home *** CD-ROM | disk | FTP | other *** search
/ PC World 2004 December / PCWorld_2004-12_cd.bin / software / temacd / tiny / tf6pro-6[1].0.140.exe / Tiny Firewall Pro 6.0.msi / IDS.xml < prev    next >
Encoding:
Extensible Markup Language  |  2004-08-03  |  1.3 MB  |  8,174 lines

Text Truncated. Only the first 1MB is shown below. Download the file for the complete contents.
  1.  ■<?xml version="1.0" encoding="UTF-16" standalone="no"?>
  2. <SecDb xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="IDS.xsd">
  3.     <VersionInfo major="2"/>
  4.     <Module id="IDS"/>
  5.     <Globals>
  6.         <Property id="SomeID" type="int">1</Property>
  7.     </Globals>
  8.     <Definitions>
  9.         <Object ot="ipaddress" id="all">
  10.             <Item>*</Item>
  11.         </Object>
  12.         <Object ot="ipaddress" id="external_net">
  13.             <Item>*</Item>
  14.         </Object>
  15.         <Object ot="ipaddress" id="home_net">
  16.             <Item>0.0.0.0</Item>
  17.             <Item>10.0.0.0/255.0.0.0</Item>
  18.             <Item>172.16.0.0/255.240.0.0</Item>
  19.             <Item>192.168.0.0/255.255.0.0</Item>
  20.         </Object>
  21.         <Object ot="ipaddress" id="smtp_servers">
  22.             <Item>10.0.0.0/255.0.0.0</Item>
  23.             <Item>172.16.0.0/255.240.0.0</Item>
  24.             <Item>192.168.0.0/255.255.0.0</Item>
  25.         </Object>
  26.         <Object ot="ipaddress" id="http_servers">
  27.             <Item>10.0.0.0/255.0.0.0</Item>
  28.             <Item>172.16.0.0/255.240.0.0</Item>
  29.             <Item>192.168.0.0/255.255.0.0</Item>
  30.         </Object>
  31.         <Object ot="ipaddress" id="sql_servers">
  32.             <Item>10.0.0.0/255.0.0.0</Item>
  33.             <Item>172.16.0.0/255.240.0.0</Item>
  34.             <Item>192.168.0.0/255.255.0.0</Item>
  35.         </Object>
  36.         <Object ot="ipaddress" id="telnet_servers">
  37.             <Item>10.0.0.0/255.0.0.0</Item>
  38.             <Item>172.16.0.0/255.240.0.0</Item>
  39.             <Item>192.168.0.0/255.255.0.0</Item>
  40.         </Object>
  41.         <Object ot="ipaddress" id="aim_servers">
  42.             <Item>64.12.24.0-64.12.24.255</Item>
  43.             <Item>64.12.25.0-64.12.25.255</Item>
  44.             <Item>64.12.26.0-64.12.26.255</Item>
  45.             <Item>64.12.28.0-64.12.28.255</Item>
  46.             <Item>64.12.29.0-64.12.29.255</Item>
  47.             <Item>64.12.161.0-64.12.161.255</Item>
  48.             <Item>64.12.163.0-64.12.163.255</Item>
  49.             <Item>205.188.5.0-205.188.5.255</Item>
  50.             <Item>205.188.9.0-205.188.9.255</Item>
  51.         </Object>
  52.         <Object ot="ipaddress" id="loopback">
  53.             <Item>127.0.0.0-127.255.255.255</Item>
  54.         </Object>
  55.         <Object ot="ipaddress" id="broadcast">
  56.             <Item>255.255.255.255</Item>
  57.         </Object>
  58.         <Object ot="ipaddress" id="multicast">
  59.             <Item>232.0.0.0-232.255.255.255</Item>
  60.             <Item>233.0.0.0-233.255.255.255</Item>
  61.             <Item>239.0.0.0-239.255.255.255</Item>
  62.         </Object>
  63.         <Object ot="ipaddress" id="address of DDOS Stacheldraht server spoof address">
  64.             <Item>3.3.3.3</Item>
  65.         </Object>
  66.         <Object ot="ipaddress" id="address of BACKDOOR Q access">
  67.             <Item>255.255.255.0-255.255.255.255</Item>
  68.         </Object>
  69.         <Object ot="ipaddress" id="address of MULTIMEDIA audio galaxy keepalive">
  70.             <Item>64.245.58.0-64.245.59.255</Item>
  71.         </Object>
  72.         <Object ot="ipaddress" id="address of POLICY poll.gotomypc.com access">
  73.             <Item>63.251.224.177</Item>
  74.         </Object>
  75.         <Object ot="ipaddress" id="address of BACKDOOR fragroute trojan connection attempt">
  76.             <Item>216.80.99.202</Item>
  77.         </Object>
  78.         <Object ot="ipaddress" id="address of BACKDOOR TCPDUMP/PCAP trojan traffic">
  79.             <Item>212.146.0.34</Item>
  80.         </Object>
  81.     </Definitions>
  82.     <RuleList name="backdoor.rules">
  83.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="27374" name="BACKDOOR subseven 22" sid="412" enabled="0">
  84.             <Token id="content" type="str">\r\n[RPL]002\r\n</Token>
  85.         </Rule>
  86.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2589" remport="1024-65535" name="BACKDOOR - Dagger_1.4.0_client_connect" sid="416" enabled="0">
  87.             <Token id="content" type="str" depth="16">\v\0\0\0\a\0\0\0Connect</Token>
  88.         </Rule>
  89.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2589" remport="1024-65535" name="BACKDOOR - Dagger_1.4.0" sid="420" enabled="0">
  90.             <Token id="content" type="str" depth="16">2\0\0\0\x06\0\0\0Drives$\0</Token>
  91.         </Rule>
  92.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1054" remport="80" name="BACKDOOR ACKcmdC trojan scan" sid="424" enabled="0">
  93.             <Token id="tcp_ack" type="int">101058054</Token>
  94.             <Token id="tcp_flg" type="str" mask="12">A</Token>
  95.             <Token id="tcp_seq" type="int">101058054</Token>
  96.         </Rule>
  97.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="16959" remport="*" name="BACKDOOR subseven DEFCON8 2.1 access" sid="428" enabled="0">
  98.             <Token id="content" type="str">PWD</Token>
  99.         </Rule>
  100.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7597" remport="*" name="BACKDOOR QAZ Worm Client Login access" sid="432" enabled="0">
  101.             <Token id="content" type="str">qazwsx.hsq</Token>
  102.         </Rule>
  103.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="12345-12346" remport="*" name="BACKDOOR netbus active" sid="436" enabled="0">
  104.             <Token id="content" type="str">NetBus</Token>
  105.         </Rule>
  106.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="12345-12346" remport="*" name="BACKDOOR netbus getinfo" sid="440" enabled="0">
  107.             <Token id="content" type="str">GetInfo\r</Token>
  108.         </Rule>
  109.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="20034" remport="*" name="BACKDOOR netbus active" sid="460" enabled="0">
  110.             <Token id="content" type="str">NetBus</Token>
  111.         </Rule>
  112.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="146" remport="1024-65535" name="BACKDOOR Infector.1.x" sid="468" enabled="0">
  113.             <Token id="content" type="str">WHATISIT</Token>
  114.         </Rule>
  115.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="666" remport="1024-65535" name="BACKDOOR SatansBackdoor.2.0.Beta" sid="472" enabled="0">
  116.             <Token id="content" type="str">Remote: You are connected to me.</Token>
  117.         </Rule>
  118.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6789" remport="*" name="BACKDOOR Doly 2.0 access" sid="476" enabled="0">
  119.             <Token id="content" type="str" depth="32">Wtzup Use</Token>
  120.         </Rule>
  121.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="146" remport="1000-1300" name="BACKDOOR Infector 1.6 Server to Client" sid="480" enabled="0">
  122.             <Token id="content" type="str">WHATISIT</Token>
  123.         </Rule>
  124.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="146" remport="1000-1300" name="BACKDOOR Infector 1.6 Client to Server Connection Request" sid="484" enabled="0">
  125.             <Token id="content" type="str">FC </Token>
  126.         </Rule>
  127.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="31785" remport="*" name="BACKDOOR HackAttack 1.20 Connect" sid="564" enabled="0">
  128.             <Token id="content" type="str">host</Token>
  129.         </Rule>
  130.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21554" remport="!80" name="BACKDOOR GirlFriendaccess" sid="580" enabled="0">
  131.             <Token id="content" type="str">Girl</Token>
  132.         </Rule>
  133.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="30100" remport="*" name="BACKDOOR NetSphere access" sid="584" enabled="0">
  134.             <Token id="content" type="str">NetSphere</Token>
  135.         </Rule>
  136.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6969" remport="*" name="BACKDOOR GateCrasher" sid="588" enabled="0">
  137.             <Token id="content" type="str">GateCrasher</Token>
  138.         </Rule>
  139.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5401-5402" remport="*" name="BACKDOOR BackConstruction 2.1 Connection" sid="608" enabled="0">
  140.             <Token id="content" type="str">c:\\</Token>
  141.         </Rule>
  142.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="23476" remport="*" name="BACKDOOR DonaldDick 1.53 Traffic" sid="612" enabled="0">
  143.             <Token id="content" type="str">pINg</Token>
  144.         </Rule>
  145.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="30100-30102" remport="*" name="BACKDOOR NetSphere 1.31.337 access" sid="620" enabled="0">
  146.             <Token id="content" type="str">NetSphere</Token>
  147.         </Rule>
  148.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="666" remport="*" name="BACKDOOR BackConstruction 2.1 Client FTP Open Request" sid="628" enabled="0">
  149.             <Token id="content" type="str">FTPON</Token>
  150.         </Rule>
  151.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="666" remport="*" name="BACKDOOR BackConstruction 2.1 Server FTP Open Reply" sid="632" enabled="0">
  152.             <Token id="content" type="str">FTP Port open</Token>
  153.         </Rule>
  154.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5032" remport="*" name="BACKDOOR NetMetro File List" sid="636" enabled="0">
  155.             <Token id="content" type="str">--</Token>
  156.         </Rule>
  157.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="3345" remport="3344" name="BACKDOOR Matrix 2.0 Client connect" sid="644" enabled="0">
  158.             <Token id="content" type="str">activate</Token>
  159.         </Rule>
  160.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="3344" remport="3345" name="BACKDOOR Matrix 2.0 Server access" sid="648" enabled="0">
  161.             <Token id="content" type="str">logged in</Token>
  162.         </Rule>
  163.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5714" remport="*" name="BACKDOOR WinCrash 1.0 Server Active" sid="652" enabled="0">
  164.             <Token id="tcp_flg" type="str" mask="12">SA</Token>
  165.             <Token id="content" type="str">\xB4\xB4</Token>
  166.         </Rule>
  167.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="address of BACKDOOR Q access" name="BACKDOOR SIGNATURE - Q ICMP" sid="732" enabled="0">
