<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003469">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+AOLToolbar]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY AOL Toolbar User-Agent (AOLToolbar)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000571">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fcompose/5fframe/2eadp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ AOL Webmail Message Send]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000572">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2flogin/2flogin/2epsp/3fsiteId/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="triedAimAuth"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ AOL Webmail Login]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006380">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0d/0aauthorization/3a/20basic"/>
        </Match>
        <Match match-order="1" within="32">
        <ExtendedPattern uri-decode="no" type="negative" pattern="yw5vbnltb3vzog/3d/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006402">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0d/0aauthorization/3a/20basic"/>
        </Match>
        <Match match-order="1" within="32">
        <ExtendedPattern uri-decode="no" type="negative" pattern="yw5vbnltb3vzog/3d/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Incoming Basic Auth Base64 HTTP Password detected unencrypted]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000419">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="MZ"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="76"/>
        </Match>
        <Match match-order="2" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="This/20program/20cannot/20be/20run/20in/20DOS/20mode/2e"/>
        </Match>
        <Match match-order="3">
        <PayloadPosition relative-to-previous="yes" byte-offset="10"/>
        </Match>
        <Match match-order="4" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="PE"/>
        </Match>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.http.binary]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ PE EXE or DLL Windows file download]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000427">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="MZ"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="76"/>
        </Match>
        <Match match-order="2" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="This/20program/20must/20be/20"/>
        </Match>
        <Match match-order="3">
        <PayloadPosition relative-to-previous="yes" byte-offset="140"/>
        </Match>
        <Match match-order="4" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="PE"/>
        </Match>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.http.binary]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ PE EXE Install Windows file download]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.program-transformation.org/Transform/PcExeFormat]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003653">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20boitho/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Boitho.com Distributed Crawler in use - User-Agent (boitho.com-dc)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007576">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="58">
        <ExtendedPattern uri-decode="no" type="binary" pattern="HTTP/2f1/2e0/20200/20Connection/20established/0d/0aProxy/2dagent/3a/20CCProxy/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ POLICY CCProxy in use remotely - Possibly Hostile/Malware]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.youngzsoft.net]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003623">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20domain/20dossier/20utility/20/28http/3a/2f/2fcentralops/2enet/2f/29"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Centralops.net Domain Dossier Utility Probe]]></Description>
        <Reference name="URLREF"><![CDATA[http://centralops.net]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003631">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20"/>
        </Match>
        <Match match-order="1" within="100">
        <ExtendedPattern uri-decode="no" type="string" pattern="centralops/2enet/2f/29"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Centralops.net Probe]]></Description>
        <Reference name="URLREF"><![CDATA[http://centralops.net]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="23" match-neg-port="no" follow-on-sig="no" name="DC:2001239">
        <ExtendedLanguage src-port="23" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="enter/20configuration/20commands/2c/20one/20per/20line"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Cisco Device in Config Mode]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="23" match-neg-port="no" follow-on-sig="no" name="DC:2001240">
        <ExtendedLanguage src-port="23" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="building/20configuration/2e/2e/2e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Cisco Device New Config Built]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="53" match-neg-port="no" follow-on-sig="no" name="DC:2002676">
        <ExtendedLanguage src-port="any" dst-port="53">
        <Match match-order="0" offset="12" depth="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="cT"/>
        </Match>
        <Match match-order="1" within="255">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/10/00/01/00/00/29/08"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY nstx DNS Tunnel Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://savannah.nongnu.org/projects/nstx/]]></Reference>
        <Reference name="URLREF"><![CDATA[http://nstx.dereference.de/nstx]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001294">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="dwrck/2edll"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ POLICY Dameware Remote Control Service Install]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006434">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2eexe"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(card|gif|jpg|jpeg|cartao)\.exe]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Possible Ecard Trojan download]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003179">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2eexe"/>
        </Match>
        <Match match-order="1" depth="150">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2eexe"/>
        </Match>
        <Match match-order="2" offset="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="get/20"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="negative" pattern="download/2ewindowsupdate/2ecom"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="no" type="negative" pattern="mms/3a/2f/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY exe download without User Agent]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="21" match-neg-port="no" follow-on-sig="no" name="DC:2003303">
