<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003897">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwhstart/2ejs/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Adobe RoboHelp XSS Attempt -- whstart.js]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-1280"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003898">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwhcsh/5fhome/2ehtm/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Adobe RoboHelp XSS Attempt -- whcsh_home.htm]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-1280"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003899">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwf/5fstartpage/2ejs/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Adobe RoboHelp XSS Attempt -- wf_startpage.js]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-1280"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003900">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwf/5fstartqs/2ehtm/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Adobe RoboHelp XSS Attempt -- wf_startqs.htm]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-1280"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003901">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwindowmanager/2edll/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Adobe RoboHelp XSS Attempt -- WindowManager.dll]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-1280"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001945">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fapage/2ecgi/3ff/3d"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(\.\|.+\|)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB WebAPP Apage.CGI Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="13637"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003156">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="crewbox/2eby/2eru/2fcrew/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ WEB Crewbox Proxy Scan]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003326">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/22rtsp/3a/2f/2f"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="400"/>
        </Match>
        <Match match-order="2" within="400" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0a"/>
        </Match>
        <Match match-order="3" within="400" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/22"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB-CLIENT Apple Quicktime RTSP Overflow (1)]]></Description>
        <Reference name="CVE" value="2007-0015"/>
        <Reference name="BUGTRAQ" value="21829"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003327">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/27rtsp/3a/2f/2f"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="400"/>
        </Match>
        <Match match-order="2" within="400" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0a"/>
        </Match>
        <Match match-order="3" within="400" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/27"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB-CLIENT Apple Quicktime RTSP Overflow (2)]]></Description>
        <Reference name="CVE" value="2007-0015"/>
        <Reference name="BUGTRAQ" value="21829"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2007703">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="rtsp/2f"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0acontent/2dtype/3a"/>
        </Match>
        <Match match-order="2" within="50">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB-CLIENT Apple Quicktime RTSP Content-Type overflow attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.kb.cert.org/vuls/id/659761]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/4657]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2007704">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="rtsp/2f"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0acontent/2dtype/3a"/>
        </Match>
        <Match match-order="2" within="50">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB-CLIENT Apple Quicktime RTSP Content-Type overflow attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.kb.cert.org/vuls/id/659761]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/4657]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002900">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fawstats/2epl/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[migrate\s*=\s*\|]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB CGI AWstats Migrate Command Attempt]]></Description>
        <Reference name="BUGTRAQ" value="17844"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002362">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fimg/2epl/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(f=.+\|)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Barracuda Spam Firewall img.pl Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14712"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002685">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fimg/2epl/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(f=\.\..+)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Barracuda Spam Firewall img.pl Remote Directory Traversal Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14710"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003086">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fpreview/5femail/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[file=.*\|]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Barracuda Spam Firewall preview_email.cgi Remote Command Execution]]></Description>
        <Reference name="BUGTRAQ" value="19276"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003087">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fpreview/5femail/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[file=.+\.\..+\|]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Barracuda Spam Firewall preview_email.cgi Remote Directory Traversal Attempt]]></Description>
        <Reference name="BUGTRAQ" value="19276"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002711">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincluder/2ecgi/3f/7c"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB includer.cgi Remote Command Execution Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?storyid=823]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002129">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(config_settings|top_graph_header)\.php\?.*=(http|https)\:\/]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ Cacti Input Validation Attack]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.cacti.net]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.idefense.com/application/poi/display?id=265&type=vulnerabilities]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.idefense.com/application/poi/display?id=266&type=vulnerabilities]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002313">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgraph/5fimage/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(graph_start=%0a.+%0a)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Cacti graph_image.php Remote Command Execution Attempt]]></Description>
