<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001217">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2epdf/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Adobe Acrobat Reader Malicious URL Null Byte]]></Description>
        <Reference name="URLREF"><![CDATA[http://idefense.com/application/poi/display?id=126&type=vulnerabilities]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/windowsntfocus/5BP0D20DPW.html]]></Reference>
        <Reference name="CVE" value="2004-0629"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="617" match-neg-port="no" follow-on-sig="no" name="DC:2001742">
        <ExtendedLanguage src-port="any" dst-port="617">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/46/4f/3a/20/59/6f/75/20/68/61/76/65/20/73/75/63"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/65/20/63/6c/69/65/6e/74/20/69/6e/66/6f/72/6d/61"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Arkeia full remote access without password or authentication]]></Description>
        <Reference name="URLREF"><![CDATA[http://metasploit.com/research/vulns/arkeia_agent]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="5250" match-neg-port="no" follow-on-sig="no" name="DC:2002791">
        <ExtendedLanguage src-port="any" dst-port="5250">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="content/2dlength/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^Content-Length\x3a\s*-\d+]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MISC Computer Associates Negative Content-Length Buffer Overflow]]></Description>
        <Reference name="CVE" value="2005-3653"/>
        <Reference name="BUGTRAQ" value="16354"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="111" match-neg-port="no" follow-on-sig="no" name="DC:2003370">
        <ExtendedLanguage src-port="any" dst-port="111">
        <Match match-order="0" offset="4" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00"/>
        </Match>
        <Match match-order="1" within="4" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/03"/>
        </Match>
        <Match match-order="2" within="4" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/08"/>
        </Match>
        <Match match-order="3" within="4" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00"/>
        </Match>
        <Match match-order="4" within="4" distance="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00"/>
        </Match>
        <Match match-order="5" within="32" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00/00/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Computer Associates Brightstor ARCServer Backup RPC Server (Catirpc.dll) DoS]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3248]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="1900" match-neg-port="no" follow-on-sig="no" name="DC:2003378">
        <ExtendedLanguage src-port="any" dst-port="1900">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="10">
        <ExtendedPattern uri-decode="no" type="binary" pattern="0000033000"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="1000"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Computer Associates Mobile Backup Service LGSERVER.EXE Stack Overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3244]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="2200" match-neg-port="no" follow-on-sig="no" name="DC:2003379">
        <ExtendedLanguage src-port="any" dst-port="2200">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="16" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/ff/ff/ff/ff"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Computer Associates BrightStor ARCserve Backup for Laptops LGServer.exe DoS]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/458650/100/0/threaded]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003518">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="16" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/06/09/7e"/>
        </Match>
        <Match match-order="1" within="4" distance="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/bf"/>
        </Match>
        <Match match-order="2" within="8" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00/00/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Computer Associates Brightstor ARCServe Backup Mediasvr.exe Remote Exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3604]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003750">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="16" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/06/09/82"/>
        </Match>
        <Match match-order="1" within="4" distance="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/01"/>
        </Match>
        <Match match-order="2" within="8" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00/00/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CA Brightstor ARCServe caloggerd DoS]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3939]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003751">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="16" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/06/09/7e"/>
        </Match>
        <Match match-order="1" within="4" distance="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/7e"/>
        </Match>
        <Match match-order="2" within="8" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00/00/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CA Brightstor ARCServe Mediasvr DoS]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3940]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002697">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="filediff/3ff/3d"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[filediff\?f=.+&v1=[\d.]+&v2=[\d.]+\;.+]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CVSTrac filediff Arbitrary Remote Code Execution]]></Description>
        <Reference name="CVE" value="2004-1456"/>
        <Reference name="BUGTRAQ" value="10878"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="2401" match-neg-port="no" follow-on-sig="no" name="DC:2000048">
        <ExtendedLanguage src-port="any" dst-port="2401">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="20">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/45/6e/74/72/79/20/43/43/43/43/43/43/43/43/43/2f/43/43"/>
        </Match>
        <PayloadSize min="512" max="1514" match-zero="no"/>