        <ExtendedLanguage src-port="any" dst-port="21">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="user"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="negative" pattern="pass/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^USER\s+(anonymous|ftp)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY FTP Login Attempt (non-anonymous)]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="21" match-neg-port="no" follow-on-sig="no" name="DC:2003410">
        <ExtendedLanguage src-port="21" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="230/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^230(\s+USER)?\s+(anonymous|ftp)]]></PCRE>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[ftp.user.login]]></FlowTag>
        <FlowTag action="test-not-defined" suppress-alert="no"><![CDATA[ftp.user.logged_in]]></FlowTag>
        <FlowTag action="define" suppress-alert="no"><![CDATA[ftp.user.logged_in]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY FTP Login Successful (non-anonymous)]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007639">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20qsp"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+QSP\s*\d+\:\d+\s*]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Policy FOX,ABC On-demand UA]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003456">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2egazzag/2ecom"/>
        </Match>
        <AlertLimit num-alerts="5" interval="300" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Gazzag.com Social Site Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="80" match-neg-port="no" follow-on-sig="no" name="DC:2003121">
        <ExtendedLanguage src-port="any" dst-port="80">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a/20docs/2egoogle/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY docs.google.com Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://docs.google.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="80" match-neg-port="no" follow-on-sig="no" name="DC:2003122">
        <ExtendedLanguage src-port="any" dst-port="80">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="writely/5fsid"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Possible docs.google.com Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://docs.google.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003599">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="200">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20GrooveInstallValidator/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Groove.net Virtual Office Suite Install/Startup Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.groove.net]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/GrooveNet]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003600">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="200">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Groove/20Install/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Groove.net Virtual Office Suite Install Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.groove.net]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/GrooveNet]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="2492" match-neg-port="no" follow-on-sig="no" name="DC:2003601">
        <ExtendedLanguage src-port="2492" dst-port="2492">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="dpp/3a/2f/2f"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="groove/2enet"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Groove.net Virtual Office In Use]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.groove.net]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/GrooveNet]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000035">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="hotmail/2emsn/2ecom"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(GET |GET (http|https)\:\/\/[-0-9a-z.]*)\/cgi-bin\/HoTMaiL\?curmbox=]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Hotmail Inbox Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000036">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="hotmail/2emsn/2ecom"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(GET |GET (http|https)\:\/\/[-0-9a-z.]*)\/cgi-bin\/getmsg\?msg=MSG]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Hotmail Message Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000037">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="curmbox/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="hotmail/2emsn/2ecom"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(GET |GET (http|https)\:\/\/[-0-9a-z.]*)\/cgi-bin\/compose\?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Hotmail Compose Message Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000038">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="hotmail/2emsn/2ecom"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(POST |POST (http|https)\:\/\/[-0-9a-z.]*)\/cgi-bin\/premail]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Hotmail Compose Message Submit]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000039">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="curmbox/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="login/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="msghdrid"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="sigflag/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Hotmail Compose Message Submit Data]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="8000" match-neg-port="no" follow-on-sig="no" name="DC:2001055">
        <ExtendedLanguage src-port="any" dst-port="8000">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2fplugins/2fframework/2fscript/2fcontent/2ehts"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="executefile"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ MISC HP Web JetAdmin ExecuteFile admin access]]></Description>
        <Reference name="BUGTRAQ" value="10224"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003455">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehi5/2ecom"/>
        </Match>
        <AlertLimit num-alerts="5" interval="300" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hi5.com Social Site Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007627">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehyves/2e"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="login/5fusername"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hyves Login Attempt]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007628">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehyves/2e"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fmessages/2finbox/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hyves Inbox Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007629">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehyves/2e"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fmessages/2finbox/2fmessages/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hyves Message Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007630">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehyves/2e"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="index/2ephp/3fl1/3dmg"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hyves Compose Message]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007631">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2ehyves/2e"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fmessages/2f"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST/20/2fmessages/2f"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="postman/5fsecret"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Hyves Message Submit]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5190" match-neg-port="no" follow-on-sig="no" name="DC:2001801">