  168.             <Token id="dsize" type="int" rel="greater">1</Token>
  169.             <Token id="icmp_type" type="int">0</Token>
  170.         </Rule>
  171.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="address of BACKDOOR Q access" locport="*" remport="*" name="BACKDOOR Q access" sid="736" enabled="0">
  172.             <Token id="dsize" type="int" rel="greater">1</Token>
  173.             <Token id="tcp_flg" type="str">A+</Token>
  174.         </Rule>
  175.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="BACKDOOR CDK" sid="740" enabled="0">
  176.             <Token id="content" type="str" depth="15" nocase="1">ypi0ca</Token>
  177.         </Rule>
  178.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="2140" remport="*" name="BACKDOOR DeepThroat 3.1 Server Response" sid="780" enabled="0">
  179.             <Token id="content" type="str">Ahhhh My Mouth Is Open</Token>
  180.         </Rule>
  181.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="555" remport="*" name="BACKDOOR PhaseZero Server Active on Network" sid="832" enabled="0">
  182.             <Token id="content" type="str">phAse</Token>
  183.         </Rule>
  184.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR w00w00 attempt" sid="836" enabled="0">
  185.             <Token id="content" type="str">w00w00</Token>
  186.         </Rule>
  187.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR attempt" sid="840" enabled="0">
  188.             <Token id="content" type="str" nocase="1">backdoor</Token>
  189.         </Rule>
  190.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC r00t attempt" sid="844" enabled="0">
  191.             <Token id="content" type="str">r00t</Token>
  192.         </Rule>
  193.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC rewt attempt" sid="848" enabled="0">
  194.             <Token id="content" type="str">rewt</Token>
  195.         </Rule>
  196.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC Linux rootkit attempt" sid="852" enabled="0">
  197.             <Token id="content" type="str">wh00t!</Token>
  198.         </Rule>
  199.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC Linux rootkit attempt lrkr0x" sid="856" enabled="0">
  200.             <Token id="content" type="str">lrkr0x</Token>
  201.         </Rule>
  202.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC Linux rootkit attempt" sid="860" enabled="0">
  203.             <Token id="content" type="str" nocase="1">d13hh[</Token>
  204.         </Rule>
  205.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC Linux rootkit satori attempt" sid="864" enabled="0">
  206.             <Token id="content" type="str">satori</Token>
  207.         </Rule>
  208.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC sm4ck attempt" sid="868" enabled="0">
  209.             <Token id="content" type="str">hax0r</Token>
  210.         </Rule>
  211.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR MISC Solaris 2.5 attempt" sid="872" enabled="0">
  212.             <Token id="content" type="str">friday</Token>
  213.         </Rule>
  214.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR HidePak backdoor attempt" sid="876" enabled="0">
  215.             <Token id="content" type="str">StoogR</Token>
  216.         </Rule>
  217.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="BACKDOOR HideSource backdoor attempt" sid="880" enabled="0">
  218.             <Token id="content" type="str">wank</Token>
  219.         </Rule>
  220.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="31789" remport="31790" name="BACKDOOR hack-a-tack attempt" sid="2456" enabled="0">
  221.             <Token id="tcp_flg" type="str">A+</Token>
  222.             <Token id="content" type="str" depth="1">A</Token>
  223.         </Rule>
  224.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="address of BACKDOOR fragroute trojan connection attempt" name="BACKDOOR fragroute trojan connection attempt" sid="7164" enabled="0"/>
  225.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="address of BACKDOOR fragroute trojan connection attempt" remaddr_id="all" name="BACKDOOR fragroute trojan connection attempt" sid="7165" enabled="0"/>
  226.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="33270" remport="*" name="BACKDOOR trinity connection attempt" sid="7372" enabled="0">
  227.             <Token id="content" type="str" depth="3">!@#</Token>
  228.         </Rule>
  229.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="35555" remport="*" name="BACKDOOR win-trin00 connection attempt" sid="7412" enabled="0">
  230.             <Token id="content" type="str" depth="14">png []..Ks l44</Token>
  231.         </Rule>
  232.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="address of BACKDOOR TCPDUMP/PCAP trojan traffic" locport="*" remport="1963" name="BACKDOOR TCPDUMP/PCAP trojan traffic" sid="7716" enabled="0"/>
  233.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="address of BACKDOOR TCPDUMP/PCAP trojan traffic" remaddr_id="all" locport="1963" remport="*" name="BACKDOOR TCPDUMP/PCAP trojan traffic" sid="7717" enabled="0"/>
  234.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="2140" remport="*" name="BACKDOOR DeepThroat 3.1 Connection attempt" sid="7920" enabled="0">
  235.             <Token id="content" type="str" depth="2">00</Token>
  236.         </Rule>
  237.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="3150" remport="*" name="BACKDOOR DeepThroat 3.1 Connection attempt [3150]" sid="7924" enabled="0">
  238.             <Token id="content" type="str" depth="2">00</Token>
  239.         </Rule>
  240.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="3150" remport="*" name="BACKDOOR DeepThroat 3.1 Server Response [3150]" sid="7928" enabled="0">
  241.             <Token id="content" type="str">Ahhhh My Mouth Is Open</Token>
  242.         </Rule>
  243.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="4120" remport="*" name="BACKDOOR DeepThroat 3.1 Connection attempt [4120]" sid="7932" enabled="0">
  244.             <Token id="content" type="str" depth="2">00</Token>
  245.         </Rule>
  246.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="4120" remport="*" name="BACKDOOR DeepThroat 3.1 Server Response [4120]" sid="7936" enabled="0">
  247.             <Token id="content" type="str">Ahhhh My Mouth Is Open</Token>
  248.         </Rule>
  249.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1094" name="BACKDOOR Doly 1.5 server response" sid="7940" enabled="0">
  250.             <Token id="content" type="str">Connected.</Token>
  251.         </Rule>
  252.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="BACKDOOR SubSeven 2.1 Gold server connection response" sid="8400" enabled="0">
  253.             <Token id="content" type="str" depth="22">connected. time/date: </Token>
  254.             <Token id="content" type="str" distance="1">version: GOLD 2.1</Token>
  255.         </Rule>
  256.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="34012" remport="*" name="BACKDOOR Remote PC Access connection attempt" sid="8496" enabled="0">
  257.             <Token id="content" type="str" depth="12">(\0\x01\0\x04\0\0\0\0\0\0\0</Token>
  258.         </Rule>
  259.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="BACKDOOR typot trojan traffic" sid="8728" enabled="0">
  260.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  261.             <Token id="tcp_window" type="int">55808</Token>
  262.         </Rule>
  263.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="BACKDOOR FsSniffer connection attempt" sid="9084" enabled="0">
  264.             <Token id="content" type="str">RemoteNC Control Password:</Token>
  265.         </Rule>
  266.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3127-3199" remport="*" name="BACKDOOR DoomJuice file upload attempt" sid="9500" enabled="0">
  267.             <Token id="content" type="str" depth="5">\x85\x13&lt;\x9E\xA2</Token>
  268.         </Rule>
  269.     </RuleList>
  270.     <RuleList name="ftp.rules">
  271.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP ADMw0rm ftp login attempt" sid="576">
  272.             <Token id="content" type="str" nocase="1">USER</Token>
  273.             <Token id="content" type="str" distance="1" nocase="1">w0rm</Token>
  274.             <Token id="pcre" type="str">=/^USER\s+w0rm/smi</Token>
  275.         </Rule>
  276.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP .forward" sid="1336">
  277.             <Token id="content" type="str">.forward</Token>
  278.         </Rule>
  279.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP .rhosts" sid="1340">
  280.             <Token id="content" type="str">.rhosts</Token>
  281.         </Rule>
  282.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CWD ~root attempt" sid="1344">
  283.             <Token id="content" type="str" nocase="1">CWD</Token>
  284.             <Token id="content" type="str" distance="1" nocase="1">~root</Token>
  285.             <Token id="pcre" type="str">=/^CWD\s+~root/smi</Token>
  286.         </Rule>
  287.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CEL overflow attempt" sid="1348">
  288.             <Token id="content" type="str" nocase="1">CEL</Token>
  289.             <Token id="isdataat" type="int" rel="relative">100</Token>
  290.             <Token id="pcre" type="str">=/^CEL\s[^\n]{100}/smi</Token>
  291.         </Rule>
  292.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP adm scan" sid="1412">
  293.             <Token id="content" type="str">PASS ddd@\n</Token>
  294.         </Rule>
  295.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP iss scan" sid="1416">
  296.             <Token id="content" type="str">pass -iss@iss</Token>
  297.         </Rule>
  298.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP pass wh00t" sid="1420">
  299.             <Token id="content" type="str" nocase="1">pass wh00t</Token>
  300.         </Rule>
  301.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP passwd retrieval attempt" sid="1424">
  302.             <Token id="content" type="str" nocase="1">RETR</Token>
  303.             <Token id="content" type="str">passwd</Token>
  304.         </Rule>
  305.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP piss scan" sid="1428">
  306.             <Token id="content" type="str">pass -cklaus</Token>
  307.         </Rule>
  308.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP saint scan" sid="1432">
  309.             <Token id="content" type="str">pass -saint</Token>
  310.         </Rule>
  311.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP satan scan" sid="1436">
  312.             <Token id="content" type="str">pass -satan</Token>
  313.         </Rule>
  314.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP serv-u directory transversal" sid="1440">
  315.             <Token id="content" type="str" nocase="1">.%20.</Token>