        <Reference name="CVE" value="CAN-2005-1524"/>
        <Reference name="BUGTRAQ" value="14129"/>
        <Reference name="BUGTRAQ" value="14042"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003334">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcmd/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Cacti cmd.php Remote Arbitrary SQL Command Execution Attempt]]></Description>
        <Reference name="CVE" value="CVE-2006-6799"/>
        <Reference name="BUGTRAQ" value="21799"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002721">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fconfigure/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fenable/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Cisco IOS HTTP set enable password attack]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.html]]></Reference>
        <Reference name="CVE" value="2005-3921"/>
        <Reference name="BUGTRAQ" value="15602"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004556">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fccmadmin/2fserverlist/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="pattern/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.*<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Cisco CallManager XSS Attempt -- serverlist.asp pattern]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secunia.com/advisories/25377]]></Reference>
        <Reference name="CVE" value="CVE-2007-2832"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003616">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20datacha0s"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ WEB DataCha0s Web Scanner/Robot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.internetofficer.com/web-robot/datacha0s.html]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002376">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="openform"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[BaseTarget=.*?\"]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ IBM Lotus Domino BaseTarget XSS attempt]]></Description>
        <Reference name="BUGTRAQ" value="14845"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002377">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="openframeset"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[src=.*\"><\/FRAMESET>.*<script>.*<\/script>]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ IBM Lotus Domino Src XSS attempt]]></Description>
        <Reference name="BUGTRAQ" value="14846"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="3443" match-neg-port="no" follow-on-sig="no" name="DC:2002365">
        <ExtendedLanguage src-port="any" dst-port="3443">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fovcgi/2fconnectednodes/2eovpl/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[node=.*\|.+\|]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB HP OpenView Network Node Manager Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14662"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002867">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fservices/2fhelp/2f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="yes"><![CDATA[module=[^\;]*\;.*\"]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Horde 3.0.9-3.1.0 Help Viewer Remote PHP Exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/1660]]></Reference>
        <Reference name="CVE" value="2006-1491"/>
        <Reference name="BUGTRAQ" value="17292"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002868">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fhorde/2fservices/2fhelp/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Horde Web Mail Help Access]]></Description>
        <Reference name="CVE" value="2006-1491"/>
        <Reference name="BUGTRAQ" value="17292"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002897">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fhorde"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/horde((2|3|-3\.(0\.[1-9]|1\.0)))?\/{1,2}README]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Horde README access probe]]></Description>
        <Reference name="URLREF"><![CDATA[http://csirt.terradon.com/postarchive.php?month=4&year=2006#article28]]></Reference>
        <Reference name="CVE" value="CVE-2006-1491"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001365">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/3a/3a/24DATA"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC Alternate Data Stream source view attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://support.microsoft.com/kb/q188806/]]></Reference>
        <Reference name="CVE" value="1999-0278"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001342">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2easpx"/>
        </Match>
        <Match match-order="1" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="2" within="200">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/5c"/>
        </Match>
        <Match match-order="3" within="100">
        <ExtendedPattern uri-decode="no" type="string" pattern="aspx"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-IIS ASP.net Auth Bypass / Canonicalization]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001343">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2easpx"/>
        </Match>
        <Match match-order="1" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="2" depth="200">
        <ExtendedPattern uri-decode="no" type="string" pattern="/255c"/>
        </Match>
        <Match match-order="3" within="100">
        <ExtendedPattern uri-decode="no" type="binary" pattern="aspx"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-IIS ASP.net Auth Bypass / Canonicalization % 5 C]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="443" match-neg-port="no" follow-on-sig="no" name="DC:2000559">