        <ExtendedLanguage src-port="any" dst-port="5190">
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2a/02"/>
        </Match>
        <Match match-order="1" offset="4" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/19/00/13/00/05"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Status Invisible]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5190" match-neg-port="no" follow-on-sig="no" name="DC:2001802">
        <ExtendedLanguage src-port="any" dst-port="5190">
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2a/02"/>
        </Match>
        <Match match-order="1" offset="4" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/0e/00/01/00/11"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Status Change (1)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5190" match-neg-port="no" follow-on-sig="no" name="DC:2001803">
        <ExtendedLanguage src-port="any" dst-port="5190">
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2a/02"/>
        </Match>
        <Match match-order="1" offset="4" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/12/00/01/00/1e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Status Change (2)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5190" match-neg-port="no" follow-on-sig="no" name="DC:2001804">
        <ExtendedLanguage src-port="any" dst-port="5190">
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2a/01"/>
        </Match>
        <Match match-order="1" offset="8" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/01/00/01"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Login]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001805">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2a/02"/>
        </Match>
        <Match match-order="1" offset="6" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/04/00/06/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Message]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002986">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpub/2ficq/5fwin95/5f98/5fnt4/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY ICQ Install Direct download - Not normal mode of install]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5222" match-neg-port="no" follow-on-sig="no" name="DC:2002327">
        <ExtendedLanguage src-port="any" dst-port="5222">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="gmail/2ecom"/>
        </Match>
        <Match match-order="1" within="6" distance="9">
        <ExtendedPattern uri-decode="no" type="string" pattern="jabber"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google Talk (Jabber) Client Login]]></Description>
        <Reference name="URLREF"><![CDATA[http://talk.google.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.xmpp.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="443" match-neg-port="no" follow-on-sig="no" name="DC:2002330">
        <ExtendedLanguage src-port="any" dst-port="443">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="gmail/2ecom"/>
        </Match>
        <Match match-order="1" within="78" distance="64">
        <ExtendedPattern uri-decode="no" type="string" pattern="jabber"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google Talk TLS Client Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://talk.google.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.xmpp.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002332">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ms/3axml/3ans/3axmpp/2ds"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="X/2dGOOGLE/2dTOKEN/22/3e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google IM traffic Windows client user sign-on]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.google.com/talk]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002333">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/22/3e/3cinvitati"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="on/20xmlns/3d/22google"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google IM traffic friend invited]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.google.com/talk]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5222" match-neg-port="no" follow-on-sig="no" name="DC:2002334">
        <ExtendedLanguage src-port="any" dst-port="5222">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="gmail"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[gmail.com]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="jabber"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[jabber.org]]></PCRE>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="version/3d"/>
        </Match>
        <Match match-order="5">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[version=]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google IM traffic Jabber client sign-on]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.google.com/talk]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002335">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3c/2fstream/3as"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="tream/3e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Google IM traffic Windows client user sign-off]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.google.com/talk]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001241">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="msg/20"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="content/2dtype/3a"/>
        </Match>
        <Match match-order="2" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="text/2fx/2dmsmsgsinvite"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="application/2dname/3a"/>
        </Match>
        <Match match-order="4" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="file/20transfer"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT MSN file transfer request]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001242">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="msg/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="content/2dtype/3a"/>
        </Match>
        <Match match-order="2" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="text/2fx/2dmsmsgsinvite"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="invitation/2dcommand/3a"/>
