Emerging Threats

  • Increase font size
  • Default font size
  • Decrease font size

Weekly New Signatures May 9th 2009

E-mail Print PDF

[+++] Added rules: [+++]

2009300 - ET TROJAN Small.zon checkin (emerging-virus.rules)
2009301 - ET POLICY Megaupload file download service access (emerging-policy.rules)
2009302 - ET POLICY Badongo file download service access (emerging-policy.rules)
2009303 - ET POLICY MediaFire file download service access (emerging-policy.rules)
2009304 - ET POLICY Gigasize file download service access (emerging-policy.rules)
2009305 - ET TROJAN Zlob post installation checkin (.php?inst_result=&hwid) (emerging-virus.rules)
2009306 - ET WEB_SPECIFIC WeBid cron.php include_path Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009307 - ET WEB_SPECIFIC WeBid cron.php include_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009308 - ET WEB_SPECIFIC WeBid ST_browsers.php include_path Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009309 - ET WEB_SPECIFIC WeBid ST_browsers.php include_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009310 - ET WEB_SPECIFIC WeBid ST_countries.php include_path Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009311 - ET WEB_SPECIFIC WeBid ST_countries.php include_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009312 - ET WEB_SPECIFIC WeBid ST_platforms.php include_path Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009313 - ET WEB_SPECIFIC WeBid ST_platforms.php include_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009314 - ET WEB_ACTIVEX Orbit Downloader ActiveX Control Arbitrary File Delete (emerging-web.rules)
2009315 - ET WEB_ACTIVEX PrecisionID Datamatrix ActiveX control Arbitrary File Overwrite (emerging-web.rules)
2009316 - ET WEB_SPECIFIC YapBB class_yapbbcooker.php cfgIncludeDirectory Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009317 - ET WEB_SPECIFIC DesktopOnNet don3_requiem.php app_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009318 - ET WEB_SPECIFIC DesktopOnNet frontpage.php app_path Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009319 - ET WEB_SPECIFIC DeZine DZcms products.php pcat parameter SQL injection (emerging-web_sql_injection.rules)
2009320 - ET WEB_SPECIFIC rgboard _footer.php skin_path parameter local file inclusion (emerging-web_sql_injection.rules)
2009321 - ET WEB_SPECIFIC rgboard footer.php _path parameter remote file inclusion (emerging-web_sql_injection.rules)
2009322 - ET WEB_ACTIVEX SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution (emerging-web.rules)
2009323 - ET WEB_SPECIFIC Demium CMS tracking.php follow_kat Parameter SQL Injection (emerging-web_sql_injection.rules)
2009324 - ET WEB_SPECIFIC Demium CMS urheber.php name Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009325 - ET WEB_SPECIFIC phPortal gunaysoft.php icerikyolu Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009326 - ET WEB_SPECIFIC phPortal gunaysoft.php sayfaid Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009327 - ET WEB_SPECIFIC phPortal gunaysoft.php uzanti Parameter Remote File Inclusion (emerging-web_sql_injection.rules)
2009328 - ET WEB_ACTIVEX GeoVision LiveAudio ActiveX Control Remote Code Execution (emerging-web.rules)
2009329 - ET WEB_SPECIFIC ZABBIX locales.php srclang Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009330 - ET WEB_SPECIFIC MyForum centre.php padmin Parameter Local File Inclusion (emerging-web_sql_injection.rules)
2009331 - ET WEB_SPECIFIC tinyCMS templater.php Local File Inclusion (emerging-web_sql_injection.rules)
2009332 - ET WEB_SPECIFIC ODARS resource_categories_view.php CLASSES_ROOT parameter local file inclusion (emerging-web_sql_injection.rules)
2009333 - ET WEB_SPECIFIC ODARS resource_categories_view.php CLASSES_ROOT parameter Remote file inclusion (emerging-web_sql_injection.rules)
2009334 - ET WEB_ACTIVEX Morovia Barcode ActiveX Control Arbitrary File Overwrite (emerging-web.rules)
2009335 - ET WEB_SPECIFIC nicLOR CMS-School showarticle.php aID Parameter SQL Injection (emerging-web_sql_injection.rules)
2009336 - ET WEB Possible Web Backdoor cfexec.cfm access (emerging-web.rules)
2009337 - ET WEB Possible Web Backdoor cmdasp.asp access (emerging-web.rules)
2009338 - ET WEB Possible Web Backdoor cmdasp.aspx access (emerging-web.rules)
2009339 - ET WEB Possible Web Backdoor simple-backdoor.php access (emerging-web.rules)
2009340 - ET WEB Possible Web Backdoor php-backdoor.php access (emerging-web.rules)
2009341 - ET WEB Possible Web Backdoor jsp-reverse.jsp access (emerging-web.rules)
2009342 - ET WEB Possible Web Backdoor perlcmd.cgi access (emerging-web.rules)
2009343 - ET WEB Possible Web Backdoor cmdjsp.jsp access (emerging-web.rules)
2009344 - ET WEB Possible Web Backdoor cmd-asp-5.1.asp access (emerging-web.rules)


[///] Modified active rules: [///]

2002035 - ET MALWARE Better Internet Spyware User Agent Activity (thin) (emerging-malware.rules)
2002750 - ET POLICY Reserved IP Space Traffic - Bogon Nets 2 (emerging-policy.rules)
2009288 - ET WEB PHP Attack Tool Revolt Scanner (emerging-web.rules)
2009296 - ET TROJAN Banker/Banbra Related HTTP Post-infection Checkin (emerging-virus.rules)
2009297 - ET TROJAN Boaxxe HTTP POST Checkin (emerging-virus.rules)
2009298 - ET SCAN Port Unreachable Response to Xprobe2 OS Fingerprint Scan (emerging-scan.rules)
2009299 - ET TROJAN General Trojan Downloader (emerging-virus.rules)

 

Contribute to ET! Try SIDReporter

SIDReporter is ready for Prime Time! Try it out and contribute anonymous statistics about the rulesets, get in depth analysis of your events vs global trends, and help make the ET Rulesets better!

Statistics now online!

http://www.emergingthreats.net/index.php/sidreporter-statistics.html

Code here!

http://doc.emergingthreats.net/bin/view/Main/SidReporter