?? web-iis.rules
字號:
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS codebrowser SDK access";flags: A+; uricontent:"/iissamples/sdk/asp/docs/codebrws.asp"; nocase;reference:bugtraq,167; classtype:attempted-recon; sid:1005; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS codebrowser access"; uricontent:"/selector/showcode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1006; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS cross-site scripting attempt"; uricontent:"/Form_JScript.asp"; nocase; flags:A+; classtype:attempted-recon; sid:1007; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS del attempt";flags: A+; content:"&del+/s+c|3a|\\*.*"; nocase; classtype:attempted-dos; sid:1008; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS directory listing"; uricontent:"/ServerVariables_Jscript.asp"; nocase; flags:A+; classtype:attempted-recon; sid:1009; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS encoding access"; flags: A+; content: "|25 31 75|"; reference:arachnids,200; classtype:bad-unknown; sid:1010; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS exec-src access";flags: A+; content:"#filename=*.exe"; nocase; classtype:attempted-recon; sid:1011; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS fpcount attempt"; flags: A+; uricontent:"/fpcount.exe"; content:"Digits=-"; nocase; reference:bugtraq,2252; classtype:attempted-dos; sid:1012; rev:2;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS fpcount access";flags: A+; uricontent:"/fpcount.exe"; nocase; reference:bugtraq,2252; classtype:attempted-recon; sid:1013; rev:2;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS getdrvrs access";flags: A+; uricontent:"/scripts/tools/getdrvrs.exe"; nocase; classtype:attempted-recon; sid:1014; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS getdrvs.exe access";flags: A+; uricontent:"/scripts/tools/getdrvs.exe"; nocase; classtype:attempted-recon; sid:1015; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS global-asa access";flags: A+; content:"global.asa"; nocase; classtype:attempted-recon; sid:1016; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS idc-srch attempt";flags: A+; content:"#filename=*.idc"; nocase; reference:cve,CVE-1999-0874; classtype:attempted-recon; sid:1017; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS iisadmpwd attempt";flags: A+; uricontent:"/iisadmpwd/aexp"; nocase; reference:bugtraq,2110; reference:cve,CVE-2000-0303; classtype:attempted-recon; sid:1018; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS index server file sourcecode attempt"; flags: A+; content:"?CiWebHitsFile=/"; content:"&CiRestriction=none&CiHiliteType=Full"; classtype:attempted-recon; sid:1019; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS isc$data attempt";flags: A+; content:".idc|3a3a|$data"; nocase; reference:bugtraq,307; reference:cve,CVE-1999-0874; classtype:attempted-recon; sid:1020; rev:2;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS ism.dll attempt"; flags: A+; content:"%20%20%20%20%20.htr"; nocase; reference:cve,CAN-2000-0457; reference:bugtraq,1193; classtype:attempted-recon; sid:1021; rev:2;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS jet vba access";flags: A+; content:"/advworks/equipment/catalog_type.asp"; nocase; reference:bugtraq,286; reference:cve,CVE-1999-0874; classtype:attempted-recon; sid:1022; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS msadc/msadcs.dll access";flags: A+; uricontent:"/msadc/msadcs.dll"; nocase; reference:cve,CVE-1999-1011; reference:bugtraq,529; classtype:attempted-recon; sid:1023; rev:2;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS newdsn.exe access";flags: A+; uricontent:"/scripts/tools/newdsn.exe"; nocase;reference:bugtraq,1818;reference:cve,CVE-1999-0191; classtype:attempted-recon; sid:1024; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS perl access";flags: A+; uricontent:"/scripts/perl"; nocase; classtype:attempted-recon; sid:1025; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS perl-browse0a attempt";flags: A+; content:"%0a.pl"; nocase; classtype:attempted-recon; sid:1026; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS perl-browse20 attempt";flags: A+; content:"%20.pl"; nocase; classtype:attempted-recon; sid:1027; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS query.asp access";flags: A+; uricontent:"/issamples/query.asp"; nocase; reference:bugtraq,193; reference:cve,CVE-1999-0449; classtype:attempted-recon; sid:1028; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS scripts-browse";flags: A+; uricontent:"/scripts/|20|"; nocase; classtype:attempted-recon; sid:1029; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS search97.vts";flags: A+; uricontent:"/search97.vts";reference:bugtraq,162; classtype:attempted-recon; sid:1030; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/SiteServer/Publishing/viewcode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1031; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/Sites/Knowledge/Membership/Inspired/ViewCode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1032; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/Sites/Knowledge/Membership/Inspiredtutorial/ViewCode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1033; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/Sites/Samples/Knowledge/Membership/Inspiredtutorial/ViewCode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1034; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/Sites/Samples/Knowledge/Push/ViewCode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1035; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode access"; uricontent:"/Sites/Samples/Knowledge/Search/ViewCode.asp"; flags: A+; nocase; classtype:attempted-recon; sid:1036; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS showcode.asp access";flags: A+; uricontent:"/selector/showcode.asp"; nocase; reference:cve,CAN-1999-0736; classtype:attempted-recon; sid:1037; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS site server config access";flags: A+; uricontent:"/adsamples/config/site.csc"; nocase;reference:bugtraq,256; classtype:attempted-recon; sid:1038; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS srch.htm access";flags: A+; uricontent:"/samples/isapi/srch.htm"; nocase; classtype:attempted-recon; sid:1039; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS srchadm access";flags: A+; uricontent:"/srchadm"; nocase; classtype:attempted-recon; sid:1040; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS uploadn.asp access";flags: A+; uricontent:"/scripts/uploadn.asp"; nocase; classtype:attempted-recon; sid:1041; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS view source via translate header"; flags: A+; content: "Translate|3a| F"; nocase;reference:arachnids,305; classtype:attempted-recon; sid:1042; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS viewcode.asp access"; uricontent:"/viewcode.asp"; nocase; flags:a+; classtype:attempted-recon; sid:1043; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS webhits access"; uricontent: ".htw"; flags: A+; dsize: >400;reference:arachnids,237; classtype:attempted-recon; sid:1044; rev:1;)alert tcp $HTTP_SERVERS 80 -> $EXTERNAL_NET any (msg:"WEB-IIS Unauthorized IP Access Attempt"; flags: A+; content:"403"; content:"Forbidden\:"; classtype:attempted-recon; sid:1045; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-IIS site/iisamples access"; flags:A+; uricontent:"/site/iisamples"; nocase; classtype:attempted-recon; sid:1046; rev:1;)alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg: "WEB-IIS CodeRed v2 root.exe access"; flags: A+; uricontent:"scripts/root.exe?"; nocase; classtype: attempted-admin; sid: 1257; rev: 1;)
?? 快捷鍵說明
復制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -