alert ip any any -> any any (SBRuleId:41; msg:"ATTACK-RESPONSES id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:498; rev:6; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert ip $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:42; msg:"ATTACK-RESPONSES id check returned userid"; content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; within:15; byte_test:5,<,65537,0,relative,string; classtype:bad-unknown; sid:1882; rev:10; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert ip any any -> 216.80.99.202 any (SBRuleId:52; msg:"BACKDOOR fragroute trojan connection attempt"; reference:bugtraq,4898; classtype:trojan-activity; sid:1791; rev:2; SBRiskLevel:2; SBCategory:"trojan-activity";)
alert tcp $EXTERNAL 1000:1300 -> $INTERNAL 146 (SBRuleId:53; msg: "BACKDOOR trojan active Infector 1.6 client to server"; flags: A+; content: "FC "; classtype: attempted-admin; reference: arachnids,503;sid:6000100;rev:1; SBRiskLevel:2; SBCategory:"attempted-admin";)
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:149; msg:"BAD-TRAFFIC 0 ttl"; ttl:0; reference:url,support.microsoft.com/default.aspx?scid=kb\;EN-US\;q138268; reference:url,www.isi.edu/in-notes/rfc1122.txt; classtype:misc-activity; sid:1321; rev:8; SBRiskLevel:0; SBCategory:"misc-activity";)
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:150; msg:"BAD-TRAFFIC Unassigned/Reserved IP protocol"; ip_proto:>134; reference:url,www.iana.org/assignments/protocol-numbers; classtype:non-standard-protocol; sid:1627; rev:3; SBRiskLevel:1; SBCategory:"non-standard-protocol";)
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:151; msg:"BAD-TRAFFIC bad frag bits"; fragbits:MD; sid:1322; classtype:misc-activity; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:152; msg:"BAD-TRAFFIC ip reserved bit set"; fragbits:R; classtype:misc-activity; sid:523; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert ip any any -> any any (SBRuleId:153; msg:"BAD-TRAFFIC IP Proto 103 PIM"; ip_proto:103; reference:bugtraq,8211; reference:cve,2003-0567; classtype:non-standard-protocol; sid:2189; rev:3; SBRiskLevel:1; SBCategory:"non-standard-protocol";)
alert ip any any -> any any (SBRuleId:154; msg:"BAD-TRAFFIC IP Proto 53 SWIPE"; ip_proto:53; reference:bugtraq,8211; reference:cve,2003-0567; classtype:non-standard-protocol; sid:2186; rev:3; SBRiskLevel:1; SBCategory:"non-standard-protocol";)
alert ip any any -> any any (SBRuleId:155; msg:"BAD-TRAFFIC IP Proto 55 IP Mobility"; ip_proto:55; reference:bugtraq,8211; reference:cve,2003-0567; classtype:non-standard-protocol; sid:2187; rev:3; SBRiskLevel:1; SBCategory:"non-standard-protocol";)
alert ip any any -> any any (SBRuleId:156; msg:"BAD-TRAFFIC IP Proto 77 Sun ND"; ip_proto:77; reference:bugtraq,8211; reference:cve,2003-0567; classtype:non-standard-protocol; sid:2188; rev:3; SBRiskLevel:1; SBCategory:"non-standard-protocol";)
alert ip any any -> any any (SBRuleId:157; msg:"BAD-TRAFFIC same SRC/DST"; sameip; reference:bugtraq,2666; reference:cve,1999-0016; reference:url,www.cert.org/advisories/CA-1997-28.html; classtype:bad-unknown; sid:527; rev:8; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert ip any any <> 127.0.0.0/8 any (SBRuleId:158; msg:"BAD-TRAFFIC loopback traffic"; reference:url,www.sans.org/y2k/egress.htm; classtype:bad-unknown; sid:528; rev:5; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert tcp $EXTERNAL_NET any <> $HOME_NET 0 (SBRuleId:159; msg:"BAD-TRAFFIC tcp port 0 traffic"; flow:stateless; classtype:misc-activity; sid:524; rev:8; SBRiskLevel:0; SBCategory:"misc-activity";)
alert tcp any any -> [232.0.0.0/8,233.0.0.0/8,239.0.0.0/8] any (SBRuleId:160; msg:"BAD-TRAFFIC syn to multicast address"; flow:stateless; flags:S+; classtype:bad-unknown; sid:1431; rev:9; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:220; msg:"ICMP Destination Unreachable Fragmentation Needed and DF bit was set"; icode:4; itype:3; classtype:misc-activity; sid:396; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:222; msg:"ICMP Destination Unreachable Host Unreachable for Type of Service"; icode:12; itype:3; classtype:misc-activity; sid:398; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:223; msg:"ICMP Destination Unreachable Network Unreachable for Type of Service"; icode:11; itype:3; classtype:misc-activity; sid:400; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:224; msg:"ICMP Destination Unreachable Port Unreachable"; icode:3; itype:3; classtype:misc-activity; sid:402; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:225; msg:"ICMP Destination Unreachable Precedence Cutoff in effect"; icode:15; itype:3; classtype:misc-activity; sid:403; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:226; msg:"ICMP Destination Unreachable Protocol Unreachable"; icode:2; itype:3; classtype:misc-activity; sid:404; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:229; msg:"ICMP Destination Unreachable cndefined code"; icode:>15; itype:3; classtype:misc-activity; sid:407; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:230; msg:"ICMP Echo Reply undefined code"; icode:>0; itype:0; classtype:misc-activity; sid:409; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
#alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP Echo Reply"; icode:0; itype:0; classtype:misc-activity; sid:408; rev:5;)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:231; msg:"ICMP Fragment Reassembly Time Exceeded"; icode:1; itype:11; classtype:misc-activity; sid:410; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:232; msg:"ICMP IPV6 I-Am-Here undefined code"; icode:>0; itype:34; classtype:misc-activity; sid:412; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:233; msg:"ICMP IPV6 I-Am-Here"; icode:0; itype:34; classtype:misc-activity; sid:411; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:234; msg:"ICMP IPV6 Where-Are-You undefined code"; icode:>0; itype:33; classtype:misc-activity; sid:414; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:235; msg:"ICMP IPV6 Where-Are-You"; icode:0; itype:33; classtype:misc-activity; sid:413; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:256; msg:"ICMP PING Cisco Type.x"; itype:8; content:"|AB CD AB CD AB CD AB CD AB CD AB CD AB CD AB CD|"; depth:32; reference:arachnids,153; classtype:misc-activity; sid:371; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:257; msg:"ICMP PING CyberKit 2.2 Windows"; itype:8; content:"|AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA|"; depth:32; reference:arachnids,154; classtype:misc-activity; sid:483; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:258; msg:"ICMP PING Delphi-Piette Windows"; itype:8; content:"Pinging from Del"; depth:32; reference:arachnids,155; classtype:misc-activity; sid:372; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:269; msg:"ICMP PING Sun Solaris"; dsize:8; itype:8; reference:arachnids,448; classtype:misc-activity; sid:381; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:270; msg:"ICMP PING WhatsupGold Windows"; itype:8; content:"WhatsUp - A Netw"; depth:32; reference:arachnids,168; classtype:misc-activity; sid:482; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:271; msg:"ICMP PING Windows"; itype:8; content:"abcdefghijklmnop"; depth:16; reference:arachnids,169; classtype:misc-activity; sid:382; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:272; msg:"ICMP PING speedera"; itype:8; content:"89|3A 3B|<=>?"; depth:100; classtype:misc-activity; sid:480; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:273; msg:"ICMP PING undefined code"; icode:>0; itype:8; classtype:misc-activity; sid:365; rev:8; SBRiskLevel:0; SBCategory:"misc-activity";)
#alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP PING"; icode:0; itype:8; classtype:misc-activity; sid:384; rev:5;)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:274; msg:"ICMP Parameter Problem Bad Length"; icode:2; itype:12; classtype:misc-activity; sid:425; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:275; msg:"ICMP Parameter Problem Missing a Required Option"; icode:1; itype:12; classtype:misc-activity; sid:426; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:276; msg:"ICMP Parameter Problem Unspecified Error"; icode:0; itype:12; classtype:misc-activity; sid:427; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:277; msg:"ICMP Parameter Problem undefined Code"; icode:>2; itype:12; classtype:misc-activity; sid:428; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:278; msg:"ICMP Photuris Reserved"; icode:0; itype:40; classtype:misc-activity; sid:429; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:280; msg:"ICMP Photuris Valid Security Parameters, But Authentication Failed"; icode:2; itype:40; classtype:misc-activity; sid:431; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:281; msg:"ICMP Photuris Valid Security Parameters, But Decryption Failed"; icode:3; itype:40; classtype:misc-activity; sid:432; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:282; msg:"ICMP Photuris undefined code!"; icode:>3; itype:40; classtype:misc-activity; sid:433; rev:8; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:283; msg:"ICMP Redirect for TOS and Host"; icode:3; itype:5; classtype:misc-activity; sid:436; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:284; msg:"ICMP Redirect for TOS and Network"; icode:2; itype:5; classtype:misc-activity; sid:437; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:285; msg:"ICMP Redirect undefined code"; icode:>3; itype:5; classtype:misc-activity; sid:438; rev:9; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:286; msg:"ICMP Reserved for Security Type 19 undefined code"; icode:>0; itype:19; classtype:misc-activity; sid:440; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:287; msg:"ICMP Reserved for Security Type 19"; icode:0; itype:19; classtype:misc-activity; sid:439; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:288; msg:"ICMP Router Advertisement"; icode:0; itype:9; reference:arachnids,173; classtype:misc-activity; sid:441; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:289; msg:"ICMP