>SPYWARE-PUT Trackware extra toolbar 1.0 runtime detection - file download</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453117295</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/b.cgi?&quot;; nocase; http_uri; content:&quot;bk=&quot;; nocase; http_uri; content:&quot;Host|3A| www.onestepsearch.net&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12623</id>
        <msg>SPYWARE-PUT Hijacker onestepsearch 1.0.118 runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=3762</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?vn&quot;; nocase; http_uri; content:&quot;partner=onestep&quot;; nocase; http_uri; content:&quot;ptag=&quot;; nocase; http_uri; content:&quot;initial_install=&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12624</id>
        <msg>SPYWARE-PUT Hijacker onestepsearch 1.0.118 runtime detection - upgrade</msg>
        <url>www.spywareguide.com/product_show.php?id=3762</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A|&quot;; nocase; content:&quot;Windows Supervisor Report&quot;; distance:0; nocase; content:&quot;&lt;title&gt;Windows Family Safety&lt;/title&gt;&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12625</id>
        <msg>SPYWARE-PUT Keylogger windows family safety 2.0 runtime detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453117306</url>
      </rule>
      <rule>
        <bugtraq>23832</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2007-2581</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sharepoint/&quot;; http_uri; pcre:&quot;/sharepoint[^\n]*\x22\s*\x29\s*\x3b/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>12629</id>
        <msg>WEB-MISC sharepoint cross site scripting attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-059.mspx</url>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;u|00|n|00|e|00|s|00|c|00|a|00|p|00|e|00|&quot;; fast_pattern:only; pcre:&quot;/(s\x00p\x00r\x00a\x00y\x00|r\x00e\x00t\x00u\x00r\x00n\x00_\x00a\x00d\x00d\x00r\x00e\x00s\x00s\x00|p\x00a\x00y\x00l\x00o\x00a\x00d\x00c\x00o\x00d\x00e\x00|s\x00h\x00e\x00l\x00l\x00c\x00o\x00d\x00e\x00|r\x00e\x00t\x00a\x00d\x00d\x00r\x00|r\x00e\x00t\x00a\x00d\x00d\x00r\x00e\x00s\x00s\x00|b\x00l\x00o\x00c\x00k\x00|p\x00a\x00y\x00l\x00o\x00a\x00d\x00|a\x00g\x00e\x00n\x00t\x00|h\x00s\x00p\x00t\x00)/smi&quot;; pcre:&quot;/u\x00n\x00e\x00s\x00c\x00a\x00p\x00e\x00\s*\x28(\x22|\x27|\x26quot\x3B|\x5c\x22)/smi&quot;; classtype:shellcode-detect;</filter2>
        <id>12630</id>
        <msg>SHELLCODE unescape unicode encoded shellcode</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3897</cve>
        <filter1>tcp $EXTERNAL_NET 119 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|12636;</filter2>
        <id>12636</id>
        <msg>NNTP XHDR buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-056.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2007-3896</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;%00%00&quot;; pcre:&quot;/(mailto|telnet|news|nntp|snews)\x3A%00%00/i&quot;; classtype:attempted-user;</filter2>
        <id>12643</id>
        <msg>WEB-CLIENT URI External handler arbitrary command attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-061.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.cgi&quot;; nocase; http_uri; content:&quot;Host|3A| www.quickbrowsersearch.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12652</id>
        <msg>SPYWARE-PUT Hijacker new.net domain 7.2.2 runtime detection - hijack browser</msg>
        <url>www.spywareguide.com/spydet_417_new_net.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/d/sr/&quot;; nocase; http_uri; content:&quot;xargs=&quot;; nocase; http_uri; content:&quot;yargs=&quot;; nocase; http_uri; content:&quot;Host|3A| rc12.overture.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12653</id>
        <msg>SPYWARE-PUT Hijacker new.net domain 7.2.2 runtime detection - download code</msg>
        <url>www.spywareguide.com/spydet_417_new_net.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/10023rel/landing.php&quot;; fast_pattern; nocase; http_uri; content:&quot;Rabio|3A|&quot;; nocase; content:&quot;search-enhancer&quot;; distance:0; nocase; pcre:&quot;/^Rabio\x3a[^\r\n]*search\x2Denhancer/smi&quot;; classtype:misc-activity;</filter2>
        <id>12654</id>
        <msg>SPYWARE-PUT Hijacker rabio 4.2 runtime detection - hijack browser</msg>
        <url>www.spywareguide.com/spydet_3770_rabio.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search-enhancer/updates/se.info&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12655</id>
        <msg>SPYWARE-PUT Hijacker rabio 4.2 runtime detection - download updates</msg>
        <url>www.spywareguide.com/spydet_3770_rabio.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/net.php&quot;; http_uri; content:&quot;login=&quot;; nocase; http_uri; content:&quot;vk=&quot;; nocase; http_uri; content:&quot;Host|3A| cserv.icoosoft.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12656</id>
        <msg>SPYWARE-PUT Adware icoo loader 2.5 runtime detection 1</msg>
        <url>www.spywareremove.com/removeICOOLoader.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upd.html&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri; content:&quot;Host|3A| www.icooloader.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12657</id>
        <msg>SPYWARE-PUT Adware icoo loader 2.5 runtime detection 2</msg>
        <url>www.spywareremove.com/removeICOOLoader.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?proto&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Updater&quot;; nocase; http_header; content:&quot;Host|3A| trial.updates.winsoftware.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12658</id>
        <msg>SPYWARE-PUT Adware winantivirus pro 2007 runtime detection</msg>
        <url>www.spywareremove.com/security/winantiviruspro2007-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get-update.php&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;said=&quot;; nocase; http_uri; content:&quot;Host|3A| www.thenmnetwork.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12659</id>
        <msg>SPYWARE-PUT Trickler zlob media codec runtime detection - automatic updates</msg>
        <url>ca.com/us/securityadvisor/pest/pest.aspx?id=453118001</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/redirect-settings.php&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;said=&quot;; nocase; http_uri; content:&quot;Host|3A| nameservicedirect.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12660</id>
        <msg>SPYWARE-PUT Trickler zlob media codec runtime detection - download redirect domains</msg>
        <url>ca.com/us/securityadvisor/pest/pest.aspx?id=453118001</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;terServer&quot;; nocase; http_header; pcre:&quot;/User-Agent\x3a[^\r\n]*terServer/iH&quot;;  metadata:service http; classtype:trojan-activity;</filter2>
        <id>12661</id>
        <msg>BACKDOOR troll.a runtime detection</msg>
        <url>www.sophos.com/virusinfo/analyses/trojtrolla.html</url>
      </rule>
      <rule>
        <bugtraq>24348</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5004</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>flow:established,to_server; content:&quot;rxrLogin~~&quot;; nocase; content:&quot;~~&quot;; distance:0; pcre:&quot;/^0*(([1-9]\d{3,})|([7-9]\d\d)|(6[7-9]\d)|(66[8-9]))/R&quot;; classtype:attempted-admin;</filter2>
        <id>12665</id>
        <msg>EXPLOIT CA BrightStor LGSever username buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25255</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-3872</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5053</filter1>
        <filter2>flow:established,to_server; content:&quot;|0F|&quot;; depth:1; byte_jump:2,0,relative; byte_test:2,&gt;,0,51,relative; classtype:attempted-admin;</filter2>
        <id>12666</id>
        <msg>EXPLOIT HP OpenView OVTrace buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/security/visit.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;qs=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| iebar&quot;; nocase; http_header; classtype:successful-recon-limited;</filter2>
        <id>12673</id>
        <msg>SPYWARE-PUT Trackware searchmiracle elitebar runtime detection - collect information</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/security/timer.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;seconds=&quot;; nocase; http_uri; content:&quot;type=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| iebar&quot;; nocase; http_header;  classtype:successful-recon-limited;</filter2>
        <id>12674</id>
        <msg>SPYWARE-PUT Trackware searchmiracle elitebar runtime detection - track activity</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 10110 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;VERSI |28|TheTheef|29|&quot;; depth:16; nocase; classtype:misc-activity;</filter2>
        <id>12675</id>
        <msg>BACKDOOR Versi TheTheef Detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;quicken_update.php&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| conspy.com&quot;; nocase; classtype:misc-activity;</filter2>
        <id>12676</id>
        <msg>SPYWARE-PUT Conspy Update Checking Detected</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2004-021210-1340-99&amp;tabid=2se</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ist/softwares/&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12677</id>
        <msg>SPYWARE-PUT Adware ISTBar runtime detection - softwares</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453075516</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/realtime-spy/&quot;; nocase; http_uri; content:&quot;Host|3A| www.spytech-web.com&quot;; nocase; http_header; classtype:misc-activity;</filter2>
        <id>12678</id>
        <msg>SPYWARE-PUT SpyTech Realtime Spy Detection</msg>
        <url>www.spytech-web.com</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;User-Agent|3A| MyWaySearchAssistant&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>12679</id>
        <msg>SPYWARE-PUT Trackware myway speedbar / mywebsearch toolbar user-agent detection</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405</url>
      </rule>
      <rule>
        <bugtraq>24542</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3369</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:established; content:&quot;Via|3A|&quot;; fast_pattern:only; pcre:&quot;/^Via\x3A\s+SIP\x2F2\x2E0\x2F(TCP|UDP)\s+[^\x3B\r\n]{63}/smi&quot;; classtype:attempted-user;</filter2>
        <id>12680</id>
        <msg>VOIP-SIP Via header hostname buffer overflow attempt - TCP</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:established; content:&quot; sip|3A|&quot;; fast_pattern:only; pcre:&quot;/^[A-Z]+\s+sip\x3A[^\r\n\x40]{256}/smi&quot;; classtype:misc-activity;</filter2>
        <id>12681</id>
        <msg>VOIP-SIP SIP URI possible overflow</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>6904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-1115</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>flow:established; content:&quot;To|3A|&quot;; fast_pattern:only; pcre:&quot;/^To\x3A\s+[^\r\n]{256}/smi&quot;; classtype:attempted-user;</filter2>
        <id>12682</id>
        <msg>VOIP-SIP From header field buffer overflow attempt - TCP</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>6904</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2003-1115</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;To|3A|&quot;; nocase; pcre:&quot;/^To\x3A\s+[^\r\n]{256}/smi&quot;; classtype:attempted-user;</filter2>
        <id>12683</id>
        <msg>VOIP-SIP From header field buffer overflow attempt - UDP</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <bugtraq>952</bugtraq>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 7323 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;SyGate |0A|&quot;; depth:8; nocase; classtype:misc-activity;</filter2>
        <id>12684</id>
        <msg>BACKDOOR Sygate Remote Administration Engine</msg>
        <url>marc.info/?l=bugtraq&amp;m=94934808714972&amp;w=2</url>
      </rule>
      <rule>
        <bugtraq>25743</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4880</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1581</filter1>
        <filter2>flow:established,to_server; content:&quot;Host|3A|&quot;; nocase; isdataat:64,relative; content:!&quot;|00|&quot;; within:64; content:!&quot;|3A|&quot;; within:64; content:!&quot;|0A|&quot;; within:64; classtype:attempted-admin;</filter2>
        <id>12685</id>
        <msg>EXPLOIT IBM Tivoli Storage Manger Express CAD Host buffer overflow</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;PWeb&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;.personalweb.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*PWeb/smiH&quot;; pcre:&quot;/^Host\x3a[^\r\n]*\x2epersonalweb\x2ecom/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>12693</id>
        <msg>SPYWARE-PUT Hijacker personalweb runtime detection</msg>
        <url>www.spywareguide.com/spydet_3785_personal_web.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?proto&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Updater&quot;; nocase; http_header; content:&quot;Host|3A| free.version.bestsellerantivirus.com&quot;; fast_pattern:only; pcre:&quot;/^User-Agent\x3a[^\r\n]*Updater/smiH&quot;; classtype:misc-activity;</filter2>
        <id>12694</id>
        <msg>SPYWARE-PUT Adware avsystemcare runtime detection</msg>
        <url>www.spywareguide.com/spydet_3529_avsystemcare.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/61/param.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;groupID=&quot;; nocase; http_uri; content:&quot;spaceIDs=&quot;; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12695</id>
        <msg>SPYWARE-PUT Adware coopen 3.6.1 runtime detection - initial connection</msg>
        <url>www.spywareguide.com/spydet_3326_coopen.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ForceUpgrade.aspx&quot;; fast_pattern; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; content:&quot;hdid=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>12696</id>
        <msg>SPYWARE-PUT Adware coopen 3.6.1 runtime detection - automatic upgrade</msg>
        <url>www.spywareguide.com/spydet_3326_coopen.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data/track.aspx&quot;; nocase; http_uri; content:&quot;Host|3A| data.browseraccelerator.com&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>12697</id>
        <msg>SPYWARE-PUT Trackware browser accelerator runtime detection - pass user information to server</msg>
        <url>www.spywareguide.com/spydet_1253_browseracclerator.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;This is an alert notification from NetVizor&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>12698</id>
        <msg>SPYWARE-PUT Keylogger net vizo 5.2 runtime detection</msg>
        <url>ca.com/us/securityadvisor/pest/pest.aspx?id=453097457</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,PoisonIvy2.3.0_initDetection; content:&quot;|E0 F5|=|C1 F0 EA 15 DB|C&gt;e|F8 9B E2 14 BA|&quot;; depth:16;  classtype:trojan-activity;</filter2>
        <id>12700</id>
        <msg>BACKDOOR poison ivy 2.3.0 runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=PoisonIvy&amp;threatid=43179</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1935</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 80</filter1>
        <filter2>flow:established,to_server; content:&quot;Authorization|3A| Negotiate YIIQegYGKwYBBQUCoIIQbjCCEGqhghBmI4IQYgOCBAEAQUFBQUF&quot;; http_header; classtype:attempted-admin;</filter2>
        <id>12709</id>
        <msg>SPECIFIC-THREATS ASN.1 constructed bit string</msg>
        <url>www.phreedom.org/solar/exploits/msasn1-bitstring/</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-1935</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 445</filter1>
        <filter2>flow:established,to_server; content:&quot;|FF|SMB&quot;; depth:8; content:&quot;+|06 01 05 05 02|&quot;; content:&quot;AAAAAAAAAA&quot;; within:10; distance:21; classtype:attempted-admin;</filter2>
        <id>12710</id>
        <msg>SPECIFIC-THREATS ASN.1 constructed bit string</msg>
        <url>www.phreedom.org/solar/exploits/msasn1-bitstring/</url>
      </rule>
      <rule>
        <bugtraq>26001</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-5381</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>content:&quot;+|06 01 02 01 01 05 00|&quot;; byte_test:1,&gt;,99,1,relative; classtype:attempted-admin;</filter2>
        <id>12712</id>
        <msg>SNMP oversized sysName set request</msg>
      </rule>
      <rule>
        <bugtraq>26374</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-4517</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;pitrig_dropmetadata&quot;; nocase; pcre:&quot;/pitrig_dropmetadata\x28[^\x29]{520,}?/i&quot;; classtype:attempted-admin;</filter2>
        <id>12713</id>
        <msg>ORACLE pitrig_dropmetadata buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/results.php?target=&quot;; nocase; http_uri; content:&quot;Host|3A| www.sidefind.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12718</id>
        <msg>SPYWARE-PUT Hijacker side find 1.0 runtime detection - initial connection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453088285</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bin/findwhat.dll?&quot;; nocase; http_uri; content:&quot;Host|3A| admedia.xmlsearch.findwhat.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12719</id>
        <msg>SPYWARE-PUT Hijacker side find 1.0 runtime detection - hijacks search engine</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453088285</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SpyBase/version.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;AlertSpy&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*AlertSpy/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>12720</id>
        <msg>SPYWARE-PUT Adware pestbot runtime detection - update</msg>
        <url>www.spywarewarrior.com/rogue_anti-spyware.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/purchase/&quot;; nocase; http_uri; content:&quot;Host|3A| pestbot.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>12721</id>
        <msg>SPYWARE-PUT Adware pestbot runtime detection - purchase</msg>
        <url>www.spywarewarrior.com/rogue_anti-spyware.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?adv=usernames&amp;p=1&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| icoonet.com&quot;; nocase; classtype:misc-activity;</filter2>
        <id>12722</id>
        <msg>SPYWARE-PUT Hijacker sexyvideoscreensaver runtime detection</msg>
        <url>www.spywareguide.com/spydet_2535_sexyvideoscreensaver.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stats/stats.php&quot;; fast_pattern; nocase; http_uri; content:&quot;AppName=WinZix&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;WakeSpace&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3a[^\r\n]*WakeSpace/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>12723</id>
        <msg>SPYWARE-PUT Trackware winzix 2.2.0 runtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453118801</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,DarkMoon411_detection; content:&quot;1bsrCwE93uxp&quot;; depth:12; classtype:trojan-activity;</filter2>
        <id>12725</id>
        <msg>BACKDOOR dark moon 4.11 runtime detection</msg>
        <url>www.spywareguide.com/spydet_2745_dark_moon.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Bandook135_detection; content:&quot;|CF AB A8 A7 AE CF|&quot;; depth:6;  classtype:trojan-activity;</filter2>
        <id>12727</id>
        <msg>BACKDOOR bandook 1.35 runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&amp;threatid=40408</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,DigiWatcher232_detection; content:&quot;Motion&quot;; nocase; content:&quot;detected!&quot;; distance:0; nocase; content:&quot;Watcher&quot;; distance:0; nocase; content:&quot;PC&quot;; distance:0; nocase; content:&quot;IP&quot;; distance:0; nocase; content:&quot;address|3A|&quot;; distance:0; nocase; pcre:&quot;/Motion\s+detected\x21/smi&quot;; pcre:&quot;/Watcher\s+PC\s+IP\s+address\x3A/smi&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12759</id>
        <msg>SPYWARE-PUT Keylogger/RAT digi watcher 2.32 runtime detection</msg>
        <url>www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453119363</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,PoweredKeylogger22_detection; content:&quot;Please,&quot;; nocase; content:&quot;find&quot;; distance:0; nocase; content:&quot;the&quot;; distance:0; nocase; content:&quot;log&quot;; distance:0; nocase; content:&quot;file&quot;; distance:0; nocase; content:&quot;|28|PKL|29|&quot;; distance:0; nocase; content:&quot;attached&quot;; distance:0; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;this&quot;; distance:0; nocase; content:&quot;e-mail.&quot;; distance:0; nocase; pcre:&quot;/Please\x2C\s+find\s+the\s+log\s+file\s+\x28PKL\x29\s+attached\s+to\s+this\s+e\x2Dmail\x2E/smi&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12761</id>
        <msg>SPYWARE-PUT Keylogger powered Keylogger 2.2 runtime detection</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453097852</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/gate/chkupdate.php&quot;; nocase; http_uri; content:&quot;Host|3A| www.sunshinespy.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12789</id>
        <msg>SPYWARE-PUT Adware sunshine spy 1.0 runtime detection - check update</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Sunshine%20Spy&amp;threatid=171191</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/utility/client/images/ProductVersion.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A| www.partycasino.com&quot;; nocase; classtype:successful-recon-limited;</filter2>
        <id>12790</id>
        <msg>SPYWARE-PUT Trackware partypoker runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=PartyPoker&amp;threatid=44086</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/application/app_counter/?gopver=&quot;; fast_pattern; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>12791</id>
        <msg>SPYWARE-PUT Adware gophoria toolbar runtime detection</msg>
        <url>www.spywareguide.com/spydet_3093_gophoria_toolbar.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,SpyLanternKeylogger6_detection; content:&quot;filename=|22|&quot;; nocase; content:&quot;.ltr&quot;; distance:0; nocase; pcre:&quot;/filename\x3D\x22[^\r\n]*\x2Eltr\x22/smi&quot;;  classtype:successful-recon-limited;</filter2>
        <id>12793</id>
        <msg>SPYWARE-PUT Keylogger spy lantern Keylogger pro 6.0 runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Spy%20Lantern%20Keylogger&amp;threatid=29156</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/SearchFraudDBProcess.php?vbfraudURL=&quot;; fast_pattern; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>12794</id>
        <msg>SPYWARE-PUT Hijacker gralicwrap runtime detection - search frauddb process</msg>
        <url>www.spywareguide.com/spydet_2594_gralicwrap.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/DisplayFraudDBInformation.php?id=&quot;; fast_pattern; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>12795</id>
        <msg>SPYWARE-PUT Hijacker gralicwrap runtime detection - display frauddb information</msg>
        <url>www.spywareguide.com/spydet_2594_gralicwrap.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htftool.php?q=&quot;; nocase; http_uri; content:&quot;Host|3A| happytofind.com&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>12796</id>
        <msg>SPYWARE-PUT Trackware happytofind toolbar runtime detection</msg>
        <url>www.spywareguide.com/spydet_3157_happytofind.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xcon/XP/update.enc?=&quot;; nocase; http_uri; content:&quot;Host|3A| x-conspywaredestroyer.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>12797</id>
        <msg>SPYWARE-PUT Adware x-con spyware destroyer eh 3.2.8 runtime detection</msg>
        <url>x-conspywaredestroyer.com</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:from_client,established; content:&quot;/readme.eml&quot;; nocase; http_uri; classtype:attempted-user;</filter2>
        <id>1284</id>
        <msg>WEB-CLIENT readme.eml download attempt</msg>
        <url>www.cert.org/advisories/CA-2001-26.html</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;window.open|28 22|readme.eml|22|&quot;; nocase; classtype:attempted-user;</filter2>
        <id>1290</id>
        <msg>WEB-CLIENT readme.eml autoload attempt</msg>
        <url>www.cert.org/advisories/CA-2001-26.html</url>
      </rule>
      <rule>
        <bugtraq>2721</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0740</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/graphics/sml3com&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1291</id>
        <msg>WEB-MISC sml3com access</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-3901</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;SAMI&gt;&quot;; fast_pattern:only; content:&quot;HEAD&quot;; distance:0; nocase; pcre:&quot;/\x3C[^\x3E\x0a]{500}/Ri&quot;; metadata:policy balanced-ips drop, service http; classtype:attempted-admin;</filter2>
        <id>12983</id>
        <msg>EXPLOIT DirectX SAMI file CRawParser attempted buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS07-064.mspx</url>
      </rule>
      <rule>
        <bugtraq>3375</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1252</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/console.exe&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1302</id>
        <msg>WEB-MISC console.exe access</msg>
      </rule>
      <rule>
        <bugtraq>3375</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2001-1252</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/cs.exe&quot;; nocase; http_uri; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1303</id>
        <msg>WEB-MISC cs.exe access</msg>
      </rule>
      <rule>
        <bugtraq>3474</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2001-0838</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4321</filter1>
        <filter2>flow:to_server,established; content:&quot;-soa %p&quot;; classtype:misc-attack;</filter2>
        <id>1323</id>
        <msg>EXPLOIT rwhoisd format string attempt</msg>
        <nessus>10790</nessus>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,ActiveKeylogger392_detection; content:&quot;filename=|22|&quot;; nocase; content:&quot;akllogs.zip|22|&quot;; distance:0; nocase; pcre:&quot;/filename\x3D\x22[^\r\n]*akllogs\x2Ezip\x22/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13237</id>
        <msg>SPYWARE-PUT Keylogger active Keylogger 3.9.2 runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Active%20Key%20Logger&amp;threatid=1622</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/nodes.cgi&quot;; fast_pattern; nocase; http_uri; content:&quot;app=Porn2Peer&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13238</id>
        <msg>SPYWARE-PUT Adware adult p2p 1.5 runtime detection</msg>
        <url>ca.com/us/securityadvisor/pest/pest.aspx?id=453122013</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/links/search.cgi&quot;; nocase; http_uri; content:&quot;query=&quot;; nocase; http_uri; content:&quot;Host|3A| www.bluewavelinks.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13239</id>
        <msg>SPYWARE-PUT Hijacker blue wave adult links toolbar runtime detection</msg>
        <url>www.bluewavelinks.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php?&quot;; nocase; http_uri; content:&quot;advid=&quot;; nocase; http_uri; content:&quot;emla=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;Host|3A| www.liveprotection.net&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13240</id>
        <msg>SPYWARE-PUT Adware live protection 2.1 runtime detection - redirects to purchase page</msg>
        <url>liveprotection.net</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;d=&quot;; nocase; http_uri; content:&quot;vs=&quot;; nocase; http_uri; content:&quot;Host|3A| www.LiveProtection.net&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13241</id>
        <msg>SPYWARE-PUT Adware live protection 2.1 runtime detection - application updates</msg>
        <url>liveprotection.net</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;NetPumper&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*NetPumper/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>13242</id>
        <msg>SPYWARE-PUT Adware netpumper 1.26 runtime detection</msg>
        <url>www.spywareguide.com/spydet_975_netpumper_1_2.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,ComputerMonitor11_detection; content:&quot;Computer&quot;; nocase; content:&quot;Monitor&quot;; distance:0; nocase; content:&quot;by&quot;; distance:0; nocase; content:&quot;Lastcomfort&quot;; distance:0; nocase; pcre:&quot;/Computer\s+Monitor\s+by\s+Lastcomfort/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13244</id>
        <msg>SPYWARE-PUT Keylogger computer monitor 1.1 by lastcomfort runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Computer%20Monitor&amp;threatid=48576</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Troya_1_4_detection; content:&quot;&lt;title&gt;&quot;; nocase; content:&quot;Troya&quot;; distance:0; nocase; content:&quot;-&quot;; distance:0; nocase; content:&quot;by&quot;; distance:0; nocase; content:&quot;Sma&quot;; distance:0; nocase; content:&quot;Soft&quot;; distance:0; nocase; content:&quot;&lt;/title&gt;&quot;; distance:0; nocase; pcre:&quot;/\x3Ctitle\x3ETroya\s+\x2D\s+by\s+Sma\s+Soft\x3C\x2Ftitle\x3E/smi&quot;; classtype:trojan-activity;</filter2>
        <id>13246</id>
        <msg>BACKDOOR troya 1.4 runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Troya&amp;threatid=41533</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Yuri_1_2_detection; content:&quot;|7C|&quot;; nocase; content:&quot;|7C|&quot;; distance:0; nocase; content:&quot;|7C|Yuri&quot;; distance:0; nocase; content:&quot;v1.&quot;; distance:0; nocase; content:&quot;|7C|&quot;; distance:0; nocase; pcre:&quot;/\x7C\d+\x2E\d+\x2E\d+\x2E\d+\x7C.*\x7CYuri\s+v1\x2E\d+\x7C/smi&quot;; classtype:trojan-activity;</filter2>
        <id>13248</id>
        <msg>BACKDOOR yuri 1.2 runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.Yuri%20RAT&amp;threatid=48528</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;nntp|3A|&quot;; nocase; pcre:&quot;/^[^\n]*?(\x2E(com|bat|cmd|exe)((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5c)00)/Ri&quot;; classtype:attempted-user;</filter2>
        <id>13269</id>
        <msg>EXPLOIT Multiple product nntp uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;news|3A|&quot;; nocase; pcre:&quot;/^[^\n]*?(\x2E(com|bat|cmd|exe)((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5c)00)/Ri&quot;; classtype:attempted-user;</filter2>
        <id>13270</id>
        <msg>EXPLOIT Multiple product news uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;telnet|3A|&quot;; nocase; pcre:&quot;/^[^\n]*?(\x2E(com|bat|cmd|exe)((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5c)00)/Ri&quot;; classtype:attempted-user;</filter2>
        <id>13271</id>
        <msg>EXPLOIT Multiple product telnet uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mailto|3A|&quot;; nocase; content:&quot;|2E|exe&quot;; within:500; nocase; pcre:&quot;/mailto\x3A[^\n]*?(\x2Eexe((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5cx)00)/i&quot;; classtype:attempted-user;</filter2>
        <id>13272</id>
        <msg>EXPLOIT Multiple product mailto uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,AdvancedSpy_detection; content:&quot;filename=&quot;; nocase; content:&quot;|22|as_report_&quot;; distance:0; nocase; content:&quot;.zip|22|&quot;; distance:0; nocase; pcre:&quot;/filename\s*\x3D\s*\x22as\x5Freport\x5F[^\x22]+\x2Ezip\x22/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13279</id>
        <msg>SPYWARE-PUT Keylogger advanced spy 4.0 runtime detection</msg>
        <url>www.advancedspy.net/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,EmailSpyMonitor_detection; content:&quot;&lt;title&gt;&quot;; nocase; content:&quot;Email&quot;; distance:0; nocase; content:&quot;Spy&quot;; distance:0; nocase; content:&quot;Monitor&quot;; distance:0; nocase; content:&quot;Logging&quot;; distance:0; nocase; content:&quot;Report&quot;; distance:0; nocase; content:&quot;&lt;/title&gt;&quot;; distance:0; nocase; pcre:&quot;/\x3CTitle\x3EEmail\s+Spy\s+Monitor\s+Logging\s+Report\x3C\x2Ftitle\x3E/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13281</id>
        <msg>SPYWARE-PUT Keylogger email spy monitor 6.9 runtime detection</msg>
        <url>www.spywareremove.com/removeEmailSpyMonitor.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/123bar/search.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;sengine=&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;Host|3A| soft.jily.net&quot;; nocase;  classtype:misc-activity;</filter2>
        <id>13282</id>
        <msg>SPYWARE-PUT Adware jily ie toolbar runtime detection</msg>
        <url>www.www.spywareguide.com/product_show.php?id=2425</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/setting/geturl_kword.html&quot;; fast_pattern; nocase; http_uri; content:&quot;uCode=&quot;; nocase; http_uri; content:&quot;Host|3A| oper.dreambar.co.kr&quot;; nocase; classtype:misc-activity;</filter2>
        <id>13283</id>
        <msg>SPYWARE-PUT Hijacker dreambar runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Dreambar&amp;threatid=97491</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/webcleaner/en/updatelist.ini&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;NetGuarder WebCleaner&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*NetGuarder\s+WebCleaner/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13284</id>
        <msg>SPYWARE-PUT Adware netguarder web cleaner runtime detection</msg>
        <url>www.spywareguide.com/spydet_1824_netguarder_web_cleaner.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/__utm.gif?&quot;; nocase; http_uri; content:&quot;utmwv=&quot;; nocase; http_uri; content:&quot;utmn=&quot;; nocase; http_uri; content:&quot;utmhn=www.crawl.ws&quot;; fast_pattern; nocase; http_uri; content:&quot;utmr=&quot;; nocase; http_uri; content:&quot;utmp=&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>13285</id>
        <msg>SPYWARE-PUT Hijacker phazebar runtime detection</msg>
        <url>www.uninstall-spyware.com/uninstallPhaZeBar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stats/stats.php&quot;; fast_pattern; nocase; http_uri; content:&quot;AppName=3wPlayer&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;WakeSpace&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3A[^\r\n]*WakeSpace/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13286</id>
        <msg>SPYWARE-PUT Adware 3wplayer 1.7 runtime detection</msg>