  316.         </Rule>
  317.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE EXEC attempt" sid="1444">
  318.             <Token id="content" type="str" nocase="1">SITE</Token>
  319.             <Token id="content" type="str" distance="0" nocase="1">EXEC</Token>
  320.             <Token id="pcre" type="str">=/^SITE\s+EXEC/smi</Token>
  321.         </Rule>
  322.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP tar parameters" sid="1448">
  323.             <Token id="content" type="str" nocase="1"> --use-compress-program </Token>
  324.         </Rule>
  325.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CWD ..." sid="4916">
  326.             <Token id="content" type="str" nocase="1">CWD</Token>
  327.             <Token id="content" type="str" distance="0">...</Token>
  328.             <Token id="pcre" type="str">=/^CWD\s[^\n]*?\.\.\./smi</Token>
  329.         </Rule>
  330.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP wu-ftp bad file completion attempt [" sid="5508">
  331.             <Token id="content" type="str">~</Token>
  332.             <Token id="content" type="str" distance="1">[</Token>
  333.         </Rule>
  334.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP wu-ftp bad file completion attempt {" sid="5512">
  335.             <Token id="content" type="str">~</Token>
  336.             <Token id="content" type="str" distance="1">{</Token>
  337.         </Rule>
  338.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP STAT overflow attempt" sid="5516">
  339.             <Token id="content" type="str" nocase="1">STAT</Token>
  340.             <Token id="isdataat" type="int" rel="relative">100</Token>
  341.             <Token id="pcre" type="str">=/^STAT\s[^\n]{100}/smi</Token>
  342.         </Rule>
  343.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE overflow attempt" sid="6116">
  344.             <Token id="content" type="str" nocase="1">SITE</Token>
  345.             <Token id="isdataat" type="int" rel="relative">100</Token>
  346.             <Token id="pcre" type="str">=/^SITE\s[^\n]{100}/smi</Token>
  347.         </Rule>
  348.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP format string attempt" sid="6120">
  349.             <Token id="content" type="str" nocase="1">%p</Token>
  350.         </Rule>
  351.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE CHOWN overflow attempt" sid="6248">
  352.             <Token id="content" type="str" nocase="1">SITE</Token>
  353.             <Token id="content" type="str" distance="0" nocase="1">CHOWN</Token>
  354.             <Token id="isdataat" type="int" rel="relative">100</Token>
  355.             <Token id="pcre" type="str">=/^SITE\s+CHOWN\s[^\n]{100}/smi</Token>
  356.         </Rule>
  357.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CMD overflow attempt" sid="6484">
  358.             <Token id="content" type="str" nocase="1">CMD</Token>
  359.             <Token id="isdataat" type="int" rel="relative">100</Token>
  360.             <Token id="pcre" type="str">=/^CMD\s[^\n]{100}/smi</Token>
  361.         </Rule>
  362.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RNFR ././ attempt" sid="6488">
  363.             <Token id="content" type="str" nocase="1">RNFR </Token>
  364.             <Token id="content" type="str" nocase="1"> ././</Token>
  365.         </Rule>
  366.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP invalid MODE" sid="6492">
  367.             <Token id="content" type="str" nocase="1">MODE</Token>
  368.             <Token id="pcre" type="str">=/^MODE\s+[^ABSC]{1}/msi</Token>
  369.         </Rule>
  370.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP large PWD command" sid="6496">
  371.             <Token id="dsize" type="int">10</Token>
  372.             <Token id="content" type="str" nocase="1">PWD</Token>
  373.         </Rule>
  374.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP large SYST command" sid="6500">
  375.             <Token id="dsize" type="int">10</Token>
  376.             <Token id="content" type="str" nocase="1">SYST</Token>
  377.         </Rule>
  378.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CWD ~ attempt" sid="6688">
  379.             <Token id="content" type="str">CWD</Token>
  380.             <Token id="pcre" type="str">=/^CWD\s+~/smi</Token>
  381.         </Rule>
  382.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP USER overflow attempt" sid="6936">
  383.             <Token id="content" type="str" nocase="1">USER</Token>
  384.             <Token id="isdataat" type="int" rel="relative">100</Token>
  385.             <Token id="pcre" type="str">=/^USER\s[^\n]{100}/smi</Token>
  386.         </Rule>
  387.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP command overflow attempt" sid="6992">
  388.             <Token id="dsize" type="int" rel="greater">100</Token>
  389.         </Rule>
  390.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP EXPLOIT STAT * dos attempt" sid="7108">
  391.             <Token id="content" type="str" nocase="1">STAT</Token>
  392.             <Token id="content" type="str" distance="1">*</Token>
  393.         </Rule>
  394.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP EXPLOIT STAT ? dos attempt" sid="7112">
  395.             <Token id="content" type="str" nocase="1">STAT</Token>
  396.             <Token id="content" type="str" distance="1">?</Token>
  397.         </Rule>
  398.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE NEWER attempt" sid="7456">
  399.             <Token id="content" type="str" nocase="1">SITE</Token>
  400.             <Token id="content" type="str" distance="1" nocase="1">NEWER</Token>
  401.             <Token id="pcre" type="str">=/^SITE\s+NEWER/smi</Token>
  402.         </Rule>
  403.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE CPWD overflow attempt" sid="7552">
  404.             <Token id="content" type="str" nocase="1">SITE</Token>
  405.             <Token id="content" type="str" distance="0" nocase="1">CPWD</Token>
  406.             <Token id="isdataat" type="int" rel="relative">100</Token>
  407.             <Token id="pcre" type="str">=/^SITE\s+CPWD\s[^\n]{100}/smi</Token>
  408.         </Rule>
  409.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CWD overflow attempt" sid="7676">
  410.             <Token id="content" type="str" nocase="1">CWD</Token>
  411.             <Token id="isdataat" type="int" rel="relative">100</Token>
  412.             <Token id="pcre" type="str">=/^CWD\s[^\n]{100}/smi</Token>
  413.         </Rule>
  414.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE NEWER overflow attempt" sid="7680">
  415.             <Token id="content" type="str" nocase="1">SITE</Token>
  416.             <Token id="content" type="str" distance="0" nocase="1">NEWER</Token>
  417.             <Token id="isdataat" type="int" rel="relative">100</Token>
  418.             <Token id="pcre" type="str">=/^SITE\s+NEWER\s[^\n]{100}/smi</Token>
  419.         </Rule>
  420.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE ZIPCHK overflow attempt" sid="7684">
  421.             <Token id="content" type="str" nocase="1">SITE</Token>
  422.             <Token id="content" type="str" distance="1" nocase="1">ZIPCHK</Token>
  423.             <Token id="isdataat" type="int" rel="relative">100</Token>
  424.             <Token id="pcre" type="str">=/^SITE\s+ZIPCHK\s[^\n]{100}/smi</Token>
  425.         </Rule>
  426.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP authorized_keys" sid="7708">
  427.             <Token id="content" type="str">authorized_keys</Token>
  428.         </Rule>
  429.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP shadow retrieval attempt" sid="7712">
  430.             <Token id="content" type="str" nocase="1">RETR</Token>
  431.             <Token id="content" type="str">shadow</Token>
  432.         </Rule>
  433.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RMDIR overflow attempt" sid="7768">
  434.             <Token id="content" type="str" nocase="1">RMDIR</Token>
  435.             <Token id="isdataat" type="int" rel="relative">100</Token>
  436.             <Token id="pcre" type="str">=/^RMDIR\s[^\n]{100}/smi</Token>
  437.         </Rule>
  438.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE EXEC format string attempt" sid="7884">
  439.             <Token id="content" type="str" nocase="1">SITE</Token>
  440.             <Token id="content" type="str" distance="0" nocase="1">EXEC</Token>
  441.             <Token id="pcre" type="str">=/^SITE\s+EXEC\s[^\n]*?%[^\n]*?%/smi</Token>
  442.         </Rule>
  443.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP PASS overflow attempt" sid="7888">
  444.             <Token id="content" type="str" nocase="1">PASS</Token>
  445.             <Token id="isdataat" type="int" rel="relative">100</Token>
  446.             <Token id="pcre" type="str">=/^PASS\s[^\n]{100}/smi</Token>
  447.         </Rule>
  448.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP MKD overflow attempt" sid="7892">
  449.             <Token id="content" type="str" nocase="1">MKD</Token>
  450.             <Token id="isdataat" type="int" rel="relative">100</Token>
  451.             <Token id="pcre" type="str">=/^MKD\s[^\n]{100}/smi</Token>
  452.         </Rule>
  453.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP REST overflow attempt" sid="7896">
  454.             <Token id="content" type="str" nocase="1">REST</Token>
  455.             <Token id="isdataat" type="int" rel="relative">100</Token>
  456.             <Token id="pcre" type="str">=/^REST\s[^\n]{100}/smi</Token>
  457.         </Rule>
  458.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP DELE overflow attempt" sid="7900">
  459.             <Token id="content" type="str" nocase="1">DELE</Token>
  460.             <Token id="isdataat" type="int" rel="relative">100</Token>
  461.             <Token id="pcre" type="str">=/^DELE\s[^\n]{100}/smi</Token>
  462.         </Rule>
  463.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RMD overflow attempt" sid="7904">
  464.             <Token id="content" type="str" nocase="1">RMD</Token>
  465.             <Token id="isdataat" type="int" rel="relative">100</Token>
  466.             <Token id="pcre" type="str">=/^RMD\s[^\n]{100}/smi</Token>
  467.         </Rule>
  468.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP LIST directory traversal attempt" sid="7968">
  469.             <Token id="content" type="str">LIST</Token>
  470.             <Token id="content" type="str" distance="1">..</Token>
  471.             <Token id="content" type="str" distance="1">..</Token>
  472.         </Rule>
  473.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP CWD Root directory transversal attempt" sid="8500">
  474.             <Token id="content" type="str" nocase="1">CWD</Token>