        <AlertLimit num-alerts="1" interval="60" hard-limit="yes" threshold-limit="yes" apply-to="dst"/>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CVS server heap overflow attempt (target Linux)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="2401" match-neg-port="no" follow-on-sig="no" name="DC:2000031">
        <ExtendedLanguage src-port="any" dst-port="2401">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="18">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/45/6e/74/72/79/20/61/61/61/61/61/61/61/61/61/61/61/61"/>
        </Match>
        <PayloadSize min="512" max="1514" match-zero="no"/>
        <AlertLimit num-alerts="1" interval="60" hard-limit="yes" threshold-limit="yes" apply-to="dst"/>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CVS server heap overflow attempt (target BSD)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="2401" match-neg-port="no" follow-on-sig="no" name="DC:2000049">
        <ExtendedLanguage src-port="any" dst-port="2401">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="18">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/41/72/67/75/6d/65/6e/74/20/62/62/62/62/62/62/62/62/62"/>
        </Match>
        <PayloadSize min="512" max="1514" match-zero="no"/>
        <AlertLimit num-alerts="1" interval="60" hard-limit="yes" threshold-limit="yes" apply-to="dst"/>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT CVS server heap overflow attempt (target Solaris)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000012">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/25u002F"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco %u IDS evasion]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="22" match-neg-port="no" follow-on-sig="no" name="DC:2000007">
        <ExtendedLanguage src-port="any" dst-port="22">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/61/25/61/25/61/25/61/25/61/25/61/25/61/25"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Catalyst SSH protocol mismatch]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000013">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fTEST/3f/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco IOS HTTP server DoS]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000009">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ferror/3f/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco IOS HTTP DoS]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003064">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="post"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fjmx/2dconsole/2fhtmladaptor"/>
        </Match>
        <FlowTag action="define" suppress-alert="no"><![CDATA[cmars.jboss]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco-MARS/JBoss jmx-console POST]]></Description>
        <Reference name="BUGTRAQ" value="19071"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003065">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="action/3dinvokeop"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="jboss/2escript"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="runtime/2egetruntime/2528/2529/2eexec/2528"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[cmars.jboss]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco-MARS/JBoss Remote Command Execution]]></Description>
        <Reference name="BUGTRAQ" value="19071"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="23" match-neg-port="no" follow-on-sig="no" name="DC:2000005">
        <ExtendedLanguage src-port="any" dst-port="23">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/3f/61/7e/20/25/25/25/25/25/58/58"/>
        </Match>
        <AlertLimit num-alerts="1" interval="120" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Cisco Telnet Buffer Overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.cisco.com/warp/public/707/cisco-sn-20040326-exploits.shtml]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="1900" match-neg-port="no" follow-on-sig="no" name="DC:2003039">
        <ExtendedLanguage src-port="any" dst-port="1900">
        <Match match-order="0" depth="9">
        <ExtendedPattern uri-decode="no" type="string" pattern="m/2dsearch/20"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="500"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[M-SEARCH\s+[^\n]{500}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT UPnP DLink M-Search Overflow Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.eeye.com/html/research/advisories/AD20060714.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002315">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Expires/3a"/>
        </Match>
        <Match match-order="1" within="300" distance="52">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/40/60/6e/63"/>
        </Match>
        <Match match-order="2" within="20" distance="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2d/70"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Incoming Electronic Mail for UNIX Expires Header Buffer Overflow Exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/exploits/20050822.elmexploit.c.php]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.instinct.org/elm/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002316">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Expires/3a"/>
        </Match>
        <Match match-order="1" within="300" distance="52">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/40/60/6e/63"/>
        </Match>
        <Match match-order="2" within="20" distance="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2d/70"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Outgoing Electronic Mail for UNIX Expires Header Buffer Overflow Exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/exploits/20050822.elmexploit.c.php]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.instinct.org/elm/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002703">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ferror/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="err/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/5fserver/5bremote/5faddr/5d/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT GuppY error.php Arbitrary Remote Code Execution]]></Description>
        <Reference name="BUGTRAQ" value="15609"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003332">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="post"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ferror/2ephp/3f"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="err/3d"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[Cookie\:\ +REMOTE_ADDR=]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT GuppY error.php POST Arbitrary Remote Code Execution]]></Description>
