[Bleeding] / sigs / POLICY
Project Root:

Bleeding: sigs/POLICY

Current directory:[Bleeding] / sigs / POLICY
Files shown:90
Query: Query revision history


File Rev. Age Author Last log entry
(dir) Attic/   [show contents]        
(file) POLICY_AOL_Toolbar  1.1  15 months  jonkman  : Thanks qru
(file) POLICY_AOL_Webmail  1.6  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Administrator_Login  1.4  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Basic_HTTP_Auth  1.10  9 months  jonkman  2006380 2006402: added a leading 0d 0a to eliminate proxy-auth falses
(file) POLICY_Binary_Downloads  1.14  7 months  jonkman  2000419 2000427: Updating for small doanload rule
(file) POLICY_Bogon_Nets  1.11  10 months  jonkman  2002749 2002750: updated from bogon
(file) POLICY_Boitho.com  1.1  13 months  jonkman  2003652 2003654: New stuff
(file) POLICY_CCProxy  1.1  10 months  jonkman  : newness
(file) POLICY_Centralops.net  1.2  14 months  jonkman  2003624 2003631: typo fixes
(file) POLICY_Cisco_Config_Change  1.4  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Classified_Information  1.10  11 months  jonkman  2002474 2002558 2002639: PCRE typo fixes, thanks Juergen
(file) POLICY_Credit_Card_Numbers  1.11  2 years  fknobbe  SIDs 2001375 2001376 2001377 2001378 2001379 2001380 2001381 2001382 2001383: Re...
(file) POLICY_DNS_Responses  1.7  18 months  jonkman  Added !SMTP_SERVERS, thanks Michael
(file) POLICY_DNS_Tunnel_nstx  1.1  2 years  jonkman  New from Myron Davis
(file) POLICY_Dameware  1.4  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_EXE  1.1  17 months  bhartstein  sid:2003325, added Policy Rule to detect generic executable attachments
(file) POLICY_EXE_HTTP  1.7  11 months  jonkman  2006434: Removed leading / per Reg's advice, makes this more versatile
(file) POLICY_EXE_NoUserAgent  1.3  14 months  jonkman  2003179 2003595: Killing some falses
(file) POLICY_Ebay  1.6  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_FTP_Login  1.7  16 months  bhartstein  sid:2003410 set unique flowbit for singleton alert per login
(file) POLICY_Fox_ABC_On_Demand  1.1  8 months  jonkman  : New from will metcalf
(file) POLICY_Gazzag.com  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_Google  1.3  10 months  jonkman  *** empty log message ***
(file) POLICY_GotoMyPC  1.10  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Groove.net  1.3  14 months  jonkman  2003602: typo fix
(file) POLICY_Gtalk  1.1  21 months  fknobbe  SID 2003092: New sig from Robert Sharp. Not tested thus disabled by default.
(file) POLICY_HOTMAIL_Mail_Use  1.9  2 years  fknobbe  SIDs 2000035 2000036 2000037: Escaped ? in pcre's.
(file) POLICY_HP_Web_Jetadmin_Executefile_Access  1.6  2 years  fknobbe  SIDs 2001055: Removed space behind reference to avoid duplicate reference_system...
(file) POLICY_HTTP_Tunneling_via_Proxy  1.6  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_HTTP_on_Off_Ports  1.1  11 months  jonkman  : In for testing
(file) POLICY_Hamachi_VPN  1.1  2 years  jonkman  New from dajackman
(file) POLICY_Hi5.com  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_Hyves  1.2  8 months  jonkman  2007627 2007628 2007629 2007630 2007631: my typo fixes
(file) POLICY_IM_ICQ  1.12  2 years  jonkman  2002986: More spyware
(file) POLICY_IM_Jabber  1.8  2 years  bhartstein  sid 2002335 had \ /, converted to hex
(file) POLICY_IM_MSN  1.11  2 years  bhartstein  sid: 2002192, changed hex to ascii
(file) POLICY_IM_Yahoo  1.8  10 months  jonkman  2007066 2007067 2007068 2007069: New from Chris Newton
(file) POLICY_IRC  1.5  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_IRS_Related  1.2  22 months  jonkman  2002658: pcre was hosed
(file) POLICY_ImageSpam  1.3  20 months  jonkman  2003118 2003120: Sid conflict fix
(file) POLICY_Infotriever  1.5  15 months  jonkman  2002082 2002082: trying this out to eliminate falses, and better document
(file) POLICY_Itunes  1.2  2 years  fknobbe  SID 2002878: Fixed typo in reference.
(file) POLICY_Kitco_Ticker  1.6  2 years  jonkman  MSG changes to eliminate dupes only
(file) POLICY_MP3_Files  1.1  2 years  bhartstein  added policy rules for mp3 file transfers
(file) POLICY_MS_Teredo_Tunnel  1.1  14 months  jonkman  : Moved from CURRENT EVENTS
(file) POLICY_Majestic-12  1.2  16 months  jonkman  2003409: Thanks Stephen