        </Match>
        <Match match-order="4" distance="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="accept"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT MSN file transfer accept]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001243">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="msg/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="content/2dtype/3a"/>
        </Match>
        <Match match-order="2" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="text/2fx/2dmsmsgsinvite"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="invitation/2dcommand/3a"/>
        </Match>
        <Match match-order="4" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="cancel"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="cancel/2dcode/3a"/>
        </Match>
        <Match match-order="6" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="reject"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT MSN file transfer reject]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001682">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgateway/2fgateway/2edll/3faction/3dpoll/26sessionid/3d"/>
        </Match>
        <AlertLimit num-alerts="10" interval="3600" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Policy MSN IM Poll via HTTP]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002192">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="55">
        <ExtendedPattern uri-decode="no" type="binary" pattern="CHG/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY MSN status change]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002312">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" within="90">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/6d/73/6e/67/61/6d/65/2e/61/73/70/78"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY MSN Game Loading]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001253">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/01"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM successful logon]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001254">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00j"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM voicechat]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001256">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/18"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM conference invitation]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001257">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/19"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM conference logon success]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001258">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/1d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM conference message]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001427">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="55">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/59/47/00/0b/00/00/00/00/00/12/00/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM Unavailable Status]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001259">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00m"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM file transfer request]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001261">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/98"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM successful chat join]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001262">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="ymsg"/>
        </Match>
        <Match match-order="1" offset="10" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00p"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM conference offer invitation]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001263">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3cR"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="yes" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^\x3c(REQIMG|RVWCFG)\x3e]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM conference request]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002659">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fycontent/2fstats/2ephp/3fversion/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="event/3dinstallbegin"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ CHAT Yahoo IM Client Install]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5050" match-neg-port="no" follow-on-sig="no" name="DC:2007066">
        <ExtendedLanguage src-port="any" dst-port="5050">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="content/2dlength/3a"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3cymsg/20command/3d/22550/22"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Yahoo Chat Signin Inside Webmail]]></Description>
        <Reference name="URLREF"><![CDATA[http://yahoo.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000355">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="notice/20auth"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="looking/20up/20your/20hostname/2e/2e/2e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY IRC authorization message]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000356">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="welcome/20to/20the/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="irc/20network"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY IRC connection]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002082">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20client/0d/0a"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/2emicrosoft/2ecom/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Unusual User Agent (Client)]]></Description>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/2002082]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002878">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+iTunes]]></PCRE>
        </Match>
        <AlertLimit num-alerts="1" interval="360" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY iTunes User Agent]]></Description>
        <Reference name="URLREF"><![CDATA[http://hcsoftware.sourceforge.net/jason-rohrer/itms4all/]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000569">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpr/2fagtray/2etxt"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY KitCo Kcast Ticker (agtray)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000570">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpr/2fautray/2etxt"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY KitCo Kcast Ticker (autray)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002722">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ID3/03"/>
        </Match>