        <Reference name="BUGTRAQ" value="15609"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="21" match-neg-port="no" follow-on-sig="no" name="DC:2002850">
        <ExtendedLanguage src-port="any" dst-port="21">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/20"/>
        </Match>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[ftp.user.login]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ FTP USER login flowbit]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="21" match-neg-port="no" follow-on-sig="no" name="DC:2002851">
        <ExtendedLanguage src-port="any" dst-port="21">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="list/20"/>
        </Match>
        <FlowTag action="test-not-defined" suppress-alert="no"><![CDATA[ftp.user.login]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ FTP HP-UX LIST command without login]]></Description>
        <Reference name="CVE" value="2005-3296"/>
        <Reference name="BUGTRAQ" value="15138"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="515" match-neg-port="no" follow-on-sig="no" name="DC:2002852">
        <ExtendedLanguage src-port="any" dst-port="515">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" within="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/02msf28/30"/>
        </Match>
        <Match match-order="1" within="20" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/60"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT HP-UX Printer LPD Command Insertion]]></Description>
        <Reference name="CVE" value="2005-3277"/>
        <Reference name="BUGTRAQ" value="15136"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001099">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="vbscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*vbscript[\:]]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Attempt to execute VBScript code]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001101">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="j"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*j[\x09\x0a\x0b\x0c\x0d]*a[\x09\x0a\x0b\x0c\x0d]*v[\x09\x0a\x0b\x0c\x0d]*a[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*c[\x09\x0a\x0b\x0c\x0d]*r[\x09\x0a\x0b\x0c\x0d]*i[\x09\x0a\x0b\x0c\x0d]*p[\x09\x0a\x0b\x0c\x0d]*t[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="javascript/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Stealth attempt to execute Javascript code]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001102">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="v"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*v[\x09\x0a\x0b\x0c\x0d]*b[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*c[\x09\x0a\x0b\x0c\x0d]*r[\x09\x0a\x0b\x0c\x0d]*i[\x09\x0a\x0b\x0c\x0d]*p[\x09\x0a\x0b\x0c\x0d]*t[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="vbscript/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Stealth attempt to execute VBScript code]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001103">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="s"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*h[\x09\x0a\x0b\x0c\x0d]*e[\x09\x0a\x0b\x0c\x0d]*l[\x09\x0a\x0b\x0c\x0d]*l[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="shell/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Stealth attempt to access SHELL\:]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001105">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="string/2efromcharcode"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[expression[\s]*\([\s]*eval[\s]*\([\s]*String\.fromCharCode[\s]*\(([\s]*[\d]+[\s]*,){20}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Javascript execution with expression eval]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/exploits/3D5Q4RFPPK.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001106">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="string/2efromcharcode"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[expression[\s]*\([\s]*eval[\s]*\([\s]*String\.fromCharCode[\s]*\(([\s]*0x[\da-fA-F]+[\s]*,){20}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Javascript execution with expression eval hex]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/exploits/3D5Q4RFPPK.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001048">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00iexplore/2eexe/00"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00GetProcAddress/00"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00LoadLibraryA/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT IE process injection iexplore.exe executable download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001181">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="06dd38d0/2dd187/2d11cf/2da80d/2d00c04fd74ad8"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2eload/28"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Internet Explorer Plugin.ocx Heap Overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.hnc3k.com/ievulnerabil.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001182">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00KERNEL32/2eDLL/00GDI32/2edll/00MSVCRT/2edll/00USER32/2edll/00/00LoadLibraryA/00/00GetProcAddress/00/00ExitProcess/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ EXPLOIT IE trojan Ants3set 1.exe - process injection]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001401">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2f/2f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(EMBED|FRAME|SRC)\s*=\s*["']*?(file|http)\://\w{578}|/W{578}]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(EMBED|FRAME|SRC|NAME)\s*=\s*["']\w{2086}|\W{2086}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT IE IFRAME Exploit]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001095">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3ciframe/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^[^>]*SRC[\s]*=[\s]*["']*[\x09\x0a\x0b\x0c\x0d]*f[\x09\x0a\x0b\x0c\x0d]*i[\x09\x0a\x0b\x0c\x0d]*l[\x09\x0a\x0b\x0c\x0d]*e[\x09\x0a\x0b\x0c\x0d]*\:]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT IFRAME ExecCommand vulnerability]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/exploits/3D5Q4RFPPK.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002860">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="document/2egetelementbyid"/>
        </Match>