  475.             <Token id="content" type="str" distance="1">C:\\</Token>
  476.         </Rule>
  477.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP USER format string attempt" sid="8712">
  478.             <Token id="content" type="str" nocase="1">USER</Token>
  479.             <Token id="pcre" type="str">=/^USER\s[^\n]*?%[^\n]*?%/smi</Token>
  480.         </Rule>
  481.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP PASS format string attempt" sid="8716">
  482.             <Token id="content" type="str" nocase="1">PASS</Token>
  483.             <Token id="pcre" type="str">=/^PASS\s[^\n]*?%[^\n]*?%/smi</Token>
  484.         </Rule>
  485.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP LIST integer overflow attempt" sid="9088">
  486.             <Token id="content" type="str" nocase="1">LIST</Token>
  487.             <Token id="pcre" type="str">=/^LIST\s+\x22-W\s+\d+/smi</Token>
  488.         </Rule>
  489.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP MKDIR format string attempt" sid="9328">
  490.             <Token id="content" type="str" nocase="1">MKDIR</Token>
  491.             <Token id="pcre" type="str">=/^MKDIR\s[^\n]*?%[^\n]*?%/smi</Token>
  492.         </Rule>
  493.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RENAME format string attempt" sid="9332">
  494.             <Token id="content" type="str" nocase="1">RENAME</Token>
  495.             <Token id="pcre" type="str">=/^RENAME\s[^\n]*?%[^\n]*?%/smi</Token>
  496.         </Rule>
  497.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3535" remport="*" name="FTP Yak! FTP server default account login attempt" sid="9336">
  498.             <Token id="content" type="str" nocase="1">USER</Token>
  499.             <Token id="content" type="str" nocase="1">y049575046</Token>
  500.             <Token id="pcre" type="str">=/^USER\s+y049575046/smi</Token>
  501.         </Rule>
  502.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3535" remport="*" name="FTP RMD / attempt" sid="9340">
  503.             <Token id="content" type="str" nocase="1">RMD</Token>
  504.             <Token id="pcre" type="str">=/^RMD\s+\x2f$/smi</Token>
  505.         </Rule>
  506.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP LIST buffer overflow attempt" sid="9352">
  507.             <Token id="content" type="str" nocase="1">LIST</Token>
  508.             <Token id="pcre" type="str">=/^LIST\s[^\n]{100,}/smi</Token>
  509.         </Rule>
  510.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP SITE CHMOD overflow attempt" sid="9360">
  511.             <Token id="content" type="str" nocase="1">SITE</Token>
  512.             <Token id="content" type="str" distance="0" nocase="1">CHMOD</Token>
  513.             <Token id="isdataat" type="int" rel="relative">100</Token>
  514.             <Token id="pcre" type="str">=/^SITE\s+CHMOD\s[^\n]{100}/smi</Token>
  515.         </Rule>
  516.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP STOR overflow attempt" sid="9372">
  517.             <Token id="content" type="str" nocase="1">STOR</Token>
  518.             <Token id="isdataat" type="int" rel="relative">100</Token>
  519.             <Token id="pcre" type="str">=/^STOR\s[^\n]{100}/smi</Token>
  520.         </Rule>
  521.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP XCWD overflow attempt" sid="9376">
  522.             <Token id="content" type="str" nocase="1">XCWD</Token>
  523.             <Token id="isdataat" type="int" rel="relative">100</Token>
  524.             <Token id="pcre" type="str">=/^XCWD\s[^\n]{100}/smi</Token>
  525.         </Rule>
  526.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP XMKD overflow attempt" sid="9492">
  527.             <Token id="content" type="str" nocase="1">XMKD</Token>
  528.             <Token id="isdataat" type="int" rel="relative">100</Token>
  529.             <Token id="pcre" type="str">=/^XMKD\s[^\n]{100}/smi</Token>
  530.         </Rule>
  531.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP NLST overflow attempt" sid="9496">
  532.             <Token id="content" type="str" nocase="1">NLST</Token>
  533.             <Token id="isdataat" type="int" rel="relative">100</Token>
  534.             <Token id="pcre" type="str">=/^NLST\s[^\n]{100}/smi</Token>
  535.         </Rule>
  536.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RNTO overflow attempt" sid="9556">
  537.             <Token id="content" type="str" nocase="1">RNTO</Token>
  538.             <Token id="isdataat" type="int" rel="relative">100</Token>
  539.             <Token id="pcre" type="str">=/^RNTO\s[^\n]{100}/smi</Token>
  540.         </Rule>
  541.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP STOU overflow attempt" sid="9560">
  542.             <Token id="content" type="str" nocase="1">STOU</Token>
  543.             <Token id="isdataat" type="int" rel="relative">100</Token>
  544.             <Token id="pcre" type="str">=/^STOU\s[^\n]{100}/smi</Token>
  545.         </Rule>
  546.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP APPE overflow attempt" sid="9564">
  547.             <Token id="content" type="str" nocase="1">APPE</Token>
  548.             <Token id="isdataat" type="int" rel="relative">100</Token>
  549.             <Token id="pcre" type="str">=/^APPE\s[^\n]{100}/smi</Token>
  550.         </Rule>
  551.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP RETR overflow attempt" sid="9568">
  552.             <Token id="content" type="str" nocase="1">RETR</Token>
  553.             <Token id="isdataat" type="int" rel="relative">100</Token>
  554.             <Token id="pcre" type="str">=/^RETR\s[^\n]{100}/smi</Token>
  555.         </Rule>
  556.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP invalid MDTM command attempt" sid="9664">
  557.             <Token id="content" type="str" nocase="1">MDTM</Token>
  558.             <Token id="pcre" type="str">=/^MDTM \d+[-+]\D/smi</Token>
  559.         </Rule>
  560.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP format string attempt" sid="9668">
  561.             <Token id="content" type="str">%</Token>
  562.             <Token id="pcre" type="str">=/\s+.*?%.*?%/smi</Token>
  563.         </Rule>
  564.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP ALLO overflow attempt" sid="9796">
  565.             <Token id="content" type="str" nocase="1">ALLO</Token>
  566.             <Token id="isdataat" type="int" rel="relative">100</Token>
  567.             <Token id="pcre" type="str">=/^ALLO\s[^\n]{100}/smi</Token>
  568.         </Rule>
  569.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="FTP MDTM overflow attempt" sid="10184">
  570.             <Token id="content" type="str" nocase="1">MDTM</Token>
  571.             <Token id="isdataat" type="int" rel="relative">100</Token>
  572.             <Token id="pcre" type="str">=/^MDTM\s[^\n]{100}/smi</Token>
  573.         </Rule>
  574.     </RuleList>
  575.     <RuleList name="ddos.rules">
  576.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS TFN Probe" sid="884">
  577.             <Token id="ip_id" type="int">678</Token>
  578.             <Token id="icmp_type" type="int">8</Token>
  579.             <Token id="content" type="str">1234</Token>
  580.         </Rule>
  581.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS tfn2k icmp possible communication" sid="888">
  582.             <Token id="echo_id" type="int">0</Token>
  583.             <Token id="icmp_type" type="int">0</Token>
  584.             <Token id="content" type="str">AAAAAAAAAA</Token>
  585.         </Rule>
  586.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="31335" remport="*" name="DDOS Trin00 Daemon to Master PONG message detected" sid="892">
  587.             <Token id="content" type="str">PONG</Token>
  588.         </Rule>
  589.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="address of DDOS Stacheldraht server spoof address" remaddr_id="external_net" name="DDOS Stacheldraht server spoof" sid="896">
  590.             <Token id="echo_id" type="int">666</Token>
  591.             <Token id="icmp_type" type="int">0</Token>
  592.         </Rule>
  593.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht gag server response" sid="900">
  594.             <Token id="echo_id" type="int">669</Token>
  595.             <Token id="icmp_type" type="int">0</Token>
  596.             <Token id="content" type="str">sicken</Token>
  597.         </Rule>
  598.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht server response" sid="904">
  599.             <Token id="echo_id" type="int">667</Token>
  600.             <Token id="icmp_type" type="int">0</Token>
  601.             <Token id="content" type="str">ficken</Token>
  602.         </Rule>
  603.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht client spoofworks" sid="908">
  604.             <Token id="echo_id" type="int">1000</Token>
  605.             <Token id="icmp_type" type="int">0</Token>
  606.             <Token id="content" type="str">spoofworks</Token>
  607.         </Rule>
  608.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS TFN client command BE" sid="912">
  609.             <Token id="echo_id" type="int">456</Token>
  610.             <Token id="echo_seq" type="int">0</Token>
  611.             <Token id="icmp_type" type="int">0</Token>
  612.         </Rule>
  613.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht client check skillz" sid="916">
  614.             <Token id="echo_id" type="int">666</Token>
  615.             <Token id="icmp_type" type="int">0</Token>
  616.             <Token id="content" type="str">skillz</Token>
  617.         </Rule>
  618.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="20432" remport="*" name="DDOS shaft client to handler" sid="920"/>
  619.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="31335" remport="*" name="DDOS Trin00 Daemon to Master message detected" sid="924">
  620.             <Token id="content" type="str">l44</Token>
  621.         </Rule>
  622.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="31335" remport="*" name="DDOS Trin00 Daemon to Master *HELLO* message detected" sid="928">
  623.             <Token id="content" type="str">*HELLO*</Token>
  624.         </Rule>
  625.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="27665" remport="*" name="DDOS Trin00 Attacker to Master default startup password" sid="932">
  626.             <Token id="content" type="str">betaalmostdone</Token>
  627.         </Rule>
  628.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="27665" remport="*" name="DDOS Trin00 Attacker to Master default password" sid="936">
  629.             <Token id="content" type="str">gOrave</Token>
  630.         </Rule>
  631.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="27665" remport="*" name="DDOS Trin00 Attacker to Master default mdie password" sid="940">