        <ExtendedLanguage src-port="any" dst-port="443">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="THCOWNZIIS/21"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ THCIISLame IIS SSL Exploit Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.thc.org/exploits/THCIISSLame.c]]></Reference>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?date=2004-07-17]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002889">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="e5f5d008/2ddd2c/2d4d32/2d977d/2d1a0adf03058b"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[param[^>]*name\s*=\s*["']?productname["']?[^>]*\s+value\s*=\s*(['"])((?!\1).|\\['"]){200}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB JuniperSetup Control Buffer Overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.eeye.com/html/research/advisories/AD20060424.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001546">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="LINK/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC LINK Method]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.w3.org/Protocols/HTTP/Methods/Link.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002777">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2findex/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[date=\d{8}\)\;.+]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Light Weight Calendar 'date' Arbitrary Remote Code Execution]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001021">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3cscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<SCRIPT[^>]*>[\s]*VAR[\s]+[\w]+[\s]*=[\s]*['"]([a-fA-F0-9]{2}){20}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ Suspicious Encrypted Webpage Content]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001811">
        <ExtendedLanguage>
        <Flow direction="target-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/31/30/30/2c111/2c99/2c117/2c109/2c101/2c110/2c116/2c46/2c119/2c114/2c105/2c116/2c101"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ WEB Encoded javascriptdocument.write - usually hostile]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001768">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Microsoft/20OLE/20DB/20Provider/20for/20SQL/20Server/20error"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB MS SQL Server OLEDB asp error]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.wiretrip.net/rfp/p/doc.asp/i2/d42.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002846">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GET/20"/>
        </Match>
        <Match match-order="1">
        <PayloadPosition relative-to-previous="yes" byte-offset="200"/>
        </Match>
        <Match match-order="2" within="200" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Minishare GET Overflow]]></Description>
        <Reference name="CVE" value="2004-2271"/>
        <Reference name="BUGTRAQ" value="11620"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001075">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3cimg"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\bonerror\b[\s]*=]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt IMG onerror or onload]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001077">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="application/2fx/2djavascript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[TYPE\s*=\s*['"]application\/x-javascript]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + JAVASCRIPT]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001078">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="text/2fjscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[TYPE\s*=\s*['"]text\/jscript]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + JSCRIPT]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001079">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="text/2fvbscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[TYPE\s*=\s*['"]text\/vbscript]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + VBSCRIPT 1]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001080">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="application/2fx/2dvbscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[TYPE\s*=\s*['"]application\/x-vbscript]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + VBSCRIPT 2]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001081">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="text/2fecmascript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[TYPE\s*=\s*['"]text\/ecmascript]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + ECMACRIPT]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001082">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="expression"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[STYLE[\s]*=[\s]*[^>]expression[\s]*\(]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + EXPRESSION 1]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001083">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="expression"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[[\s]*expression[\s]*\([^}]}[\s]*<\/STYLE>]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt STYLE + EXPRESSION 2]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001084">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3cxml"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/3c/21/5bcdata/5b/3c/5d/5d/3escript"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt using XML]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001085">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="innerhtml"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[eval[\s]*\([\s]*[^\.]\.innerHTML[\s]*\)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt executing hidden Javascript 1]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001086">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="window/2eexecscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[window.execScript[\s]*\(]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt executing hidden Javascript 2]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001087">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="javascript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*javascript[\:]]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt to execute Javascript code]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001088">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="vbscript"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*vbscript[\:]]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt to execute VBScript code]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001089">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="shell"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*shell[\:]]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting attempt to access SHELL\:]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001090">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="j"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*j[\x09\x0a\x0b\x0c\x0d]*a[\x09\x0a\x0b\x0c\x0d]*v[\x09\x0a\x0b\x0c\x0d]*a[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*c[\x09\x0a\x0b\x0c\x0d]*r[\x09\x0a\x0b\x0c\x0d]*i[\x09\x0a\x0b\x0c\x0d]*p[\x09\x0a\x0b\x0c\x0d]*t[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="javascript/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting stealth attempt to execute Javascript code]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001091">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="v"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*v[\x09\x0a\x0b\x0c\x0d]*b[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*c[\x09\x0a\x0b\x0c\x0d]*r[\x09\x0a\x0b\x0c\x0d]*i[\x09\x0a\x0b\x0c\x0d]*p[\x09\x0a\x0b\x0c\x0d]*t[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="vbscript/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting stealth attempt to execute VBScript code]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001092">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="s"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(((URL|SRC|HREF|LOWSRC)[\s]*=)|(url[\s]*[\(]))[\s]*['"]*[\x09\x0a\x0b\x0c\x0d]*s[\x09\x0a\x0b\x0c\x0d]*h[\x09\x0a\x0b\x0c\x0d]*e[\x09\x0a\x0b\x0c\x0d]*l[\x09\x0a\x0b\x0c\x0d]*l[\x09\x0a\x0b\x0c\x0d]*[\:]]]></PCRE>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="shell/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB-MISC cross site scripting stealth attempt to access SHELL\:]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003466">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+Morfeus\x20F]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ EXPLOIT PHP Attack Tool Morfeus F Scanner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.webmasterworld.com/search_engine_spiders/3227720.