        <Match match-order="1" within="50" distance="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="createtextrange"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[=\s*document\.getElementById.{0,30}?createTextRange]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Internet Explorer createTextRange Code Execution]]></Description>
        <Reference name="CVE" value="2006-1359"/>
        <Reference name="BUGTRAQ" value="17196"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002682">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="window"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<[a-z][^>]+on[^>]+[^a-z_]window\s*\(\s*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Internet Explorer Window() Possible Code Execution]]></Description>
        <Reference name="URLREF"><![CDATA[http://secunia.com/advisories/15546]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.computerterrorism.com/research/ie/ct21-11-2005]]></Reference>
        <Reference name="CVE" value="2005-1790"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003023">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="DirectAnimation/2eStructuredGraphicsControl"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT IE StructuredGraphicsControl SourceURL Bug MoBB#6]]></Description>
        <Reference name="URLREF"><![CDATA[http://browserfun.blogspot.com/2006/07/mobb-6-structuredgraphicscontrol.html]]></Reference>
        <Reference name="CVE" value="2006-3427"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003102">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="d7a7d7c3/2dd47f/2d11d0/2d89d3/2d00a0c90833e6"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2espline/28"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*D7A7D7C3-D47F-11D0-89D3-00A0C90833E6]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Multimedia Controls - ActiveX control's spline function call CSLID]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.osvdb.org/displayvuln.php?osvdb_id=28841]]></Reference>
        <Reference name="CVE" value="2006-4446"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003103">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20directanimation/2epathcontrol"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2espline/28"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation\.PathControl\x22|\x27DirectAnimation\.PathControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation\.PathControl\x22|\x27DirectAnimation\.PathControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Multimedia Controls - ActiveX control's spline function call Object]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.osvdb.org/displayvuln.php?osvdb_id=28841]]></Reference>
        <Reference name="CVE" value="2006-4446"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003104">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="d7a7d7c3/2dd47f/2d11d0/2d89d3/2d00a0c90833e6"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2ekeyframe/28"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Multimedia Controls - ActiveX control's KeyFrame function call CSLID]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.osvdb.org/displayvuln.php?osvdb_id=28842]]></Reference>
        <Reference name="CVE" value="2006-4777"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003105">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="activexobject"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="directanimation/2epathcontrol"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2ekeyframe/28"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22DirectAnimation\.PathControl\x22|\x27DirectAnimation\.PathControl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22DirectAnimation\.PathControl\x22|\x27DirectAnimation\.PathControl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Multimedia Controls - ActiveX control's KeyFrame function call Object]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.osvdb.org/displayvuln.php?osvdb_id=28842]]></Reference>
        <Reference name="CVE" value="2006-4777"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003109">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3afill"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="method"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[method\s*=\s*['"]+[^'"]{256}]]></PCRE>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\x3a(rect|roundrect|line|polyline|oval|image|arc|curve)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Internet Explorer VML Fill Method Attribute Overflow]]></Description>
        <Reference name="CVE" value="2006-4868"/>
        <Reference name="BUGTRAQ" value="20096"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003110">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="webviewfoldericon"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2esetslice"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="0x7ffffff"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MSIE WebViewFolderIcon setSlice invalid memory copy]]></Description>
        <Reference name="URLREF"><![CDATA[http://riosec.com/msie-setslice-vuln]]></Reference>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/27110]]></Reference>
        <Reference name="CVE" value="2006-3730"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003158">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="7f5b7f63/2df06f/2d4331/2d8a26/2d339e03c0ae3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft WMIScriptUtils.WMIObjectBroker object call CSLID]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/20843]]></Reference>
        <Reference name="URLREF"><![CDATA[http://secunia.com/advisories/22603]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/ms06-073.mspx]]></Reference>