Router Selection"; icode:0; itype:10; reference:arachnids,174; classtype:misc-activity; sid:443; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:290; msg:"ICMP SKIP undefined code"; icode:>0; itype:39; classtype:misc-activity; sid:446; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:291; msg:"ICMP SKIP"; icode:0; itype:39; classtype:misc-activity; sid:445; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:292; msg:"ICMP Source Quench undefined code"; icode:>0; itype:4; classtype:misc-activity; sid:448; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:293; msg:"ICMP Source Quench"; icode:0; itype:4; classtype:bad-unknown; sid:477; rev:2; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:294; msg:"ICMP TJPingPro1.1Build 2 Windows"; itype:8; content:"TJPingPro by Jim"; depth:32; reference:arachnids,167; classtype:misc-activity; sid:481; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:295; msg:"ICMP Timestamp Reply undefined code"; icode:>0; itype:14; classtype:misc-activity; sid:452; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:296; msg:"ICMP Timestamp Reply"; icode:0; itype:14; classtype:misc-activity; sid:451; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:297; msg:"ICMP Timestamp Request undefined code"; icode:>0; itype:13; classtype:misc-activity; sid:454; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:298; msg:"ICMP Timestamp Request"; icode:0; itype:13; classtype:misc-activity; sid:453; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:299; msg:"ICMP Traceroute undefined code"; icode:>0; itype:30; classtype:misc-activity; sid:457; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:300; msg:"ICMP Traceroute"; icode:0; itype:30; classtype:misc-activity; sid:456; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:301; msg:"ICMP digital island bandwidth query"; content:"mailto|3A|ops@digisle.com"; depth:22; classtype:misc-activity; sid:1813; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:316; msg:"ICMP Address Mask Reply"; icode:0; itype:18; classtype:misc-activity; sid:386; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:317; msg:"ICMP Information Reply undefined code"; icode:>0; itype:16; classtype:misc-activity; sid:416; rev:7; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:318; msg:"ICMP Information Reply"; icode:0; itype:16; classtype:misc-activity; sid:415; rev:5; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:319; msg:"ICMP Time-To-Live Exceeded in Transit undefined code"; icode:>1; itype:11; classtype:misc-activity; sid:450; rev:8; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (SBRuleId:320; msg:"ICMP Time-To-Live Exceeded in Transit"; icode:0; itype:11; classtype:misc-activity; sid:449; rev:6; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp any any -> any any (SBRuleId:321; msg:"ICMP Destination Unreachable Communication Administratively Prohibited"; icode:13; itype:3; classtype:misc-activity; sid:485; rev:4; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp any any -> any any (SBRuleId:322; msg:"ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited"; icode:10; itype:3; classtype:misc-activity; sid:486; rev:4; SBRiskLevel:0; SBCategory:"misc-activity";)
alert icmp any any -> any any (SBRuleId:323; msg:"ICMP Destination Unreachable Communication with Destination Network is Administratively Prohibited"; icode:9; itype:3; classtype:misc-activity; sid:487; rev:4; SBRiskLevel:0; SBCategory:"misc-activity";)
#rulegroup Miscellaneous
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:324; msg:"MISC source route lssr"; ipopts:lsrr; reference:arachnids,418; reference:bugtraq,646; reference:cve,1999-0909; reference:url,www.microsoft.com/technet/security/bulletin/MS99-038.mspx; classtype:bad-unknown; sid:500; rev:5; SBRiskLevel:1; SBCategory:"bad-unknown";)
#alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:325; msg:"MISC source route lssre"; ipopts:lsrre; reference:arachnids,420; reference:bugtraq,646; reference:cve,1999-0909; reference:url,www.microsoft.com/technet/security/bulletin/MS99-038.mspx; classtype:bad-unknown; sid:501; rev:5; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert ip $EXTERNAL_NET any -> $HOME_NET any (SBRuleId:326; msg:"MISC source route ssrr"; ipopts:ssrr ; reference:arachnids,422; classtype:bad-unknown; sid:502; rev:2; SBRiskLevel:1; SBCategory:"bad-unknown";)
alert tcp any any -> any any (SBRuleId:442; msg:"PortScan"; kportscan; classtype:network-scan; sid:5000555; rev:2; SBRiskLevel:0; SBCategory:"network-scan";)
alert udp $EXTERNAL_NET any -> $HOME_NET 10080:10081 (SBRuleId:443; msg:"SCAN Amanda client version request"; content:"Amanda"; nocase; classtype:attempted-recon; sid:634; rev:2; SBRiskLevel:1; SBCategory:"attempted-recon";)
alert udp $EXTERNAL_NET any -> $HOME_NET 10080:10081 (SBRuleId:444; msg:"SCAN Amanda client version request"; content:"Amanda"; nocase; classtype:attempted-recon; sid:634; rev:2; SBRiskLevel:1; SBCategory:"attempted-recon";)