  632.             <Token id="content" type="str">killme</Token>
  633.         </Rule>
  634.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht client check gag" sid="944">
  635.             <Token id="echo_id" type="int">668</Token>
  636.             <Token id="icmp_type" type="int">0</Token>
  637.             <Token id="content" type="str">gesundheit!</Token>
  638.         </Rule>
  639.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="27444" remport="*" name="DDOS Trin00 Master to Daemon default password attempt" sid="948">
  640.             <Token id="content" type="str">l44adsl</Token>
  641.         </Rule>
  642.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS TFN server response" sid="952">
  643.             <Token id="echo_id" type="int">123</Token>
  644.             <Token id="echo_seq" type="int">0</Token>
  645.             <Token id="icmp_type" type="int">0</Token>
  646.             <Token id="content" type="str">shell bound to port</Token>
  647.         </Rule>
  648.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="18753" remport="*" name="DDOS shaft handler to agent" sid="956">
  649.             <Token id="content" type="str">alive tijgu</Token>
  650.         </Rule>
  651.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="20433" remport="*" name="DDOS shaft agent to handler" sid="960">
  652.             <Token id="content" type="str">alive</Token>
  653.         </Rule>
  654.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="DDOS shaft synflood" sid="964">
  655.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  656.             <Token id="tcp_seq" type="int">674711609</Token>
  657.         </Rule>
  658.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="DDOS shaft synflood" sid="965">
  659.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  660.             <Token id="tcp_seq" type="int">674711609</Token>
  661.         </Rule>
  662.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="6838" remport="*" name="DDOS mstream agent to handler" sid="972">
  663.             <Token id="content" type="str">newserver</Token>
  664.         </Rule>
  665.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="10498" remport="*" name="DDOS mstream handler to agent" sid="976">
  666.             <Token id="content" type="str">stream/</Token>
  667.         </Rule>
  668.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="10498" remport="*" name="DDOS mstream handler ping to agent" sid="980">
  669.             <Token id="content" type="str">ping</Token>
  670.         </Rule>
  671.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="10498" remport="*" name="DDOS mstream agent pong to handler" sid="984">
  672.             <Token id="content" type="str">pong</Token>
  673.         </Rule>
  674.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="12754" remport="*" name="DDOS mstream client to handler" sid="988">
  675.             <Token id="content" type="str">&gt;</Token>
  676.         </Rule>
  677.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="12754" remport="*" name="DDOS mstream handler to client" sid="992">
  678.             <Token id="content" type="str">&gt;</Token>
  679.         </Rule>
  680.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="15104" remport="*" name="DDOS mstream client to handler" sid="996">
  681.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  682.         </Rule>
  683.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="15104" remport="*" name="DDOS mstream handler to client" sid="1000">
  684.             <Token id="content" type="str">&gt;</Token>
  685.         </Rule>
  686.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS - TFN client command LE" sid="1004">
  687.             <Token id="echo_id" type="int">51201</Token>
  688.             <Token id="echo_seq" type="int">0</Token>
  689.             <Token id="icmp_type" type="int">0</Token>
  690.         </Rule>
  691.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht handler-&gt;agent niggahbitch" sid="7416">
  692.             <Token id="echo_id" type="int">9015</Token>
  693.             <Token id="icmp_type" type="int">0</Token>
  694.             <Token id="content" type="str">niggahbitch</Token>
  695.         </Rule>
  696.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht handler-&gt;agent niggahbitch" sid="7417">
  697.             <Token id="echo_id" type="int">9015</Token>
  698.             <Token id="icmp_type" type="int">0</Token>
  699.             <Token id="content" type="str">niggahbitch</Token>
  700.         </Rule>
  701.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht agent-&gt;handler skillz" sid="7420">
  702.             <Token id="echo_id" type="int">6666</Token>
  703.             <Token id="icmp_type" type="int">0</Token>
  704.             <Token id="content" type="str">skillz</Token>
  705.         </Rule>
  706.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht agent-&gt;handler skillz" sid="7421">
  707.             <Token id="echo_id" type="int">6666</Token>
  708.             <Token id="icmp_type" type="int">0</Token>
  709.             <Token id="content" type="str">skillz</Token>
  710.         </Rule>
  711.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht handler-&gt;agent ficken" sid="7424">
  712.             <Token id="echo_id" type="int">6667</Token>
  713.             <Token id="icmp_type" type="int">0</Token>
  714.             <Token id="content" type="str">ficken</Token>
  715.         </Rule>
  716.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DDOS Stacheldraht handler-&gt;agent ficken" sid="7425">
  717.             <Token id="echo_id" type="int">6667</Token>
  718.             <Token id="icmp_type" type="int">0</Token>
  719.             <Token id="content" type="str">ficken</Token>
  720.         </Rule>
  721.     </RuleList>
  722.     <RuleList name="dns.rules">
  723.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="53" name="DNS SPOOF query response PTR with TTL of 1 min. and no authority" sid="1012">
  724.             <Token id="content" type="str">\x85\x80\0\x01\0\x01\0\0\0\0</Token>
  725.             <Token id="content" type="str">\xC0\f\0\f\0\x01\0\0\0&lt;\0\x0F</Token>
  726.         </Rule>
  727.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="53" name="DNS SPOOF query response with TTL of 1 min. and no authority" sid="1016">
  728.             <Token id="content" type="str">\x81\x80\0\x01\0\x01\0\0\0\0</Token>
  729.             <Token id="content" type="str">\xC0\f\0\x01\0\x01\0\0\0&lt;\0\x04</Token>
  730.         </Rule>
  731.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS zone transfer TCP" sid="1020">
  732.             <Token id="content" type="str" offset="15">\0\0\xFC</Token>
  733.         </Rule>
  734.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS named authors attempt" sid="1024">
  735.             <Token id="content" type="str" nocase="1" offset="12">\aauthors</Token>
  736.             <Token id="content" type="str" nocase="1" offset="12">\x04bind</Token>
  737.         </Rule>
  738.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS named version attempt" sid="1028">
  739.             <Token id="content" type="str" nocase="1" offset="12">\aversion</Token>
  740.             <Token id="content" type="str" nocase="1" offset="12">\x04bind</Token>
  741.         </Rule>
  742.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named 8.2-&gt;8.2.1" sid="1032">
  743.             <Token id="content" type="str">../../../</Token>
  744.         </Rule>
  745.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named overflow ADM" sid="1036">
  746.             <Token id="content" type="str">thisissometempspaceforthesockinaddrinyeahyeahiknowthisislamebutanywaywhocareshorizongotitworkingsoalliscool</Token>
  747.         </Rule>
  748.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named overflow ADMROCKS" sid="1040">
  749.             <Token id="content" type="str">ADMROCKS</Token>
  750.         </Rule>
  751.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named overflow attempt" sid="1044">
  752.             <Token id="content" type="str">\xCD\x80\xE8\xD7\xFF\xFF\xFF/bin/sh</Token>
  753.         </Rule>
  754.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT x86 Linux overflow attempt" sid="1048">
  755.             <Token id="content" type="str">1\xC0\xB0?1\xDB\xB3\xFF1\xC9\xCD\x801\xC0</Token>
  756.         </Rule>
  757.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT x86 Linux overflow attempt" sid="1056">
  758.             <Token id="content" type="str">1\xC0\xB0\x02\xCD\x80\x85\xC0uL\xEBL^\xB0</Token>
  759.         </Rule>
  760.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT x86 Linux overflow attempt ADMv2" sid="1060">
  761.             <Token id="content" type="str">\x89\xF7)\xC7\x89\xF3\x89\xF9\x89\xF2\xAC&lt;\xFE</Token>
  762.         </Rule>
  763.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT x86 FreeBSD overflow attempt" sid="1064">
  764.             <Token id="content" type="str">\xEBn^\xC6\x06\x9A1\xC9\x89N\x01\xC6F\x05</Token>
  765.         </Rule>
  766.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT sparc overflow attempt" sid="1068">
  767.             <Token id="content" type="str">\x90\x1A\xC0\x0F\x90\x02 \b\x92\x02 \x0F\xD0#\xBF\xF8</Token>
  768.         </Rule>
  769.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named tsig overflow attempt" sid="1212">
  770.             <Token id="content" type="str">\xAB\xCD\t\x80\0\0\0\x01\0\0\0\0\0\0\x01\0\x01    \x02a</Token>
  771.         </Rule>
  772.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS EXPLOIT named tsig overflow attempt" sid="1256">
  773.             <Token id="content" type="str">\x80\0\a\0\0\0\0\0\x01?\0\x01\x02</Token>
  774.         </Rule>
  775.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS named authors attempt" sid="5740">
  776.             <Token id="content" type="str" nocase="1" offset="12">\aauthors</Token>
  777.             <Token id="content" type="str" nocase="1" offset="12">\x04bind</Token>
  778.         </Rule>
  779.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS named version attempt" sid="6464">
  780.             <Token id="content" type="str" nocase="1" offset="12">\aversion</Token>
  781.             <Token id="content" type="str" nocase="1" offset="12">\x04bind</Token>
  782.         </Rule>
  783.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="53" remport="*" name="DNS zone transfer UDP" sid="7792">
  784.             <Token id="content" type="str" offset="14">\0\0\xFC</Token>
  785.         </Rule>
  786.     </RuleList>
  787.     <RuleList name="dos.rules">
  788.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="DOS Jolt attack" sid="1072">
  789.             <Token id="dsize" type="int">408</Token>
  790.             <Token id="ip_frg" type="str">M</Token>
  791.         </Rule>