        <Reference name="CVE" value="2006-4704"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003159">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="06723e09/2df4c2/2d43c8/2d8358/2d09fcd1db0766"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft VsmIDE.DTE object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003160">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="639f725f/2d1b2d/2d4831/2da9fd/2d874847682010"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft DExplore.AppObj.8.0 object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003161">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="ba018599/2d1db3/2d44f9/2d83b4/2d461454c84bf8"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft VisualStudio.DTE.8.0 object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003162">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="d0c07d56/2d7c69/2d43f1/2db4a0/2d25f5a11fab19"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Microsoft.DbgClr.DTE.8.0 object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003163">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="e8cccddf/2dca28/2d496b/2db050/2d6c07c962476b"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft VsaIDE.DTE object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003164">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="ab9bcedd/2dec7e/2d47e1/2d9322/2dd4a210617116"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Business Object Factory object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003165">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="0006f033/2d0000/2d0000/2dc000/2d000000000046"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Outlook Data Object object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003166">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="0006f03a/2d0000/2d0000/2dc000/2d000000000046"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft Outlook.Application object call CSLID]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003230">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="ftp/3a/2f/2f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[ftp\://[^\' \"]*%0a]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Microsoft IE FTP URL Arbitrary Command Injection]]></Description>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/12299]]></Reference>
        <Reference name="CVE" value="2004-1166"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003231">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="6e449683/2dc509/2d11cf/2daafa/2d00aa00b6015c"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="baseurl"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="setciffile"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*6E449683-C509-11CF-AAFA-00AA00B6015C]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible Microsoft IE Install Engine Inseng.dll Arbitrary Code Execution]]></Description>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/10705]]></Reference>
        <Reference name="CVE" value="2004-0216"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003232">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20ascontrols/2einstallenginectl"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="baseurl"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="setciffile"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22ASControls\.InstallEngineCtl\x22|\x27ASControls\.InstallEngineCtl\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22ASControls\.InstallEngineCtl\x22|\x27ASControls\.InstallEngineCtl\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible Microsoft IE Install Engine Inseng.dll Arbitrary Code Execution (2)]]></Description>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/10705]]></Reference>
        <Reference name="CVE" value="2004-0216"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003233">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20shell/2eapplication"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="getlink"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*(\x22Shell\.Application\x22|\x27Shell\.Application\x27)[\r\n\s]*\)|(\w+)[\r\n\s]*=[\r\n\s]*(\x22Shell\.Application\x22|\x27Shell\.Application\x27)[\r\n\s]*\x3b.*new[\r\n\s]*ActiveXObject[\r\n\s]*\([\r\n\s]*\1[\r\n\s]*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible Microsoft IE Shell.Application ActiveX Arbitrary Command Execution]]></Description>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/7913]]></Reference>
        <Reference name="CVE" value="2004-2291"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003234">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="13709620/2dc279/2d11ce/2da49e/2d444553540000"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="getlink"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*13709620-C279-11CE-A49E-444553540000]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible Microsoft IE Shell.Application ActiveX Arbitrary Command Execution (2)]]></Description>
        <Reference name="URLREF"><![CDATA[http://osvdb.org/7913]]></Reference>
        <Reference name="CVE" value="2004-2291"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003514">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="00000535/2d0000/2d0010/2d8000/2d00aa006d2ea4"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible Microsoft Internet Explorer ADODB.Redcordset Double Free Memory Exploit - MS07-009]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3577]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003329">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="post/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fg"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="back/3d/2b/2bback/2b/2b"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^\/g($|[?#])]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Centrality IP Phone (PA-168 Chipset) Session Hijacking]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3189]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001023">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Frag bit="MF" match-negative="no" match-greedy="no"/>
        <TCPFlags syn-flag="no" fin-flag="no" ack-flag="yes" rst-flag="no" psh-flag="no" null="no" reserve-bit1="no" reserve-bit2="no" match-negative="yes" match-greedy="no" match-or="no">
        <TCPFlagsMask syn-mask="no" fin-mask="no" ack-mask="no" rst-mask="no" psh-mask="no" reserve-bit1="yes" reserve-bit2="yes"/>
        </TCPFlags>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Invalid fragment - ACK reset]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001024">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Frag bit="MF" match-negative="no" match-greedy="no"/>
        <TCPFlags syn-flag="yes" fin-flag="yes" ack-flag="no" rst-flag="yes" psh-flag="no" null="no" reserve-bit1="no" reserve-bit2="no" match-negative="no" match-greedy="no" match-or="no">
        <TCPFlagsMask syn-mask="no" fin-mask="no" ack-mask="no" rst-mask="no" psh-mask="no" reserve-bit1="yes" reserve-bit2="yes"/>