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007705">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="get/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\?u\d_\d_\d{3,4}_\d_\d_\d{10}_\d{10}_\d{9,10}[_\da-z]{0,9}$]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Neosploit 1.5.x URL Loader]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002361">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fnquser/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(host=\|.+)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Netquery Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14373"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="8300" match-neg-port="no" follow-on-sig="no" name="DC:2002865">
        <ExtendedLanguage src-port="any" dst-port="8300">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="accept/2dlanguage"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="yes" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^Accept-Language\:[^\n]*?[^,\;\n]{17}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB MISC Novell GroupWise Messenger Accept Language Buffer Overflow]]></Description>
        <Reference name="CVE" value="2006-0992"/>
        <Reference name="BUGTRAQ" value="17503"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002864">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="extras/2fupdate/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ WEB osCommerce extras/update.php disclosure]]></Description>
        <Reference name="URLREF"><![CDATA[http://retrogod.altervista.org/oscommerce_22_adv.html;classtype:attempted-recon]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001767">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="OraOLEDB/20error"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB ORACLE OLEDB asp error]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.wiretrip.net/rfp/p/doc.asp/i2/d42.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001781">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="cgi/2dbin/2frwcgi60"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB ORACLE rwcgi60 information leak attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.kb.cert.org/vuls/id/997403]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002130">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(showenv|parsequery|rwservlet)\?.*=\<]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Oracle Reports XSS Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.oracle.com/technology/products/reports/index.html]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.red-database-security.com/advisory/oracle_reports_various_css.html]]></Reference>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002131">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(showenv|parsequery|rwservlet)\?.*CUSTOMIZE=\/]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Oracle Reports XML Information Disclosure]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.oracle.com/technology/products/reports/index.html]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002132">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(showenv|parsequery|rwservlet)\?.*destype=file.*desformat=\/]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Oracle Reports DESFORMAT Information Disclosure]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.oracle.com/technology/products/reports/index.html]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002133">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="get"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(showenv|parsequery|rwservlet)\?.*report=.*\.(rdf|rep)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB Oracle Reports OS Command Injection Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.oracle.com/technology/products/reports/index.html]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.red-database-security.com/advisory/oracle_reports_run_any_os_command.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002997">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="http"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(path|page|lib|dir|file|root|icon|lang(uage)?|folder|type|agenda|gallery|domain|calendar|settings|news|name|auth|prog|config|cfg|incl|ext|fad|mod|sbp|rf|id|df|[a-z](\[.*\])+)\s*=\s*https?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB PHP Remote File Inclusion (monster list http)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sans.org/top20/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003098">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ftp/3a"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(path|page|lib|dir|file|root|icon|lang(uage)?|folder|type|agenda|gallery|domain|calendar|settings|news|name|auth|prog|config|cfg|incl|ext|fad|mod|sbp|rf|id|df|[a-z](\[.*\])+)\s*=\s*ftp]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB PHP Remote File Inclusion (monster list ftp)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sans.org/top20/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003935">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="php"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(path|page|lib|dir|file|root|icon|lang(uage)?|folder|type|agenda|gallery|domain|calendar|settings|news|name|auth|prog|config|cfg|incl|ext|fad|mod|sbp|rf|id|df|[a-z](\[.*\])+)\s*=\s*php]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB PHP Remote File Inclusion (monster list php)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sans.org/top20/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002730">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fhelp/5ftext/5fvars/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[PGV_BASE_DIRECTORY=(f|ht)tp\:\/]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ PHPGedView Remote Script Code Execution attempt]]></Description>