        <url>www.spywareremove.com/remove3wPlayer.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search_total.asp&quot;; nocase; http_uri; content:&quot;recid=directtb&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| search.interich.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13339</id>
        <msg>SPYWARE-PUT Hijacker direct toolbar runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Direct.Toolbar&amp;threatid=133225</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/0409/as.asp?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A| www.search4top.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13340</id>
        <msg>SPYWARE-PUT Hijacker search4top runtime detection - hijack ie searches and error pages</msg>
        <url>www.spywareguide.com/spydet_3578_search4top.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adjs.php?&quot;; nocase; http_uri; content:&quot;n=&quot;; nocase; http_uri; content:&quot;what=&quot;; nocase; http_uri; content:&quot;target=&quot;; nocase; http_uri; content:&quot;exclude=&quot;; nocase; http_uri; content:&quot;Referer|3A| www.search4top.com/english.asp?q=&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>13341</id>
        <msg>SPYWARE-PUT Hijacker search4top runtime detection - popup ads</msg>
        <url>www.spywareguide.com/spydet_3578_search4top.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/searchResults.asp&quot;; nocase; http_uri; content:&quot;mainToolbar=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;ss=&quot;; nocase; http_uri; content:&quot;Host|3A| www.ditto.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13342</id>
        <msg>SPYWARE-PUT Hijacker ditto toolbar runtime detection</msg>
        <url>www.emsisoft.it/it/malware/?Adware.Win32.Ditto+Toolbar</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/go/go.php&quot;; nocase; http_uri; content:&quot;Host|3A| 2005-search.com&quot;; fast_pattern:only;  classtype:misc-activity;</filter2>
        <id>13343</id>
        <msg>SPYWARE-PUT Adware 2005-search loader runtime detection</msg>
        <url>www.malware.com.br/cgi/submit?action=list_comp</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/privacy/presale.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;lp=&quot;; nocase; http_uri; content:&quot;addt=&quot;; nocase; http_uri; content:&quot;air=&quot;; nocase; http_uri; content:&quot;lir=&quot;; nocase; http_uri; content:&quot;afr=&quot;; nocase; http_uri; content:&quot;rem=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13344</id>
        <msg>SPYWARE-PUT Adware yourprivacyguard runtime detection - presale request</msg>
        <url>www.spywaredetector.net/spyware_encyclopedia/Adware.Yourprivacyguard.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;proto=&quot;; nocase; http_uri; content:&quot;rc=&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;abbr=&quot;; nocase; http_uri; content:&quot;platform=&quot;; nocase; http_uri; content:&quot;os_version=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| Updater&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13345</id>
        <msg>SPYWARE-PUT Adware yourprivacyguard runtime detection - update</msg>
        <url>www.spywaredetector.net/spyware_encyclopedia/Adware.Yourprivacyguard.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,RemoteDesktopInspector_detection; content:&quot;DS&quot;; depth:2; nocase; content:&quot;|00 00 01 00 00 00 00 FE 01 00 00 F1 00 00 00 00|&quot;; within:16; distance:2; nocase; classtype:successful-recon-limited;</filter2>
        <id>13347</id>
        <msg>SPYWARE-PUT Snoopware remote desktop inspector runtime detection - init connection</msg>
        <url>www.emsisoft.com/es/malware/?Adware.Win32.Remote+Desktop+Inspector</url>
      </rule>
      <rule>
        <bugtraq>26927</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6335</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MZ&quot;; depth:2; content:&quot;PE&quot;; content:&quot;MEW&quot;; content:!&quot;|00|&quot;; within:1; distance:8; metadata:service http; classtype:attempted-user;</filter2>
        <id>13361</id>
        <msg>EXPLOIT ClamAV MEW PE file integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>26927</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6335</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;MZ&quot;; depth:2; content:&quot;PE&quot;; content:&quot;MEW&quot;; content:!&quot;|00|&quot;; within:1; distance:48; metadata:service http; classtype:attempted-user;</filter2>
        <id>13362</id>
        <msg>EXPLOIT ClamAV MEW PE file integer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>20986</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-5821</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2513</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|13417;</filter2>
        <id>13417</id>
        <msg>EXPLOIT Citrix MetaFrame IMA authentication processing buffer overflow attempt</msg>
        <url>support.citrix.com/article/CTX111186</url>
      </rule>
      <rule>
        <bugtraq>16593</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2006-0717</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13418;</filter2>
        <id>13418</id>
        <msg>DOS IBM Tivoli Director LDAP server invalid DN message buffer overflow attempt</msg>
        <url>www-1.ibm.com/support/docview.wss?uid=swq21230820</url>
      </rule>
      <rule>
        <bugtraq>20939</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2006-5779</cve>
        <filter1>tcp any any -&gt; $HOME_NET 389</filter1>
        <filter2>gid:3; classtype:denial-of-service; metadata: engine shared, soid 3|13425;</filter2>
        <id>13425</id>
        <msg>DOS openldap server bind request denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0083</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13448;</filter2>
        <id>13448</id>
        <msg>WEB-CLIENT vbscript/jscript scripting engine begin buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-022.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-0083</cve>
        <filter1>tcp $EXTERNAL_NET 80 -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|13449;</filter2>
        <id>13449</id>
        <msg>WEB-CLIENT vbscript/jscript scripting engine end buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-022.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2008-0084</cve>
        <filter1>udp $HOME_NET 67 -&gt; $HOME_NET 68</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|13450;</filter2>
        <id>13450</id>
        <msg>BAD-TRAFFIC invalid dhcp offer denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-004.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,FindNotGuardDog_detection; content:&quot;X-Mailer|3A|&quot;; nocase; content:&quot;FindNot&quot;; distance:0; nocase; content:&quot;GuardDog&quot;; distance:0; nocase; pcre:&quot;/^X\x2DMailer\x3A[^\r\n]*FindNot\s+GuardDog/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13480</id>
        <msg>SPYWARE-PUT Keylogger findnot guarddog 4.0 runtime detection</msg>
        <url>www.findnot.eu/pg_guarddog.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/baidu?&quot;; fast_pattern; nocase; http_uri; content:&quot;tn=&quot;; nocase; http_uri; content:&quot;baiducb&quot;; nocase; http_uri; content:&quot;word=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13481</id>
        <msg>SPYWARE-PUT Hijacker baidu toolbar runtime detection - hijacks search engine</msg>
        <url>www.spywareguide.com/product_show.php?id=1250</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bdinfo.txt?&quot;; fast_pattern; nocase; http_uri; content:&quot;userip=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;navigate=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;bar-get&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3A[^\r\n]*bar\x2Dget/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13482</id>
        <msg>SPYWARE-PUT Hijacker baidu toolbar runtime detection - discloses information</msg>
        <url>www.spywareguide.com/product_show.php?id=1250</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; flowbits:isset,BaiduToolbar_detection; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;bar-get&quot;; nocase; http_header; pcre:&quot;/^User\x2DAgent\x3A[^\r\n]*bar\x2Dget/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13484</id>
        <msg>SPYWARE-PUT Hijacker baidu toolbar runtime detection - updates automatically</msg>
        <url>www.spywareguide.com/product_show.php?id=1250</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.htm?&quot;; fast_pattern; nocase; http_uri; content:&quot;st=&quot;; nocase; http_uri; content:&quot;dir=&quot;; nocase; http_uri; content:&quot;wd=&quot;; nocase; http_uri; content:&quot;wid=&quot;; nocase; http_uri; content:&quot;sofa&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;soft&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13485</id>
        <msg>SPYWARE-PUT Hijacker sofa toolbar runtime detection - hijacks search engine</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.Softomate.ag</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cm?&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;010.eqiso.com&quot;; fast_pattern; nocase; http_uri; content:&quot;i=&quot;; nocase; http_uri; content:&quot;w=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13486</id>
        <msg>SPYWARE-PUT Hijacker sofa toolbar runtime detection - records search information</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.Softomate.ag</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;EliteProtector&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*EliteProtector/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13487</id>
        <msg>SPYWARE-PUT Adware elite protector runtime detection</msg>
        <url>www.threatexpert.com/report.aspx?uid=413fd424-4727-46bb-af1b-125e21b34afb</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/peoplepal/upgrade/?&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;PeoplePal Version Checker&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*PeoplePal\s+Version\s+Checker/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13488</id>
        <msg>SPYWARE-PUT Hijacker people pal toolbar runtime detection - automatic upgrade</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.PeoplePal</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search?&quot;; nocase; http_uri; content:&quot;area=&quot;; nocase; http_uri; content:&quot;cgid=&quot;; nocase; http_uri; content:&quot;category=&quot;; fast_pattern; nocase; http_uri; content:&quot;peoplepal&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>13489</id>
        <msg>SPYWARE-PUT Hijacker people pal toolbar runtime detection - traffic for searching</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.PeoplePal</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php?&quot;; nocase; http_uri; content:&quot;advid=&quot;; nocase; http_uri; content:&quot;emla=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;Host|3A| www.spy-shredder.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13490</id>
        <msg>SPYWARE-PUT Adware spy shredder 2.1 runtime detection - presale request</msg>
        <url>www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453123853</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;d=&quot;; nocase; http_uri; content:&quot;Host|3A| www.spy-shredder.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13491</id>
        <msg>SPYWARE-PUT Adware spy shredder 2.1 runtime detection - update</msg>
        <url>www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453123853</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/baidu?&quot;; nocase; http_uri; content:&quot;word=&quot;; nocase; http_uri; content:&quot;tn=deepbar&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13492</id>
        <msg>SPYWARE-PUT Hijacker deepdo toolbar runtime detection - redirects search engine</msg>
        <url>www.spywareguide.com/product_show.php?id=3367</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download/toolbar.ini&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;DeepdoUpdate&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*DeepdoUpdate/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13493</id>
        <msg>SPYWARE-PUT Hijacker deepdo toolbar runtime detection - automatic update</msg>
        <url>www.spywareguide.com/product_show.php?id=3367</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Smart PC Keylogger - Log File Mailing&quot;; fast_pattern:only; content:&quot;X-Mailer|3A| Smart PC Keylogger&quot;; nocase; classtype:successful-recon-limited;</filter2>
        <id>13494</id>
        <msg>SPYWARE-PUT Keylogger smart pc Keylogger runtime detection</msg>
        <url>www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453124511</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/ezt_serverside.xml&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13495</id>
        <msg>SPYWARE-PUT Hijacker ez-tracks toolbar runtime detection - initial traffic 1</msg>
        <url>www.spywareremove.com/removeEZTracks.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ezt/toolbar/&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13496</id>
        <msg>SPYWARE-PUT Hijacker ez-tracks toolbar runtime detection - initial traffic 2</msg>
        <url>www.spywareremove.com/removeEZTracks.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/TBTracking/TrackLinkClicks.cfm?&quot;; fast_pattern; nocase; http_uri; content:&quot;linkID=&quot;; nocase; http_uri; content:&quot;ToolBarID=&quot;; nocase; http_uri; content:&quot;TBSearch=&quot;; nocase; http_uri; content:&quot;Host|3A| ez-tracks.com&quot;; nocase;  classtype:misc-activity;</filter2>
        <id>13497</id>
        <msg>SPYWARE-PUT Hijacker ez-tracks toolbar runtime detection - tracking traffic</msg>
        <url>www.spywareremove.com/removeEZTracks.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jump.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;t2t21&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;siteid=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13498</id>
        <msg>SPYWARE-PUT Hijacker hbtbar runtime detection - search traffic 1</msg>
        <url>www.spywareremove.com/removeHDTBar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/baidu?&quot;; nocase; http_uri; content:&quot;tn=t2t21&quot;; fast_pattern; nocase; http_uri; content:&quot;word=&quot;; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>13499</id>
        <msg>SPYWARE-PUT Hijacker hbtbar runtime detection - search traffic 2</msg>
        <url>www.spywareremove.com/removeHDTBar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/log.htm?&quot;; nocase; http_uri; content:&quot;website_id=&quot;; fast_pattern; nocase; http_uri; content:&quot;unique=&quot;; nocase; http_uri; content:&quot;all_unique=&quot;; nocase; http_uri; content:&quot;dpi=&quot;; nocase; http_uri; content:&quot;location=&quot;; nocase; http_uri; content:&quot;t2t21&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13500</id>
        <msg>SPYWARE-PUT Hijacker hbtbar runtime detection - log information</msg>
        <url>www.spywareremove.com/removeHDTBar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy2.php?&quot;; nocase; http_uri; content:&quot;date=&quot;; nocase; http_uri; content:&quot;currentDate=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;Host|3A| www.contraviruspro.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13501</id>
        <msg>SPYWARE-PUT Adware contravirus runtime detection - presale request</msg>
        <url>www.spywareguide.com/spydet_3552_contravirus.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;ContraVirusPro&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*ContraVirusPro/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13502</id>
        <msg>SPYWARE-PUT Adware contravirus runtime detection - update</msg>
        <url>www.spywareguide.com/spydet_3552_contravirus.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ie/&quot;; nocase; http_uri; content:&quot;Host|3A| iedefender.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13504</id>
        <msg>SPYWARE-PUT Adware iedefender runtime detection - presale request</msg>
        <url>www.spywareguide.com/spydet_5318_ie_defender.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates.php?&quot;; nocase; http_uri; content:&quot;data1=&quot;; nocase; http_uri; content:&quot;data2=&quot;; nocase; http_uri; content:&quot;Host|3A| iedefender.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13505</id>
        <msg>SPYWARE-PUT Adware iedefender runtime detection - update</msg>
        <url>www.spywareguide.com/spydet_5318_ie_defender.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,Evilotus_detection; content:&quot;|0C|~|7F D8|&quot;; depth:4; content:&quot;|00 00 00|d|C8 00 00|&quot;; within:8; distance:1; content:&quot;|00 00 00|&quot;; within:3; distance:1;  classtype:trojan-activity;</filter2>
        <id>13507</id>
        <msg>BACKDOOR evilotus 1.3.2 runtime detection - init connection</msg>
        <url>www.megasecurity.org/trojans/e/evilotus/Evilotus1.3.2.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Xploit1_4_5_detection; content:&quot;|01 00|&quot;; depth:2;  classtype:trojan-activity;</filter2>
        <id>13509</id>
        <msg>BACKDOOR xploit 1.4.5 pc runtime detection</msg>
        <url>spywaredetector.net/spyware_encyclopedia/Backdoor.Xploit.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/kompasst&quot;; nocase; http_uri; content:&quot;.php&quot;; nocase; http_uri; content:&quot;Host|3A| www.kompass-intl.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13559</id>
        <msg>SPYWARE-PUT Hijacker kompass toolbar runtime detection - initial connection</msg>
        <url>spywaresignatures.com/details/kompasstoolbar.pdf</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/kinl/static/index_kitoolbar.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;_Choix=&quot;; nocase; http_uri; content:&quot;_Lang=&quot;; nocase; http_uri; content:&quot;_Zone=&quot;; nocase; http_uri; content:&quot;Kprov=Toolbar&quot;; nocase; http_uri; content:&quot;_Keyword=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13560</id>
        <msg>SPYWARE-PUT Hijacker kompass toolbar runtime detection - search traffic</msg>
        <url>spywaresignatures.com/details/kompasstoolbar.pdf</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php?&quot;; nocase; http_uri; content:&quot;advid=&quot;; nocase; http_uri; content:&quot;emla=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;Host|3A| www.malware-alarm.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13561</id>
        <msg>SPYWARE-PUT Adware malware alarm runtime detection - presale request</msg>
        <url>www.sophos.com/security/analyses/malwarealarm.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;d=&quot;; nocase; http_uri; content:&quot;vs=&quot;; nocase; http_uri; content:&quot;Host|3A| www.malware-alarm.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13562</id>
        <msg>SPYWARE-PUT Adware malware alarm runtime detection - update request</msg>
        <url>www.sophos.com/security/analyses/malwarealarm.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download/2006/order.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;Host|3A| systemdoctor.com&quot;; nocase; classtype:misc-activity;</filter2>
        <id>13563</id>
        <msg>SPYWARE-PUT Adware system doctor runtime detection - presale request</msg>
        <url>www.spywareguide.com/spydet_3049_systemdoctor_2006.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stats.php?&quot;; nocase; http_uri; content:&quot;site_id=systemdoctor&quot;; fast_pattern; nocase; http_uri; content:&quot;lp=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;ref=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;USDR&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n].*USDR\d+/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13564</id>
        <msg>SPYWARE-PUT Adware system doctor runtime detection - update status</msg>
        <url>www.spywareguide.com/spydet_3049_systemdoctor_2006.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/hb.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;Host|3A| vscodecsupport.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13565</id>
        <msg>SPYWARE-PUT Trickler iecodec runtime detection - initial traffic</msg>
        <url>www.prevx.com/filenames/X743654547251516036-0/IECODEC.DLL.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/a/pic1.gif&quot;; nocase; http_uri; content:&quot;Host|3A| vscodecsupport.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>13566</id>
        <msg>SPYWARE-PUT Trickler iecodec runtime detection - message dialog</msg>
        <url>www.prevx.com/filenames/X743654547251516036-0/IECODEC.DLL.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;TITLE&gt;MSN Spy Monitor Logging Report&lt;/TITLE&gt;&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>13567</id>
        <msg>SPYWARE-PUT Keylogger msn spy monitor runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=MSN%20Spy%20Monitor&amp;threatid=41180</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;This is the file kept 'LOG', of the program Sys=&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>13568</id>
        <msg>SPYWARE-PUT Keylogger sys keylog 1.3 advanced runtime detection</msg>
        <url>spywaredetector.net/spyware_encyclopedia/Spyware.SysKeylog.htm</url>
      </rule>
      <rule>
        <bugtraq>6849</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2003-0095</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_server; content:&quot;|E8|15aaaaaaaaaaaaaaaaaaaaa|B9|15^_|81 EF|15|FC F3 A4|&quot;; classtype:attempted-admin;</filter2>
        <id>13618</id>
        <msg>SPECIFIC-THREATS Oracle database version 9 username buffer overflow attempt</msg>
        <url>otn.oracle.com/deploy/security/pdf/2003alert51.pdf</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST /ld/mat18/s.php&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>13625</id>
        <msg>BACKDOOR MBR rootkit HTTP POST activity detected</msg>
        <url>www.sophos.com/security/blog/2008/01/987.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get.php?&quot;; nocase; http_uri; content:&quot;partner=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.allcollisions.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Eallcollisions\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13635</id>
        <msg>SPYWARE-PUT Trickler downloader trojan.gen runtime detection - get malicious link</msg>
        <url>www.prevx.com/filenames/X1895686732762432147-0/LAF4.EXE.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download.php?&quot;; nocase; http_uri; content:&quot;track_id=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;dl1.virusheat.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*dl1\x2Evirusheat\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13636</id>
        <msg>SPYWARE-PUT Trickler downloader trojan.gen runtime detection - download malicious link</msg>
        <url>www.prevx.com/filenames/X1895686732762432147-0/LAF4.EXE.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy_online.php?&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.virusheat.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2evirusheat\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13637</id>
        <msg>SPYWARE-PUT Adware virus heat runtime detection - presale request</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=VirusHeat&amp;threatid=203189</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/db/dbver.dat&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;VirusHeat&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*VirusHeat/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13638</id>
        <msg>SPYWARE-PUT Adware virus heat runtime detection - initial database connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=VirusHeat&amp;threatid=203189</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/contents2.php?&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;cnt=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;toolbar.locmag.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*toolbar\x2Elocmag\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13639</id>
        <msg>SPYWARE-PUT Hijacker locmag toolbar runtime detection - connection to toolbar</msg>
        <url>www.360zd.com/spyware/433.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/multi_search/&quot;; fast_pattern; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.locmag.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Elocmag\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13640</id>
        <msg>SPYWARE-PUT Hijacker locmag toolbar runtime detection - hijacks address bar</msg>
        <url>www.360zd.com/spyware/433.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search/?&quot;; nocase; http_uri; content:&quot;Terms=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.eclickz.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eeclickz\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13641</id>
        <msg>SPYWARE-PUT Hijacker eclickz toolbar runtime detection - search traffic</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.eClickz+Toolbar</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;DQp+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fg0KV2luZG93IFRpd&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>13642</id>
        <msg>SPYWARE-PUT Keylogger easy Keylogger runtime detection</msg>
        <url>spywaresignatures.com/details.php?spyware=easykeyloggerfree5.0</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/rank/Info.do?&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;tbar.chinarank.org.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*tbar\x2Echinarank\x2Eorg\x2Ecn/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13643</id>
        <msg>SPYWARE-PUT Hijacker zztoolbar runtime detection - toolbar traffic</msg>
        <url>www.spywareguide.com/spydet_5949_zztoolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/s?&quot;; nocase; http_uri; content:&quot;wd=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Chinarank&quot;; nocase; http_header; content:&quot;Toolbar|29|&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n].*Chinarank\s+Toolbar\x29/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13644</id>
        <msg>SPYWARE-PUT Hijacker zztoolbar runtime detection - search traffic</msg>
        <url>www.spywareguide.com/spydet_5949_zztoolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/search.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;key=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.mxs.co.kr&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Emxs\x2Eco\x2Ekr/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13645</id>
        <msg>SPYWARE-PUT Hijacker mxs toolbar runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=MXS.Toolbar&amp;threatid=97487</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/shoppingcart.aspx?&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;dlg=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.registrydefender.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eregistrydefender\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13646</id>
        <msg>SPYWARE-PUT Adware registry defender runtime detection - presale request</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.Registry+Defender</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/report_error.aspx?&quot;; nocase; http_uri; content:&quot;l=&quot;; nocase; http_uri; content:&quot;e=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;registrydefender.techwithyou.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*registrydefender\x2Etechwithyou\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13647</id>
        <msg>SPYWARE-PUT Adware registry defender runtime detection - error report request</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.Registry+Defender</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jsp/&quot;; nocase; http_uri; content:&quot;?st=bar&quot;; nocase; http_uri; content:&quot;searchfor=&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/jsp\/(GG(main|img|dirs?)|A(jmain|wns|wimg|wvid|waud)|Lsmain)\x2Ejsp\?st=bar&amp;searchfor=/Ui&quot;;  classtype:misc-activity;</filter2>
        <id>13648</id>
        <msg>SPYWARE-PUT Hijacker mysearch bar 2.0.2.28 runtime detection</msg>
        <url>www.emsisoft.com/en/malware/?Adware.Win32.My+Search+Bar</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/register.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.spywarestop.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2espywarestop\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13649</id>
        <msg>SPYWARE-PUT Adware spyware stop runtime detection - presale request</msg>
        <url>www.prevx.com/filenames/1299278770072512825-0/SPYWARESTOP.MSI.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/info&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SpywareStop&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*SpywareStop/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13650</id>
        <msg>SPYWARE-PUT Adware spyware stop runtime detection - auto updates</msg>
        <url>www.prevx.com/filenames/1299278770072512825-0/SPYWARESTOP.MSI.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;All In One Keylogger report.&quot;; nocase; content:&quot;PGh0bWw+PGhlYWQ+PHRpdGxlPkFsbCBJbiBPbmUgS2V5bG9nZ2VyIFJlcG9y&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>13652</id>
        <msg>SPYWARE-PUT Keylogger all in one Keylogger runtime detection</msg>
        <url>www.noadware.net/research/index2.php?item_id=1201&amp;item_name=all-in-one%20spy</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/partners/alex.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;t=&quot;; nocase; http_uri; content:&quot;dm=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.cashfiesta.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3A[^\r\n]*www\x2Ecashfiesta\x2Ecom/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>13653</id>
        <msg>SPYWARE-PUT Adware cashfiesta adbar runtime detection - updates traffic</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=CashFiesta%20AdBar&amp;threatid=42051</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Nuclear_RAT_2_1_detection; content:&quot;|1E 0D 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:13;  classtype:trojan-activity;</filter2>
        <id>13655</id>
        <msg>BACKDOOR nuclear rat 2.1 runtime detection - init connection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Nuclear%20RAT&amp;threatid=43578</url>
      </rule>
      <rule>
        <bugtraq>6454</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-1643</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:established,to_server; content:&quot;GET &quot;; depth:4; nocase; isdataat:200; content:!&quot;|0A|&quot;; depth:200; classtype:attempted-user;</filter2>
        <id>13694</id>
        <msg>EXPLOIT RealNetworks Helix RTSP long get request exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>6454</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2002-1643</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SETUP&quot;; depth:5; nocase; isdataat:256,relative; content:!&quot;|0A|&quot;; within:256; metadata:service rtsp; classtype:attempted-user;</filter2>
        <id>13695</id>
        <msg>EXPLOIT RealNetworks Helix RTSP long setup request exploit attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.htgroup&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1374</id>
        <msg>WEB-MISC .htgroup access</msg>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;GET x HTTP/1.0&quot;; depth:15; metadata:service http; classtype:attempted-recon;</filter2>
        <id>1375</id>
        <msg>WEB-MISC sadmind worm access</msg>
        <url>www.cert.org/advisories/CA-2001-11.html</url>
      </rule>
      <rule>
        <bugtraq>3592</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?.jsp&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1376</id>
        <msg>WEB-MISC jrun directory browse attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SystemDefender&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*SystemDefender/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13762</id>
        <msg>SPYWARE-PUT Adware system defender runtime detection</msg>
        <url>www.enigmasoftware.com/support/systemdefender-removal/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/order.php?&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.winxdefender.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Ewinxdefender\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13765</id>
        <msg>SPYWARE-PUT Adware winxdefender runtime detection - presale request</msg>
        <url>www.411-spyware.com/remove-winxdefender</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/checkupdate.php&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;WinXDefender.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*WinXDefender\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13766</id>
        <msg>SPYWARE-PUT Adware winxdefender runtime detection - auto update</msg>
        <url>www.411-spyware.com/remove-winxdefender</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; flowbits:isset,cyberSitter_detection; content:&quot;CYBERsitter&quot;; nocase; content:&quot;appears&quot;; distance:0; nocase; content:&quot;to&quot;; distance:0; nocase; content:&quot;be&quot;; distance:0; nocase; content:&quot;functioning&quot;; distance:0; nocase; pcre:&quot;/CYBERsitter\s+appears\s+to\s+be\s+functioning/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>13768</id>
        <msg>SPYWARE-PUT Keylogger cyber sitter runtime detection</msg>
        <url>www.spywareguide.com/spydet_1056_cybersitter.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/response.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;search=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;searchnine.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*searchnine\x2Ecn/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13769</id>
        <msg>SPYWARE-PUT Hijacker searchnine toolbar runtime detection - hijacks address bar</msg>
        <url>spywarefiles.prevx.com/spywarefiles.asp?FXC=DJFC24641892</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/s?&quot;; nocase; http_uri; content:&quot;tn=searchnine_dg&quot;; fast_pattern; nocase; http_uri; content:&quot;wd=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13770</id>
        <msg>SPYWARE-PUT Hijacker searchnine toolbar runtime detection - redirects search function</msg>
        <url>spywarefiles.prevx.com/spywarefiles.asp?FXC=DJFC24641892</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;catch=&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;musicoffaith&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n].*musicoffaith/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13771</id>