        </TCPFlags>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Invalid fragment - illegal flags]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001990">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fjammail/2epl/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(mail=\|.+\|)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT JamMail Jammail.pl Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="13937"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001883">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fbanned/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="cmd/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Kali Tagboard Command Execution Attempt]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="445" match-neg-port="no" follow-on-sig="no" name="DC:2000046">
        <ExtendedLanguage src-port="any" dst-port="445">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00/9a/a8/40/00/01/00/00/00/00/00/00/00"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00/00/00/00/00/9a/a8/40/00/01/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04011 Lsasrv.dll RPC exploit (Win2k)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="445" match-neg-port="no" follow-on-sig="no" name="DC:2000033">
        <ExtendedLanguage src-port="any" dst-port="445">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/95/14/40/00/03/00/00/00/7c/70/40/00/01"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/78/85/13/00/ab/5b/a6/e9/31/31"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04011 Lsasrv.dll RPC exploit (WinXP)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001190">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/89/50/4e/47/0d/0a/1a/0a"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="0x80000000" jump="0" endian="big" string-data="yes" string-format="hexadecimal"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT libPNG - Possible NULL-pointer crash in png_handle_iCCP]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/unixfocus/5ZP0C0KDPG.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001191">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/89/50/4e/47/0d/0a/1a/0a"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="0x80000000" jump="8" endian="big" string-data="yes" string-format="hexadecimal"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT libPNG - Width exceeds limit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/unixfocus/5ZP0C0KDPG.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001192">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/89/50/4e/47/0d/0a/1a/0a"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="0x80000000" jump="12" endian="big" string-data="yes" string-format="hexadecimal"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT libPNG - Height exceeds limit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/unixfocus/5ZP0C0KDPG.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001195">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/89/50/4e/47/0d/0a/1a/0a"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="sPLT"/>
        </Match>
        <Match match-order="2">
        <PayloadPosition relative-to-previous="yes" byte-offset="80"/>
        </Match>
        <Match match-order="3" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT libPNG - Possible integer overflow in allocation in png_handle_sPLT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securiteam.com/unixfocus/5ZP0C0KDPG.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001058">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/89PNG/0d/0a/1a/0a"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="negative" pattern="PLTE"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="tRNS"/>
        </Match>
        <Match match-order="3">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="256" jump="-8" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT libpng tRNS overflow attempt]]></Description>
        <Reference name="CVE" value="CAN-2004-0597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003072">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsecurity/2etri"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="securitymode/3d0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Linksys WRT54g Authentication Bypass Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://secunia.com/advisories/21372/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="6667" match-neg-port="no" follow-on-sig="no" name="DC:2000329">
        <ExtendedLanguage src-port="6667" dst-port="any">
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="dcc/20send/20"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="100"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT mIRC <=6.12 DCC Buffer Overflow]]></Description>
        <Reference name="BUGTRAQ" value="8880"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003206">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2emov"/>
        </Match>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BE.movuri]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Quicktime .mov File Requested]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003207">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="javascript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[A<[^>]*javascript\:.*>T<.*>]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.movuri]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Quicktime .mov File with embedded Javascript]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="445" match-neg-port="no" follow-on-sig="no" name="DC:2001944">
        <ExtendedLanguage src-port="any" dst-port="445">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="CCCC/20/f0/fd/7fSVWf"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04-007 Kill-Bill ASN1 exploit attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.phreedom.org/solar/exploits/msasn1-bitstring/]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/MS04-007.mspx]]></Reference>
        <Reference name="CVE" value="CAN-2003-0818"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001369">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/45/4d/46"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/eb/12/90/90/90/90/90/90"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="/9e/5c/05/78"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04-032 Windows Metafile (.emf) Heap Overflow Exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.k-otik.com/exploits/20041020.HOD-ms04032-emf-expl2.c.php]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001363">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/45/4d/46"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/23/6a/75/4e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Possible MS04-032 Windows Metafile (.emf) Heap Overflow Portbind Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/ms04-032.mspx]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001364">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/45/4d/46"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/5e/79/72/63"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/48/4f/44/21"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04-032 Windows Metafile (.emf) Heap Overflow Connectback Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/ms04-032.mspx]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001374">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00"/>