        <Match match-order="1" within="10" distance="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="TIT2"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY MP3 File Transfer Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://filext.com/detaillist.php?extdetail=mp3&Search=Search]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="3544" match-neg-port="no" follow-on-sig="no" name="DC:2003155">
        <ExtendedLanguage src-port="any" dst-port="3544">
        <Match match-order="0" offset="21" depth="16">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/fe/80/00/00/00/00/00/00/80/00TEREDO"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY Microsoft TEREDO IPv6 tunneling]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003409">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+MJ12bot]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ POLICY Majestic-12 Spider Bot User-Agent (MJ12bot)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.majestic12.co.uk/]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006367">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2emetacafe/2ecom"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="submit/3dContinue/2b/2d/2bI/2527m/2bover/2b18"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Metacafe.com family filter off]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006368">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="post"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ffiles/2f"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a"/>
        </Match>
        <Match match-order="3" within="40">
        <ExtendedPattern uri-decode="no" type="string" pattern="rapidshare/2ecom"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26accesscode/3d"/>
        </Match>
        <Match match-order="5" within="50">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26actionstring/3ddownload"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Rapidshare download unauthd image post]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/RapidShare]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006369">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="get"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2ffiles/2f"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a"/>
        </Match>
        <Match match-order="3" within="40">
        <ExtendedPattern uri-decode="no" type="string" pattern="rapidshare/2ecom"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="cookie/3a/20user/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Rapidshare auth cookie download]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/RapidShare]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003457">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2emetacafe/2ecom"/>
        </Match>
        <AlertLimit num-alerts="5" interval="300" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Metacafe.com Social Site Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002872">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="login/2emyspace/2ecom"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2findex/2ecfm/3ffuseaction/3dlogin"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Myspace Login Attempt]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006779">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20check/5fhttp/2f"/>
        </Match>
        <Match match-order="1" within="30">
        <ExtendedPattern uri-decode="no" type="string" pattern="/28nagios/2dplugins/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Nagios HTTP Monitoring Connection]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007638">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20wmphostinternetconnection"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Netflix On-demand User-Agent]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001597">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/55/4b/30/30/37/36/30/53/37/47/31/30"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ Policy Netop Remote Control Usage]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.netop.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003453">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2enetvacy/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Netvacy.com Anonymizing Proxy Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001979">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="SSH/2d"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="gt" match-negative="no" comparison-val="48" jump="0" endian="big" string-data="no" string-format="none"/>
        </Match>
        <Match match-order="2">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="lt" match-negative="no" comparison-val="51" jump="0" endian="big" string-data="no" string-format="none"/>
        </Match>
        <Match match-order="3">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="eq" match-negative="no" comparison-val="46" jump="1" endian="big" string-data="no" string-format="none"/>
        </Match>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[is_ssh_server_banner]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSH Server Banner Detected on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001980">
        <ExtendedLanguage>
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" offset="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="SSH/2d"/>
        </Match>
        <Match match-order="1">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="gt" match-negative="no" comparison-val="48" jump="0" endian="big" string-data="no" string-format="none"/>
        </Match>
        <Match match-order="2">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="lt" match-negative="no" comparison-val="51" jump="0" endian="big" string-data="no" string-format="none"/>
        </Match>
        <Match match-order="3">
        <PayloadTest relative-to-previous="yes" num-bytes="1" comparison-op="eq" match-negative="no" comparison-val="46" jump="1" endian="big" string-data="no" string-format="none"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[is_ssh_server_banner]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[is_ssh_client_banner]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSH Client Banner Detected on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001981">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <PayloadTest relative-to-previous="no" num-bytes="1" comparison-op="eq" match-negative="no" comparison-val="20" jump="5" endian="big" string-data="no" string-format="none"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[is_ssh_client_banner]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[is_ssh_server_kex]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSHv2 Server KEX Detected on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001982">
        <ExtendedLanguage>
        <Flow direction="source-client" state="established"/>
        <Match match-order="0">
        <PayloadTest relative-to-previous="no" num-bytes="1" comparison-op="eq" match-negative="no" comparison-val="20" jump="5" endian="big" string-data="no" string-format="none"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[is_ssh_server_kex]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[is_ssh_client_kex]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSHv2 Client KEX Detected on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001983">