        <msg>SPYWARE-PUT Hijacker music of faith toolbar runtime detection - hijacks search engine traffic #1</msg>
        <url>www.spywareterminator.com/item/3836/MusicOfFaith.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dosearch/search.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;EngineID=musicoffaith&quot;; nocase; http_uri; content:&quot;LinkID=&quot;; nocase; http_uri; content:&quot;refer=mof_toolbar&quot;; nocase; http_uri; content:&quot;keywords=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13772</id>
        <msg>SPYWARE-PUT Hijacker music of faith toolbar runtime detection - hijacks search engine traffic #2</msg>
        <url>www.spywareterminator.com/item/3836/MusicOfFaith.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/in.cgi?&quot;; nocase; http_uri; content:&quot;group=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; content:&quot;theonlybookmark.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*theonlybookmark\x2ecom/smi&quot;; classtype:misc-activity;</filter2>
        <id>13774</id>
        <msg>SPYWARE-PUT Trickler trojan ecodec runtime detection - initial server connection #1</msg>
        <url>virusinfo.prevx.com/viruscenter.asp?GRP=4812100013</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/spbrn/cinst.php?&quot;; nocase; http_uri; content:&quot;affid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; content:&quot;safe-strip-download.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*safe-strip-download\x2ecom/smi&quot;; classtype:misc-activity;</filter2>
        <id>13775</id>
        <msg>SPYWARE-PUT Trickler trojan ecodec runtime detection - initial server connection #2</msg>
        <url>virusinfo.prevx.com/viruscenter.asp?GRP=4812100013</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/order.php?&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;context=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.sys-cleaner.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Esys-cleaner\x2Ecom/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13776</id>
        <msg>SPYWARE-PUT Trackware syscleaner runtime detection - presale traffic</msg>
        <url>spywaredetector.net/spyware_encyclopedia/Fake%20Anti%20Spyware.SysCleaner.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/get_lic.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;context=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SysCleaner&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*SysCleaner/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13777</id>
        <msg>SPYWARE-PUT Trackware syscleaner runtime detection - get update</msg>
        <url>spywaredetector.net/spyware_encyclopedia/Fake%20Anti%20Spyware.SysCleaner.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;&lt;TIT= LE&gt; KGB log &lt;/TITLE&gt;&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>13778</id>
        <msg>SPYWARE-PUT Keylogger kgb employee monitor runtime detection</msg>
        <url>www.spywareremove.com/removeKGBKeylogger.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xml_toolbar.php&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Toolbar&quot;; nocase; http_header; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.proofile.com&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Toolbar/smiH&quot;; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Eproofile\x2Ecom/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13779</id>
        <msg>SPYWARE-PUT Trackware proofile toolbar runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Proofile%20Toolbar&amp;threatid=127931</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.find.fm&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Efind\x2Efm/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13780</id>
        <msg>SPYWARE-PUT Hijacker find.fm toolbar runtime detection - automatic updates</msg>
        <url>www.spywaresignatures.com/details.php?spyware=find.fmtoolbar</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;keyword=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.find.fm&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Efind\x2Efm/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13781</id>
        <msg>SPYWARE-PUT Hijacker find.fm toolbar runtime detection - hijacks address bar</msg>
        <url>www.spywaresignatures.com/details.php?spyware=find.fmtoolbar</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/keyword/keyword_list.php&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;EzReward&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*EzReward/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13782</id>
        <msg>SPYWARE-PUT Hijacker ezreward runtime detection</msg>
        <url>www.sophos.com/security/analyses/adware-and-puas/ezreward.html</url>
      </rule>
      <rule>
        <bugtraq>28730</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1910</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00|R&quot;; depth:4; byte_test:4,&gt;,848,8; classtype:attempted-admin;</filter2>
        <id>13804</id>
        <msg>MISC Borland Software InterBase ibserver.exe Service Attach Request buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>15356</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2124</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; flowbits:isset,wmf.download; content:&quot;|00 09 00|&quot;; content:&quot;|FF FF FF|&quot;; distance:12; content:&quot;|00|&quot;; within:1; distance:2; pcre:&quot;/[\x00\x01]\x00\x09\x00.*?\xff\xff\xff[\xff\xf7][\x36\x37]\x00/smi&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>13807</id>
        <msg>WEB-CLIENT Windows metafile SetPaletteEntries heap overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms05-053.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/index.php?&quot;; nocase; http_uri; content:&quot;la=order&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ieantivirus.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ieantivirus\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13808</id>
        <msg>SPYWARE-PUT Adware ie antivirus runtime detection - presale request</msg>
        <url>www.411-spyware.com/remove-ie-antivirus-3-2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates.php?&quot;; nocase; http_uri; content:&quot;data1=&quot;; nocase; http_uri; content:&quot;data2=&quot;; nocase; http_uri; content:&quot;data3=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ieantivirus.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ieantivirus\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13809</id>
        <msg>SPYWARE-PUT Adware ie antivirus runtime detection - update request</msg>
        <url>www.411-spyware.com/remove-ie-antivirus-3-2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/order_xp.php?&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;liveresponsesite.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*liveresponsesite\x2Ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13811</id>
        <msg>SPYWARE-PUT Adware xp antivirus runtime detection</msg>
        <url>www.spywareguide.com/spydet_27817_xpantivirus.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;NextPart_2&quot;; nocase; content:&quot;&lt;TIT=|0D 0A|LE&gt;REFOG log&lt;/TITLE&gt;&quot;; fast_pattern:only;  classtype:successful-recon-limited;</filter2>
        <id>13812</id>
        <msg>SPYWARE-PUT Keylogger refog Keylogger runtime detection</msg>
        <url>www.refog.com</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;MZKERNEL32.DLL&quot;; nocase; content:&quot;LoadLibraryA&quot;; distance:0; nocase; content:&quot;GetProcAddress&quot;; distance:0; nocase; pcre:&quot;/^MZKERNEL32\x2eDLL\x00\x00LoadLibraryA\x00\x00\x00\x00GetProcAddress/smi&quot;;  classtype:misc-activity;</filter2>
        <id>13813</id>
        <msg>SPYWARE-PUT Trickler mm.exe runtime detection</msg>
        <url>www.fbmsoftware.com/spyware-net/process/mm_exe/1960/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;ZOMBIES_HTTP_GET&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*ZOMBIES\x5fHTTP\x5fGET/smiH&quot;; classtype:trojan-activity;</filter2>
        <id>13815</id>
        <msg>BACKDOOR zombget.03 runtime detection</msg>
        <url>www.pctools.com/mrc/infections/id/Trojan-Downloader.ZombGet/</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp any any -&gt; any 6666:7000</filter1>
        <filter2>flow:to_server,established; content:&quot;PRIVMSG&quot;; fast_pattern:only; content:&quot;nickserv&quot;; nocase; content:&quot;IDENTIFY&quot;; nocase; isdataat:100,relative; pcre:&quot;/^PRIVMSG\s+nickserv\s+IDENTIFY\s[^\n]{100}/smi&quot;; classtype:misc-attack;</filter2>
        <id>1382</id>
        <msg>EXPLOIT CHAT IRC Ettercap parse overflow attempt</msg>
        <url>www.bugtraq.org/dev/GOBBLES-12.txt</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/viperML/phoenician/phoenician.cab&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13847</id>
        <msg>SPYWARE-PUT Adware phoenician casino runtime detection</msg>
        <url>www.spywareguide.com/spydet_3441_phoenician_casino.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/registration/logins.jhtml?&quot;; fast_pattern; nocase; http_uri; content:&quot;caller=desktop&quot;; nocase; http_uri; content:&quot;action=check&quot;; nocase; http_uri; content:&quot;username=&quot;; nocase; http_uri; content:&quot;dt=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13848</id>
        <msg>SPYWARE-PUT Trickler zwinky runtime detection</msg>
        <url>www.emsisoft.net/fr/malware/?Adware.Win32.Zwinky_Test</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/10025rel/landing.php&quot;; fast_pattern:only; content:&quot;Rabio|3A|&quot;; nocase; content:&quot;RCSE&quot;; distance:0; nocase; pcre:&quot;/^Rabio\x3a[^\r\n]*RCSE/smi&quot;;  classtype:misc-activity;</filter2>
        <id>13849</id>
        <msg>SPYWARE-PUT Hijacker rcse 4.4 runtime detection - hijack ie browser</msg>
        <url>www.spywareguide.com/spydet_3770_rabio.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;VER=&quot;; nocase; http_uri; content:&quot;AdID=&quot;; nocase; http_uri; content:&quot;UID=&quot;; nocase; http_uri; content:&quot;SURL=&quot;; nocase; http_uri; content:&quot;Host=&quot;; nocase; http_uri; content:&quot;ConditionID=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;show.newroogoo.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*show\x2enewroogoo\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13850</id>
        <msg>SPYWARE-PUT Adware roogoo 2.0 runtime detection - popup ads</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upgrade/?&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; content:&quot;fromid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;show.newRooGoo.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*show\x2enewRooGoo\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13851</id>
        <msg>SPYWARE-PUT Adware roogoo 2.0 runtime detection - upgrade</msg>
        <url>www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/banner.php?&quot;; nocase; http_uri; content:&quot;skin=Flexi.skf&quot;; fast_pattern; nocase; http_uri;  classtype:misc-activity;</filter2>
        <id>13852</id>
        <msg>SPYWARE-PUT Hijacker bitroll 5.0 runtime detection</msg>
        <url>www.spywareremove.com/removeBitroll.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/widgets/weather/tb&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;widget.alot.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*widget\x2ealot\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13853</id>
        <msg>SPYWARE-PUT Hijacker alot toolbar runtime detection - weather request</msg>
        <url>www.spywareremove.com/removeALOTToolbar.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/update_configs/update_config_11077_0.xml?&quot;; fast_pattern; nocase; http_uri; content:&quot;src_id=&quot;; nocase; http_uri; content:&quot;camp_id=&quot;; nocase; http_uri; content:&quot;tb_version=&quot;; nocase; http_uri; content:&quot;pr=tbar&quot;; nocase; http_uri; content:&quot;client_id=&quot;; nocase; http_uri; content:&quot;install_time=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13854</id>
        <msg>SPYWARE-PUT Hijacker alot toolbar runtime detection - auto update</msg>
        <url>www.spywareremove.com/removeALOTToolbar.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/pop.php&quot;; nocase; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;SpeedRunner&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*SpeedRunner/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>13855</id>
        <msg>SPYWARE-PUT Trackware speed runner runtime detection</msg>
        <url>www.bleepingcomputer.com/startups/SpeedRunner-22778.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/binaries/2/2_mslagent.dll&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;HTTPRequest&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*HTTPRequest/smiH&quot;;  classtype:trojan-activity;</filter2>
        <id>13856</id>
        <msg>BACKDOOR wintrim.z runtime detection</msg>
        <url>www.spywareguide.com/product_show.php?id=2225</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/r.php?&quot;; nocase; http_uri; content:&quot;sid=&quot;; nocase; http_uri; content:&quot;pn=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;said=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;directnameservice2008.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*directnameservice2008\x2ecom/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13866</id>
        <msg>SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection - popup ads</msg>
        <url>www.threatexpert.com/report.aspx?uid=c2699ec8-6cd1-4ad1-ace5-f29bb1133d91</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;cmpname=&quot;; nocase; http_uri; content:&quot;gai=&quot;; nocase; http_uri; content:&quot;gli=&quot;; nocase; http_uri; content:&quot;gff=&quot;; nocase; http_uri; content:&quot;ed=&quot;; nocase; http_uri; content:&quot;ex=&quot;; nocase; http_uri; content:&quot;eu=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;intervarioclick.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*intervarioclick\x2ecom/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>13867</id>
        <msg>SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection</msg>
        <url>www.threatexpert.com/report.aspx?uid=c2699ec8-6cd1-4ad1-ace5-f29bb1133d91</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;gai=&quot;; nocase; http_uri; content:&quot;gli=&quot;; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;abbr=UASM&quot;; fast_pattern; nocase; http_uri; content:&quot;err=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13868</id>
        <msg>SPYWARE-PUT Adware antispywaremaster runtime detection - start fake scanning</msg>
        <url>www.xp-vista.com/spyware-removal/antispywaremaster-antispyware-master-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data/sale.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;abbr=UASM&quot;; nocase; http_uri; content:&quot;nid=UASM&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13869</id>
        <msg>SPYWARE-PUT Adware antispywaremaster runtime detection - sale/register request</msg>
        <url>www.xp-vista.com/spyware-removal/antispywaremaster-antispyware-master-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/87/param.aspx?&quot;; fast_pattern; nocase; http_uri; content:&quot;groupID=&quot;; nocase; http_uri; content:&quot;spaceIDs=&quot;; nocase; http_uri; content:&quot;mac=&quot;; nocase; http_uri; content:&quot;ver=5.0.0.87&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>13870</id>
        <msg>SPYWARE-PUT Adware coopen 5.0.0.87 runtime detection - init conn</msg>
        <url>www.spywaresignatures.com/details.php?spyware=coopen</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Adpic/&quot;; fast_pattern; nocase; http_uri; content:&quot;.jpg&quot;; nocase; http_uri; pcre:&quot;/\x2fAdpic\x2f\d+\x2f\d+ad\x28\d+\x2c\d+\x2c\d+\x2c\d+\x29\x2ejpg/Ui&quot;; classtype:misc-activity;</filter2>
        <id>13871</id>
        <msg>SPYWARE-PUT Adware coopen 5.0.0.87 runtime detection - ads</msg>
        <url>www.spywaresignatures.com/details.php?spyware=coopen</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sobar/notice/notice_baiducb.txt?&quot;; fast_pattern; nocase; http_uri; content:&quot;tn=funshion&quot;; nocase; http_uri; content:&quot;ss=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;bar-get&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*bar\x2dget/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13872</id>
        <msg>SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection - notice</msg>
        <url>www.siteadvisor.pl/sites/funshion.com/downloads/11570528/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/account_logout&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;xikee.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*xikee\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13873</id>
        <msg>SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection - underground traffic</msg>
        <url>www.siteadvisor.pl/sites/funshion.com/downloads/11570528/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/order.php?&quot;; nocase; http_uri; content:&quot;date=&quot;; nocase; http_uri; content:&quot;currentDate=&quot;; nocase; http_uri; content:&quot;pid=&quot;; nocase; http_uri; content:&quot;aid=&quot;; nocase; http_uri; content:&quot;lang=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.malwaredestructor.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2emalwaredestructor\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13874</id>
        <msg>SPYWARE-PUT Adware malware destructor 4.5 runtime detection - order request</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-090713-4427-99</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/application/appver.php&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;MalwareDestructor&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*MalwareDestructor/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13875</id>
        <msg>SPYWARE-PUT Adware malware destructor 4.5 runtime detection - auto update</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-090713-4427-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/inst/setup_&quot;; nocase; http_uri; content:&quot;.exe&quot;; nocase; http_uri; pcre:&quot;/\x2finst\x2fsetup\x5f\d+\x5f\d+\x5f\x2eexe/Ui&quot;; content:&quot;Host|3A| dl.winspywareprotects.com&quot;; nocase;  classtype:trojan-activity;</filter2>
        <id>13876</id>
        <msg>BACKDOOR zlob.acc runtime detection</msg>
        <url>www.spywarelib.com/removal-info/Trojan-Downloader.Zlob.acc/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Trojan-Spy.Win32.Delf.uv_Detection; content:&quot;[|00|u|00|p|00|d|00|a|00|t|00|e|00|]&quot;; content:&quot;[|00|p|00|o|00|p|00|w|00|i|00|n|00|]&quot;; classtype:trojan-activity;</filter2>
        <id>13878</id>
        <msg>BACKDOOR trojan-spy.win32.delf.uv runtime detection</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Spy.Win32.Delf.uv&amp;threatid=134949</url>
      </rule>
      <rule>
        <bugtraq>3723</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2007-2386</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;Location&quot;; fast_pattern:only; pcre:&quot;/^Location\s*\x3a\s*\w+\x3a\/\/([^\n]*\x3a)?[^\n]{128}/smi&quot;; classtype:misc-attack;</filter2>
        <id>1388</id>
        <msg>MISC UPnP Location overflow attempt</msg>
        <nessus>10829</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS01-059.mspx</url>
      </rule>
      <rule>
        <bugtraq>3769</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0005</cve>
        <filter1>tcp $AIM_SERVERS any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;aim|3A|AddGame?&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>1393</id>
        <msg>MISC AIM AddGame attempt</msg>
        <url>www.w00w00.org/files/w00aimexp/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/2009/order/index.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;abbr=UPCPC&quot;; nocase; http_uri; content:&quot;nid=UPCPC&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;UPCPC&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*UPCPC/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13930</id>
        <msg>SPYWARE-PUT Trickler pc privacy cleaner runtime detection - order/register request</msg>
        <url>www.xp-vista.com/spyware-removal/pcprivacycleaner-pc-privacy-cleaner-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;proto=&quot;; nocase; http_uri; content:&quot;ac=&quot;; nocase; http_uri; content:&quot;abbr=UPCPC&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;rc=UPCPC&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;PcPcUpdater&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*PcPcUpdater/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13931</id>
        <msg>SPYWARE-PUT Trickler pc privacy cleaner runtime detection - auto update</msg>
        <url>www.xp-vista.com/spyware-removal/pcprivacycleaner-pc-privacy-cleaner-removal-instructions</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/ip.php&quot;; nocase; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;opera&quot;; nocase; http_header; content:&quot;Host|3A| rightonadz.biz&quot;; distance:0; nocase; pcre:&quot;/^User-Agent\x3a[^\r\n]*opera/smiH&quot;; pcre:&quot;/^Host\x3a[^\r\n]*rightonadz\x2ebiz/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13932</id>
        <msg>SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection - post user info to remote server</msg>
        <url>www.nettrafficchat.com/showthread.php?t=1347</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/123kah.php&quot;; fast_pattern:only; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;rightonadz.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*rightonadz\x2ebiz/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>13933</id>
        <msg>SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection - ads</msg>
        <url>www.nettrafficchat.com/showthread.php?t=1347</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jump.php?&quot;; nocase; http_uri; content:&quot;wmid=&quot;; nocase; http_uri; content:&quot;mid=&quot;; nocase; http_uri; content:&quot;lid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;softwarereferral.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*softwarereferral\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13934</id>
        <msg>SPYWARE-PUT Hijacker mediatubecodec 1.470.0 runtime detection - hijack ie</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.NewMediaCodec&amp;threatid=149335</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/thandler.php?&quot;; nocase; http_uri; content:&quot;p=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;safewebnavigate2008.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*safewebnavigate2008\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13935</id>
        <msg>SPYWARE-PUT Hijacker mediatubecodec 1.470.0 runtime detection - download other malware</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.NewMediaCodec&amp;threatid=149335</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,Dropper_Agent.rqg_Detection; content:&quot;|7C|http|3A|//xxx.ads555.com/rj/cc1.exe|7C|&quot;; classtype:misc-activity;</filter2>
        <id>13936</id>
        <msg>SPYWARE-PUT Trickler dropper agent.rqg runtime detection - call home</msg>
        <url>virscan.org/report/2b00cbb9a861bd3dd79ef19a75de92f8.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/topnew/passdomain.txt&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.web228.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2eweb228\x2ecn/smiH&quot;; classtype:misc-activity;</filter2>
        <id>13937</id>
        <msg>SPYWARE-PUT Hijacker adware.win32.ejik.ec variant runtime detection - call home</msg>
        <url>www.emsisoft.fr/fr/malware/?Adware.Win32.Ejik.ec</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,AdWare_Ejik.ec_Detection; content:&quot;|3B|aa88.dll|3B|&quot;; pcre:&quot;/^\d+\x3baa88\x2edll\x3b\d+\x3b/smi&quot;; classtype:misc-activity;</filter2>
        <id>13939</id>
        <msg>SPYWARE-PUT Hijacker adware.win32.ejik.ec variant runtime detection - auto update</msg>
        <url>www.emsisoft.fr/fr/malware/?Adware.Win32.Ejik.ec</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/105/bmw.q?&quot;; nocase; http_uri; content:&quot;uid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;44.770304123.cn&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*44\x2e770304123\x2ecn/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>13940</id>
        <msg>SPYWARE-PUT Hijacker win32.bho.bgf runtime detection</msg>
        <url>www.threatexpert.com/report.aspx?uid=77b8d3c8-e630-4719-b6fd-b5461820d8f1</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/in.cgi?&quot;; nocase; http_uri; content:&quot;key=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;bfirst.info&quot;; nocase; http_header;  classtype:trojan-activity;</filter2>
        <id>13941</id>
        <msg>BACKDOOR trojan agent.nac runtime detection - click fraud</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Downloader.Win32.Agent.nac&amp;threatid=234088</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fd/sea.php?&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;User-Agent|3A| clk_jdfhid&quot;; nocase; http_header;  classtype:trojan-activity;</filter2>
        <id>13942</id>
        <msg>BACKDOOR trojan agent.nac runtime detection - call home</msg>
        <url>research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Downloader.Win32.Agent.nac&amp;threatid=234088</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/grand/data/whitelist.txt&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>13944</id>
        <msg>BACKDOOR trojan downloader small.gy runtime detection - get whitelist</msg>
        <url>www.iss.net/security_center/reference/vuln/Trojan.Spy.Small.GY.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/grand/addme.php?&quot;; nocase; http_uri; content:&quot;botid=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; content:&quot;smtp=&quot;; nocase; http_uri; content:&quot;ipstring=&quot;; nocase; http_uri; content:&quot;connect,ok&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>13945</id>
        <msg>BACKDOOR trojan downloader small.gy runtime detection - update</msg>
        <url>www.iss.net/security_center/reference/vuln/Trojan.Spy.Small.GY.html</url>
      </rule>
      <rule>
        <bugtraq>3517</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2001-0803</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6112</filter1>
        <filter2>flow:to_server,established; content:&quot;1&quot;; depth:1; offset:10; content:!&quot;000&quot;; depth:3; offset:11; classtype:misc-attack;</filter2>
        <id>1398</id>
        <msg>EXPLOIT CDE dtspcd exploit attempt</msg>
        <nessus>10833</nessus>
        <url>www.cert.org/advisories/CA-2002-01.html</url>
      </rule>
      <rule>
        <bugtraq>30341</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.m3u.download; content:&quot;Content-Length&quot;; nocase; http_header; pcre:&quot;/Content-Length\x3a\s*(\d{7}|[5-9]\d{5})/iH&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14019</id>
        <msg>WEB-CLIENT CyberLink PowerDVD playlist file handling stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30341</bugtraq>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.pls.download; content:&quot;Content-Length&quot;; nocase; http_header; pcre:&quot;/Content-Length\x3a\s*(\d{7}|[5-9]\d{5})/iH&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>14020</id>
        <msg>WEB-CLIENT CyberLink PowerDVD playlist file handling stack overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update/info&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;AdwareAlert&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*AdwareAlert/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14054</id>
        <msg>SPYWARE-PUT Adware AdwareALERT runtime detection - auto update</msg>
        <url>www.411-spyware.com/remove-adwarealert</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dirsrch/default.asp?&quot;; fast_pattern; nocase; http_uri; content:&quot;MT=&quot;; nocase; http_uri; content:&quot;mode=toolbar&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;search.rediff.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*search\x2erediff\x2ecom/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>14055</id>
        <msg>SPYWARE-PUT Hijacker rediff toolbar runtime detection - hijack ie auto search</msg>
        <url>www.fbmsoftware.com/spyware-net/application/Rediff_Toolbar/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/toolbar/&quot;; nocase; http_uri; content:&quot;/news.xml&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;server.toolbar.rediff.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*server\x2etoolbar\x2erediff\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14056</id>
        <msg>SPYWARE-PUT Hijacker rediff toolbar runtime detection - get news info</msg>
        <url>www.fbmsoftware.com/spyware-net/application/Rediff_Toolbar/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/murzilka2//data.php&quot;; fast_pattern:only; content:&quot;phid=&quot;; nocase; content:&quot;lg=&quot;; nocase; content:&quot;user=&quot;; nocase; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;DMFR&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*DMFR/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>14057</id>
        <msg>SPYWARE-PUT Trackware murzilka2 runtime detection</msg>
        <url>www.liveinternet.ru/users/murzilka2/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $HOME_NET any -&gt; $EXTERNAL_NET 80</filter1>
        <filter2>content:&quot;|01 0F|_H&quot;; depth:4; content:&quot;|00 00 00|&quot;; offset:26; nocase; content:&quot;|00 00|http|3A|//&quot;; offset:1; nocase; classtype:misc-activity;</filter2>
        <id>14058</id>
        <msg>SPYWARE-PUT Hijacker cpush 2 runtime detection - pass info to controlling server</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-031215-0744-99</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/fav.php?&quot;; nocase; http_uri; content:&quot;i=&quot;; nocase; http_uri; content:&quot;t=&quot;; nocase; http_uri; content:&quot;u=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;CPUSH_HOMEPAGE&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*CPUSH\x5fHOMEPAGE/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14059</id>
        <msg>SPYWARE-PUT Hijacker cpush 2 runtime detection - hijack ie home page</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-031215-0744-99</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cpush/version.txt?&quot;; fast_pattern; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;CPUSH_UPDATER&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*CPUSH\x5fUPDATER/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14060</id>
        <msg>SPYWARE-PUT Hijacker cpush 2 runtime detection - auto update</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2007-031215-0744-99</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/2009/order/index.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;abbr=3P_UAMG&quot;; nocase; http_uri; content:&quot;aa=&quot;; nocase; http_uri; content:&quot;al=&quot;; nocase; http_uri; content:&quot;af=&quot;; nocase; http_uri; content:&quot;an=&quot;; nocase; http_uri; content:&quot;addt=&quot;; nocase; http_uri; content:&quot;nid=3P_UAMG&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>14061</id>
        <msg>SPYWARE-PUT Trickler antimalware guard runtime detection - order/register request</msg>
        <url>www.xp-vista.com/spyware-removal/antimalwareguard-antimalware-guard-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;proto=&quot;; nocase; http_uri; content:&quot;ac=&quot;; nocase; http_uri; content:&quot;abbr=3P_UAMG&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;rc=3P_UAMG&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>14062</id>
        <msg>SPYWARE-PUT Trickler antimalware guard runtime detection - auto update</msg>
        <url>www.xp-vista.com/spyware-removal/antimalwareguard-antimalware-guard-removal-instructions</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search/search.php?&quot;; fast_pattern; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.cashon.co.kr&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2ecashon\x2eco\x2ekr/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14063</id>
        <msg>SPYWARE-PUT Hijacker cashon runtime detection - hijack ie searches</msg>
        <url>vil.nai.com/vil/content/v_142287.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/app/cashonband/bin/CashOnUpdate.exe&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>14064</id>
        <msg>SPYWARE-PUT Hijacker cashon runtime detection - auto update</msg>
        <url>vil.nai.com/vil/content/v_142287.htm</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/th/script.php?&quot;; nocase; content:&quot;boundary=--__abcd-xyz789__--&quot;; distance:0; nocase; content:&quot;name=|22|Module|22 0D 0A 0D 0A|&quot;; distance:0; nocase; content:&quot;IE&quot;; distance:0; nocase; pcre:&quot;/name\x3d\x22Module\x22\x0d\x0a\x0d\x0a(IEGrabber|IEInjector|IEFaker|IEKeylogger|IETanGrabber|IEScrGrabber|IECertGrab|IEFileGrabber)/smi&quot;;  classtype:successful-recon-limited;</filter2>
        <id>14065</id>
        <msg>SPYWARE-PUT Keylogger emptybase j runtime detection</msg>
        <url>www.sophos.com/security/analyses/viruses-and-spyware/malencpkay.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tba/cm&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ads.netbios-local.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ads\x2enetbios\x2dlocal\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14067</id>
        <msg>SPYWARE-PUT Adware swizzor runtime detection</msg>
        <url>www.411-spyware.com/remove-swizzor</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/st?&quot;; nocase; http_uri; content:&quot;ad_type=pop&quot;; nocase; http_uri; content:&quot;ad_size=&quot;; nocase; http_uri; content:&quot;section=&quot;; nocase; http_uri; content:&quot;banned_pop_types=&quot;; nocase; http_uri; content:&quot;pop_times=&quot;; nocase; http_uri; content:&quot;http|3A|//mtn5.goole.ws/ac.php&quot;; distance:0; nocase; pcre:&quot;/^Referer\x3a[^\r\n]*http\x3A\x2F\x2Fmtn5\x2Egoole\x2Ews\x2Fac\x2Ephp/smi&quot;; classtype:misc-activity;</filter2>
        <id>14068</id>
        <msg>SPYWARE-PUT Adware rond runtime detection</msg>
