home *** CD-ROM | disk | FTP | other *** search
- # this library is for hostile scans and protocol pokes
-
- # Fragmentation Attacks
- alert tcp any any -> any any (msg:"Tiny Fragments, possible hostile activity"; MinFrag: 128;)
-
-
- # look for stealth port scans/sweeps
- alert tcp any any -> 192.168.1.0/24 any (msg:"SYN FIN Scan"; flags: SF;)
- alert tcp any any -> 192.168.1.0/24 any (msg:"FIN Scan"; flags: F;)
- alert tcp any any -> 192.168.1.0/24 any (msg:"NULL Scan"; flags: 0;)
- alert tcp any any -> 192.168.1.0/24 any (msg:"XMAS Scan"; flags: FPU;)
- alert tcp any any -> 192.168.1.0/24 any (msg:"Full XMAS Scan"; flags: SRAFPU;)
- alert tcp any any -> 192.168.1.0/24 any (flags: A; ack: 0; msg:"NMAP TCP ping!";)
-
- # detect fingerprinting attempts
- alert tcp any any -> 192.168.1.0/24 any (msg:"Possible NMAP Fingerprint attempt"; flags: SFPU;)
- alert tcp any any -> 192.168.1.0/24 any (msg:"Possible Queso Fingerprint attempt"; flags: S12;)
-
- # Windows Traceroutes
- alert icmp any any -> 192.168.1.0/24 any (msg:"Windows Traceroute"; TTL: 1; itype: 8;)
-
- # Standard Traceroutes
- alert icmp any any -> 192.168.1.0/24 any (msg:"Traceroute"; TTL: 1;)
-
- # Watch for WinGate Scans
- alert tcp any any -> 192.168.1.0/24 1080 (msg:"WinGate 1080 Attempt";)
- alert udp any any -> 192.168.1.0/24 1080 (msg:"WinGate 1080 Attempt";)
- alert tcp any any -> 192.168.1.0/24 8080 (msg:"WinGate 8080 Attempt";)
- alert udp any any -> 192.168.1.0/24 8080 (msg:"WinGate 8080 Attempt";)
-