  792.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="DOS Teardrop attack" sid="1080">
  793.             <Token id="ip_frg" type="str">M</Token>
  794.             <Token id="ip_id" type="int">242</Token>
  795.         </Rule>
  796.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="19" remport="7" name="DOS UDP echo+chargen bomb" sid="1084"/>
  797.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="7" remport="19" name="DOS UDP echo+chargen bomb" sid="1085"/>
  798.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="19" remport="7" name="DOS UDP echo+chargen bomb" sid="1086"/>
  799.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="7" remport="19" name="DOS UDP echo+chargen bomb" sid="1087"/>
  800.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="DOS IGMP dos attack" sid="1088">
  801.             <Token id="ip_frg" type="str">M+</Token>
  802.             <Token id="ip_ptc" type="int">2</Token>
  803.             <Token id="content" type="str" depth="2">\x02\0</Token>
  804.         </Rule>
  805.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="DOS IGMP dos attack" sid="1092">
  806.             <Token id="ip_frg" type="str">M+</Token>
  807.             <Token id="ip_ptc" type="int">2</Token>
  808.             <Token id="content" type="str" depth="2">\0\0</Token>
  809.         </Rule>
  810.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="DOS ath" sid="1096">
  811.             <Token id="icmp_type" type="int">8</Token>
  812.             <Token id="content" type="str" nocase="1">+++ath</Token>
  813.         </Rule>
  814.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="DOS NAPTHA" sid="1100">
  815.             <Token id="tcp_flg" type="str">S</Token>
  816.             <Token id="ip_id" type="int">413</Token>
  817.             <Token id="tcp_seq" type="int">6060842</Token>
  818.         </Rule>
  819.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="DOS NAPTHA" sid="1101">
  820.             <Token id="tcp_flg" type="str">S</Token>
  821.             <Token id="ip_id" type="int">413</Token>
  822.             <Token id="tcp_seq" type="int">6060842</Token>
  823.         </Rule>
  824.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7070" remport="*" name="DOS Real Audio Server" sid="1104">
  825.             <Token id="content" type="str">\xFF\xF4\xFF\xFD\x06</Token>
  826.         </Rule>
  827.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7070" remport="*" name="DOS Real Server template.html" sid="1108">
  828.             <Token id="content" type="str" nocase="1">/viewsource/template.html?</Token>
  829.         </Rule>
  830.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="DOS Real Server template.html" sid="1112">
  831.             <Token id="content" type="str" nocase="1">/viewsource/template.html?</Token>
  832.         </Rule>
  833.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="161" remport="*" name="DOS Bay/Nortel Nautica Marlin" sid="1116">
  834.             <Token id="dsize" type="int">0</Token>
  835.         </Rule>
  836.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="9" remport="*" name="DOS Ascend Route" sid="1124">
  837.             <Token id="content" type="str" depth="50" offset="25">NAMENAME</Token>
  838.         </Rule>
  839.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="617" remport="*" name="DOS arkiea backup" sid="1128">
  840.             <Token id="dsize" type="int" rel="greater">1445</Token>
  841.         </Rule>
  842.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="135-139" remport="*" name="DOS Winnuke attack" sid="5028">
  843.             <Token id="tcp_flg" type="str">U+</Token>
  844.         </Rule>
  845.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3372" remport="*" name="DOS MSDTC attempt" sid="5632">
  846.             <Token id="dsize" type="int" rel="greater">1023</Token>
  847.         </Rule>
  848.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="DOS Cisco attempt" sid="6180">
  849.             <Token id="dsize" type="int">1</Token>
  850.             <Token id="content" type="str">\x13</Token>
  851.         </Rule>
  852.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6004" remport="*" name="DOS iParty DOS attempt" sid="6420">
  853.             <Token id="content" type="str">\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  854.         </Rule>
  855.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6789-6790" remport="*" name="DOS DB2 dos attempt" sid="6564">
  856.             <Token id="dsize" type="int">1</Token>
  857.         </Rule>
  858.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="DOS ISAKMP invalid identification payload attempt" sid="9944">
  859.             <Token id="content" type="str" depth="1" offset="16">\x05</Token>
  860.             <Token id="byte_test" type="int" format="big" offset="30" oper="greater" size="2">4</Token>
  861.             <Token id="byte_test" type="int" format="big" offset="30" oper="less" size="2">8</Token>
  862.         </Rule>
  863.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="179" remport="*" name="DOS BGP spoofed connection reset attempt" sid="10092">
  864.             <Token id="tcp_flg" type="str">FSR*</Token>
  865.         </Rule>
  866.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="179" remport="*" name="DOS BGP spoofed connection reset attempt" sid="10093">
  867.             <Token id="tcp_flg" type="str">FSR*</Token>
  868.         </Rule>
  869.     </RuleList>
  870.     <RuleList name="exploit.rules">
  871.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="80" name="EXPLOIT Netscape 4.7 client overflow" sid="1132">
  872.             <Token id="content" type="str">3\xC9\xB1\x10?\xE9\x06Q&lt;\xFAG3\xC0P\xF7\xD0P</Token>
  873.         </Rule>
  874.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="EXPLOIT x86 Linux samba overflow" sid="1168">
  875.             <Token id="content" type="str">\xEB/_\xEBJ^\x89\xFB\x89&gt;\x89\xF2</Token>
  876.         </Rule>
  877.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2766" remport="*" name="EXPLOIT nlps x86 Solaris overflow" sid="1200">
  878.             <Token id="content" type="str">\xEB#^3\xC0\x88F\xFA\x89F\xF5\x896</Token>
  879.         </Rule>
  880.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="515" remport="*" name="EXPLOIT LPRng overflow" sid="1204">
  881.             <Token id="content" type="str">C\a\x89[\b\x8DK\b\x89C\f\xB0\v\xCD\x801\xC0\xFE\xC0\xCD\x80\xE8\x94\xFF\xFF\xFF/bin/sh\n</Token>
  882.         </Rule>
  883.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="515" remport="*" name="EXPLOIT Redhat 7.0 lprd overflow" sid="1208">
  884.             <Token id="content" type="str">XXXX%.172u%300$n</Token>
  885.         </Rule>
  886.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6373" remport="*" name="EXPLOIT SCO calserver overflow" sid="1216">
  887.             <Token id="content" type="str">\xEB\x7F]U\xFEM\x98\xFEM\x9B</Token>
  888.         </Rule>
  889.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="EXPLOIT delegate proxy overflow" sid="1220">
  890.             <Token id="dsize" type="int" rel="greater">1000</Token>
  891.             <Token id="content" type="str" nocase="1">whois://</Token>
  892.         </Rule>
  893.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="9090" remport="*" name="EXPLOIT VQServer admin" sid="1224">
  894.             <Token id="content" type="str" nocase="1">GET / HTTP/1.1</Token>
  895.         </Rule>
  896.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6666-7000" remport="*" name="EXPLOIT CHAT IRC topic overflow" sid="1228">
  897.             <Token id="content" type="str">\xEBK[S2\xE4\x83\xC3\vK\x88#\xB8Pw</Token>
  898.         </Rule>
  899.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="21" name="EXPLOIT NextFTP client overflow" sid="1232">
  900.             <Token id="content" type="str">\xB4 \xB4!\x8B\xCC\x83\xE9\x04\x8B\x193\xC9f\xB9\x10</Token>
  901.         </Rule>
  902.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="EXPLOIT sniffit overflow" sid="1236">
  903.             <Token id="dsize" type="int" rel="greater">512</Token>
  904.             <Token id="tcp_flg" type="str">A+</Token>
  905.             <Token id="content" type="str" nocase="1">from:\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90</Token>
  906.         </Rule>
  907.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="EXPLOIT x86 windows MailMax overflow" sid="1240">
  908.             <Token id="content" type="str">\xEBE\xEB [\xFC3\xC9\xB1\x82\x8B\xF3\x80+</Token>
  909.         </Rule>
  910.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="80" name="EXPLOIT Netscape 4.7 unsucessful overflow" sid="1244">
  911.             <Token id="content" type="str">3\xC9\xB1\x10?\xE9\x06Q&lt;\xFAG3\xC0P\xF7\xD0P</Token>
  912.         </Rule>
  913.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="123" remport="*" name="EXPLOIT ntpdx overflow attempt" sid="1248">
  914.             <Token id="dsize" type="int" rel="greater">128</Token>
  915.         </Rule>
  916.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="518" remport="*" name="EXPLOIT ntalkd x86 Linux overflow" sid="1252">
  917.             <Token id="content" type="str">\x01\x03\0\0\0\0\0\x01\0\x02\x02\xE8</Token>
  918.         </Rule>
  919.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="635" remport="*" name="EXPLOIT x86 Linux mountd overflow" sid="1260">
  920.             <Token id="content" type="str">^\xB0\x02\x89\x06\xFE\xC8\x89F\x04\xB0\x06\x89F</Token>
  921.         </Rule>
  922.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="635" remport="*" name="EXPLOIT x86 Linux mountd overflow" sid="1264">
  923.             <Token id="content" type="str">\xEBV^VVV1\xD2\x88V\v\x88V\x1E</Token>
  924.         </Rule>
  925.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="635" remport="*" name="EXPLOIT x86 Linux mountd overflow" sid="1268">
  926.             <Token id="content" type="str">\xEB@^1\xC0@\x89F\x04\x89\xC3@\x89\x06</Token>
  927.         </Rule>
  928.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2224" remport="*" name="EXPLOIT MDBMS overflow" sid="4960">
  929.             <Token id="content" type="str">\x011\xDB\xCD\x80\xE8[\xFF\xFF\xFF</Token>
  930.         </Rule>
  931.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="4242" remport="*" name="EXPLOIT AIX pdnsd overflow" sid="5044">
  932.             <Token id="dsize" type="int" rel="greater">1000</Token>
  933.             <Token id="content" type="str">\x7F\xFF\xFBx\x7F\xFF\xFBx\x7F\xFF\xFBx\x7F\xFF\xFBx</Token>
  934.             <Token id="content" type="str">@\x8A\xFF\xC8@\x82\xFF\xD8;6\xFE\x03;v\xFE\x02</Token>
  935.         </Rule>
  936.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="4321" remport="*" name="EXPLOIT rwhoisd format string attempt" sid="5292">
