<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007504">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007505">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007506">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007507">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007508">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007509">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007510">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007511">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007512">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007513">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007514">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007515">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="categoryid/5flist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp categoryID_list UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007516">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007517">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007518">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007519">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007520">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007521">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="sale/5ftype/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp sale_type UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007522">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007523">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007524">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007525">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007526">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007527">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="stock/5fnumber/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp stock_number UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007528">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007529">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007530">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007531">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007532">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007533">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="manufacturer/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp manufacturer UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007534">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007535">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007536">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007537">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007538">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007539">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="model/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp model UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007540">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007541">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007542">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007543">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007544">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007545">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vehicleid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vehicleID UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007546">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007547">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007548">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007549">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007550">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007551">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="year/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp year UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007552">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007553">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007554">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007555">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007556">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007557">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="vin/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp vin UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007558">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007559">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007560">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007561">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007562">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007563">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvehiclelistings/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="listing/5fprice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 20/20 Auto Gallery SQL Injection Attempt -- vehiclelistings.asp listing_price UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/21154]]></Reference>
        <Reference name="CVE" value="CVE-2006-6092"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004059">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004060">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004061">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004062">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004063">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004064">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rating/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php rating UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2898"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004071">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004072">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004073">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004074">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004075">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004076">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fincludes/2frating/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="post/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 2z Project SQL Injection Attempt -- rating.php post_id UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded]]></Reference>
        <Reference name="CVE" value="CVE-2007-2905"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007217">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007218">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007219">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007220">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007221">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ascii"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007222">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadmin/2fedit/2easp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[.+UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB 8pixel.net simpleblog SQL Injection Attempt -- edit.asp id UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.milw0rm.com/exploits/2853]]></Reference>
        <Reference name="CVE" value="CVE-2006-6191"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005057">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[SELECT.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005058">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="union"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[UNION\s+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod UNION SELECT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005059">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="insert"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[INSERT.+INTO]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod INSERT]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005060">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="delete"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[DELETE.+FROM]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod DELETE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005061">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="select"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[ASCII\(.+SELECT]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod ASCII]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005062">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftemplates/2fmodif/2ehtml/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/5fmod/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="update"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[UPDATE.+SET]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-SQL-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACGVannu SQL Injection Attempt -- modif.html id_mod UPDATE]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.frsirt.com/english/advisories/2007/0388]]></Reference>
        <Reference name="CVE" value="CVE-2007-0698"/>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003905">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsearch/2flist/2faction/5fsearch/2findex/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="form/5bmods/5d/5b"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[<?(java|vb)?script>?.*<.+\/script>?]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>WEB-XSS-ATTACK</EventGroup>
        <Description><![CDATA[ WEB ACP3 XSS Attempt -- index.php form[mods]]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.securityfocus.com/bid/23834]]></Reference>
        <Reference name="CVE" value="CVE-2007-2579"/>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003906">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-o