(file) POLICY_McAffee  1.2  16 months  jonkman  2003381: msg update
(file) POLICY_Metacafe  1.1  12 months  jonkman  : New from will metcalf
(file) POLICY_Metacafe.com  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_Mozilla_XPI_Install  1.6  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Myspace  1.2  18 months  fknobbe  SIDs 2002872: Added missing flow statement.
(file) POLICY_Nagios  1.1  10 months  jonkman  : might be interesting
(file) POLICY_Netflix  1.1  8 months  jonkman  : New from will metcalf
(file) POLICY_Netop_Remote_Control  1.6  2 years  fknobbe  SIDs 2001597: Removed space behind reference to avoid duplicate reference_system...
(file) POLICY_Netvacy.com  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_Non-Standard_SSH_Port  1.19  2 years  bhartstein  sid:2001984, old one ok
(file) POLICY_Orkut.com  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_PCMesh  1.3  23 months  jonkman  2003040 2003069: PCMesh Sigs work now! THanks Scott
(file) POLICY_PHP_Proxy  1.3  11 months  jonkman  2006410: updated reference
(file) POLICY_Pingdom_Monitoring  1.3  18 months  jonkman  typo fixes
(file) POLICY_Possible_Infection_Emails  1.5  7 months  jonkman  2007611 2007612: distance update
(file) POLICY_Prospero_Chat  1.7  2 years  fknobbe  SIDs 2001989: Removed space behind reference to avoid duplicate reference_system...
(file) POLICY_Proxy_Judge  1.1  23 months  jonkman  : New from Scott Melnick
(file) POLICY_RAR_Files  1.4  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_RDP_Connections  1.9  10 months  jonkman  2007571: typo fix
(file) POLICY_Radmin  1.2  15 months  jonkman  2003479 2003480 2003481 2003482: typo fix
(file) POLICY_Real.com_Game_Installs  1.2  23 months  fknobbe  SID 2003045: Removed http.Useragent flowbit and reverted to content check. Snort...
(file) POLICY_SC-KeyLog  1.2  2 years  jonkman  Typo
(file) POLICY_SSH  1.6  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_SSL_TLS_on_High_Port  1.14  12 months  jonkman  2004598: Excluding aol traffic
(file) POLICY_SSN_in_the_Clear  1.10  2 years  bhartstein  sid 2001328,2001384 pcre fix, thanks William O'Malley
(file) POLICY_Skype  1.13  23 months  fknobbe  SID 2003022: Added HOME_NET and EXTERNAL_NET, and changed source ports to 1024:6...
(file) POLICY_Small_Binary_Downloads  1.6  7 months  jonkman  2007671: not going down to 100k or less
(file) POLICY_Tor  1.17  8 months  jonkman  2001728: removed a duplicate
(file) POLICY_Unauthorized_Proxying  1.5  3 years  fknobbe  Implemented Joel Ebrahimi's rule optimizations (re-ordering of options for perfo...
(file) POLICY_Unauthorized_SMTP  1.14  13 months  jonkman  2003864: New, seeing bots use 587 to send mail
(file) POLICY_WebEx_Traffic  1.5  2 years  fknobbe  SIDs 2001712 2001713 2001714: Removed space behind reference to avoid duplicate ...
(file) POLICY_WebShots  1.4  23 months  fknobbe  SID 2002407: Removed http.Useragent flowbit and reverted to content check. Snort...
(file) POLICY_Web_Crawling  1.12  2 years  jonkman  Name updates
(file) POLICY_Webmail  1.6  2 years  jonkman  Wasn't interesting, removed SurfMK sig
(file) POLICY_Winamp  1.1  20 months  jonkman  : New by Andrew Wood
(file) POLICY_Windows_98  1.3  7 months  jonkman  2007695: reference typo fix, thanks markus
(file) POLICY_Windows_Updates  1.8  18 months  fknobbe  SIDs: 2002948 2002949 2002969 2003179 2003196 2003197: Added missing classtype.
(file) POLICY_Winpcap_Install  1.1  2 years  jonkman  Found that installing winpcap results in a specific http get to winpcap.org to p...
(file) POLICY_Xbox  1.4  2 years  jonkman  Fixed a bad escape error
(file) POLICY_Yahoo360  1.1  16 months  jonkman  : Not bad sites, just not always appropriate. Use these sigs where needed only
(file) POLICY_Zip_Contents  1.9  3 years  jonkman  Putting all flowbits write operations after content
(file) POLICY_bodog.com  1.3  21 months  mwarren  SID:2003100; Added domain to sig
(file) POLICY_iMesh  1.1  21 months  fknobbe  SID 2003093: New sig for iMesh from Russ.
POLICY_TROJAN_DNS_Lookups This entry is unreadable

NOTE: One or more files were unreadable. The files in the CVS repository should be readable by the web server process. Please report this condition to the administrator of this CVS repository.
Show files using tag:  
 
Download tarball
CVS Admin

Powered by ViewCVS 1.0-dev
(Powered by ViewCVS)

ViewCVS and CVS Help