  937.             <Token id="content" type="str">-soa %p</Token>
  938.         </Rule>
  939.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="EXPLOIT ssh CRC32 overflow /bin/sh" sid="5296">
  940.             <Token id="content" type="str">/bin/sh</Token>
  941.         </Rule>
  942.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="EXPLOIT ssh CRC32 overflow NOOP" sid="5304">
  943.             <Token id="content" type="str">\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90</Token>
  944.         </Rule>
  945.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="EXPLOIT ssh CRC32 overflow" sid="5308">
  946.             <Token id="content" type="str" depth="7">\0\x01W\0\0\0\x18</Token>
  947.             <Token id="content" type="str" depth="14" offset="8">\xFF\xFF\xFF\xFF\0\0</Token>
  948.         </Rule>
  949.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="6666-7000" name="EXPLOIT CHAT IRC Ettercap parse overflow attempt" sid="5528">
  950.             <Token id="content" type="str" nocase="1">PRIVMSG</Token>
  951.             <Token id="content" type="str" nocase="1">nickserv</Token>
  952.             <Token id="content" type="str" nocase="1">IDENTIFY</Token>
  953.             <Token id="isdataat" type="int" rel="relative">100</Token>
  954.             <Token id="pcre" type="str">=/^PRIVMSG\s+nickserv\s+IDENTIFY\s[^\n]{100}/smi</Token>
  955.         </Rule>
  956.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="6666-7000" remport="*" name="EXPLOIT CHAT IRC Ettercap parse overflow attempt" sid="5529">
  957.             <Token id="content" type="str" nocase="1">PRIVMSG</Token>
  958.             <Token id="content" type="str" nocase="1">nickserv</Token>
  959.             <Token id="content" type="str" nocase="1">IDENTIFY</Token>
  960.             <Token id="isdataat" type="int" rel="relative">100</Token>
  961.             <Token id="pcre" type="str">=/^PRIVMSG\s+nickserv\s+IDENTIFY\s[^\n]{100}/smi</Token>
  962.         </Rule>
  963.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="6112" remport="*" name="EXPLOIT CDE dtspcd exploit attempt" sid="5592">
  964.             <Token id="content" type="str" depth="1" offset="10">1</Token>
  965.             <Token id="content" type="str" complement="1" depth="3" offset="11">000</Token>
  966.         </Rule>
  967.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="32772-34000" remport="*" name="EXPLOIT cachefsd buffer overflow attempt" sid="7004">
  968.             <Token id="dsize" type="int" rel="greater">720</Token>
  969.             <Token id="content" type="str">\0\x01\x87\x86\0\0\0\x01\0\0\0\x05</Token>
  970.         </Rule>
  971.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="EXPLOIT gobbles SSH exploit attempt" sid="7248">
  972.             <Token id="content" type="str">GOBBLES</Token>
  973.         </Rule>
  974.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="515" remport="*" name="EXPLOIT LPD dvips remote command execution attempt" sid="7284">
  975.             <Token id="content" type="str">psfile=\"`</Token>
  976.         </Rule>
  977.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="22" name="EXPLOIT SSH server banner overflow" sid="7352">
  978.             <Token id="content" type="str" nocase="1">SSH-</Token>
  979.             <Token id="isdataat" type="int" rel="relative">200</Token>
  980.             <Token id="pcre" type="str">=/^SSH-\s[^\n]{200}/ism</Token>
  981.         </Rule>
  982.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="749" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7576">
  983.             <Token id="content" type="str">\0\xC0\x05\b\0\xC0\x05\b\0\xC0\x05\b\0\xC0\x05\b</Token>
  984.         </Rule>
  985.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="751" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7580">
  986.             <Token id="content" type="str">\0\xC0\x05\b\0\xC0\x05\b\0\xC0\x05\b\0\xC0\x05\b</Token>
  987.         </Rule>
  988.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="749" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7584">
  989.             <Token id="content" type="str">\xFF\xFFKADM0.0A\0\0\xFB\x03</Token>
  990.         </Rule>
  991.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="751" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7588">
  992.             <Token id="content" type="str">\xFF\xFFKADM0.0A\0\0\xFB\x03</Token>
  993.         </Rule>
  994.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="749" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7592">
  995.             <Token id="content" type="str">/shh//bi</Token>
  996.         </Rule>
  997.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="751" remport="*" name="EXPLOIT kadmind buffer overflow attempt" sid="7596">
  998.             <Token id="content" type="str">/shh//bi</Token>
  999.         </Rule>
  1000.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1655" remport="*" name="EXPLOIT ebola PASS overflow attempt" sid="9276">
  1001.             <Token id="content" type="str" nocase="1">PASS</Token>
  1002.             <Token id="pcre" type="str">=/^PASS\s[^\n]{49}/smi</Token>
  1003.         </Rule>
  1004.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1655" remport="*" name="EXPLOIT ebola USER overflow attempt" sid="9280">
  1005.             <Token id="content" type="str" nocase="1">USER</Token>
  1006.             <Token id="pcre" type="str">=/^USER\s[^\n]{49}/smi</Token>
  1007.         </Rule>
  1008.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP first payload certificate request length overflow attempt" sid="9504">
  1009.             <Token id="byte_test" type="int" format="big" offset="24" oper="greater" size="4">2043</Token>
  1010.             <Token id="content" type="str" depth="1" offset="16">\a</Token>
  1011.             <Token id="byte_test" type="int" format="big" offset="30" oper="greater" size="2">2043</Token>
  1012.         </Rule>
  1013.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP second payload certificate request length overflow attempt" sid="9508">
  1014.             <Token id="byte_test" type="int" format="big" offset="24" oper="greater" size="4">2043</Token>
  1015.             <Token id="content" type="str" depth="1" offset="28">\a</Token>
  1016.             <Token id="byte_jump" type="int" format="big" offset="30">2</Token>
  1017.             <Token id="byte_test" type="int" format="big" offset="-2" oper="greater" relative="1" size="2">2043</Token>
  1018.         </Rule>
  1019.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP third payload certificate request length overflow attempt" sid="9512">
  1020.             <Token id="byte_test" type="int" format="big" offset="24" oper="greater" size="4">2043</Token>
  1021.             <Token id="byte_jump" type="int" format="big" offset="30" relative="1">2</Token>
  1022.             <Token id="content" type="str" distance="-4" within="1">\a</Token>
  1023.             <Token id="byte_jump" type="int" format="big" offset="1" relative="1">2</Token>
  1024.             <Token id="byte_test" type="int" format="big" offset="-2" oper="greater" relative="1" size="2">2043</Token>
  1025.         </Rule>
  1026.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP forth payload certificate request length overflow attempt" sid="9516">
  1027.             <Token id="byte_test" type="int" format="big" offset="24" oper="greater" size="4">2043</Token>
  1028.             <Token id="byte_jump" type="int" format="big" offset="30" relative="1">2</Token>
  1029.             <Token id="byte_jump" type="int" format="big" offset="-2" relative="1">2</Token>
  1030.             <Token id="content" type="str" distance="-4" within="1">\a</Token>
  1031.             <Token id="byte_jump" type="int" format="big" offset="1" relative="1">2</Token>
  1032.             <Token id="byte_test" type="int" format="big" offset="-2" oper="greater" relative="1" size="2">2043</Token>
  1033.         </Rule>
  1034.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP fifth payload certificate request length overflow attempt" sid="9520">
  1035.             <Token id="byte_test" type="int" format="big" offset="24" oper="greater" size="4">2043</Token>
  1036.             <Token id="byte_jump" type="int" format="big" offset="30" relative="1">2</Token>
  1037.             <Token id="byte_jump" type="int" format="big" offset="-2" relative="1">2</Token>
  1038.             <Token id="byte_jump" type="int" format="big" offset="-2" relative="1">2</Token>
  1039.             <Token id="content" type="str" distance="-4" within="1">\a</Token>
  1040.             <Token id="byte_jump" type="int" format="big" offset="1" relative="1">2</Token>
  1041.             <Token id="byte_test" type="int" format="big" offset="-2" oper="greater" relative="1" size="2">2043</Token>
  1042.         </Rule>
  1043.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP delete hash with empty hash attempt" sid="9652">
  1044.             <Token id="content" type="str" depth="1" offset="16">\b</Token>
  1045.             <Token id="content" type="str" depth="1" offset="28">\f</Token>
  1046.             <Token id="content" type="str" depth="2" offset="30">\0\x04</Token>
  1047.         </Rule>
  1048.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP initial contact notification without SPI attempt" sid="9656">
  1049.             <Token id="content" type="str" depth="1" offset="16">\v</Token>
  1050.             <Token id="content" type="str" depth="10" offset="30">\0\f\0\0\0\x01\x01\0\x06\x02</Token>
  1051.         </Rule>
  1052.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="EXPLOIT ISAKMP second payload initial contact notification without SPI attempt" sid="9660">
  1053.             <Token id="content" type="str" depth="1" offset="28">\v</Token>
  1054.             <Token id="byte_jump" type="int" format="big" offset="30">2</Token>
  1055.             <Token id="content" type="str" distance="-2" within="10">\0\f\0\0\0\x01\x01\0`\x02</Token>
  1056.         </Rule>
  1057.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="4000" remport="*" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt" sid="9772">
  1058.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1059.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1060.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1061.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1062.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1063.             <Token id="content" type="str">\x05\0</Token>
  1064.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1065.             <Token id="byte_test" type="int" offset="18" oper="greater" relative="1" size="2">128</Token>
  1066.         </Rule>
  1067.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="4000" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt" sid="9773">