        <Reference name="BUGTRAQ" value="15983"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002314">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fprod/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(argv[1]=\|.+)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB PHPOutsourcing Zorum prod.php Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14601"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001344">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="edp/5frelative/5fpath/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB-PHP EasyDynamicPages exploit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securitytracker.com/alerts/2004/Jan/1008584.html]]></Reference>
        <Reference name="CVE" value="CAN-2004-0073"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002972">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="filename/3d"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^\s*\.htaccess]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB PHP ZeroBoard .htaccess upload]]></Description>
        <Reference name="URLREF"><![CDATA[http://secunia.com/advisories/20592/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001738">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="forumdisplay/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="comma/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(\.system\(.+\)\.)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB PHP vBulletin Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="12542"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002388">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fmisc/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26template/3d/2e/2a/7b/24/7b"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB vBulletin misc.php Template Name Arbitrary Code Execution]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.osvdb.org/14047]]></Reference>
        <Reference name="URLREF"><![CDATA[http://metasploit.com/projects/Framework/exploits.html#php_vbulletin_template]]></Reference>
        <Reference name="CVE" value="2005-0511"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002837">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpmwiki/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="globals/5bfarmd/5d/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[GLOBALS\x5bFarmD\x5d\x3d]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB PmWiki Globals Variables Overwrite Attempt]]></Description>
        <Reference name="CVE" value="CVE-2006-0479"/>
        <Reference name="BUGTRAQ" value="16421"/>
        <Reference name="NESSUS" value="20891"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004449">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2frpttop/2ehtm"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[MEAS\.TYPE=(?!(link|class)&)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[BLEDING-EDGE WEB PacketShaper DoS attempt]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002331">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fpiranha/2fsecure/2fcontrol/2ephp3"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Authorization/3a/20Basic/20cGlyYW5oYTp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>PROBE</EventGroup>
        <Description><![CDATA[ WEB Piranha default passwd attempt]]></Description>
        <Reference name="CVE" value="2000-0248"/>
        <Reference name="BUGTRAQ" value="1148"/>
        <Reference name="NESSUS" value="10381"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002947">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpbsvweb"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="webkey/3d"/>
        </Match>
        <Match match-order="2">
        <PayloadPosition relative-to-previous="yes" byte-offset="500"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="yes" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[^[^&\n]{500}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB MISC PunkBuster Server webkey Buffer Overflow]]></Description>
        <Reference name="URLREF"><![CDATA[http://aluigi.altervista.org/adv/pbwebbof-adv.txt]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002660">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fwebid/2fiiswebagentif/2edll"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fredirect/3f"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[url=.{8000}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB RSA Web Auth Exploit Attempt - Long URL]]></Description>
        <Reference name="URLREF"><![CDATA[http://secunia.com/advisories/17281]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.metasploit.com/projects/Framework/modules/exploits/rsa_iiswebagent_redirect.pm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006443">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/20from/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Possible SQL Injection Attempt -- DELETE FROM]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/SQL_injection]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006444">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/20into/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Possible SQL Injection Attempt -- INSERT INTO]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/SQL_injection]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006445">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/20from/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Possible SQL Injection Attempt -- SELECT FROM]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/SQL_injection]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006446">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/20select/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Possible SQL Injection Attempt -- UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/SQL_injection]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006447">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/20set/20"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[[&\?].*UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Possible SQL Injection Attempt -- UPDATE SET]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/SQL_injection]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003903">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdefault/2easpx/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="script"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Microsoft SharePoint XSS Attempt -- default.aspx]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/23832]]></Reference>
        <Reference name="CVE" value="CVE-2007-2581"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003904">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcontact/2fcontact/2findex/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="form/5bmail/5d/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="script"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Microsoft SharePoint XSS Attempt -- index.php form[mail]]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/23834]]></Reference>