        </Match>
        <Match match-order="1" offset="40" depth="44">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20/45/4d/46"/>
        </Match>
        <Match match-order="2">
        <PayloadTest relative-to-previous="no" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val=" 256" jump=" 60" endian="little" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS04-032 Bad EMF file]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sygate.com/alerts/SSR20041013-0001.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001668">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="RIFF"/>
        </Match>
        <Match match-order="1" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ACON"/>
        </Match>
        <Match match-order="2" distance="160">
        <ExtendedPattern uri-decode="no" type="binary" pattern="anih"/>
        </Match>
        <Match match-order="3">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="36" jump="0" endian="little" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Exploit MS05-002 Malformed .ANI stack overflow attack]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001727">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2edoc"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\x2edoc\x2500.{500}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-005 Office XP .doc Remote Code Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2005/0119]]></Reference>
        <Reference name="CVE" value="2004-0848"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002799">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2ertf"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\x2ertf\x2500.{500}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-005 Office XP .rtf Remote Code Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2005/0119]]></Reference>
        <Reference name="CVE" value="2004-0848"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="any" dynamic-collection="0" port="445" match-neg-port="no" follow-on-sig="no" name="DC:2002064">
        <ExtendedLanguage src-port="445" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00"/>
        </Match>
        <Match match-order="1" offset="4" depth="9">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/ffSMB/32"/>
        </Match>
        <Match match-order="2" offset="132" depth="141">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/ff/ff/ff/ff/00/00/00/00/ff"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT ms05-011 exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/exploits/20050623.mssmb_poc.c.php]]></Reference>
        <Reference name="BUGTRAQ" value="12484"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001725">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3cobject/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[codebase[ \t]*=[ \t]*[\x22\x27].*\?\.exe]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-014 HTML OBJECT tag local zone exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2001848">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlink2state"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-021 Exchange Link State - Possible Attack (1)]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?date=2005-04-12]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/MS05-021.mspx]]></Reference>
        <Reference name="CVE" value="CAN-2005-0560"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="691" match-neg-port="no" follow-on-sig="no" name="DC:2001849">
        <ExtendedLanguage src-port="any" dst-port="691">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlsa/2d2"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-021 Exchange Link State - Possible Attack (2)]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?date=2005-04-12]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/MS05-021.mspx]]></Reference>
        <Reference name="CVE" value="CAN-2005-0560"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2001874">
        <ExtendedLanguage src-port="25" dst-port="any">
        <TCPFlags syn-flag="no" fin-flag="no" ack-flag="no" rst-flag="yes" psh-flag="no" null="no" reserve-bit1="no" reserve-bit2="no" match-negative="no" match-greedy="no" match-or="no">
        </TCPFlags>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[msxlsa]]></FlowTag>
        <FlowTag action="clear" suppress-alert="no"><![CDATA[msxlsa]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT TCP Reset from MS Exchange after chunked data, probably crashed it (MS05-021)]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?date=2005-04-12]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/bulletin/MS05-021.mspx]]></Reference>
        <Reference name="CVE" value="CAN-2005-0560"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002120">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICC/5fPROFILE/00/01"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="1048576" jump="1" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Potential MS05-036 exploit - JPEG with embedded ICC - Excessive Profile Size]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002121">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICC/5fPROFILE/00/01"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="1024" jump="127" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Potential MS05-036 exploit - JPEG with embedded ICC - Excessive Tag Count]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002122">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICCRGBG1012"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="1048576" jump="1" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Potential MS05-036 exploit - GIF with embedded ICC - Excessive Profile Size]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002123">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICCRGBG1012"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="gt" match-negative="no" comparison-val="1024" jump="129" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT Potential MS05-036 exploit - GIF with embedded ICC - Excessive Tag Count]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002134">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICC/5fPROFILE/00"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[[rbg]XYZ]]></PCRE>