        <url>www.spywaredetector.net/spyware_encyclopedia/Adware.Rond.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php?&quot;; nocase; http_uri; content:&quot;advid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.bravesentry.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2ebravesentry\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14069</id>
        <msg>SPYWARE-PUT Adware brave sentry runtime detection - order request</msg>
        <url>www.spywareremove.com/removeBravesentry.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update.php?&quot;; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;d=&quot;; nocase; http_uri; content:&quot;vs=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.bravesentry.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2ebravesentry\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14070</id>
        <msg>SPYWARE-PUT Adware brave sentry runtime detection - self update</msg>
        <url>www.spywareremove.com/removeBravesentry.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/id/&quot;; nocase; http_uri; content:&quot;free-viruscan.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*free\x2Dviruscan\x2Ecom/smi&quot;; classtype:misc-activity;</filter2>
        <id>14071</id>
        <msg>SPYWARE-PUT Hijacker Adware bho.gen runtime detection - pop-up window traffic #1</msg>
        <url>www.pctools.com/mrc/infections/id/Adware.BHO.GEN/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?pp&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;free-viruscan.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*free\x2Dviruscan\x2Ecom/smi&quot;; classtype:misc-activity;</filter2>
        <id>14072</id>
        <msg>SPYWARE-PUT Hijacker Adware bho.gen runtime detection - pop-up window traffic #2</msg>
        <url>www.pctools.com/mrc/infections/id/Adware.BHO.GEN/</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download.php&quot;; nocase; http_uri; content:&quot;ieantivirus.com&quot;; distance:0; nocase; pcre:&quot;/^Host\x3a[^\r\n]*ieantivirus\x2Ecom/smi&quot;; classtype:misc-activity;</filter2>
        <id>14073</id>
        <msg>SPYWARE-PUT Hijacker Adware bho.gen runtime detection - prompt download page</msg>
        <url>www.pctools.com/mrc/infections/id/Adware.BHO.GEN/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| SpyBoss Pro - Log File Mailing&quot;; fast_pattern:only; content:&quot;X-Mailer|3A| SpyBoss Pro&quot;; nocase; classtype:successful-recon-limited;</filter2>
        <id>14074</id>
        <msg>SPYWARE-PUT Keylogger spybosspro 4.2 runtime detection</msg>
        <url>www.411-spyware.com/remove/spyboss-pro</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Subject|3A| Ultimate Keylogger Report from&quot;; fast_pattern:only; content:&quot;Activity Report from Ultimate&quot;; nocase; classtype:successful-recon-limited;</filter2>
        <id>14075</id>
        <msg>SPYWARE-PUT Keylogger ultimate Keylogger pro runtime detection</msg>
        <url>www.411-spyware.com/remove-ultimate-keylogger</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search/&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;pstv=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.powersearchtool.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2epowersearchtool\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14076</id>
        <msg>SPYWARE-PUT Hijacker Adware win32 mostofate runtime detection - hijack search</msg>
        <url>www.f-secure.com/sw-desc/adware_w32_mostofate.shtml</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/results/?&quot;; nocase; http_uri; content:&quot;q=&quot;; nocase; http_uri; content:&quot;pstv=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.powersearchtool.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2epowersearchtool\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>14077</id>
        <msg>SPYWARE-PUT Hijacker Adware win32 mostofate runtime detection - redirect search results</msg>
        <url>www.f-secure.com/sw-desc/adware_w32_mostofate.shtml</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/scripts/worker.php&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;hujashka.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>14081</id>
        <msg>BACKDOOR trojan agent.aarm runtime detection - call home</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.AARM&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/spm/&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;tick=&quot;; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;smtp=&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>14082</id>
        <msg>BACKDOOR trojan agent.aarm runtime detection - spread via spam</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.AARM&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/retadpu.php?&quot;; nocase; http_uri; content:&quot;version=&quot;; nocase; http_uri; content:&quot;configversion=&quot;; nocase; http_uri; content:&quot;GUID=&quot;; nocase; http_uri; content:&quot;cmd=&quot;; nocase; http_uri; content:&quot;p=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;wr.mcboo.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>14083</id>
        <msg>BACKDOOR trojan agent.aarm runtime detection - download other malware</msg>
        <url>www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.AARM&amp;VSect=T</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/panel/cfg.bin&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;leacherz.net&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>14084</id>
        <msg>BACKDOOR infostealer.banker.c runtime detection - download cfg.bin</msg>
        <url>www.symantec.com/business/security_response/writeup.jsp?docid=2007-040208-5335-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/panel/s.php?&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;leacherz.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*leacherz\x2enet/smiH&quot;;  classtype:trojan-activity;</filter2>
        <id>14085</id>
        <msg>BACKDOOR infostealer.banker.c runtime detection - collect user info</msg>
        <url>www.symantec.com/business/security_response/writeup.jsp?docid=2007-040208-5335-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?VFJDSz0&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.visit-tracker.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2Evisit\x2Dtracker\x2Ebiz/smiH&quot;;  classtype:trojan-activity;</filter2>
        <id>14086</id>
        <msg>BACKDOOR Adware.Win32.Agent.BM runtime detection #1</msg>
        <url>www.threatexpert.com/threats/not-a-virus-adware-win32-agent-bm.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/template/top.html&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;http|3A|//www.visit-tracker.biz/?VFJDSz0&quot;; nocase; http_header; pcre:&quot;/^Referer\x3a[^\r\n]*http\x3A\x2F\x2Fwww\x2Evisit\x2Dtracker\x2Ebiz\x2F\x3FVFJDSz0/smiH&quot;;  classtype:trojan-activity;</filter2>
        <id>14087</id>
        <msg>BACKDOOR Adware.Win32.Agent.BM runtime detection #2</msg>
        <url>www.threatexpert.com/threats/not-a-virus-adware-win32-agent-bm.html</url>
      </rule>
      <rule>
        <bugtraq>4089</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0013</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161:162</filter1>
        <filter2>flow:to_server; content:&quot;|02 01 00 04 82 01 00|&quot;; offset:4; metadata:service snmp; classtype:misc-attack;</filter2>
        <id>1409</id>
        <msg>SNMP community string buffer overflow attempt</msg>
        <url>www.cert.org/advisories/CA-2002-03.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 31785 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;host&quot;; classtype:misc-activity;</filter2>
        <id>141</id>
        <msg>BACKDOOR HackAttack 1.20 Connect</msg>
      </rule>
      <rule>
        <bugtraq>7212</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2002-0013</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>flow:to_server,established; content:&quot;public&quot;; metadata:service snmp; classtype:attempted-recon;</filter2>
        <id>1412</id>
        <msg>SNMP public access tcp</msg>
      </rule>
      <rule>
        <bugtraq>7212</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2002-0013</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>flow:to_server; content:&quot;private&quot;; metadata:service snmp; classtype:attempted-recon;</filter2>
        <id>1413</id>
        <msg>SNMP private access udp</msg>
      </rule>
      <rule>
        <bugtraq>4132</bugtraq>
        <classtype>attempted-recon</classtype>
        <cve>2002-0013</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>flow:to_server,established; content:&quot;private&quot;; metadata:service snmp; classtype:attempted-recon;</filter2>
        <id>1414</id>
        <msg>SNMP private access tcp</msg>
      </rule>
      <rule>
        <bugtraq>4089</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0013</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161:162</filter1>
        <filter2>flow:to_server; content:&quot; |04 82 01 00|&quot;; depth:5; offset:7; metadata:service snmp; classtype:misc-attack;</filter2>
        <id>1422</id>
        <msg>SNMP community string buffer overflow attempt with evasion</msg>
        <url>www.cert.org/advisories/CA-2002-03.html</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>content:&quot;0&amp;|02 01 00 04 06|public|A0 19 02 01 00 02 01 00 02 01 00|0|0E|0|0C 06 08|+|06 01 02 01 01 05 00 05 00|&quot;; fast_pattern:only; metadata:service snmp; classtype:misc-attack;</filter2>
        <id>1426</id>
        <msg>SNMP PROTOS test-suite-req-app attempt</msg>
        <url>www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2008-3007</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:web-application-attack; metadata: engine shared, soid 3|14262;</filter2>
        <id>14262</id>
        <msg>WEB-CLIENT OneNote iframe caller exploit attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS08-055.mspx</url>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 162</filter1>
        <filter2>content:&quot;08|02 01 00 04 06|public|A4|+|06|&quot;; fast_pattern:only; metadata:service snmp; classtype:misc-attack;</filter2>
        <id>1427</id>
        <msg>SNMP PROTOS test-suite-trap-app attempt</msg>
        <url>www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.history&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1433</id>
        <msg>WEB-MISC .history access</msg>
      </rule>
      <rule>
        <bugtraq>337</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0408</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.bash_history&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1434</id>
        <msg>WEB-MISC .bash_history access</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET !80 -&gt; $HOME_NET 21554</filter1>
        <filter2>flow:to_server,established; content:&quot;Girl&quot;; classtype:misc-activity;</filter2>
        <id>145</id>
        <msg>BACKDOOR GirlFriendaccess</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 30100:30102 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;NetSphere&quot;; classtype:trojan-activity;</filter2>
        <id>146</id>
        <msg>BACKDOOR NetSphere access</msg>
      </rule>
      <rule>
        <bugtraq>24765</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-3624</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [8100,3600]</filter1>
        <filter2>flow:to_server,established; content:&quot;GET /msgserver/html/group?group=&quot;; nocase; isdataat:498,relative; content:!&quot; &quot;; within:498; classtype:attempted-user;</filter2>
        <id>14600</id>
        <msg>EXPLOIT SAP Message Server Heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>25917</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-5244</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3050</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 00 00 13|&quot;; byte_test:4,&gt;,1024,4,relative; classtype:attempted-user;</filter2>
        <id>14602</id>
        <msg>EXPLOIT Borland Interbase open_marker_file overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23648</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2293</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;a=T38FaxRateManagement|3A|&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^a=T38FaxRateManagement\x3A[^\r\n]{256}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>14608</id>
        <msg>VOIP-SIP SDP T.38 fax rate management attribute possible buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>23648</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-2293</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 5060</filter1>
        <filter2>content:&quot;Content-Type|3A|&quot;; nocase; content:&quot;application/sdp&quot;; distance:0; nocase; content:&quot;a=T38FaxUdpEC|3A|&quot;; distance:0; nocase; pcre:&quot;/^Content-Type\x3A\s+application\x2Fsdp/smi&quot;; pcre:&quot;/^a=T38FaxUdpEC\x3A[^\r\n]{256}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>14609</id>
        <msg>VOIP-SIP SDP T.38 fax UDP EC attribute possible buffer overflow</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET 6969 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;GateCrasher&quot;; depth:11; nocase; content:&quot;Server&quot;; distance:0; nocase; content:&quot;On-Line...&quot;; distance:0; nocase; pcre:&quot;/^GateCrasher\s+v\d+\x2E\d+\x2C\s+Server\s+On-Line\x2E\x2E\x2E/smi&quot;; classtype:trojan-activity;</filter2>
        <id>147</id>
        <msg>BACKDOOR GateCrasher</msg>
        <url>www.spywareguide.com/product_show.php?id=973</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [80,3443]</filter1>
        <filter2>flow:to_server,established; content:&quot;OvCGI/connectedNodes.ovpl&quot;; fast_pattern:only; pcre:&quot;/\x3fnode\x3d[^\x3b\x26]+[\x27\x24\x7c\x22\x25\x3c\x3e]/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>14774</id>
        <msg>EXPLOIT HP OpenView Network Node Manger connectedNodes command injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [80,3443]</filter1>
        <filter2>flow:to_server,established; content:&quot;OvCGI/cdpView.ovpl&quot;; fast_pattern:only; pcre:&quot;/\x3fcdpnode\x3d[^\x3b\x26]+[\x27\x24\x7c\x22\x25\x3c\x3e]/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>14775</id>
        <msg>EXPLOIT HP OpenView Network Node Manger cdpnode command injection attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2005-2773</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [80,3443]</filter1>
        <filter2>flow:to_server,established; content:&quot;OvCGI/freeIPaddrs.ovpl&quot;; fast_pattern:only; pcre:&quot;/\x3fnetid\x3d[^\x3b\x26]+[\x27\x24\x7c\x22\x25\x3c\x3e]/i&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>14776</id>
        <msg>EXPLOIT HP OpenView Network Node Manager freeIPaddrs command injection attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/~nobody&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1489</id>
        <msg>WEB-MISC /~nobody access</msg>
        <nessus>10484</nessus>
      </rule>
      <rule>
        <bugtraq>1704</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-1036</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newuser?Image=../..&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1492</id>
        <msg>WEB-MISC RBS ISP /newuser  directory traversal attempt</msg>
        <nessus>10521</nessus>
      </rule>
      <rule>
        <bugtraq>1704</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1036</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/newuser&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1493</id>
        <msg>WEB-MISC RBS ISP /newuser access</msg>
        <nessus>10521</nessus>
      </rule>
      <rule>
        <bugtraq>193</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0449</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/exair/search/&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1500</id>
        <msg>WEB-MISC ExAir access</msg>
        <nessus>10004</nessus>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 7001</filter1>
        <filter2>flow:to_server; content:&quot;|00 00 03 E7 00 00 00 00 00 00 00|e|00 00 00 00 00 00 00 00 0D 05 00 00 00 00 00 00 00|&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>1504</id>
        <msg>MISC AFS access</msg>
        <nessus>10441</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET 502 -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; byte_test:1,&amp;,128,7;  classtype:protocol-command-decode;</filter2>
        <id>15071</id>
        <msg>SCADA Modbus exception returned</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; byte_test:2,&gt;,0,2;  classtype:protocol-command-decode;</filter2>
        <id>15072</id>
        <msg>SCADA Modbus invalid protocol version</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; byte_test:2,&gt;,256,4;  classtype:protocol-command-decode;</filter2>
        <id>15073</id>
        <msg>SCADA Modbus oversized payload</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; byte_test:1,&gt;,64,7; byte_test:1,&lt;,73,7;  classtype:protocol-command-decode;</filter2>
        <id>15074</id>
        <msg>SCADA Modbus user-defined function code - 65 to 72</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; byte_test:1,&gt;,99,7; byte_test:1,&lt;,111,7;  classtype:protocol-command-decode;</filter2>
        <id>15075</id>
        <msg>SCADA Modbus user-defined function code - 100 to 110</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|0F|&quot;; depth:1; offset:7; byte_test:2,&gt;,1968,2,relative;  classtype:protocol-command-decode;</filter2>
        <id>15076</id>
        <msg>SCADA Modbus write multiple coils - too many outputs</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|01|&quot;; depth:1; offset:7; byte_test:2,&gt;,2000,2,relative;  classtype:protocol-command-decode;</filter2>
        <id>15077</id>
        <msg>SCADA Modbus read multiple coils - too many inputs</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2008-1852</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2954</filter1>
        <filter2>flow:to_server,established; pcre:&quot;/^((22|33|35|36|44) \d+ [^\s\x00]{129})|((25|45) \d+ \d+ \d+ [^\s\x00]{129})|((46|47) \d+ \d+ [^\x0a]{129})|((61|62) [^\x0a]{129})/smi&quot;; classtype:attempted-admin;</filter2>
        <id>15078</id>
        <msg>EXPLOIT HP Openview Network Node Manager OValarmsrv buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2008-4259</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15115;</filter2>
        <id>15115</id>
        <msg>WEB-CLIENT WebDAV pathname buffer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS08-073.mspx</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8000</filter1>
        <filter2>flow:to_server,established; content:&quot;/nstelemetry.adp&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1518</id>
        <msg>WEB-MISC nstelemetry.adp access</msg>
        <nessus>10753</nessus>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 5401:5402 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:established,from_server; content:&quot;c|3A 5C|&quot;; classtype:misc-activity;</filter2>
        <id>152</id>
        <msg>BACKDOOR BackConstruction 2.1 Connection</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/server-info&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1520</id>
        <msg>WEB-MISC server-info access</msg>
        <url>httpd.apache.org/docs/mod/mod_info.html</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/server-status&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1521</id>
        <msg>WEB-MISC server-status access</msg>
        <url>httpd.apache.org/docs/mod/mod_info.html</url>
      </rule>
      <rule>
        <bugtraq>4149</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0307</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ans.pl?p=../../&quot;; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1522</id>
        <msg>WEB-MISC ans.pl attempt</msg>
        <nessus>10875</nessus>
      </rule>
      <rule>
        <bugtraq>4149</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2002-0307</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ans.pl&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1523</id>
        <msg>WEB-MISC ans.pl access</msg>
        <nessus>10875</nessus>
      </rule>
      <rule>
        <bugtraq>1025</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0191</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cd/../config/html/cnf_gi.htm&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1524</id>
        <msg>WEB-MISC Axis Storpoint CD attempt</msg>
        <nessus>10023</nessus>
      </rule>
      <rule>
        <bugtraq>1025</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0191</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/config/html/cnf_gi.htm&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1525</id>
        <msg>WEB-MISC Axis Storpoint CD access</msg>
        <nessus>10023</nessus>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2008-4014</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/BPELConsole/default/activities.jsp?'&quot;; http_uri; metadata:policy balanced-ips drop, service http; classtype:web-application-attack;</filter2>
        <id>15256</id>
        <msg>ORACLE BPEL process manager XSS injection attempt</msg>
        <url>www.securityfocus.com/archive/1/500060</url>
      </rule>
      <rule>
        <bugtraq>1459</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0629</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/servlet/sunexamples.BBoardServlet&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1528</id>
        <msg>WEB-MISC BBoard access</msg>
        <nessus>10507</nessus>
      </rule>
      <rule>
        <bugtraq>24004</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2788</cve>
        <filter1>tcp $HOME_NET 80 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|15328;</filter2>
        <id>15328</id>
        <msg>WEB-CLIENT Sun JDK image parsing library ICC buffer overflow attempt</msg>
        <url>scary.beasts.org/security/CESA-2006-004.html</url>
      </rule>
      <rule>
        <bugtraq>1156</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2000-0341</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 119</filter1>
        <filter2>flow:to_server,established; content:&quot;AUTHINFO&quot;; nocase; content:&quot;USER&quot;; distance:0; nocase; isdataat:200,relative; pcre:&quot;/^AUTHINFO\s+USER\s[^\n]{200}/smi&quot;; metadata:service nntp; classtype:attempted-admin;</filter2>
        <id>1538</id>
        <msg>NNTP AUTHINFO USER overflow attempt</msg>
        <nessus>10388</nessus>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|01 02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15389</id>
        <msg>SCADA OMRON-FINS memory area write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|01 03|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15390</id>
        <msg>SCADA OMRON-FINS memory area fill attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|01 05|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15391</id>
        <msg>SCADA OMRON-FINS memory area transfer attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|02 02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15392</id>
        <msg>SCADA OMRON-FINS parameter area write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|02 03|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15393</id>
        <msg>SCADA OMRON-FINS parameter area clear attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|03 04|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15394</id>
        <msg>SCADA OMRON-FINS program area protect attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|03 07|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15396</id>
        <msg>SCADA OMRON-FINS program area write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|03 08|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15397</id>
        <msg>SCADA OMRON-FINS program area clear attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|04 01|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15398</id>
        <msg>SCADA OMRON-FINS RUN attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|04 02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15399</id>
        <msg>SCADA OMRON-FINS STOP attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|07 02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15400</id>
        <msg>SCADA OMRON-FINS clock write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|0C 01|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15401</id>
        <msg>SCADA OMRON-FINS access right acquire attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|0C 02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15402</id>
        <msg>SCADA OMRON-FINS access right forced acquire attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|22 03|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15403</id>
        <msg>SCADA OMRON-FINS single file write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|22 05|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15404</id>
        <msg>SCADA OMRON-FINS file delete attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|23 01|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15405</id>
        <msg>SCADA OMRON-FINS forced set/reset attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|23 01|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15406</id>
        <msg>SCADA OMRON-FINS forced set/reset cancel attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|22 11|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15407</id>
        <msg>SCADA OMRON-FINS file memory write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|02|!&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15408</id>
        <msg>SCADA OMRON-FINS data link table write attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|04 03|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15409</id>
        <msg>SCADA OMRON-FINS RESET attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>attempted-recon</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 79</filter1>
        <filter2>flow:to_server,established; content:&quot;version&quot;; metadata:service finger; classtype:attempted-recon;</filter2>
        <id>1541</id>
        <msg>FINGER version query</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;&amp;|02|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15410</id>
        <msg>SCADA OMRON-FINS name delete attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|22 04|&quot;; depth:2; offset:10; classtype:protocol-command-decode;</filter2>
        <id>15411</id>
        <msg>SCADA OMRON-FINS memory card format attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|01 02|&quot;; depth:2; offset:10; isdataat:10,relative; classtype:protocol-command-decode;</filter2>
        <id>15412</id>
        <msg>SCADA OMRON-FINS memory area write overflow attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|01 03|&quot;; depth:2; offset:10; isdataat:8,relative; classtype:protocol-command-decode;</filter2>
        <id>15413</id>
        <msg>SCADA OMRON-FINS memory area fill overflow attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 9600</filter1>
        <filter2>flow:established,to_server; byte_test:1,!&amp;,64,0; content:&quot;|00 02|&quot;; depth:2; offset:1; content:&quot;|03 05 00 00 00 00 00 00 00 FF FF FF FF|&quot;; depth:13; offset:10; detection_filter:track by_src, count 10, seconds 60; classtype:protocol-command-decode;</filter2>
        <id>15414</id>
        <msg>SCADA OMRON-FINS program area protect clear brute force attempt</msg>
        <url>forums.mrplc.com/index.php?download=467</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;o=c&amp;s=00000&quot;; nocase; pcre:&quot;/^POST \x2F[A-Z\d]{16} /smi&quot;;  metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>15423</id>
        <msg>BOTNET-CNC Clampi virus communication detected</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-011616-5036-99</url>
      </rule>
      <rule>
        <bugtraq>34061</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-0879</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6988</filter1>
        <filter2>flow:to_server,established; content:&quot;POST&quot;; fast_pattern:only; content:&quot;HTTP&quot;; distance:1; nocase; pcre:&quot;/^.*POST\s+\x2f[^\s\x2f]{9,}\x2f[^\s]{235}/i&quot;; classtype:attempted-dos;</filter2>
        <id>15435</id>
        <msg>EXPLOIT IBM Director CIM server consumer name handling denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:trojan-activity; metadata: engine shared, soid 3|15451, service http;</filter2>
        <id>15451</id>
        <msg>EXPLOIT possible Conficker.C HTTP traffic 1</msg>
        <url>mtc.sri.com/Conficker/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>gid:3; classtype:trojan-activity; metadata: engine shared, soid 3|15452, service http;</filter2>
        <id>15452</id>
        <msg>EXPLOIT possible Conficker.C HTTP traffic 2</msg>
        <url>mtc.sri.com/Conficker/</url>
      </rule>
      <rule>
        <bugtraq>21206</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6063</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;|23|EXTM3U&quot;; nocase; pcre:&quot;/^[^\x0a]{501}/m&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15473</id>
        <msg>WEB-CLIENT Multiple media players M3U playlist file handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33059</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5911</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;Proxy-Require&quot;; fast_pattern:only; pcre:&quot;/^Proxy-Require\s*\x3a\s*[^\x0a]{33}/mi&quot;; classtype:attempted-admin;</filter2>
        <id>15479</id>
        <msg>EXPLOIT RealNetworks Helix Server RTSP Request Proxy-Require header heap buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>33059</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-5911</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 554</filter1>
        <filter2>flow:to_server,established; content:&quot;SETUP&quot;; depth:5; nocase; pcre:&quot;/[A-Z0-9][^\x3f\x0a\x0d]{1023,}\x3f/iR&quot;; classtype:attempted-admin;</filter2>
        <id>15571</id>
        <msg>EXPLOIT RealNetworks Helix Server RTSP SETUP stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>2000-0165</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 8080</filter1>
        <filter2>flow:to_server,established; content:&quot;whois|3A|//&quot;; nocase; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1558</id>
        <msg>WEB-MISC Delegate whois overflow attempt</msg>
        <nessus>10054</nessus>
      </rule>
      <rule>
        <bugtraq>1707</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-1016</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/doc/packages&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1559</id>
        <msg>WEB-MISC /doc/packages access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <bugtraq>318</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-0678</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/doc/&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1560</id>
        <msg>WEB-MISC /doc/ access</msg>
      </rule>
      <rule>
        <bugtraq>665</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>1999-1533</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login.htm?password=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1563</id>
        <msg>WEB-MISC login.htm attempt</msg>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;snews|3A|&quot;; nocase; pcre:&quot;/^[^\n]*?(\x2E(com|bat|cmd|exe)((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5c)00)/Ri&quot;; classtype:attempted-user;</filter2>
        <id>15684</id>
        <msg>EXPLOIT Multiple product snews uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>35494</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1628</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [3985,3986]</filter1>
        <filter2>flow:to_server,established; content:&quot;|16|?&quot;; depth:2; byte_test:4,&gt;,24,2,big; classtype:attempted-admin;</filter2>
        <id>15708</id>
        <msg>EXPLOIT Unisys Business Information Server stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&lt;,5,0,relative;  classtype:protocol-command-decode;</filter2>
        <id>15712</id>
        <msg>SCADA DNP3 declared length too small</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,64,13;  classtype:protocol-command-decode;</filter2>
        <id>15713</id>
        <msg>SCADA DNP3 device trouble</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,32,14;  classtype:protocol-command-decode;</filter2>
        <id>15714</id>
        <msg>SCADA DNP3 corrupt configuration</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,8,14;  classtype:protocol-command-decode;</filter2>
        <id>15715</id>
        <msg>SCADA DNP3 event buffer overflow error</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,4,14;  classtype:protocol-command-decode;</filter2>
        <id>15716</id>
        <msg>SCADA DNP3 parameter error</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,2,14;  classtype:protocol-command-decode;</filter2>
        <id>15717</id>
        <msg>SCADA DNP3 unknown object error</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,&amp;,64,1,relative; byte_test:1,&amp;,1,14;  classtype:protocol-command-decode;</filter2>
        <id>15718</id>
        <msg>SCADA DNP3 unsupported function code error</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:1,!&amp;,64,1,relative; byte_test:1,&amp;,15,3;  classtype:protocol-command-decode;</filter2>
        <id>15719</id>
        <msg>SCADA DNP3 link service not supported</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:2,&gt;,65519,6,little; byte_test:2,&lt;,65532,6,little;  classtype:protocol-command-decode;</filter2>
        <id>15720</id>
        <msg>SCADA DNP3 reserved source address</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 20000</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|d&quot;; depth:2; byte_test:2,&gt;,65519,4,little; byte_test:2,&lt;,65532,4,little;  classtype:protocol-command-decode;</filter2>
        <id>15721</id>
        <msg>SCADA DNP3 reserved destination address</msg>
        <url>www.dnp.org/About/Default.aspx</url>
      </rule>
      <rule>
        <bugtraq>1089</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0289</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/slxweb.dll&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1588</id>
        <msg>WEB-MISC SalesLogix Eviewer access</msg>
      </rule>
      <rule>
        <bugtraq>2374</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2001-0224</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/empower?DB=&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1589</id>
        <msg>WEB-MISC musicat empower attempt</msg>
        <nessus>10609</nessus>
      </rule>
      <rule>
        <bugtraq>29792</bugtraq>
        <classtype>misc-activity</classtype>