        <Reference name="CVE" value="CVE-2007-2579"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003705">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsite/5fconf/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ordnertiefe/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion site_conf.php ordnertiefe]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003706">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fclass/2ecsv/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion class.csv.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003707">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fprodukte/5fnach/5fserie/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion produkte_nach_serie.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003708">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ffunctionen/2fref/5fkd/5frubrik/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion ref_kd_rubrik.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003709">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fhg/5freferenz/5fjobgalerie/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion hg_referenz_jobgalerie.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003710">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsurfer/5fanmeldung/5fnwl/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion surfer_anmeldung_NWL.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003711">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fprodukte/5fnach/5fserie/5falle/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion produkte_nach_serie_alle.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003712">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsurfer/5faendern/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion surfer_aendern.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003715">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fref/5fkd/5frubrik/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion ref_kd_rubrik.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003713">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fmodule/2freferenz/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion referenz.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003714">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fstandard/2f1/2flay/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion lay.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003867">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fstandard/2f3/2flay/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="tt/5fdocroot/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ WEB TellTarget CMS Remote Inclusion 3_lay.php tt_docroot]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/3885]]></Reference>
        <Reference name="CVE" value="CVE-2007-2597"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002662">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="include"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[%INCLUDE\s*{.*rev=\"\d+\|.+\".*}\s*%]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB TWiki INCLUDE remote command execution attempt]]></Description>
        <Reference name="BUGTRAQ" value="14960"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003085">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="typeof"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[&TYPEOF\:.+system\s*\(]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB TWiki Configure Script TYPEOF Remote Command Execution Attempt]]></Description>
        <Reference name="CVE" value="CVE-2006-3819"/>
        <Reference name="BUGTRAQ" value="19188"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003099">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="400">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ WEB-MISC Poison Null Byte]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.security-assessment.com/Whitepapers/0x00_vs_ASP_File_Uploads.pdf]]></Reference>
        <Reference name="CVE" value="2006-4542"/>
        <Reference name="CVE" value="2006-4458"/>
        <Reference name="CVE" value="2006-3602"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002494">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2findex/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[select=.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB Versatile Bulletin Board SQL Injection Attack]]></Description>
        <Reference name="BUGTRAQ" value="15068"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002100">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwps/5fshop/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[(art=\|.+\|)]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB WPS wps_shop.cgi Remote Command Execution Attempt]]></Description>
        <Reference name="BUGTRAQ" value="14245"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="1000" match-neg-port="no" follow-on-sig="no" name="DC:2002847">
        <ExtendedLanguage src-port="any" dst-port="1000">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2fwebadmin/2edll/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/3d"/>
        </Match>
        <Match match-order="2" within="200" distance="0">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB WebAdmin User Overflow]]></Description>
        <Reference name="CVE" value="2003-471"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003520">
        <ExtendedLanguage>
        <Flow direction="source-client" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="includedir/3d"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/ws\/(login|get_reminders|get_events)\.php]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-FILE-INCLUDE</EventGroup>
        <Description><![CDATA[ EXPLOIT webCalendar Remote File include]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/462957]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002870">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ie0604/2ecgi/3fexploit"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB WebAttacker kit (exploit ie0604)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002871">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ie0604/2ecgi/3fbug/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB WebAttacker kit (bug ie0604)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002869">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ie0601/2ecgi/3fexploit"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>ATTACKS</EventGroup>
        <Description><![CDATA[ WEB WebAttacker kit (exploit1 ie0601)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002937">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ie0606/2ecgi/3f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventGroup>
        <Description><![CDATA[ WEB WebAttacker kit (ie0606)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003063">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rleadmin/2ecgi/3fgetexe/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-APPLICATION-ATTACK</EventG