        </Match>
        <Match match-order="2">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="eq" match-negative="yes" comparison-val="20" jump="4" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-036 exploit - JPEG ICC r/b/g/XYZ GetColorProfileElement overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002137">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ICCRGBG1012"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[[rbg]XYZ]]></PCRE>
        </Match>
        <Match match-order="2">
        <PayloadTest relative-to-previous="yes" num-bytes="4" comparison-op="eq" match-negative="yes" comparison-val="20" jump="4" endian="big" string-data="no" string-format="none"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT MS05-036 exploit - GIF ICC r/b/g/XYZ GetColorProfileElement overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx]]></Reference>
        <Reference name="CVE" value="CVE-2005-1219"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002174">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[CLSID\s*\:(?=\x7b?[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\x7d?)]]></PCRE>
        </Match>
        <FlowTag action="test-not-defined" suppress-alert="yes"><![CDATA[CLSID_DETECTED]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT CLSID Pattern Matched]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002171">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[03D9F3F2-B0E3-11D2-B081-006008039BF0|860BB310-5D01-11D0-BD3B-00A0C911CE86|E0F158E1-CB04-11D0-BD4E-00A0C911CE86|33D9A761-90C8-11D0-BD43-00A0C911CE86|4EFE2452-168A-11D1-BC76-00C04FB9453B|33D9A760-90C8-11D0-BD43-00A0C911CE86|33D9A762-90C8-11D0-BD43-00A0C911CE86|083863F1-70DE-11D0-BD40-00A0C911CE86|18AB439E-FCF4-40D4-90DA-F79BAA3B0655|31087270-D348-432C-899E-2D2F38FF29A0|D2923B86-15F1-46FF-A19A-DE825F919576|FD78D554-4C6E-11D0-970D-00A0C9191601|52CA3BCF-3B9B-419E-A3D6-5D28C0B0B50C]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT COM Object Instantiation Memory Corruption Vulnerability (group 1)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspx]]></Reference>
        <Reference name="CVE" value="2005-1990"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002172">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[01E04581-4EEE-11D0-BFE9-00AA005B4383|AF604EFE-8897-11D1-B944-00A0C90312E1|7849596A-48EA-486E-8937-A2A3009F31A9|FBEB8A05-BEEE-4442-804E-409D6C4515E9|3050F391-98B5-11CF-BB82-00AA00BDCE0B|8EE42293-C315-11D0-8D6F-00A0C9A06E1F|2A6EB050-7F1C-11CE-BE57-00AA0051FE20|510A4910-7F1C-11CE-BE57-00AA0051FE20|6D36CE10-7F1C-11CE-BE57-00AA0051FE20|860D28D0-8BF4-11CE-BE59-00AA0051FE20|9478F640-7F1C-11CE-BE57-00AA0051FE20|B0516FF0-7F1C-11CE-BE57-00AA0051FE20|D99F7670-7F1A-11CE-BE57-00AA0051FE20]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT COM Object Instantiation Memory Corruption Vulnerability (group 2)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspx]]></Reference>
        <Reference name="CVE" value="2005-1990"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002173">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[EEED4C20-7F1B-11CE-BE57-00AA0051FE20|C7B6C04A-CBB5-11D0-BB4C-00C04FC2F410|85BBD920-42A0-1069-A2E4-08002B30309D|E846F0A0-D367-11D1-8286-00A0C9231C29|B4B3AECB-DFD6-11D1-9DAA-00805F85CFE3|ECABB0BF-7F19-11D2-978E-0000F8757E2A|466D66FA-9616-11D2-9342-0000F875AE17|67DCC487-AA48-11D1-8F4F-00C04FB611C7|00022613-0000-0000-C000-000000000046|D2D588B5-D081-11D0-99E0-00C04FC2F8EC|5D08B586-343A-11D0-AD46-00C04FD8FDFF|CC7BFB42-F175-11D1-A392-00E0291F3959|CC7BFB43-F175-11D1-A392-00E0291F3959|3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT COM Object Instantiation Memory Corruption Vulnerability (group 3)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspx]]></Reference>
        <Reference name="CVE" value="2005-1990"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002308">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="ec444cb6/2d3e7e/2d4865/2db1c3/2d0de72ef39b3f"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT Internet Explorer Vulnerable CLSID (Msdds.dll)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/exploits/20050817.IE-Msddsdll-0day.php]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002491">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[BC5F1E51-5110-11D1-AFF5-006097C9A284|F27CE930-4CA3-11D1-AFF2-006097C9A284|3BC4F3A7-652A-11D1-B4D4-00C04FC2DB8D|ECABAFC2-7F19-11D2-978E-0000F8757E2A|283807B8-2C60-11D0-A31D-00AA00B92C03|250770F3-6AF2-11CF-A915-008029E31FCD|D24D4453-1F01-11D1-8E63-006097D2DF48|03CB9467-FD9D-42A8-82F9-8615B4223E6E|598EBA02-B49A-11D2-A1C1-00609778EA66|8FE7E181-BB96-11D2-A1CB-00609778EA66|4CFB5280-800B-4367-848F-5A13EBF27F1D|B3E0E785-BD78-4366-9560-B7DABE2723BE|208DD6A3-E12B-4755-9607-2E39EF84CFC5]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT COM Object MS05-052 (group 1)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-052.mspx]]></Reference>
        <Reference name="CVE" value="2005-2127"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002492">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="clsid"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[4FAAB301-CEF6-477C-9F58-F601039E9B78|6CBE0382-A879-4D2A-8EC3-1F2A43611BA8|F117831B-C052-11D1-B1C0-00C04FC2F3EF|3050F667-98B5-11CF-BB82-00AA00BDCE0B|1AA06BA1-0E88-11D1-8391-00C04FBD7C09|F28D867A-DDB1-11D3-B8E8-00A0C981AEEB|6B7F1602-D44C-11D0-A7D9-AE3D17000000|7007ACCF-3202-11D1-AAD2-00805FC1270E|992CFFA0-F557-101A-88EC-00DD010CCC48|00020420-0000-0000-C000-000000000046|0006F02A-0000-0000-C000-000000000046|ABBA001B-3075-11D6-88A4-00B0D0200F88|CE292861-FC88-11D0-9E69-00C04FD7C15B]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[CLSID_DETECTED]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>WEB-BROWSER-ATTACK</EventGroup>
        <Description><![CDATA[ EXPLOIT COM Object MS05-052 (group 2)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.microsoft.com/technet/security/Bulletin/MS05-052.mspx]]></Reference>
        <Reference name="CVE" value="2005-2127"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-