        <cve>2008-2959</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;fCreateShellLink|28|&quot;; nocase; metadata:service http; classtype:misc-activity;</filter2>
        <id>15893</id>
        <msg>WEB-CLIENT fCreateShellLink function use - potential attack</msg>
      </rule>
      <rule>
        <bugtraq>11015</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0826</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS 443</filter1>
        <filter2>flow:to_server,established; content:&quot;|01 00 01|&quot;; depth:3; offset:2; byte_test:1,&gt;,127,0; byte_test:2,&gt;,32,9; metadata:service ssl; classtype:attempted-admin;</filter2>
        <id>15897</id>
        <msg>WEB-MISC SSLv1 Client_Hello Challenge Length overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2003-0605</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 135</filter1>
        <filter2>flow:established,to_server; content:&quot;|05 00 06 01 00 00 00 00|11111111111111111111111111111111|00 00 00 00 00 00 00 00|&quot;; fast_pattern:only; classtype:attempted-user;</filter2>
        <id>15903</id>
        <msg>SHELLCODE x86 PoC CVE-2003-0605</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1720</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 00 00 01 80 88 19 08 16|aaaaaaaaaaaaaaaaaa&quot;; classtype:attempted-admin;</filter2>
        <id>15937</id>
        <msg>SPECIFIC-THREATS protos h323 buffer overflow</msg>
        <url>www.ee.oulu.fi/research/ouspg/protos/testing/c07/h2250v4/index.html</url>
      </rule>
      <rule>
        <bugtraq>23906</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2522</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12168</filter1>
        <filter2>flow:to_server,established; content:&quot;|96|8|9E 04|&quot;; depth:8; offset:4; byte_test:4,&gt;,83,0; content:!&quot;|F6|v|D0|&quot;; depth:24; offset:21; classtype:attempted-user;</filter2>
        <id>15942</id>
        <msg>MISC CA Multiple Products Console Server login credentials handling overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>23906</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-2522</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 12168</filter1>
        <filter2>flow:to_server,established; content:&quot;|96|8|9E 04|&quot;; depth:8; offset:4; byte_test:4,&gt;,83,0; byte_test:1,&amp;,192,20; classtype:attempted-user;</filter2>
        <id>15943</id>
        <msg>MISC CA Multiple Products Console Server login credentials handling overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>12705</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0581</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [10202,10203,10204]</filter1>
        <filter2>flow:to_server,established; content:&quot;A0 &quot;; depth:3; isdataat:50,relative; classtype:attempted-user;</filter2>
        <id>15948</id>
        <msg>SPECIFIC-THREATS CA License Software Invalid Command overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>10243</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;testfile|F8 1B|U|05 00|P|B4 81 94 01 01|AAAA&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15949</id>
        <msg>SPECIFIC-THREATS McAfee LHA file handling overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <cve>2004-0444</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 1900</filter1>
        <filter2>content:&quot;|00 03 80| |00 01 00 01 00 00 00 00 01|V|01|&quot;; byte_test:1, &amp;, 128, 2; byte_test:2, &gt;, 0, 4; byte_test:2, &gt;, 0, 6; pcre:&quot;/^.{12}(\x01.){20}/&quot;; metadata:service dns; classtype:misc-attack;</filter2>
        <id>15972</id>
        <msg>SPECIFIC-THREATS single byte encoded name response</msg>
      </rule>
      <rule>
        <bugtraq>10820</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0699</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 500</filter1>
        <filter2>flow:to_server; content:&quot;|84 FF FF FF FE|&quot;; fast_pattern:only; pcre:&quot;/[\x04\x0c\x14\x16\x1c\x1e\x24\x34]\x84\xff{3}\xfe/&quot;; classtype:attempted-dos;</filter2>
        <id>15979</id>
        <msg>EXPLOIT Check Point VPN-1 ASN.1 Decoding heap overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>11385</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2004-0918</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 3401</filter1>
        <filter2>flow:to_server; content:&quot;0|84 FF FF FF|&quot;; byte_test:1,&gt;,0xf9,0,relative; metadata:service snmp; classtype:attempted-dos;</filter2>
        <id>15989</id>
        <msg>EXPLOIT Squid ASN.1 header parsing denial of service attempt</msg>
      </rule>
      <rule>
        <bugtraq>19106</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2006-3853</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.jsp&quot;; http_uri; pcre:&quot;/^[^\x3b]*\x3b.*\x2ejsp/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>15990</id>
        <msg>WEB-MISC Multiple Vendor server file disclosure attempt</msg>
      </rule>
      <rule>
        <bugtraq>12643</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-0533</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;NEKP2E|00 00 00|E|00 00 00 DB|+|D0 1D 00 00| |00 00 00|AAAA&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>15992</id>
        <msg>SPECIFIC-THREATS Trend Micro Products Antivirus Library overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-0465</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.pkg&quot;; nocase; http_uri; pcre:&quot;/GET\s+[^\x0D\x0A]*\x25[^\x0D\x0A]*\x2Epkg/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>16002</id>
        <msg>WEB-CLIENT Apple Mac OS X installer package filename format string vulnerability</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-0465</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.distz&quot;; nocase; http_uri; pcre:&quot;/GET\s+[^\x0D\x0A]*\x25[^\x0D\x0A]*\x2Edistz/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>16003</id>
        <msg>WEB-CLIENT Apple Mac OS X installer package filename format string vulnerability</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2007-0465</cve>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.mpkg&quot;; nocase; http_uri; pcre:&quot;/GET\s+[^\x0D\x0A]*\x25[^\x0D\x0A]*\x2Empkg/smi&quot;; metadata:service http; classtype:attempted-admin;</filter2>
        <id>16004</id>
        <msg>WEB-CLIENT Apple Mac OS X installer package filename format string vulnerability</msg>
      </rule>
      <rule>
        <bugtraq>10333</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2004-0444</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 137</filter1>
        <filter2>flow:to_server; byte_test:1,&gt;,127,2; content:&quot;|00 01|&quot;; depth:2; offset:6; byte_test:1,&gt;,32,12; metadata:service netbios-ns; classtype:attempted-admin;</filter2>
        <id>16015</id>
        <msg>SPECIFIC-THREATS Norton Internet Security NBNS response processing stack overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>28689</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-1842</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777</filter1>
        <filter2>flow:established,to_server; isdataat:1000; byte_test:4,&gt;,16384,0; content:&quot;aaaaaaaaaaaaaaaaa&quot;; classtype:attempted-admin;</filter2>
        <id>16018</id>
        <msg>SPECIFIC-THREATS HP OpenView network node manager buffer overflow</msg>
      </rule>
      <rule>
        <classtype>denial-of-service</classtype>
        <cve>2006-0995</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 497</filter1>
        <filter2>flow:to_server,established; content:&quot;|87 00 00|&quot;; depth:3; offset:1; content:&quot;|00 00 00 00|&quot;; within:4; distance:4; metadata:policy connectivity-ips drop; classtype:denial-of-service;</filter2>
        <id>16039</id>
        <msg>MISC EMC Dantz Retrospect Backup Agent denial of service attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <cve>1999-0897</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 4080</filter1>
        <filter2>flow:to_server,established; content:&quot;/../../&quot;; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1604</id>
        <msg>WEB-MISC iChat directory traversal attempt</msg>
      </rule>
      <rule>
        <bugtraq>6844</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>1999-1566</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6004</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF FF FF FF FF FF|&quot;; offset:0; classtype:misc-attack;</filter2>
        <id>1605</id>
        <msg>DOS iParty DOS attempt</msg>
        <nessus>10111</nessus>
      </rule>
      <rule>
        <bugtraq>26554</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-6009</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.xpm; content:&quot;static&quot;; fast_pattern:only; content:&quot;Content-Type|3A|&quot;; nocase; http_header; pcre:&quot;/^static\s+(\w+\s+)??char\s*\x2A\s*\w+\s*\x5B\x5D\s*\x3D\s*\x7B.*\x22[^\x22]{200}/smiH&quot;; classtype:attempted-user;</filter2>
        <id>16062</id>
        <msg>MISC ACD Systems ACDSee Products XPM values section buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/wm.php&quot;; nocase; content:&quot;ver=&quot;; distance:0; nocase; content:&quot;MAX_EXECUTE_TIME=&quot;; distance:0; nocase; content:&quot;RELOAD_JOBS=&quot;; distance:0; nocase; content:&quot;BROWSER_DELAY=&quot;; distance:0; nocase; content:&quot;CONTROL_PAGE=&quot;; distance:0; nocase; content:&quot;lastlogcount=&quot;; distance:0; nocase; content:&quot;REPORTS_PAGE=&quot;; distance:0; nocase; content:&quot;TICKETS_PAGE=&quot;; distance:0; nocase; content:&quot;botid=&quot;; distance:0; nocase; content:&quot;REG_NAME=&quot;; distance:0; nocase; content:&quot;botlogin=&quot;; distance:0; nocase;  classtype:trojan-activity;</filter2>
        <id>16092</id>
        <msg>BACKDOOR win32.delf.jwh runtime detection</msg>
        <url>www.emsisoft.com/en/malware/?Backdoor.Win32.Delf.jwh</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ftpgd.exe&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>16094</id>
        <msg>BACKDOOR trojan downloader exchan.gen variant runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-041717-0829-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/getfiles.php&quot;; nocase; content:&quot;id=&quot;; distance:0; nocase; content:&quot;sid=anycrc&quot;; distance:0; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;flz.anycracks.com&quot;; nocase; http_header;  classtype:trojan-activity;</filter2>
        <id>16095</id>
        <msg>BACKDOOR td.exe runtime detection - getfile</msg>
        <url>www.spywareremove.com/removetdexe.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/download.php&quot;; nocase; content:&quot;id=&quot;; distance:0; nocase; content:&quot;Submit=Download+Crack+and+Keygen&quot;; distance:0; nocase;  classtype:trojan-activity;</filter2>
        <id>16096</id>
        <msg>BACKDOOR td.exe runtime detection - download</msg>
        <url>www.spywareremove.com/removetdexe.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;mode=gen&quot;; nocase; http_uri; content:&quot;gd=&quot;; nocase; http_uri; content:&quot;affid=&quot;; nocase; http_uri; content:&quot;W10=&quot;; nocase; http_uri; content:&quot;subid=&quot;; nocase; http_uri; content:&quot;prov=&quot;; nocase; http_uri; content:&quot;ua=&quot;; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.zabeedly.com/search.php?q=&quot;; nocase; http_header; pcre:&quot;/^Referer\x3a[^\r\n]*www\x2ezabeedly\x2ecom\x2fsearch\x2ephp\x3fq\x3d/smiH&quot;; classtype:trojan-activity;</filter2>
        <id>16097</id>
        <msg>BACKDOOR trojan win32.agent.vvm runtime detection</msg>
        <url>www.kaspersky.co.jp/viruswatchlite?hour_offset=-4&amp;search_virus=dropper&amp;page=1</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/new.rar&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;htfc8.cn&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16099</id>
        <msg>BACKDOOR trojan-dropper.win32.agent.wdv runtime detection</msg>
        <url>www.spywaredetector.net/spyware_encyclopedia/Clicker.Agent.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET 3344 -&gt; $HOME_NET 3345</filter1>
        <filter2>flow:to_server; content:&quot;activate&quot;; classtype:misc-activity;</filter2>
        <id>161</id>
        <msg>BACKDOOR Matrix 2.0 Client connect</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files/56/v2test7/file.exe&quot;; http_uri; classtype:trojan-activity;</filter2>
        <id>16100</id>
        <msg>BACKDOOR trojan-downloader.win32.delf.phh runtime detection - file.exe</msg>
        <url>www.threatexpert.com/report.aspx?uid=37b59ba2-9a43-458f-8e8e-d150ab422b5c</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/lm/57329.exe&quot;; http_uri; classtype:trojan-activity;</filter2>
        <id>16101</id>
        <msg>BACKDOOR trojan-downloader.win32.delf.phh runtime detection - 57329.exe</msg>
        <url>www.threatexpert.com/report.aspx?uid=37b59ba2-9a43-458f-8e8e-d150ab422b5c</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/sft/cvs/cache/sft_ver1.1454.0.exe&quot;; http_uri; classtype:trojan-activity;</filter2>
        <id>16102</id>
        <msg>BACKDOOR trojan-downloader.win32.delf.phh runtime detection - sft_ver1.1454.0.exe</msg>
        <url>www.threatexpert.com/report.aspx?uid=37b59ba2-9a43-458f-8e8e-d150ab422b5c</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,LostDoor3_InitConn; content:&quot;v1ct1m[|5C|AS/]&quot;; depth:12; nocase; classtype:trojan-activity;</filter2>
        <id>16104</id>
        <msg>BACKDOOR lost door 3.0 runtime detection - init</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/servlet/ajrotator/9105&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;servedby.topqualityads.net&quot;; nocase; http_header;  classtype:trojan-activity;</filter2>
        <id>16105</id>
        <msg>BACKDOOR trojan.zlob runtime detection - topqualityads</msg>
        <url>www.threatexpert.com/report.aspx?uid=8b81ce31-7f67-4880-8ec0-8359f96d6303</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,SynRat2.1_initconn; content:&quot;CON&quot;; depth:3; nocase; pcre:&quot;/^CON\w+\d+\xAE/smi&quot;; classtype:trojan-activity;</filter2>
        <id>16107</id>
        <msg>BACKDOOR synrat 2.1 pro runtime detection - init</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/templates/onestoponlineshop.net/images/css.css&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;onestoponlineshop.net&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16109</id>
        <msg>BACKDOOR trojan-downloader.win32.zlob.wwv runtime detection - onestoponlineshop</msg>
        <url>www.threatexpert.com/report.aspx?uid=0f289bca-21bb-40ac-bec6-8eef22a6172a</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pas/apstpldr.dll.html?affid=152174&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;childhe.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16110</id>
        <msg>BACKDOOR trojan-downloader.win32.zlob.wwv runtime detection - childhe</msg>
        <url>www.threatexpert.com/report.aspx?uid=0f289bca-21bb-40ac-bec6-8eef22a6172a</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/Setup_ver1.1427.0.exe&quot;; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;slpm12345.googlepages.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16111</id>
        <msg>BACKDOOR trojan-downloader.win32.zlob.wwv installtime detection</msg>
        <url>www.threatexpert.com/report.aspx?uid=0f289bca-21bb-40ac-bec6-8eef22a6172a</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/post.asp?&quot;; nocase; http_uri; content:&quot;HD=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;rebot1.whatthisdown.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16112</id>
        <msg>BACKDOOR trojan downloader.agent.vhb runtime detection - contact remote server</msg>
        <url>www.virustotal.com/analisis/0326fdbb9ff5e2fa6fa847a095ec9e45</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/login.htm&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.sf123.com&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16113</id>
        <msg>BACKDOOR trojan downloader.agent.vhb runtime detection - request login page</msg>
        <url>www.virustotal.com/analisis/0326fdbb9ff5e2fa6fa847a095ec9e45</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/style/style1_21.css&quot;; fast_pattern; nocase; http_uri; content:&quot;Referer|3A|&quot;; nocase; http_header; content:&quot;www.fuck-portal.com&quot;; nocase; http_header; pcre:&quot;/^Referer\x3a[^\r\n]*www\x2efuck\x2dportal\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16114</id>
        <msg>SPYWARE-PUT Hijacker cramtoolbar runtime detection - hijack</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2005-091817-2335-99&amp;tabid=1</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/n4.g?&quot;; nocase; http_uri; content:&quot;login=craxam&quot;; fast_pattern; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;pv=&quot;; nocase; http_uri; content:&quot;jv=&quot;; nocase; http_uri; content:&quot;j=&quot;; nocase; http_uri; content:&quot;srw=&quot;; nocase; http_uri; content:&quot;srb=&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>16115</id>
        <msg>SPYWARE-PUT Hijacker cramtoolbar runtime detection - search</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2005-091817-2335-99&amp;tabid=1</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/ip.php&quot;; nocase; content:&quot;Host|3A| ads.targetedbanner.biz&quot;; distance:0; nocase;  classtype:successful-recon-limited;</filter2>
        <id>16116</id>
        <msg>SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection - pass user info to remote server</msg>
        <url>www.sophos.com/security/analyses/adware-and-puas/rightonadz.html</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/123kah.php&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ads.targetedbanner.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ads\x2etargetedbanner\x2ebiz/smiH&quot;;  classtype:successful-recon-limited;</filter2>
        <id>16117</id>
        <msg>SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection - ads</msg>
        <url>www.sophos.com/security/analyses/adware-and-puas/rightonadz.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.html&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.winreanimator.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2ewinreanimator\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16118</id>
        <msg>SPYWARE-PUT Adware winreanimator runtime detection - register request</msg>
        <url>www.windowsvistaplace.com/winreanimator-removal-instructions-winreanimator/spyware-removal</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/WinReanimator/daily.cvd&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>16119</id>
        <msg>SPYWARE-PUT Adware winreanimator runtime detection - daily update</msg>
        <url>www.windowsvistaplace.com/winreanimator-removal-instructions-winreanimator/spyware-removal</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/data.aspx?&quot;; nocase; http_uri; content:&quot;pn=sixsigmaToolbar&quot;; fast_pattern; nocase; http_uri; content:&quot;ver=&quot;; nocase; http_uri; content:&quot;url=&quot;; nocase; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Asynchronous&quot;; nocase; http_header; content:&quot;WinInet&quot;; nocase; http_header; content:&quot;CLASS&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Asynchronous\s+WinInet\s+CLASS/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>16120</id>
        <msg>SPYWARE-PUT Trackware 6sq toolbar runtime detection</msg>
        <url>www.spycheck.es/genera.php?processfile=6sqtoolbar.dll&amp;dir=otros&amp;pag=165</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dp/&quot;; nocase; http_uri; content:&quot;x=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;as.weatherstudio.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*as\x2eweatherstudio\x2ecom/smiH&quot;;  classtype:misc-activity;</filter2>
        <id>16121</id>
        <msg>SPYWARE-PUT Hijacker weatherstudio runtime detection</msg>
        <url>vil.nai.com/vil/content/v_137487.htm</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy2/&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.anti-virusxp2008.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2eanti\x2dvirusxp2008\x2enet/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16122</id>
        <msg>SPYWARE-PUT rogue antivirus xp 2008 runtime detection - buy</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/updates/check.html&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.anti-virusxp2008.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2eanti\x2dvirusxp2008\x2enet/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16123</id>
        <msg>SPYWARE-PUT rogue antivirus xp 2008 runtime detection - update</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/keyword/urlRedirect.cfm?&quot;; fast_pattern; nocase; http_uri; content:&quot;v=&quot;; nocase; http_uri; content:&quot;a=SEARCHFST&quot;; nocase; http_uri; content:&quot;k=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.metadirect.net&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2emetadirect\x2enet/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16124</id>
        <msg>SPYWARE-PUT downloader trojan.nsis.agent.s runtime detection</msg>
        <url>www.pctools.com/mrc/infections/id/Adware.Metadirect_hijacker/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;RETR k3ylogger.txt&quot;; fast_pattern:only; classtype:successful-recon-limited;</filter2>
        <id>16125</id>
        <msg>SPYWARE-PUT Keylogger spyyahoo v2.2 runtime detection</msg>
        <url>www.megasecurity.org/trojans/s/spyyahoo/Spyyahoo2.2.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/2009/order/index.html?&quot;; fast_pattern; nocase; http_uri; content:&quot;addt=&quot;; nocase; http_uri; content:&quot;pc_id=&quot;; nocase; http_uri; content:&quot;abbr=3P_UVRM&quot;; nocase; http_uri; content:&quot;nid=3P_UVRM&quot;; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>16126</id>
        <msg>SPYWARE-PUT Trickler virusremover 2008 runtime detection</msg>
        <url>www.spywareremove.com/removeVirusRemover2008.html</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/123kah.php&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;superiorads.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*superiorads\x2ebiz/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16127</id>
        <msg>SPYWARE-PUT Adware superiorads runtime detection</msg>
        <url>www.precisesecurity.com/threats/adwaresuperiorads/</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ahmad.php&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.kamyab-hack.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2ekamyab-hack\x2ecom/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>16129</id>
        <msg>SPYWARE-PUT Keylogger kamyab Keylogger v.3 runtime detection</msg>
        <url>www.megasecurity.org/trojans/k/keylogger/Kamyabkeylogger3.0.html</url>
      </rule>
      <rule>
        <bugtraq>380</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>1999-0148</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/handler&quot;; http_uri; content:&quot;|7C|&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1613</id>
        <msg>WEB-MISC handler attempt</msg>
        <nessus>10100</nessus>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;POST //&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;www.fakemailer.info&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*www\x2efakemailer\x2einfo/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>16130</id>
        <msg>SPYWARE-PUT Keylogger lord spy pro 1.4 runtime detection</msg>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bc/123kah.php&quot;; nocase; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;ads.gooochi.biz&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*ads\x2egooochi\x2ebiz/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>16131</id>
        <msg>SPYWARE-PUT Trackware adclicker trojan zlob.dnz runtime detection - ads</msg>
        <url>www.threatexpert.com/report.aspx?uid=6b4f9be8-f080-4aa7-bb1a-c25231426315</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/success.php?&quot;; nocase; http_uri; content:&quot;itemname=&quot;; http_uri; content:&quot;User-Agent|3A| Nimo Software HTTP Retriever&quot;; fast_pattern:only; nocase; classtype:successful-recon-limited;</filter2>
        <id>16132</id>
        <msg>SPYWARE-PUT Trackware owlforce runtime detection - remote server #1</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453113210</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/status.php?&quot;; nocase; http_uri; content:&quot;searchurl=&quot;; http_uri; content:&quot;version=&quot;; http_uri; content:&quot;act=&quot;; http_uri; content:&quot;User-Agent|3A|&quot;; nocase; http_header; content:&quot;Nimo Software HTTP Retriever&quot;; nocase; http_header; pcre:&quot;/^User-Agent\x3a[^\r\n]*Nimo\x20Software\x20HTTP\x20Retriever/smiH&quot;; classtype:successful-recon-limited;</filter2>
        <id>16133</id>
        <msg>SPYWARE-PUT Trackware owlforce runtime detection - remote server #2</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453113210</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/api.php?&quot;; nocase; http_uri; content:&quot;data=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;cmserv.org&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*cmserv\x2eorg/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16134</id>
        <msg>SPYWARE-PUT Adware spyware guard 2008 runtime detection - contacts remote server</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453141606</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.html?&quot;; nocase; http_uri; content:&quot;track_id=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;gosg2008.com&quot;; nocase; http_header; pcre:&quot;/^Host\x3a[^\r\n]*gosg2008\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16135</id>
        <msg>SPYWARE-PUT Adware spyware guard 2008 runtime detection - purchase page</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453141606</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.html?&quot;; nocase; http_uri; content:&quot;wmid=&quot;; nocase; http_uri; content:&quot;skey=&quot;; nocase; http_uri; content:&quot;Host|3A| www.xpas2009.com&quot;; fast_pattern; nocase; http_header; classtype:misc-activity;</filter2>
        <id>16136</id>
        <msg>SPYWARE-PUT Hijacker xp antispyware 2009 runtime detection - pre-sale webpage</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453141780</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;Report&quot;; nocase; content:&quot;@&quot;; nocase; content:&quot;name=cheatmonitorR_SCREEN.DATETIME.&quot;; fast_pattern:only; pcre:&quot;/Report\x20\x40.*name\x3dcheatmonitorR\x5fSCREEN\x2eDATETIME/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>16137</id>
        <msg>SPYWARE-PUT Keylogger cheat monitor runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-090408-5607-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;sendmail.php?&quot;; nocase; http_uri; content:&quot;mail=&quot;; nocase; http_uri; content:&quot;subject=&quot;; nocase; http_uri; content:&quot;Odesa mpsteal form&quot;; fast_pattern; nocase; http_uri; classtype:misc-activity;</filter2>
        <id>16138</id>
        <msg>SPYWARE-PUT Hacker-Tool 0desa msn pass stealer 8.5 runtime detection</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?&quot;; nocase; http_uri; content:&quot;advid=&quot;; nocase; http_uri; content:&quot;Host|3A|&quot;; nocase; http_header; content:&quot;scanner.vav-x-scanner.com&quot;; nocase; http_header; pcre:&quot;/\x2F\d+\x2F\x3Fadvid\x3D/smi&quot;; pcre:&quot;/Host\x3a[^\r\n]*scanner\x2evav\x2dx\x2dscanner\x2ecom/smiH&quot;; classtype:misc-activity;</filter2>
        <id>16139</id>
        <msg>SPYWARE-PUT downloader_trojan.gen2 runtime detection - scanner page</msg>
        <url>www.threatexpert.com/report.aspx?uid=6a5f4829-667f-4f53-876d-ca74fe4cfcf0</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;kos-main.jar&quot;; nocase; http_uri; content:!&quot;Host|3A| www.kaspersky.com|0D 0A|&quot;; nocase; http_header; metadata:service http; classtype:trojan-activity;</filter2>
        <id>16141</id>
        <msg>SPECIFIC-THREATS Kaspersky Online Scanner trojaned Dll download attempt</msg>
        <url>intevydis.com/blog/?p=77</url>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <cve>2000-0832</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/htgrep&quot;; http_uri; content:&quot;hdr=/&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1615</id>
        <msg>WEB-MISC htgrep attempt</msg>
        <nessus>10495</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2500</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16153;</filter2>
        <id>16153</id>
        <msg>WEB-CLIENT malformed WMF meta escape record memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2504</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,exe.download; metadata: engine shared, soid 3|16154;</filter2>
        <id>16154</id>
        <msg>WEB-CLIENT GDI+ .NET image property parsing memory corruption</msg>
        <url>www.microsoft.com/technet/security/Bulletin/MS09-062.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>udp $EXTERNAL_NET 3345 -&gt; $HOME_NET 3344</filter1>
        <filter2>flow:to_server; content:&quot;logged in&quot;; classtype:misc-activity;</filter2>
        <id>162</id>
        <msg>BACKDOOR Matrix 2.0 Server access</msg>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; flowbits:isset,http.mp4; metadata: engine shared, soid 3|16224;</filter2>
        <id>16224</id>
        <msg>WEB-CLIENT TRUFFLEHUNTER SFVRT-1004 attack attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2009-2514</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|16231;</filter2>
        <id>16231</id>
        <msg>WEB-CLIENT Windows kernel-mode drivers core font parsing integer overflow attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS09-065.mspx</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/adv/058/adload.php&quot;; http_uri; content:&quot;Host|3A| all1count.net&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16242</id>
        <msg>BACKDOOR downloader-ash.gen.b runtime detection - adload</msg>
        <url>www.threatexpert.com/report.aspx?md5=bffe465b5949e78821ffb76b0ed25bb4</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/xpbuy/&quot;; nocase; http_uri; content:&quot;Host|3A| xp-police.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16244</id>
        <msg>BACKDOOR rogue software xp police antivirus runtime detection - purchase</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453151932</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/controller.php&quot;; nocase; http_uri; content:&quot;action=&quot;; nocase; http_uri; content:&quot;guid=&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>16245</id>
        <msg>BACKDOOR rogue software xp police antivirus install-timedetection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453151932</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/purchase?&quot;; nocase; http_uri; content:&quot;r=&quot;; nocase; http_uri; content:&quot;Host|3A| spywprotect.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16246</id>
        <msg>BACKDOOR rogue software spyware protect 2009 runtime detection - purchase request</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453151948</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/block.php?&quot;; nocase; http_uri; content:&quot;r=19.0&quot;; nocase; http_uri; content:&quot;Host|3A| browser-security.microsoft.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16247</id>
        <msg>BACKDOOR rogue software spyware protect 2009 runtime detection - block</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453151948</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stat.php&quot;; http_uri; content:&quot;func=&quot;; nocase; http_uri; content:&quot;Host|3A| int.ms-asreport1.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16248</id>
        <msg>BACKDOOR rogue software ms antispyware 2009 runtime detection - start</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453146855</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pay/&quot;; http_uri; content:&quot;Host|3A| sales.buy-msantispyware2009.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16249</id>
        <msg>BACKDOOR rogue software ms antispyware 2009 runtime detection - pay</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453146855</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pp/?id=&quot;; nocase; http_uri; content:&quot;Host|3A| billingpayment.net&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16250</id>
        <msg>BACKDOOR rogue software win pc defender runtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453153970</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/installed.php?&quot;; nocase; http_uri; content:&quot;id=&quot;; nocase; http_uri; content:&quot;Host|3A| win-pc-defender.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16251</id>
        <msg>BACKDOOR rogue software win pc defender installtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453153970</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/pay/&quot;; http_uri; content:&quot;Host|3A| sales.proantispyware-2009-buy.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16252</id>
        <msg>BACKDOOR rogue software pro antispyware 2009 runtime detection - purchase</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453144054</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cards/&quot;; http_uri; content:&quot;affid=&quot;; http_uri; content:&quot;Host|3A| electronicbillinghost.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16253</id>
        <msg>BACKDOOR rogue software system security 2009 runtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453154339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,systemsecurity2009; content:&quot;location|3A| in.php?url=&quot;; nocase; http_header; classtype:trojan-activity;</filter2>
        <id>16255</id>
        <msg>BACKDOOR rogue software system security 2009 installtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453154339</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/c.dat&quot;; http_uri; content:&quot;Host|3A| guardlab2009.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16256</id>
        <msg>BACKDOOR rogue software coreguard antivirus 2009 runtime detection</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453157038</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upd1.php&quot;; http_uri; content:&quot;dbbasediv=&quot;; http_uri; content:&quot;Host|3A| download.pdefender2009.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16257</id>