        <ExtendedLanguage>
        <Flow direction="source-client" state="established"/>
        <Match match-order="0">
        <PayloadTest relative-to-previous="no" num-bytes="1" comparison-op="eq" match-negative="no" comparison-val="21" jump="5" endian="big" string-data="no" string-format="none"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[is_ssh_client_kex]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[is_proto_ssh]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSHv2 Client New Keys Detected on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="U" match-neg-port="yes" follow-on-sig="no" name="DC:2001984">
        <ExtendedLanguage>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[is_proto_ssh]]></FlowTag>
        <AlertLimit num-alerts="2" interval="300" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ POLICY SSH session in progress on Unusual Port]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003458">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20www/2eorkut/2ecom"/>
        </Match>
        <AlertLimit num-alerts="5" interval="300" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Orkut.com Social Site Access]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="yes" follow-on-sig="no" name="DC:2003040">
        <ExtendedLanguage>
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" offset="4" depth="37">
        <ExtendedPattern uri-decode="no" type="binary" pattern="http/3a/2f/2fwww/2epcmesh/2ecom/3a80/2fip/2dcheck/2ecgi"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY PCMesh Anonymous Proxy client connect]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006410">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="get/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2findex/2ephp/3fq/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[index\.php\?q=(uggc|jjj|http|www|aHR0c|d3d3)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY PHP Anonymizing/Evasion Proxy In Use]]></Description>
        <Reference name="URLREF"><![CDATA[http://sourceforge.net/projects/php-proxy/]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003214">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20pingdom/20gigrib"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ POLICY Pingdom.com Monitoring detected]]></Description>
        <Reference name="URLREF"><![CDATA[http://royal.pingdom.com/?p=46]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003215">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20pingdom/20gigrib"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ POLICY Pingdom.com Monitoring Node Active]]></Description>
        <Reference name="URLREF"><![CDATA[http://royal.pingdom.com/?p=46]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2007611">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0aX/2dPriority/3a/201/0d/0aX/2dLibrary/3a/20Indy/20"/>
        </Match>
        <Match match-order="1" within="30">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0a/0d/0a/2e/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Possible Infection Report Mail - Indy Mail lib and No Message Body - Priority 1]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2007612">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0aX/2dPriority/3a/203/0d/0aX/2dLibrary/3a/20Indy/20"/>
        </Match>
        <Match match-order="1" within="30">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0a/0d/0a/2e/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Possible Infection Report Mail - Indy Mail lib and No Message Body - Priority 3]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2007613">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0ax/2dpriority/3a/201/0d/0ax/2dlibrary/3a/20indy/20"/>
        </Match>
        <Match match-order="1" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0d/0amac/2e/2e/2e/2e/2e/2e/2e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Possible Infection Report Mail - Indy Mail lib and MAC Message Body - Priority 1]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2007614">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0ax/2dpriority/3a/203/0d/0ax/2dlibrary/3a/20indy/20"/>
        </Match>
        <Match match-order="1" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0d/0amac/2e/2e/2e/2e/2e/2e/2e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY Possible Infection Report Mail - Indy Mail lib and MAC Message Body - Priority 3]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001989">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="pchat2/20"/>
        </Match>
        <Match match-order="1" offset="8" depth="400">
        <ExtendedPattern uri-decode="no" type="string" pattern="v/3d/27"/>
        </Match>
        <Match match-order="2" offset="8" depth="400">
        <ExtendedPattern uri-decode="no" type="string" pattern="jv/3d/27"/>
        </Match>
        <Match match-order="3" offset="8" depth="400">
        <ExtendedPattern uri-decode="no" type="string" pattern="u/3d/27"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Prospero Chat Session in Progress]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.prospero.com/technology.htm]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003047">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fprxjdg/2ecgi"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Proxy Judge Discovery/Evasion (prxjdg.cgi)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003048">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fproxyjudge/2ecgi"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Proxy Judge Discovery/Evasion (proxyjudge.cgi)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001950">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/52/61/72/21"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY RAR File Outbound]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="3389" match-neg-port="no" follow-on-sig="no" name="DC:2001329">
        <ExtendedLanguage src-port="any" dst-port="3389">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/03"/>
        </Match>
        <Match match-order="1" offset="5" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>APPS</EventGroup>
        <Description><![CDATA[ POLICY RDP connection request]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="3389" match-neg-port="no" follow-on-sig="no" name="DC:2001330">
        <ExtendedLanguage src-port="3389" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/03"/>
        </Match>
        <Match match-order="1" offset="5" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/d0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>APPS</EventGroup>
        <Description><![CDATA[ POLICY RDP connection confirm]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="3389" match-neg-port="no" follow-on-sig="no" name="DC:2001331">
        <ExtendedLanguage src-port="any" dst-port="3389">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/03"/>
        </Match>
        <Match match-order="1" offset="5" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/80"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>APPS</EventGroup>
        <Description><![CDATA[ POLICY RDP disconnect request]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="3389" match-neg-port="yes" follow-on-sig="no" name="DC:2007571">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/03"/>
        </Match>
        <Match match-order="1" offset="5" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e0"/>
        </Match>
        <Match match-order="2" offset="11" depth="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Cookie/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>APPS</EventGroup>
        <Description><![CDATA[ POLICY Remote Desktop Connection via non RDP Port]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003479">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00/01/00/00/00/08/08"/>
        </Match>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.Radmin.Challenge]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Radmin Remote Control Session Setup Initiate]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.radmin.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003480">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00/25/00/00/02/12/08/02/00/00/0a/00/00/00/00/00/00"/>
        </Match>
        <PayloadSize min="0" max="50" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[BE.Radmin.Challenge]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Radmin Remote Control Session Setup Response]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.radmin.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003481">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00/05/00/00/02/27/27/02/00/00/00"/>
        </Match>
        <PayloadSize min="0" max="20" match-zero="no"/>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.Radmin.Auth.Challenge]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Radmin Remote Control Session Authentication Initiate]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.radmin.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003482">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/00/00/00/05/00/00/00/27/27/00/00/00/00"/>
        </Match>
        <PayloadSize min="0" max="20" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[BE.Radmin.Auth.Challenge]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Radmin Remote Control Session Authentication Response]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.radmin.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003045">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+ARCADE_BUNDLE_DOWNLOADER]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Real.com Game Arcade Install (User agent)]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003046">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2fgameconsole/2fbundlescripts/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Real.com Game Arcade Install]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002979">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="installation/20of/20sc/2dkeylog/20on/20host/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3cp/3eyou/20will/20receive/20a/20log/20report/20every/20"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="document/20sent/20by/20/3ca/20href/3d/27http/3a/2f/2fwww/2esoft/2dcentral/2enet/2fkeylog/2ephp/27/3esc/2dkeylog/3c/2fa/3e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ POLICY SC-KeyLog Keylogger Installed - Sending Initial Email Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.soft-central.net/keylog.php]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="443" match-neg-port="no" follow-on-sig="no" name="DC:2003026">
        <ExtendedLanguage src-port="any" dst-port="443">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 443 being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="9001" match-neg-port="no" follow-on-sig="no" name="DC:2004598">
        <ExtendedLanguage src-port="any" dst-port="9001">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 9001 (aol) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8000" match-neg-port="no" follow-on-sig="no" name="DC:2003027">
        <ExtendedLanguage src-port="any" dst-port="8000">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8000 being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8080" match-neg-port="no" follow-on-sig="no" name="DC:2003028">
        <ExtendedLanguage src-port="any" dst-port="8080">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8080 being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8200" match-neg-port="no" follow-on-sig="no" name="DC:2003029">
        <ExtendedLanguage src-port="any" dst-port="8200">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8200 being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8443" match-neg-port="no" follow-on-sig="no" name="DC:2003030">
        <ExtendedLanguage src-port="any" dst-port="8443">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8443 being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="5222" match-neg-port="no" follow-on-sig="no" name="DC:2003031">
        <ExtendedLanguage src-port="any" dst-port="5222">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 5222 (Jabber) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="5223" match-neg-port="no" follow-on-sig="no" name="DC:2003032">
        <ExtendedLanguage src-port="any" dst-port="5223">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 5223 (Jabber) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="2967" match-neg-port="no" follow-on-sig="no" name="DC:2003033">
        <ExtendedLanguage src-port="any" dst-port="2967">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 2967 (Symantec) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="3128" match-neg-port="no" follow-on-sig="no" name="DC:2003035">
        <ExtendedLanguage src-port="any" dst-port="3128">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 3128 (proxy) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8080" match-neg-port="no" follow-on-sig="no" name="DC:2003036">
        <ExtendedLanguage src-port="any" dst-port="8080">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8080 (proxy) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="8292" match-neg-port="no" follow-on-sig="no" name="DC:2003037">
        <ExtendedLanguage src-port="any" dst-port="8292">
        <Flow direction="target-server" state="established"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BS.SSL.Known.Port]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>LEGACY</EventGroup>
        <Description><![CDATA[ POLICY Known SSL traffic on port 8292 (Bloomberg) being excluded from SSL Alerts]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="no"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-coll