        <msg>BACKDOOR rogue software perfect defender 2009 runtime detection - update</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453144750</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php&quot;; http_uri; content:&quot;Host|3A| www.pdefender2009.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16258</id>
        <msg>BACKDOOR rogue software perfect defender 2009 runtime detection - purchase</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453144750</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/join.html&quot;; http_uri; content:&quot;Host|3A| www.antivirus-doktor.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16259</id>
        <msg>BACKDOOR rogue software antivirusdoktor2009 runtime detection</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453164387</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/firstrun.php&quot;; nocase; http_uri; content:&quot;product=XPA&quot;; nocase; http_uri; content:&quot;aff=&quot;; nocase; http_uri; content:&quot;Host|3A| liveresponsesite.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16260</id>
        <msg>BACKDOOR rogue software xp antivirus protection runtime detection - installation</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453122012</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/order_xp.php&quot;; nocase; http_uri; content:&quot;ver=&quot;; http_uri; content:&quot;Host|3A| liveresponsesite.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16261</id>
        <msg>BACKDOOR rogue software xp antivirus protection runtime detection - runtime</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453122012</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/purchase.htm?aid&quot;; http_uri; content:&quot;Host|3A| www.xp-shield.cn&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16262</id>
        <msg>BACKDOOR rogue software xp-shield runtime detection</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453133950</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/install/?aid&quot;; http_uri; content:&quot;Host|3A| www.xp-shield.cn&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16263</id>
        <msg>BACKDOOR rogue software xp-shield runtime detection - installation</msg>
        <url>www.ca.com/securityadvisor/pest/pest.aspx?id=453133950</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/007AS/update/Update.ini&quot;; http_uri; content:&quot;Host|3A| www.webslt.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16264</id>
        <msg>BACKDOOR rogue software 007 anti-spyware runtime detection - update</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2009-073120-1433-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/register&quot;; http_uri; content:&quot;Host|3A| www.007antispyware.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16265</id>
        <msg>BACKDOOR rogue software 007 anti-spyware runtime detection - register</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2009-073120-1433-99</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.html&quot;; http_uri; content:&quot;Host|3A| pc-antispy2010.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16266</id>
        <msg>BACKDOOR rogue software pc antispyware 2010 runtime detection - buy</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453172046</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/files&quot;; http_uri; content:&quot;Host|3A| gomafobianiotas.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16267</id>
        <msg>BACKDOOR rogue software pc antispyware 2010 runtime detection - files</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453172046</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tdss/&quot;; http_uri; content:&quot;Host|3A| yournewsblog.net&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16268</id>
        <msg>BACKDOOR trojan.tdss.1.gen install-time detection - yournewsblog.net</msg>
        <url>www.threatexpert.com/report.aspx?uid=cffa846b-93ba-438d-8715-0665b6cd9627</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/botmon/readdata/&quot;; http_uri; content:&quot;Host|3A| findzproportal1.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16269</id>
        <msg>BACKDOOR trojan.tdss.1.gen install-time detection - findzproportal1.com</msg>
        <url>www.threatexpert.com/report.aspx?uid=cffa846b-93ba-438d-8715-0665b6cd9627</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET 1503 -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; flowbits:isset,SRat_1.6; content:&quot;|00 00 00 00 00 00 00|&quot;; depth:7; offset:1; content:&quot;|AA AA AA AA|&quot;; within:4; distance:4; fast_pattern;  classtype:trojan-activity;</filter2>
        <id>16271</id>
        <msg>BACKDOOR srat 1.6 runtime detection</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/includes/editor/&quot;; http_uri; content:&quot;Host|3A| www.lordhack.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16272</id>
        <msg>BACKDOOR trojan-dropper.irc.tkb runtime detection - lordhack</msg>
        <url>www.threatexpert.com/report.aspx?md5=e77f4df496a182bf5d16172cda47b91f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/images/dxcpm&quot;; http_uri; content:&quot;Host|3A| www.dxcpm.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16273</id>
        <msg>BACKDOOR trojan-dropper.irc.tkb runtime detection - dxcpm</msg>
        <url>www.threatexpert.com/report.aspx?md5=e77f4df496a182bf5d16172cda47b91f</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/list.htm?&quot;; http_uri; content:&quot;frandom=&quot;; http_uri; content:&quot;Host|3A| vip.47tu.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>16274</id>
        <msg>SPYWARE-PUT Trickler trojan-spy.win32.pophot runtime detection - connect to server</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453142055</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bawang/&quot;; http_uri; content:&quot;.exe?&quot;; http_uri; content:&quot;frandom=&quot;; http_uri; classtype:misc-activity;</filter2>
        <id>16275</id>
        <msg>SPYWARE-PUT Trickler trojan-spy.win32.pophot runtime detection - download files</msg>
        <url>www.ca.com/us/securityadvisor/pest/pest.aspx?id=453142055</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.html?&quot;; http_uri; content:&quot;wmid=&quot;; http_uri; content:&quot;l=&quot;; http_uri; content:&quot;s=&quot;; http_uri; content:&quot;skey=&quot;; http_uri; content:&quot;Host|3A| www.av-pro-2009.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>16276</id>
        <msg>SPYWARE-PUT Trickler win32-fakealert.kl runtime detection</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-050916-1055-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/binary/AntivirusPro2009/Binaries1.cab&quot;; http_uri; content:&quot;Host|3A| down-soft-index.com&quot;; nocase; classtype:misc-activity;</filter2>
        <id>16277</id>
        <msg>SPYWARE-PUT Trickler win32-fakealert.kl installtime detection - downloads malicious files</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-050916-1055-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/update_inst.php?&quot;; http_uri; content:&quot;wmid=&quot;; http_uri; content:&quot;subid=&quot;; http_uri; content:&quot;pid=&quot;; http_uri; content:&quot;lid=&quot;; http_uri; content:&quot;hs=&quot;; http_uri; content:&quot;Host|3A| do-monster-scan.com&quot;; fast_pattern:only; classtype:misc-activity;</filter2>
        <id>16278</id>
        <msg>SPYWARE-PUT Trickler win32-fakealert.kl installime detection - updates remote server</msg>
        <url>www.symantec.com/security_response/writeup.jsp?docid=2008-050916-1055-99&amp;tabid=2</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/buy.php?&quot;; http_uri; content:&quot;frame=&quot;; http_uri; content:&quot;advid=&quot;; http_uri; content:&quot;Host|3A| winavsentry.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16279</id>
        <msg>BACKDOOR rogue-software windows antivirus 2008 runtime detection - pre-sale page</msg>
        <url>www.spywareremove.com/removeWindowsAntivirus2008.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/purchase/secure.php?&quot;; http_uri; content:&quot;frame=&quot;; nocase; http_uri; content:&quot;orderid=&quot;; nocase; http_uri; content:&quot;orderid1=&quot;; nocase; http_uri; content:&quot;orderid2=&quot;; nocase; http_uri; content:&quot;disc=&quot;; nocase; http_uri; content:&quot;product_name=Windows+Antivirus+2008&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>16280</id>
        <msg>BACKDOOR rogue-software windows antivirus 2008 runtime detection - registration and payment page</msg>
        <url>www.spywareremove.com/removeWindowsAntivirus2008.html</url>
      </rule>
      <rule>
        <bugtraq>28602</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0311</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 3057</filter1>
        <filter2>flow:established,to_server; content:&quot;GET AAAAAAAAAAAAAAAAAAAAA&quot;; depth:25; classtype:attempted-admin;</filter2>
        <id>16283</id>
        <msg>WEB-MISC Borland StarTeam Multicast Service buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $HOME_NET 5714 -&gt; $EXTERNAL_NET any</filter1>
        <filter2>flow:stateless; flags:SA,12; content:&quot;|B4 B4|&quot;; classtype:misc-activity;</filter2>
        <id>163</id>
        <msg>BACKDOOR WinCrash 1.0 Server Active</msg>
      </rule>
      <rule>
        <bugtraq>35102</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-2643</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;JBIG2Decode&quot;; nocase; content:&quot;stream&quot;; distance:0; pcre:&quot;/JBIG2Decode.*?stream(\x0d\x0a|\x0a|\x0d)/smi&quot;; byte_test:1, !&amp;, 63, 4, relative; byte_test:4, &gt;, 2147483647, 17, relative; metadata:service http; classtype:attempted-admin;</filter2>
        <id>16336</id>
        <msg>WEB-CLIENT Blackberry Server PDF JBIG2 numnewsyms remote code execution attempt</msg>
        <url>www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB18327</url>
      </rule>
      <rule>
        <bugtraq>36015</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2009-2726</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 5060:5061</filter1>
        <filter2>flow:to_server,established; content:&quot;CSeq|3A|&quot;; nocase; isdataat:25,relative; content:!&quot;|0A|&quot;; within:25; classtype:attempted-dos;</filter2>
        <id>16351</id>
        <msg>VOIP-SIP CSeq buffer overflow attempt</msg>
        <url>www.ietf.org/rfc/rfc3261.txt</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_server,established; flowbits:isset,BugsPrey_detection; content:&quot;GHOST,&quot;; depth:6; nocase; classtype:trojan-activity;</filter2>
        <id>16358</id>
        <msg>BACKDOOR bugsprey runtime detection - initial connection</msg>
        <url>www.econsultant.com/spyware-database/b/bugsprey-a.html</url>
      </rule>
      <rule>
        <bugtraq>791</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>1999-1511</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32000</filter1>
        <filter2>flow:to_server,established; content:&quot;Username|3A|&quot;; nocase; isdataat:100,relative; pcre:&quot;/^Username\:[^\n]{100}/smi&quot;; classtype:attempted-admin;</filter2>
        <id>1636</id>
        <msg>MISC Xtramail Username overflow attempt</msg>
        <nessus>10323</nessus>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 389</filter1>
        <filter2>flow:to_server,established; content:&quot;|82 82 82 82 82 82 82 82 82 82 82 82 82 82 82 82|&quot;; fast_pattern:only; classtype:attempted-admin;</filter2>
        <id>16374</id>
        <msg>EXPLOIT Oracle Internet Directory heap corruption attempt</msg>
      </rule>
      <rule>
        <bugtraq>27666</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-0077</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:established,to_client; content:&quot;ANIMATEMOTION&quot;; nocase; pcre:&quot;/&lt;[A-Z_]+\s*\x3A\s*ANIMATEMOTION[^&gt;]+?id=(?P&lt;q&gt;\x22|\x27|)(?P&lt;n&gt;[A-Z][A-Z\d\x2D\x2E\x3A\x5F]*)(?P=q).*?(?P=n)\./Osmi&quot;; classtype:attempted-user;</filter2>
        <id>16382</id>
        <msg>WEB-CLIENT HTML+TIME animatemotion property memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-010.mspx</url>
      </rule>
      <rule>
        <bugtraq>3010</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2001-1143</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 6789:6790</filter1>
        <filter2>flow:to_server,established; dsize:1; classtype:denial-of-service;</filter2>
        <id>1641</id>
        <msg>DOS DB2 dos attempt</msg>
        <nessus>10871</nessus>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0243</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; flowbits:isset,http.xls; metadata: engine shared, soid 3|16416;</filter2>
        <id>16416</id>
        <msg>WEB-CLIENT Malformed XLS MSODrawing Record</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-003.mspx</url>
      </rule>
      <rule>
        <classtype>successful-recon-limited</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 25</filter1>
        <filter2>flow:to_server,established; content:&quot;From|3A|&quot;; nocase; content:&quot;EgySpy&quot;; distance:0; nocase; content:&quot;Victim&quot;; distance:0; nocase; pcre:&quot;/^From\x3a[^\r\n]*EgySpy\s+Victim/smi&quot;; classtype:successful-recon-limited;</filter2>
        <id>16455</id>
        <msg>SPYWARE-PUT Keylogger egyspy keylogger 1.13 runtime detection</msg>
        <url>www.sunbeltsecurity.com/threatdisplay.aspx?name=EgySpy&amp;tid=48410&amp;cs=6ECDDEC7712C7CE701773045B519AE38</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/angantivirus-2009.com/&quot;; http_uri; content:&quot;Host|3A| setup.angantivirus2009.info&quot;; fast_pattern:only; classtype:trojan-activity;</filter2>
        <id>16456</id>
        <msg>SPYWARE-PUT Rogue-Software ang antivirus 09 runtime detection</msg>
        <url>en.wikipedia.org/wiki/ANG_Antivirus</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/40E800143030303030303030303030&quot;; http_uri; content:&quot;Host|3A| mxe06vc528b.com&quot;; nocase; classtype:trojan-activity;</filter2>
        <id>16457</id>
        <msg>BACKDOOR Trojan.Downloader.Win32.Cutwail.AI runtime detection</msg>
        <url>www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Cutwail.AI</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0490</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16506;</filter2>
        <id>16506</id>
        <msg>WEB-CLIENT IE innerHTML against incomplete element heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0492</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16508;</filter2>
        <id>16508</id>
        <msg>WEB-CLIENT IE8 non-IE8 compatibility mode htmltime remote code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2010-0807</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-user; metadata: engine shared, soid 3|16512, service http;</filter2>
        <id>16512</id>
        <msg>EXPLOIT IE malformed span/div html document heap corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-018.mspx</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,lmageshack.request; content:&quot;lmageshack&quot;; nocase; metadata:service http; classtype:misc-activity;</filter2>
        <id>16557</id>
        <msg>SPECIFIC-THREATS 2imaegshack/lmageshack IM worm inbound communication attempt</msg>
        <url>anubis.iseclab.org/?action=result&amp;task_id=1d4d78a7507bb63143d45d2a5898fe3bf&amp;format=html</url>
      </rule>
      <rule>
        <bugtraq>39564</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-1318</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 705</filter1>
        <filter2>flow:established,to_server; flags:*P; dsize:&lt;20; detection_filter:track by_src, count 2, seconds 2; metadata:service snmp; classtype:attempted-admin;</filter2>
        <id>16576</id>
        <msg>EXPLOIT RealNetworks Helix AgentX receive_agentx stack buffer overflow attempt</msg>
        <url>labs.idefense.com/intelligence/vulnerabilities/display.php?id=867</url>
      </rule>
      <rule>
        <bugtraq>33047</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2009-0323</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;&lt;bdo&quot;; nocase; pcre:&quot;/^.*?dir\s*=\s*(\x22[^\x22]{500}|\x27[^\x27]{500}|[^\s\&gt;]{500})/isR&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16601</id>
        <msg>WEB-CLIENT Amaya web editor XML and HTML Parser Buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; .pl&quot;; nocase; http_uri; pcre:&quot;/\/[^\r\n]*\x20.pl/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1663</id>
        <msg>WEB-MISC *%20.pl access</msg>
        <nessus>11007</nessus>
        <url>www.securityfocus.com/archive/1/149482</url>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mkplog.exe&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1664</id>
        <msg>WEB-MISC mkplog.exe access</msg>
      </rule>
      <rule>
        <bugtraq>40097</bugtraq>
        <classtype>denial-of-service</classtype>
        <cve>2010-1642</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:established, to_server; content:&quot;|FF|SMB|73|&quot;; fast_pattern; byte_test:2,&gt;,0x8000,42,relative,little; metadata:service netbios-ssn; classtype:denial-of-service;</filter2>
        <id>16684</id>
        <msg>DOS Samba smbd Session Setup AndX security blob length dos attempt </msg>
        <url>samba.org/samba/history/samba-3.4.8.html</url>
      </rule>
      <rule>
        <classtype>attempted-admin</classtype>
        <cve>2010-0743</cve>
        <filter1>tcp any any -&gt; $HOME_NET 1024:</filter1>
        <filter2>flow:established, to_server; content:&quot;|00 01 00 08|&quot;; content:&quot;|00 00 00 20|&quot;; within:4; distance:8; pcre:&quot;/%([0-9]+$)?([-+ #0-9]+)?([0-9]+)?\.?([0-9]+)?[hlL]?[cdieEfgGosuxXpn]/Rims&quot;; classtype:attempted-admin;</filter2>
        <id>16688</id>
        <msg>EXPLOIT iscsi target format string code execution attempt</msg>
        <url>osvdb.org/show/osvdb/63418</url>
      </rule>
      <rule>
        <bugtraq>21337</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-6199</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.plf; content:&quot;Content-Type: application/octet-stream&quot;; http_header; file_data; pcre:&quot;/^[^\s]{256}/R&quot;; classtype:attempted-user;</filter2>
        <id>16692</id>
        <msg>WEB-CLIENT BlazeVideo BlazeDVD PLF playlist file name buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/home/www&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1671</id>
        <msg>WEB-MISC /home/www access</msg>
        <nessus>11032</nessus>
      </rule>
      <rule>
        <classtype>system-call-detect</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;EXECUTE_SYSTEM&quot;; nocase; classtype:system-call-detect;</filter2>
        <id>1673</id>
        <msg>ORACLE EXECUTE_SYSTEM attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; isdataat:92,relative; content:!&quot;|00|&quot;; within:92; content:&quot;|FD A4 00 10|&quot;; within:4; distance:92; metadata:service http; classtype:attempted-user;</filter2>
        <id>16737</id>
        <msg>SPECIFIC-THREATS Xenorate Media Player XPL file handling overflow attempt - 1</msg>
        <url>osvdb.org/show/osvdb/57162</url>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2009-2650</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.m3u.download; file_data; content:&quot;http|3A 2F 2F|&quot;; within:7; pcre:&quot;/^[^\s]{256}/R&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16739</id>
        <msg>WEB-CLIENT MultiMedia Jukebox multiple playlist file handling overflow attempt</msg>
        <url>osvdb.org/show/osvdb/55924</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;connect_data|28|command=version|29|&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1674</id>
        <msg>ORACLE connect_data remote version detection attempt</msg>
      </rule>
      <rule>
        <bugtraq>32543</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-5405</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; flowbits:isset,http.rdp; file_data; pcre:&quot;/^[a-z0-9]{500}/iR&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>16743</id>
        <msg>WEB-CLIENT Cain &amp; Abel Remote Desktop Protocol file handling buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>suspicious-login</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:from_server,established; content:&quot;description=|28|&quot;; nocase; content:!&quot;connect_data=|28|sid=&quot;; nocase; content:!&quot;address=|28|protocol=tcp&quot;; nocase; classtype:suspicious-login;</filter2>
        <id>1675</id>
        <msg>ORACLE misparsed login response</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;select &quot;; nocase; content:&quot; union &quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1676</id>
        <msg>ORACLE select union attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; where &quot;; nocase; content:&quot; like '%'&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1677</id>
        <msg>ORACLE select like '%' attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot; where &quot;; nocase; content:&quot; like |22|%|22|&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1678</id>
        <msg>ORACLE select like '%' attempt backslash escaped</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;describe &quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1679</id>
        <msg>ORACLE describe attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_constraints&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1680</id>
        <msg>ORACLE all_constraints access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/jl/jloader.pl&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>16804</id>
        <msg>BACKDOOR  Backdoor.Win32.Qakbot.E - initial load</msg>
        <url>www.threatexpert.com/report.aspx?md5=8171d3223f89a495f98c4e3a65537b8f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/u/updates.cb&quot;; nocase; http_uri; pcre:&quot;/^Host\x3A[^\r\n]+((up\d+)|(adserv))/Hmi&quot;; classtype:trojan-activity;</filter2>
        <id>16805</id>
        <msg>BACKDOOR  Backdoor.Win32.Qakbot.E config check</msg>
        <url>www.threatexpert.com/report.aspx?md5=8171d3223f89a495f98c4e3a65537b8f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cgi-bin/clientinfo3.pl&quot;; nocase; http_uri; classtype:trojan-activity;</filter2>
        <id>16808</id>
        <msg>BACKDOOR Backdoor.Win32.Qakbot.E - register client</msg>
        <url>www.threatexpert.com/report.aspx?md5=8171d3223f89a495f98c4e3a65537b8f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;borders.php&quot;; nocase; http_uri; content:&quot;data=&quot;; nocase; http_client_body; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16809</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16809.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_views&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1681</id>
        <msg>ORACLE all_views access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/werber/&quot;; nocase; http_uri; content:&quot;217.gif&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16810</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16810.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/perce/&quot;; nocase; http_uri; content:&quot;qwerce.gif&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16811</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16811.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/vscript/vercheck.psc?pcrc=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16812</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16812.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.aspx?ver=2.0.&quot;; nocase; http_uri; content:&quot;rnd=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16813</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16813.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/cursors/&quot;; nocase; http_uri; content:&quot;cursor_upp.gif&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16814</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16814.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/player/blog.updata&quot;; nocase; http_uri; content:&quot;os=Windows&quot;; nocase; http_uri; content:&quot;&amp;mid=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16815</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16815.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ue000/38sw.e?uid=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16816</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16816.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ll.php?v=3&quot;; nocase; http_uri; content:&quot;wm_id=acc00&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16817</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16817.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/css/pragma/knock.php&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16818</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16818.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ad_type.php?a=&quot;; nocase; http_uri; pcre:&quot;/ad_type.php?a=[A-Z\d]{13}/Ui&quot;; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16819</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16819.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_source&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1682</id>
        <msg>ORACLE all_source access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ini=v22Mm2exH4anDDE0u1AXRrVqb7&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16820</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16820.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;kx.php&quot;; nocase; http_uri; content:&quot;SIY1|5C|Y)_XYEFDK7M76MKIIL&lt;OH&quot;; nocase; http_client_body; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16821</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16821.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/clcount/ip.asp?action=install&amp;mac=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16822</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16822.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/piao1.asp?AC=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16823</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16823.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/bar/v16-106/c1/jsc/fmr.js?c=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16824</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16824.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;adv=adv&quot;; nocase; http_uri; content:&quot;code1=&quot;; nocase; http_uri; content:&quot;code2=uri:id=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16825</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16825.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/p6.asp?MAC=&quot;; nocase; http_uri; content:&quot;Publicer=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16826</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16826.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/code/pop_data3.asp?f=48843&amp;t=a&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16827</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16827.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/indeh.php&quot;; nocase; http_uri; content:&quot;&amp;v=5&amp;z=com&amp;s=f01&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16828</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16828.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/web/counter/install.check.php&quot;; nocase; http_uri; content:&quot;in_mac=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16829</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16829.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_tables&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1683</id>
        <msg>ORACLE all_tables access</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/socks.php?name=&quot;; nocase; http_uri; content:&quot;port=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16830</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16830.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/count/inst.php?ucode=&quot;; nocase; http_uri; content:&quot;pcode=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16831</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16831.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/LockIeHome/?mac=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16832</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16832.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ping.txt?u=&quot;; nocase; http_uri; content:&quot;pg=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16833</id>
        <msg>BOTNET-CNC known command and control channel traffic</msg>
        <url>labs.snort.org/docs/16833.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_tab_columns&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1684</id>
        <msg>ORACLE all_tab_columns access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;all_tab_privs&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1685</id>
        <msg>ORACLE all_tab_privs access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;dba_tablespace&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1686</id>
        <msg>ORACLE dba_tablespace access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;user_tablespace&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1688</id>
        <msg>ORACLE user_tablespace access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;sys.all_users&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1689</id>
        <msg>ORACLE sys.all_users access</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;alter user&quot;; nocase; content:&quot; identified by &quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1691</id>
        <msg>ORACLE ALTER USER attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;ucsp0416.exe?t=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16911</id>
        <msg>BLACKLIST URI request for known malicious URI - ucsp0416.exe?t=</msg>
        <url>labs.snort.org/docs/16911.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;net/cfg2.bin&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16912</id>
        <msg>BLACKLIST URI request for known malicious URI - net/cfg2.bin</msg>
        <url>labs.snort.org/docs/16912.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;.bin?ucsp&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16914</id>
        <msg>BLACKLIST URI request for known malicious URI - .bin?ucsp</msg>
        <url>labs.snort.org/docs/16914.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/MNG/Download/?File=AZF&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16915</id>
        <msg>BLACKLIST URI request for known malicious URI - /MNG/Download/?File=AZF</msg>
        <url>labs.snort.org/docs/16915.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/jarun/jezerce&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16916</id>
        <msg>BLACKLIST URI request for known malicious URI - /jarun/jezerce</msg>
        <url>labs.snort.org/docs/16916.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ekaterina/velika&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16917</id>
        <msg>BLACKLIST URI request for known malicious URI - /ekaterina/velika</msg>
        <url>labs.snort.org/docs/16917.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ultimate/fight&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16918</id>
        <msg>BLACKLIST URI request for known malicious URI - /ultimate/fight</msg>
        <url>labs.snort.org/docs/16918.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tmp/pm.exe?t=&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16919</id>
        <msg>BLACKLIST URI request for known malicious URI - /tmp/pm.exe?t=</msg>
        <url>labs.snort.org/docs/16919.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;drop table&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1692</id>
        <msg>ORACLE drop table attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/DownLoadFile/BaePo/ver&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16920</id>
        <msg>BLACKLIST URI request for known malicious URI - /DownLoadFile/BaePo/ver</msg>
        <url>labs.snort.org/docs/16920.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/s1/launcher/update/Update/data/&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16921</id>
        <msg>BLACKLIST URI request for known malicious URI - /s1/launcher/update/Update/data/</msg>
        <url>labs.snort.org/docs/16921.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/stat.html?0dPg0uXTraCSqrOdlrKpmpyorePbz&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16928</id>
        <msg>BLACKLIST URI request for known malicious URI - /stat.html?0dPg0uXTraCSqrOdlrKpmpyorePbz</msg>
        <url>labs.snort.org/docs/16928.html</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;create table&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1693</id>
        <msg>ORACLE create table attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;count.asp?mac=&quot;; nocase; http_uri; content:&quot;os=Windows&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16930</id>
        <msg>BLACKLIST URI request for known malicious URI - count.asp?mac=</msg>
        <url>labs.snort.org/docs/16930.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/qqnongchang/qqkj.&quot;; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16932</id>
        <msg>BLACKLIST URI request for known malicious URI - /qqnongchang/qqkj.</msg>
        <url>labs.snort.org/docs/16932.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/root/9&quot;; nocase; http_uri; content:&quot;.rar&quot;; nocase; http_uri; pcre:&quot;/\/root\/9\d\d\/frt\d\.rar/Ui&quot;; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>16933</id>
        <msg>BLACKLIST URI request for known malicious URI - /root/9 frt.rar</msg>
        <url>labs.snort.org/docs/16933.html</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pku-edp.cn&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16934</id>
        <msg>PHISHING-SPAM pku-edp.cn known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;sjtu-edp.cn&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16935</id>
        <msg>PHISHING-SPAM sjtu-edp.cn known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;xoposuhop.cn&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16936</id>
        <msg>PHISHING-SPAM xoposuhop.cn xoposuhop.cn known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;bestdrug-store.com&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16937</id>
        <msg>PHISHING-SPAM bestdrug-store.com known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pharmrik66y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16938</id>
        <msg>PHISHING-SPAM pharmrik66y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;refillleonardo59y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16939</id>
        <msg>PHISHING-SPAM refillleonardo59y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;alter table&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1694</id>
        <msg>ORACLE alter table attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;medfreddie55a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16940</id>
        <msg>PHISHING-SPAM medfreddie55a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugshershel38w.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16941</id>
        <msg>PHISHING-SPAM drugshershel38w.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugshayyim77n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16942</id>
        <msg>PHISHING-SPAM drugshayyim77n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erectguthry99c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16943</id>
        <msg>PHISHING-SPAM erectguthry99c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pilldory92n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16944</id>
        <msg>PHISHING-SPAM pilldory92n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabwinn77t.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16945</id>
        <msg>PHISHING-SPAM tabwinn77t.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pillrenault15j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16946</id>
        <msg>PHISHING-SPAM pillrenault15j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pharmrolland95h.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16947</id>
        <msg>PHISHING-SPAM pharmrolland95h.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;onlineheindrick60i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16948</id>
        <msg>PHISHING-SPAM onlineheindrick60i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erectnormie71a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16949</id>
        <msg>PHISHING-SPAM erectnormie71a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;truncate table&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1695</id>
        <msg>ORACLE truncate table attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsjudd45f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16951</id>
        <msg>PHISHING-SPAM drugsjudd45f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pharmharman55y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16952</id>
        <msg>PHISHING-SPAM pharmharman55y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;medgaultiero11e.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16953</id>
        <msg>PHISHING-SPAM medgaultiero11e.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pillgaylor21n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16954</id>
        <msg>PHISHING-SPAM pillgaylor21n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugspenn84f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16955</id>
        <msg>PHISHING-SPAM drugspenn84f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;medebeneser68c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16956</id>
        <msg>PHISHING-SPAM medebeneser68c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabmario94r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16957</id>
        <msg>PHISHING-SPAM tabmario94r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tablennard88q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16958</id>
        <msg>PHISHING-SPAM tablennard88q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;medforster79j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16959</id>
        <msg>PHISHING-SPAM medforster79j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;create database&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1696</id>
        <msg>ORACLE create database attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erectvincent21v.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16960</id>
        <msg>PHISHING-SPAM erectvincent21v.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsdemott21o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16961</id>
        <msg>PHISHING-SPAM drugsdemott21o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;onlinelovell30p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16962</id>
        <msg>PHISHING-SPAM onlinelovell30p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erecttaylor49i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16963</id>
        <msg>PHISHING-SPAM erecttaylor49i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;smellexact.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16964</id>
        <msg>PHISHING-SPAM smellexact.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;givehome.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16965</id>
        <msg>PHISHING-SPAM givehome.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;thingpath.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16966</id>
        <msg>PHISHING-SPAM thingpath.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;wereif.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16967</id>
        <msg>PHISHING-SPAM wereif.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;bassmax.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16968</id>
        <msg>PHISHING-SPAM bassmax.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;steadfig.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16969</id>
        <msg>PHISHING-SPAM steadfig.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SQL_SERVERS $ORACLE_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;alter database&quot;; nocase; classtype:protocol-command-decode;</filter2>
        <id>1697</id>
        <msg>ORACLE alter database attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsmayne5a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16970</id>
        <msg>PHISHING-SPAM drugsmayne5a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;mystick.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16971</id>
        <msg>PHISHING-SPAM mystick.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsrey95a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16972</id>
        <msg>PHISHING-SPAM drugsrey95a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;milklowly.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16973</id>
        <msg>PHISHING-SPAM milklowly.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;numberenough.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16974</id>
        <msg>PHISHING-SPAM numberenough.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oldsheer.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16975</id>
        <msg>PHISHING-SPAM oldsheer.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;logzest.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16976</id>
        <msg>PHISHING-SPAM logzest.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;energypotent.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16977</id>
        <msg>PHISHING-SPAM energypotent.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;outhave.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16978</id>
        <msg>PHISHING-SPAM outhave.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;solvecalm.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16979</id>
        <msg>PHISHING-SPAM solvecalm.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;stillvisit.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16980</id>
        <msg>PHISHING-SPAM stillvisit.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;livelycall.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16981</id>
        <msg>PHISHING-SPAM livelycall.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;64.com1.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16982</id>
        <msg>PHISHING-SPAM 64.com1.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;heatsettle.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16983</id>
        <msg>PHISHING-SPAM heatsettle.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;freshmuch.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16984</id>
        <msg>PHISHING-SPAM freshmuch.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;extoleye.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16985</id>
        <msg>PHISHING-SPAM extoleye.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;extoleye.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16986</id>
        <msg>PHISHING-SPAM extoleye.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabemmerich86b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16987</id>
        <msg>PHISHING-SPAM tabemmerich86b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;moderneight.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16988</id>
        <msg>PHISHING-SPAM moderneight.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabferd49a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16989</id>
        <msg>PHISHING-SPAM tabferd49a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;nextmail.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16990</id>
        <msg>PHISHING-SPAM nextmail.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;fruitone.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16991</id>
        <msg>PHISHING-SPAM fruitone.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;liquideat.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16992</id>
        <msg>PHISHING-SPAM liquideat.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabwinn2a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16993</id>
        <msg>PHISHING-SPAM tabwinn2a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;abletool.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16994</id>
        <msg>PHISHING-SPAM abletool.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;miltyrefil.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16995</id>
        <msg>PHISHING-SPAM miltyrefil.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;quincytab.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16996</id>
        <msg>PHISHING-SPAM quincytab.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;giacoporx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16997</id>
        <msg>PHISHING-SPAM giacoporx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsnevile.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16998</id>
        <msg>PHISHING-SPAM drugsnevile.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jasemed.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>16999</id>
        <msg>PHISHING-SPAM jasemed.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ximenezdrug.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17000</id>
        <msg>PHISHING-SPAM ximenezdrug.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;dillonline.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17001</id>
        <msg>PHISHING-SPAM dillonline.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;swellliquid.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17002</id>
        <msg>PHISHING-SPAM swellliquid.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;younglaugh.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17003</id>
        <msg>PHISHING-SPAM younglaugh.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;2047757.kaskad-travel.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17004</id>
        <msg>PHISHING-SPAM 2047757.kaskad-travel.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;paintwater.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17005</id>
        <msg>PHISHING-SPAM paintwater.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;lovingover.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17006</id>
        <msg>PHISHING-SPAM lovingover.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pharmerastus.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17007</id>
        <msg>PHISHING-SPAM pharmerastus.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;hisoffer.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17008</id>
        <msg>PHISHING-SPAM hisoffer.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;butleft.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17009</id>
        <msg>PHISHING-SPAM butleft.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;starknow.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17010</id>
        <msg>PHISHING-SPAM starknow.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;beginwisdom.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17011</id>
        <msg>PHISHING-SPAM beginwisdom.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oneus.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17012</id>
        <msg>PHISHING-SPAM oneus.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;reapcomfy.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17013</id>
        <msg>PHISHING-SPAM reapcomfy.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;rowsay.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17014</id>
        <msg>PHISHING-SPAM rowsay.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pamperletter.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17015</id>
        <msg>PHISHING-SPAM pamperletter.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;boxdouble.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17016</id>
        <msg>PHISHING-SPAM boxdouble.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;beatmoon.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17017</id>
        <msg>PHISHING-SPAM beatmoon.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ensureequate.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17018</id>
        <msg>PHISHING-SPAM ensureequate.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;miltyrefil.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17019</id>
        <msg>PHISHING-SPAM miltyrefil.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;sheerwheel.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17020</id>
        <msg>PHISHING-SPAM sheerwheel.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;nearpass.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17021</id>
        <msg>PHISHING-SPAM nearpass.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;thatmile.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17022</id>
        <msg>PHISHING-SPAM thatmile.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;hillfoot.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17023</id>
        <msg>PHISHING-SPAM hillfoot.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;writeobject.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17024</id>
        <msg>PHISHING-SPAM writeobject.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;thoughthese.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17025</id>
        <msg>PHISHING-SPAM thoughthese.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;redlead.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17026</id>
        <msg>PHISHING-SPAM redlead.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pamperletter.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17028</id>
        <msg>PHISHING-SPAM pamperletter.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tenderpower.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17029</id>
        <msg>PHISHING-SPAM tenderpower.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;fewvalley.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17030</id>
        <msg>PHISHING-SPAM fewvalley.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;burnshy.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17031</id>
        <msg>PHISHING-SPAM burnshy.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;centtry.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17032</id>
        <msg>PHISHING-SPAM centtry.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;signpearl.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17033</id>
        <msg>PHISHING-SPAM signpearl.ru known spam email attempt</msg>
      </rule>
      <rule>
        <bugtraq>40097</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2010-1635</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMBs|00 00 00 00 18 03 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 41 00 41 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:100; offset:4; metadata:service netbios-ssn; classtype:attempted-dos;</filter2>
        <id>17151</id>
        <msg>SPECIFIC-THREATS Samba smbd flags2 header parsing denial of service attempt - 1</msg>
      </rule>
      <rule>
        <bugtraq>40097</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2010-1635</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [139,445]</filter1>
        <filter2>flow:to_server,established; content:&quot;|FF|SMBs|00 00 00 00 18 01 C8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 41 00 41 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|&quot;; depth:100; offset:4; metadata:service netbios-ssn; classtype:attempted-dos;</filter2>
        <id>17152</id>
        <msg>SPECIFIC-THREATS Samba smbd flags2 header parsing denial of service attempt - 2</msg>
      </rule>
      <rule>
        <bugtraq>40403</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2010-1938</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 21</filter1>
        <filter2>flow:to_server,established; content:&quot;USER AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; fast_pattern:only; metadata:service ftp; classtype:attempted-admin;</filter2>
        <id>17155</id>
        <msg>SPECIFIC-THREATS Multiple vendors OPIE off-by-one stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-3382</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established,no_stream; content:&quot;Content|2D|Type|3A 20|text|2F|html&quot;; fast_pattern:3,20; nocase; http_header; file_data; pcre:&quot;/^(MZ|PK|BZh|BZ|GIF8|BM|IC|PI|CI|CP)/R&quot;; classtype:attempted-user;</filter2>
        <id>17276</id>
        <msg>MISC Multiple vendor Antivirus magic byte detection evasion attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-3382</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established,no_stream; content:&quot;Content|2D|Type|3A 20|message|2F|rfc822&quot;; fast_pattern:8,20; nocase; http_header; pcre:&quot;/\x0D\x0A?(MZ|PK|BZh|BZ|GIF8|BM|IC|PI|CI|CP)/&quot;; classtype:attempted-user;</filter2>
        <id>17277</id>
        <msg>WEB-MISC Multiple vendor Antivirus magic byte detection evasion attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-3382</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established,no_stream; content:&quot;Content|2D|Type|3A 20|application|2F|bat&quot;; fast_pattern:9,20; nocase; http_header; pcre:&quot;/\x0D\x0A?(MZ|PK|BZh|BZ|GIF8|BM|IC|PI|CI|CP)/&quot;; classtype:attempted-user;</filter2>
        <id>17278</id>
        <msg>WEB-MISC Multiple vendor Antivirus magic byte detection evasion attempt</msg>
      </rule>
      <rule>
        <classtype>attempted-user</classtype>
        <cve>2005-3922</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;Rar!|1A|&quot;; within:5; content:&quot;|77|&quot;; content:&quot;|01 01 00|&quot;; within:3; distance:8; byte_test:2,&gt;,3168,0,relative; classtype:attempted-user;</filter2>
        <id>17282</id>
        <msg>MISC Panda Antivirus ZOO archive decompression buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>30418</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2008-3408</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Content-Type|3A| audio|2F|x-mpegurl&quot;; http_header; content:&quot;aaaaaaaaaaaaa&quot;; nocase; classtype:attempted-user;</filter2>
        <id>17309</id>
        <msg>SPECIFIC-THREATS CoolPlayer Playlist File Handling Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>15907</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-3652</cve>
        <filter1>udp $EXTERNAL_NET 1604 -&gt; $HOME_NET any</filter1>
        <filter2>content:&quot;|04 33|&quot;; depth:2; offset:2; isdataat:292,relative; pcre:&quot;/\x04\x33.{36}[^\n]{256}/smi&quot;; classtype:attempted-user;</filter2>
        <id>17326</id>
        <msg>EXPLOIT Citrix Program Neighborhood Client buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>4628</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0354</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;new XMLHttpRequest|28|&quot;; content:&quot;file|3A|//&quot;; nocase; classtype:web-application-attack;</filter2>
        <id>1735</id>
        <msg>WEB-CLIENT XMLHttpRequest attempt</msg>
      </rule>
      <rule>
        <bugtraq>14359</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2450</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|50 4D 47 4C 4A 0D 00 00 00 00 00 00 FF FF FF FF FF FF FF FF 01 2F 00 00 00 8F FF FF FF 7F 58 48 44 52|&quot;; classtype:attempted-user;</filter2>
        <id>17352</id>
        <msg>EXPLOIT ClamAV CHM File Handling Integer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14773</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2005-2903</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; file_data; content:&quot;|60 EA|&quot;; within:2; byte_jump:2,0,relative,little; content:&quot;|60 EA|&quot;; within:2; distance:6; byte_test:2,&gt;,256,0,relative,little; classtype:attempted-admin;</filter2>
        <id>17356</id>
        <msg>EXPLOIT NOD32 Anti-Virus ARJ Archive Handling Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>14866</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2005-2920</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:from_server,established; content:&quot;|55 50 58 31 00 00 00 00 00 50 00 00 00 10 10 00 00 48 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 E0|&quot;; content:&quot;|D7 FE EF 14 02 2D 8B F8 8D 44 24 18 50 FF 74 04 10 03 7F 1D 2F FF 6F DF 8B D8 19 B5 2E 18 5F 5E 8B C3 5B C3 83 3D E8 A6 02 74 05 BE BD EB 76 16|&quot;; distance:0; classtype:attempted-user;</filter2>
        <id>17358</id>
        <msg>EXPLOIT ClamAV UPX File Handling Buffer Overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>4612</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-0614</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/global.inc&quot;; nocase; http_uri; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1738</id>
        <msg>WEB-MISC global.inc access</msg>
      </rule>
      <rule>
        <bugtraq>4621</bugtraq>
        <classtype>web-application-attack</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;secure_site, ok&quot;; nocase; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1744</id>
        <msg>WEB-MISC SecureSite authentication bypass attempt</msg>
      </rule>
      <rule>
        <bugtraq>4631</bugtraq>
        <classtype>misc-attack</classtype>
        <cve>2002-0084</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 32772:34000</filter1>
        <filter2>flow:to_server,established; isdataat:720; content:&quot;|00 01 87 86 00 00 00 01 00 00 00 05|&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>1751</id>
        <msg>EXPLOIT cachefsd buffer overflow attempt</msg>
        <nessus>10951</nessus>
      </rule>
      <rule>
        <classtype>misc-attack</classtype>
        <filter1>tcp $AIM_SERVERS any -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;aim|3A|AddExternalApp?&quot;; fast_pattern:only; classtype:misc-attack;</filter2>
        <id>1752</id>
        <msg>MISC AIM AddExternalApp attempt</msg>
        <url>www.w00w00.org/files/w00aimexp/</url>
      </rule>
      <rule>
        <bugtraq>33342</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-0270</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 4011</filter1>
        <filter2>dsize:&gt;1024; classtype:attempted-admin;</filter2>
        <id>17524</id>
        <msg>SPECIFIC-THREATS Fujitsu SystemcastWizard Lite PXEService UDP Handling Buffer Overflow</msg>
      </rule>
      <rule>
        <bugtraq>23483</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2007-1674</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 65535</filter1>
        <filter2>dsize:&gt;268; classtype:attempted-admin;</filter2>
        <id>17567</id>
        <msg>SPECIFIC-THREATS LANDesk Management Suite Alerting Service buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>13793</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2005-1747</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 7001</filter1>
        <filter2>flow:to_server,established; content:&quot;/console/login/LoginForm.jsp?j_password=|22 22|onBlur=|22|window.open&quot;; nocase; http_uri; classtype:web-application-attack;</filter2>
        <id>17569</id>
        <msg>EXPLOIT BEA Weblogic Admin Console Cross Site Scripting Vulnerability attempt</msg>
      </rule>
      <rule>
        <bugtraq>4673</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1466</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/b2/b2-include/&quot;; http_uri; content:&quot;b2inc&quot;; content:&quot;http|3A|//&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1757</id>
        <msg>WEB-MISC b2 arbitrary command execution attempt</msg>
        <nessus>11667</nessus>
      </rule>
      <rule>
        <bugtraq>21565</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2006-6222</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 13782</filter1>
        <filter2>flow:to_server,established; content:&quot;|00 18 00 24 00 01 00 00 EE 0B|&quot;; depth:10; classtype:attempted-admin;</filter2>
        <id>17657</id>
        <msg>EXPLOIT Symantec NetBackup BPCD Daemon exploit attempt</msg>
      </rule>
      <rule>
        <bugtraq>1684</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2000-0835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.dll&quot;; http_uri; content:&quot;query=%00&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1766</id>
        <msg>WEB-MISC search.dll directory listing attempt</msg>
        <nessus>10514</nessus>
      </rule>
      <rule>
        <bugtraq>22630</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-1071</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; file_data; content:&quot;GIF8&quot;; within:4; content:&quot;a&quot;; within:1; distance:1; byte_test:1,!&amp;,0x80,4,relative; pcre:&quot;/^.{7}\x2C.{5}([\xE0-\xFF]|.{2}[\xE0-\xFF])/sR&quot;; metadata:service http; classtype:attempted-user;</filter2>
        <id>17664</id>
        <msg>WEB-CLIENT GIF image descriptor memory corruption attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-039.mspx</url>
      </rule>
      <rule>
        <bugtraq>29509</bugtraq>
        <classtype>attempted-dos</classtype>
        <cve>2008-1441</cve>
        <filter1>ip $HOME_NET any -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|17667;</filter2>
        <id>17667</id>
        <msg>MISC Windows Pragmatic General Multicast Protocol memory consumption denial of service attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms08-036.mspx</url>
      </rule>
      <rule>
        <bugtraq>1684</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2000-0835</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/search.dll&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1767</id>
        <msg>WEB-MISC search.dll access</msg>
        <nessus>10514</nessus>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.DS_Store&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1769</id>
        <msg>WEB-MISC .DS_Store access</msg>
        <url>www.macintouch.com/mosxreaderreports46.html</url>
      </rule>
      <rule>
        <bugtraq>29623</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-0960</cve>
        <filter1>udp $EXTERNAL_NET any -&gt; $HOME_NET 161</filter1>
        <filter2>gid:3; classtype:attempted-admin; metadata: engine shared, soid 3|17699, service snmp;</filter2>
        <id>17699</id>
        <msg>SNMP Multiple vendor SNMPv3 HMAC handling authentication bypass attempt</msg>
      </rule>
      <rule>
        <classtype>web-application-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/.FBCIndex&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1770</id>
        <msg>WEB-MISC .FBCIndex access</msg>
        <url>www.securiteam.com/securitynews/5LP0O005FS.html</url>
      </rule>
      <rule>
        <bugtraq>18858</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-0026</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 1958</filter1>
        <filter2>flow:established,to_server; content:&quot;&lt;!--|23|include file=|22 61 61 61 61 61 61 61 61|&quot;; fast_pattern:only; nocase; metadata:service http; classtype:attempted-user;</filter2>
        <id>17724</id>
        <msg>SPECIFIC-THREATS malicious ASP file upload attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms06-034.mspx</url>
      </rule>
      <rule>
        <classtype>shellcode-detect</classtype>
        <filter1>ip $EXTERNAL_NET any -&gt; $HOME_NET any</filter1>
        <filter2>gid:3; classtype:shellcode-detect; metadata: engine shared, soid 3|17775;</filter2>
        <id>17775</id>
        <msg>SHELLCODE Shikata Ga Nai x86 polymorphic shellcode decoder detected</msg>
      </rule>
      <rule>
        <bugtraq>34086</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2008-4564</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $SMTP_SERVERS 25</filter1>
        <filter2>flow:established,to_server; content:&quot;=FFWPC=3D=06=00=00=01=0A&quot;; nocase; content:&quot;=D5ju=FC=16=F8=AE2&quot;; distance:0; nocase; metadata:service smtp; classtype:attempted-admin;</filter2>
        <id>17777</id>
        <msg>SPECIFIC-THREATS IBM Lotus Notes WPD attachment handling buffer overflow</msg>
      </rule>
      <rule>
        <bugtraq>13944</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2006-3448</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;Microsoft Interactive Training]&quot;; content:&quot;|43 43 43 43 43 43 43 43 43 43 43 43 43 43 43 43|&quot;; content:&quot;Syllabus=&quot;; content:&quot;|41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41|&quot;; classtype:attempted-user;</filter2>
        <id>17780</id>
        <msg>SPECIFIC-THREATS CBO CBL CBM buffer overflow attempt</msg>
        <nessus>18492</nessus>
        <url>www.microsoft.com/technet/security/bulletin/MS05-031.mspx</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|16|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17782</id>
        <msg>SCADA Modbus write multiple registers from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|06|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17783</id>
        <msg>SCADA Modbus write single register from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|05|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17784</id>
        <msg>SCADA Modbus write single coil from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|15|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17785</id>
        <msg>SCADA Modbus write multiple coils from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|21|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17786</id>
        <msg>SCADA Modbus write file record from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|02|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17787</id>
        <msg>SCADA Modbus read discrete inputs from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|01|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17788</id>
        <msg>SCADA Modbus read coils from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|04|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17789</id>
        <msg>SCADA Modbus read input register from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|03|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17790</id>
        <msg>SCADA Modbus read holding registers from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|23|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17791</id>
        <msg>SCADA Modbus read/write multiple registers from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|24|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17792</id>
        <msg>SCADA Modbus read fifo queue from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|20|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17793</id>
        <msg>SCADA Modbus read file record from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|07|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17794</id>
        <msg>SCADA Modbus read exception status from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|08|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17795</id>
        <msg>SCADA Modbus initiate diagnostic from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|11|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17796</id>
        <msg>SCADA Modbus get com event counter from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|12|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17797</id>
        <msg>SCADA Modbus get com event log from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|17|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17798</id>
        <msg>SCADA Modbus report slave id from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|43|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17799</id>
        <msg>SCADA Modbus read device identification from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>protocol-command-decode</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 502</filter1>
        <filter2>flow:established,to_server; content:&quot;|22|&quot;; depth:1; offset:7; classtype:protocol-command-decode;</filter2>
        <id>17800</id>
        <msg>SCADA Modbus mask write register from external source</msg>
        <url>www.modbus.org/docs/Modbus_Application_Protocol_V1_1b.pdf</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET 1024:</filter1>
        <filter2>flow:to_server,established; content:&quot;|0A|USER VirUs|20 22 22 20 22|lol|22 20 3A|&quot;; fast_pattern:only; classtype:trojan-activity;</filter2>
        <id>17805</id>
        <msg>SPYWARE-PUT Worm.Win32.Neeris.BF contact to server attempt</msg>
        <url>www.virustotal.com/latest-report.html?resource=968470dd871f3047cf48b23f0c83985f</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/reques0.asp?kind=006&amp;mac=&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17899</id>
        <msg>BLACKLIST URI request for known malicious URI - /reques0.asp?kind=006&amp;mac=</msg>
        <url>labs.snort.org/docs/17899.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/basic/cn3c2/c&quot;; nocase; http_uri; pcre:&quot;//basic/cn3c2/c.*dll/Ui&quot;; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17900</id>
        <msg>BLACKLIST URI request for known malicious URI - /basic/cn3c2/c.*dll</msg>
        <url>labs.snort.org/docs/17900.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/mybackup21.rar&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17901</id>
        <msg>BLACKLIST URI request for known malicious URI - /mybackup21.rar</msg>
        <url>labs.snort.org/docs/17901.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/?getexe=loader.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17902</id>
        <msg>BLACKLIST URI request for known malicious URI - /?getexe=loader.exe</msg>
        <url>labs.snort.org/docs/17902.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;stid=&quot;; nocase; http_uri; content:&quot;unq=&quot;; nocase; http_uri; content:&quot;hs=www.play65.com&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17903</id>
        <msg>BLACKLIST URI request for known malicious URI - stid=</msg>
        <url>labs.snort.org/docs/17903.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/tongji.js&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17904</id>
        <msg>BLACKLIST URI request for known malicious URI - /tongji.js</msg>
        <url>labs.snort.org/docs/17904.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/MNG/Download/?File=AZF:|7C|DATADIR|7C|Download&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17907</id>
        <msg>BLACKLIST URI request for known malicious URI - /MNG/Download/?File=AZF|DATADIR|Download</msg>
        <url>labs.snort.org/docs/17907.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/images/crypt_22.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17908</id>
        <msg>BLACKLIST URI request for known malicious URI - /images/crypt_22.exe</msg>
        <url>labs.snort.org/docs/17908.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/images/css/1.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17909</id>
        <msg>BLACKLIST URI request for known malicious URI - /images/css/1.exe</msg>
        <url>labs.snort.org/docs/17909.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/7xdown.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17910</id>
        <msg>BLACKLIST URI request for known malicious URI - /7xdown.exe</msg>
        <url>labs.snort.org/docs/17910.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/winhelper.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17911</id>
        <msg>BLACKLIST URI request for known malicious URI - /winhelper.exe</msg>
        <url>labs.snort.org/docs/17911.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/upopwin/count.asp?mac=&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17912</id>
        <msg>BLACKLIST URI request for known malicious URI - /upopwin/count.asp?mac=</msg>
        <url>labs.snort.org/docs/17912.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/ok.exe&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17913</id>
        <msg>BLACKLIST URI request for known malicious URI - /ok.exe</msg>
        <url>labs.snort.org/docs/17913.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/LjBin/Bin.Dll&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17914</id>
        <msg>BLACKLIST URI request for known malicious URI - /LjBin/Bin.Dll</msg>
        <url>labs.snort.org/docs/17914.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/1001ns/cfg3n.bin&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17915</id>
        <msg>BLACKLIST URI request for known malicious URI - /1001ns/cfg3n.bin</msg>
        <url>labs.snort.org/docs/17915.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/dh/stats.bin&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17916</id>
        <msg>BLACKLIST URI request for known malicious URI - /dh/stats.bin</msg>
        <url>labs.snort.org/docs/17916.html</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;/zeus/config.bin&quot;; nocase; http_uri; metadata:service http; classtype:trojan-activity;</filter2>
        <id>17917</id>
        <msg>BLACKLIST URI request for known malicious URI - /zeus/config.bin</msg>
        <url>labs.snort.org/docs/17917.html</url>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;aaof.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17918</id>
        <msg>PHISHING-SPAM aaof.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;akiq.onlinetommie54y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17919</id>
        <msg>PHISHING-SPAM akiq.onlinetommie54y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <bugtraq>4900</bugtraq>
        <classtype>protocol-command-decode</classtype>
        <cve>2002-0909</cve>
        <filter1>tcp $EXTERNAL_NET 119 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;200&quot;; isdataat:256,relative; pcre:&quot;/^200\s[^\n]{256}/smi&quot;; metadata:service nntp; classtype:protocol-command-decode;</filter2>
        <id>1792</id>
        <msg>NNTP return code buffer overflow attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;aobuii.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17920</id>
        <msg>PHISHING-SPAM aobuii.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;argue.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17921</id>
        <msg>PHISHING-SPAM argue.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ava.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17922</id>
        <msg>PHISHING-SPAM ava.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;axoseb.medicdrugsxck.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17923</id>
        <msg>PHISHING-SPAM axoseb.medicdrugsxck.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;azo.onlinetommie54y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17924</id>
        <msg>PHISHING-SPAM azo.onlinetommie54y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;back.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17925</id>
        <msg>PHISHING-SPAM back.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;by.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17926</id>
        <msg>PHISHING-SPAM by.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;cardinals.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17927</id>
        <msg>PHISHING-SPAM cardinals.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;chemist.onlineruggiero33q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17928</id>
        <msg>PHISHING-SPAM chemist.onlineruggiero33q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;chula.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17929</id>
        <msg>PHISHING-SPAM chula.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;classification.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17930</id>
        <msg>PHISHING-SPAM classification.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;compensate.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17931</id>
        <msg>PHISHING-SPAM compensate.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;cswjlxey.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17932</id>
        <msg>PHISHING-SPAM cswjlxey.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;current.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17933</id>
        <msg>PHISHING-SPAM current.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;cyacaz.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17934</id>
        <msg>PHISHING-SPAM cyacaz.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;deepcenter.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17935</id>
        <msg>PHISHING-SPAM deepcenter.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;delegate.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17936</id>
        <msg>PHISHING-SPAM delegate.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;diet.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17937</id>
        <msg>PHISHING-SPAM diet.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;direct.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17938</id>
        <msg>PHISHING-SPAM direct.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;divyo.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17939</id>
        <msg>PHISHING-SPAM divyo.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;drugsgeorge65g.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17940</id>
        <msg>PHISHING-SPAM drugsgeorge65g.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;dux.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17941</id>
        <msg>PHISHING-SPAM dux.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;dypoh.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17942</id>
        <msg>PHISHING-SPAM dypoh.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;eaihar.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17943</id>
        <msg>PHISHING-SPAM eaihar.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;eeez.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17944</id>
        <msg>PHISHING-SPAM eeez.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;egi.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17945</id>
        <msg>PHISHING-SPAM egi.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ehyw.cumedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17946</id>
        <msg>PHISHING-SPAM ehyw.cumedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;eka.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17947</id>
        <msg>PHISHING-SPAM eka.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;election.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17948</id>
        <msg>PHISHING-SPAM election.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;elik.drugslevy46b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17949</id>
        <msg>PHISHING-SPAM elik.drugslevy46b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;epeno.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17950</id>
        <msg>PHISHING-SPAM epeno.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erectgodart30s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17951</id>
        <msg>PHISHING-SPAM erectgodart30s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;erol.camedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17952</id>
        <msg>PHISHING-SPAM erol.camedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;exa.drugslevy46b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17953</id>
        <msg>PHISHING-SPAM exa.drugslevy46b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;eyu.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17954</id>
        <msg>PHISHING-SPAM eyu.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;fashionchannel.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17955</id>
        <msg>PHISHING-SPAM fashionchannel.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;fauxy.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17956</id>
        <msg>PHISHING-SPAM fauxy.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;food.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17957</id>
        <msg>PHISHING-SPAM food.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;generality.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17958</id>
        <msg>PHISHING-SPAM generality.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;goyry.ramedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17959</id>
        <msg>PHISHING-SPAM goyry.ramedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;gueepa.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17960</id>
        <msg>PHISHING-SPAM gueepa.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;has.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17961</id>
        <msg>PHISHING-SPAM has.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;have.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17962</id>
        <msg>PHISHING-SPAM have.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;headtest.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17963</id>
        <msg>PHISHING-SPAM headtest.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;huhuh.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17964</id>
        <msg>PHISHING-SPAM huhuh.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;hyem.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17965</id>
        <msg>PHISHING-SPAM hyem.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;icysa.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17966</id>
        <msg>PHISHING-SPAM icysa.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iiy.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17967</id>
        <msg>PHISHING-SPAM iiy.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iki.onlinetommie54y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17968</id>
        <msg>PHISHING-SPAM iki.onlinetommie54y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iner.medicdrugsxdl.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17969</id>
        <msg>PHISHING-SPAM iner.medicdrugsxdl.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;in.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17970</id>
        <msg>PHISHING-SPAM in.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;intelpost.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17971</id>
        <msg>PHISHING-SPAM intelpost.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;inunuw.medicdrugsxpo.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17972</id>
        <msg>PHISHING-SPAM inunuw.medicdrugsxpo.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ipiig.drugslevy46b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17973</id>
        <msg>PHISHING-SPAM ipiig.drugslevy46b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iqor.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17974</id>
        <msg>PHISHING-SPAM iqor.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;is.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17975</id>
        <msg>PHISHING-SPAM is.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;itaca.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17976</id>
        <msg>PHISHING-SPAM itaca.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ive.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17977</id>
        <msg>PHISHING-SPAM ive.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iweqyz.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17978</id>
        <msg>PHISHING-SPAM iweqyz.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iycyde.medicdrugsxco.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17979</id>
        <msg>PHISHING-SPAM iycyde.medicdrugsxco.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;iyw.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17980</id>
        <msg>PHISHING-SPAM iyw.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jaecoh.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17981</id>
        <msg>PHISHING-SPAM jaecoh.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jael.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17982</id>
        <msg>PHISHING-SPAM jael.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jex.remedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17983</id>
        <msg>PHISHING-SPAM jex.remedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;john.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17984</id>
        <msg>PHISHING-SPAM john.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;joseph.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17985</id>
        <msg>PHISHING-SPAM joseph.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jyn.medicdrugsxdl.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17986</id>
        <msg>PHISHING-SPAM jyn.medicdrugsxdl.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;jyzyv.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17987</id>
        <msg>PHISHING-SPAM jyzyv.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;koosaf.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17988</id>
        <msg>PHISHING-SPAM koosaf.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;lybah.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17989</id>
        <msg>PHISHING-SPAM lybah.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;manila.onlinephilbert42f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17990</id>
        <msg>PHISHING-SPAM manila.onlinephilbert42f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;masa.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17991</id>
        <msg>PHISHING-SPAM masa.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;medpenny17j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17992</id>
        <msg>PHISHING-SPAM medpenny17j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;minionspre.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17993</id>
        <msg>PHISHING-SPAM minionspre.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;nazuwu.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17994</id>
        <msg>PHISHING-SPAM nazuwu.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;negotiations.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17995</id>
        <msg>PHISHING-SPAM negotiations.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;niqiv.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17996</id>
        <msg>PHISHING-SPAM niqiv.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;odimys.medicdrugsxlb.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17997</id>
        <msg>PHISHING-SPAM odimys.medicdrugsxlb.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;odoog.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17998</id>
        <msg>PHISHING-SPAM odoog.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oekaka.aimedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>17999</id>
        <msg>PHISHING-SPAM oekaka.aimedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oeqio.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18000</id>
        <msg>PHISHING-SPAM oeqio.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;of.onlinephilbert42f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18001</id>
        <msg>PHISHING-SPAM of.onlinephilbert42f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;of.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18002</id>
        <msg>PHISHING-SPAM of.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;of.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18003</id>
        <msg>PHISHING-SPAM of.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oipek.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18004</id>
        <msg>PHISHING-SPAM oipek.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oji.medicdrugsxto.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18005</id>
        <msg>PHISHING-SPAM oji.medicdrugsxto.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;onotye.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18006</id>
        <msg>PHISHING-SPAM onotye.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;opy.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18007</id>
        <msg>PHISHING-SPAM opy.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;orderbuzz.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18008</id>
        <msg>PHISHING-SPAM orderbuzz.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ouu.almedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18009</id>
        <msg>PHISHING-SPAM ouu.almedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;oxuc.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18010</id>
        <msg>PHISHING-SPAM oxuc.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;pillrolfe64l.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18011</id>
        <msg>PHISHING-SPAM pillrolfe64l.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;recently.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18012</id>
        <msg>PHISHING-SPAM recently.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;records.onlinephilbert42f.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18013</id>
        <msg>PHISHING-SPAM records.onlinephilbert42f.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;reobaj.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18014</id>
        <msg>PHISHING-SPAM reobaj.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;research.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18015</id>
        <msg>PHISHING-SPAM research.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;returning.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18016</id>
        <msg>PHISHING-SPAM returning.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;right.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18017</id>
        <msg>PHISHING-SPAM right.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;riwaro.erectjefferey85n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18018</id>
        <msg>PHISHING-SPAM riwaro.erectjefferey85n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ruuav.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18019</id>
        <msg>PHISHING-SPAM ruuav.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ryhux.medicdrugsxpa.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18020</id>
        <msg>PHISHING-SPAM ryhux.medicdrugsxpa.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;software-buyshop-7.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18021</id>
        <msg>PHISHING-SPAM software-buyshop-7.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;specialyou.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18022</id>
        <msg>PHISHING-SPAM specialyou.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;starring.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18023</id>
        <msg>PHISHING-SPAM starring.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;store-softwarebuy-7.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18024</id>
        <msg>PHISHING-SPAM store-softwarebuy-7.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;sya.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18025</id>
        <msg>PHISHING-SPAM sya.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabdarin80s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18026</id>
        <msg>PHISHING-SPAM tabdarin80s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabgordan13n.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18027</id>
        <msg>PHISHING-SPAM tabgordan13n.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tablangston19a.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18028</id>
        <msg>PHISHING-SPAM tablangston19a.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tabwebster77c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18029</id>
        <msg>PHISHING-SPAM tabwebster77c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tanuen.dimedicdrugsx.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18030</id>
        <msg>PHISHING-SPAM tanuen.dimedicdrugsx.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;the.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18031</id>
        <msg>PHISHING-SPAM the.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;the.onlineruggiero33q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18032</id>
        <msg>PHISHING-SPAM the.onlineruggiero33q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;to.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18033</id>
        <msg>PHISHING-SPAM to.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;trails.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18034</id>
        <msg>PHISHING-SPAM trails.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;trusting-me.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18035</id>
        <msg>PHISHING-SPAM trusting-me.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;twodays.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18036</id>
        <msg>PHISHING-SPAM twodays.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;tyqaja.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18037</id>
        <msg>PHISHING-SPAM tyqaja.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;uboi.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18038</id>
        <msg>PHISHING-SPAM uboi.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;uf.drugslevy46b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18039</id>
        <msg>PHISHING-SPAM uf.drugslevy46b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;uielij.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18040</id>
        <msg>PHISHING-SPAM uielij.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;unasu.medicdrugsxto.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18041</id>
        <msg>PHISHING-SPAM unasu.medicdrugsxto.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;upazo.pilltodd73p.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18042</id>
        <msg>PHISHING-SPAM upazo.pilltodd73p.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;utuqaj.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18043</id>
        <msg>PHISHING-SPAM utuqaj.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;uuji.refilleldredge89r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18044</id>
        <msg>PHISHING-SPAM uuji.refilleldredge89r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;variation.refilldud86o.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18045</id>
        <msg>PHISHING-SPAM variation.refilldud86o.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;via.refillreade47j.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18046</id>
        <msg>PHISHING-SPAM via.refillreade47j.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;voiceless.pharmroyce83b.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18047</id>
        <msg>PHISHING-SPAM voiceless.pharmroyce83b.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;was.medrayner44c.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18048</id>
        <msg>PHISHING-SPAM was.medrayner44c.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;world.onlinehill21q.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18050</id>
        <msg>PHISHING-SPAM world.onlinehill21q.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;www.buhni.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18051</id>
        <msg>PHISHING-SPAM www.buhni.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;www.visitcover.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18052</id>
        <msg>PHISHING-SPAM www.visitcover.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;xob.erectnoll24k.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18053</id>
        <msg>PHISHING-SPAM xob.erectnoll24k.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ygy.onlinetommie54y.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18054</id>
        <msg>PHISHING-SPAM ygy.onlinetommie54y.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;yit.medicdrugsxor.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18055</id>
        <msg>PHISHING-SPAM yit.medicdrugsxor.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ylum.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18056</id>
        <msg>PHISHING-SPAM ylum.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;ymyuto.onlinelewiss22r.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18057</id>
        <msg>PHISHING-SPAM ymyuto.onlinelewiss22r.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;yomy.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18058</id>
        <msg>PHISHING-SPAM yomy.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;yzugez.pillking74s.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18059</id>
        <msg>PHISHING-SPAM yzugez.pillking74s.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;zeroprices.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18060</id>
        <msg>PHISHING-SPAM zeroprices.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>policy-violation</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 25</filter1>
        <filter2>flow:to_server, established; content:&quot;zueuz.onlinehamel83i.ru&quot;; nocase; classtype:policy-violation;</filter2>
        <id>18061</id>
        <msg>PHISHING-SPAM zueuz.onlinehamel83i.ru known spam email attempt</msg>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; nocase; http_method; content:&quot;/set/first.html&quot;; nocase; http_uri; content:&quot;os=Windows&quot;; nocase; metadata:service http; classtype:trojan-activity;</filter2>
        <id>18098</id>
        <msg>BLACKLIST URI request for known malicious URI - /set/first.html</msg>
        <url>www.trustdefender.com/blog/2010/10/06/carberp-%E2%80%93-a-new-trojan-in-the-making/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/cfg/&quot;; nocase; http_uri; content:&quot;.plug&quot;; fast_pattern; nocase; http_uri; pcre:&quot;/\/cfg\/[A-Z]+\.plug/Ui&quot;; metadata:service http; classtype:trojan-activity;</filter2>
        <id>18099</id>
        <msg>BLACKLIST URI request for known malicious URI - /cfg/*.plug</msg>
        <url>www.trustdefender.com/blog/2010/10/06/carberp-%E2%80%93-a-new-trojan-in-the-making/</url>
      </rule>
      <rule>
        <classtype>trojan-activity</classtype>
        <filter1>tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;POST&quot;; nocase; http_method; content:&quot;/nfoc.php&quot;; fast_pattern; nocase; http_uri; metadata:impact_flag red, service http; classtype:trojan-activity;</filter2>
        <id>18100</id>
        <msg>BOTNET-CNC Tidserv malware command and control channel traffic</msg>
        <url>www.threatexpert.com/report.aspx?uid=cffa846b-93ba-438d-8715-0665b6cd9627</url>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2006-0647</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [389,9833]</filter1>
        <filter2>gid:3; classtype:attempted-dos; metadata: engine shared, soid 3|18101;</filter2>
        <id>18101</id>
        <msg>EXPLOIT Sun Directory Server LDAP denial of service attempt</msg>
        <url>lists.immunitysec.com/pipermail/dailydave/2006-February/002914.html</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mailto|3A|&quot;; nocase; content:&quot;|2E|bat&quot;; within:500; nocase; pcre:&quot;/mailto\x3A[^\n]*?(\x2Ebat((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5cx)00)/i&quot;; classtype:attempted-user;</filter2>
        <id>18171</id>
        <msg>EXPLOIT Multiple product mailto uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mailto|3A|&quot;; nocase; content:&quot;|2E|cmd&quot;; within:500; nocase; pcre:&quot;/mailto\x3A[^\n]*?(\x2Ecmd((?&lt;=[\x25\x22].{4})|(?=(\x2520|\x20|\x26)))|(\x25|\x26\x23x|\x5cx)00)/i&quot;; classtype:attempted-user;</filter2>
        <id>18172</id>
        <msg>EXPLOIT Multiple product mailto uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <bugtraq>25945</bugtraq>
        <classtype>attempted-user</classtype>
        <cve>2007-4041</cve>
        <filter1>tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; content:&quot;mailto|3A|&quot;; nocase; content:&quot;|2E|com&quot;; within:500; nocase; pcre:&quot;/mailto\x3A[^\n]*?([\x25\x22]\x2Ecom|(\x25|\x26\x23x|\x5cx)00)/i&quot;; classtype:attempted-user;</filter2>
        <id>18173</id>
        <msg>EXPLOIT Multiple product mailto uri handling code execution attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/ms07-057.mspx</url>
      </rule>
      <rule>
        <classtype>network-scan</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET $HTTP_PORTS</filter1>
        <filter2>flow:to_server,established; content:&quot;proxyfire.net/fastenv&quot;; nocase; http_uri; metadata:service http; classtype:network-scan;</filter2>
        <id>18179</id>
        <msg>SCAN Proxyfire.net anonymous proxy scan</msg>
        <url>www.proxyfire.net/index.php</url>
      </rule>
      <rule>
        <classtype>misc-activity</classtype>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 2533</filter1>
        <filter2>flow:established,to_server; content:&quot;|00 01|C&quot;; depth:3; classtype:misc-activity;</filter2>
        <id>1819</id>
        <msg>MISC Alcatel PABX 4400 connection attempt</msg>
        <nessus>11019</nessus>
      </rule>
      <rule>
        <classtype>attempted-dos</classtype>
        <cve>2009-3676</cve>
        <filter1>tcp $EXTERNAL_NET 445 -&gt; $HOME_NET any</filter1>
        <filter2>flow:to_client,established; dsize:4; content:&quot;|00 00 00 01|&quot;; depth:4; classtype:attempted-dos;</filter2>
        <id>18195</id>
        <msg>SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt</msg>
        <url>www.microsoft.com/technet/security/bulletin/MS10-020.mspx</url>
      </rule>
      <rule>
        <bugtraq>2350</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0319</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/ncommerce3/ExecMacro/orderdspc.d2w&quot;; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1820</id>
        <msg>WEB-MISC IBM Net.Commerce orderdspc.d2w access</msg>
        <nessus>11020</nessus>
      </rule>
      <rule>
        <bugtraq>3241</bugtraq>
        <classtype>system-call-detect</classtype>
        <cve>2001-1002</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET 515</filter1>
        <filter2>flow:to_server,established; content:&quot;psfile=|22|`&quot;; classtype:system-call-detect;</filter2>
        <id>1821</id>
        <msg>EXPLOIT LPD dvips remote command execution attempt</msg>
        <nessus>11023</nessus>
      </rule>
      <rule>
        <bugtraq>35494</bugtraq>
        <classtype>attempted-admin</classtype>
        <cve>2009-1628</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HOME_NET [3985,3986]</filter1>
        <filter2>flow:to_server,established; content:&quot;|16 07|&quot;; depth:2; byte_test:2,&gt;,24,2,big; classtype:attempted-admin;</filter2>
        <id>18248</id>
        <msg>EXPLOIT Unisys Business Information Server stack buffer overflow attempt</msg>
      </rule>
      <rule>
        <bugtraq>5119</bugtraq>
        <classtype>web-application-activity</classtype>
        <cve>2001-0179</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/WEB-INF&quot;; nocase; http_uri; metadata:service http; classtype:web-application-activity;</filter2>
        <id>1826</id>
        <msg>WEB-MISC WEB-INF access</msg>
        <nessus>11037</nessus>
      </rule>
      <rule>
        <bugtraq>5191</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1042</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/search&quot;; http_uri; content:&quot;NS-query-pat=&quot;; content:&quot;../../&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1828</id>
        <msg>WEB-MISC iPlanet Search directory traversal attempt</msg>
        <nessus>11043</nessus>
      </rule>
      <rule>
        <bugtraq>5258</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1052</cve>
        <filter1>tcp $EXTERNAL_NET any -&gt; $HTTP_SERVERS $HTTP_PORTS</filter1>
        <filter2>flow:established,to_server; content:&quot;/servlet/con&quot;; http_uri; pcre:&quot;/\x2Fcon\b/Ui&quot;; metadata:service http; classtype:web-application-attack;</filter2>
        <id>1831</id>
        <msg>WEB-MISC jigsaw dos attempt</msg>
        <nessus>11047</nessus>
      </rule>
      <rule>
        <bugtraq>5249</bugtraq>
        <classtype>web-application-attack</classtype>
        <cve>2002-1027</