  1068.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1069.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1070.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1071.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1072.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1073.             <Token id="content" type="str">\x05\0</Token>
  1074.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1075.             <Token id="byte_test" type="int" offset="18" oper="greater" relative="1" size="2">128</Token>
  1076.         </Rule>
  1077.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="4000" remport="*" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt" sid="9776">
  1078.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1079.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1080.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1081.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1082.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1083.             <Token id="content" type="str">\x05\0</Token>
  1084.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1085.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1086.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1087.         </Rule>
  1088.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="4000" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt" sid="9777">
  1089.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1090.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1091.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1092.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1093.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1094.             <Token id="content" type="str">\x05\0</Token>
  1095.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1096.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1097.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1098.         </Rule>
  1099.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="4000" remport="*" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER last name overflow attempt" sid="9780">
  1100.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1101.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1102.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1103.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1104.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1105.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1106.             <Token id="content" type="str">\x05\0</Token>
  1107.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1108.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1109.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1110.         </Rule>
  1111.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="4000" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER last name overflow attempt" sid="9781">
  1112.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1113.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1114.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1115.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1116.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1117.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1118.             <Token id="content" type="str">\x05\0</Token>
  1119.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1120.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1121.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1122.         </Rule>
  1123.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="4000" remport="*" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER email overflow attempt" sid="9784">
  1124.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1125.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1126.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1127.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1128.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1129.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1130.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1131.             <Token id="content" type="str">\x05\0</Token>
  1132.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1133.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1134.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1135.         </Rule>
  1136.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="4000" name="EXPLOIT ICQ SRV_MULTI/SRV_META_USER email overflow attempt" sid="9785">
  1137.             <Token id="content" type="str" depth="2">\x05\0</Token>
  1138.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1139.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">128</Token>
  1140.             <Token id="content" type="str" distance="5" within="2">\x12\x02</Token>
  1141.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="1">1</Token>
  1142.             <Token id="content" type="str" distance="0">\x05\0</Token>
  1143.             <Token id="content" type="str" distance="5" within="2">n\0</Token>
  1144.             <Token id="content" type="str">\x05\0</Token>
  1145.             <Token id="content" type="str" distance="5" within="2">\xDE\x03</Token>
  1146.             <Token id="byte_jump" type="int" offset="18" relative="1">2</Token>
  1147.             <Token id="byte_jump" type="int" relative="1">2</Token>
  1148.         </Rule>
  1149.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT IGMP IGAP account overflow attempt" sid="9848">
  1150.             <Token id="ip_ptc" type="int">2</Token>
  1151.             <Token id="byte_test" type="int" format="big" oper="greater" size="1">63</Token>
  1152.             <Token id="byte_test" type="int" format="big" oper="less" size="1">67</Token>
  1153.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" size="1">16</Token>
  1154.         </Rule>
  1155.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT IGMP IGAP account overflow attempt" sid="9849">
  1156.             <Token id="ip_ptc" type="int">2</Token>
  1157.             <Token id="byte_test" type="int" format="big" oper="greater" size="1">63</Token>
  1158.             <Token id="byte_test" type="int" format="big" oper="less" size="1">67</Token>
  1159.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" size="1">16</Token>
  1160.         </Rule>
  1161.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT IGMP IGAP message overflow attempt" sid="9852">
  1162.             <Token id="ip_ptc" type="int">2</Token>
  1163.             <Token id="byte_test" type="int" format="big" oper="greater" size="1">63</Token>
  1164.             <Token id="byte_test" type="int" format="big" oper="less" size="1">67</Token>
  1165.             <Token id="byte_test" type="int" format="big" offset="13" oper="greater" size="1">64</Token>
  1166.         </Rule>
  1167.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT IGMP IGAP message overflow attempt" sid="9853">
  1168.             <Token id="ip_ptc" type="int">2</Token>
  1169.             <Token id="byte_test" type="int" format="big" oper="greater" size="1">63</Token>
  1170.             <Token id="byte_test" type="int" format="big" oper="less" size="1">67</Token>
  1171.             <Token id="byte_test" type="int" format="big" offset="13" oper="greater" size="1">64</Token>
  1172.         </Rule>
  1173.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT EIGRP prefix length overflow attempt" sid="9856">
  1174.             <Token id="ip_ptc" type="int">88</Token>
  1175.             <Token id="byte_test" type="int" format="big" offset="44" oper="greater" size="1">32</Token>
  1176.         </Rule>
  1177.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="EXPLOIT EIGRP prefix length overflow attempt" sid="9857">
  1178.             <Token id="ip_ptc" type="int">88</Token>
  1179.             <Token id="byte_test" type="int" format="big" offset="44" oper="greater" size="1">32</Token>
  1180.         </Rule>
  1181.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="EXPLOIT esignal STREAMQUOTE buffer overflow attempt" sid="9956">
  1182.             <Token id="content" type="str" nocase="1">&lt;STREAMQUOTE&gt;</Token>
  1183.             <Token id="isdataat" type="int" rel="relative">1024</Token>
  1184.             <Token id="content" type="str" complement="1" nocase="1" within="1054">&lt;/STREAMQUOTE&gt;</Token>
  1185.         </Rule>
  1186.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="EXPLOIT esignal SNAPQUOTE buffer overflow attempt" sid="9960">
  1187.             <Token id="content" type="str" nocase="1">&lt;SNAPQUOTE&gt;</Token>
  1188.             <Token id="isdataat" type="int" rel="relative">1024</Token>
  1189.             <Token id="content" type="str" complement="1" nocase="1" within="1052">&lt;/SNAPQUOTE&gt;</Token>
  1190.         </Rule>
  1191.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="548" remport="*" name="EXPLOIT AFP FPLoginExt username buffer overflow attempt" sid="10180">
  1192.             <Token id="content" type="str" depth="2">\0\x02</Token>
  1193.             <Token id="content" type="str" distance="14" within="1">?</Token>
  1194.             <Token id="content" type="str" nocase="1">cleartxt passwrd</Token>
  1195.             <Token id="byte_jump" type="int" format="big" offset="1" relative="1">2</Token>
  1196.             <Token id="byte_jump" type="int" format="big" offset="1" relative="1">2</Token>
  1197.             <Token id="isdataat" type="int" rel="relative">2</Token>
  1198.         </Rule>
  1199.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="80" name="EXPLOIT winamp XM module name overflow" sid="10200">
  1200.             <Token id="content" type="str" nocase="1">Extended module:</Token>
  1201.             <Token id="isdataat" type="int" rel="relative">20</Token>
  1202.             <Token id="content" type="str" complement="1" within="21">\x1A</Token>
  1203.         </Rule>
  1204.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache GET overflow attempt" sid="10204">
  1205.             <Token id="content" type="str">GET</Token>
  1206.             <Token id="pcre" type="str">=/^GET[^s]{432}/sm</Token>
  1207.         </Rule>
  1208.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache HEAD overflow attempt" sid="10208">
  1209.             <Token id="content" type="str">HEAD</Token>
  1210.             <Token id="pcre" type="str">=/^HEAD[^s]{432}/sm</Token>
  1211.         </Rule>
  1212.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache PUT overflow attempt" sid="10212">
  1213.             <Token id="content" type="str">PUT</Token>
  1214.             <Token id="pcre" type="str">=/^PUT[^s]{432}/sm</Token>
  1215.         </Rule>
  1216.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache POST overflow attempt" sid="10216">
  1217.             <Token id="content" type="str">POST</Token>
  1218.             <Token id="pcre" type="str">=/^POST[^s]{432}/sm</Token>
  1219.         </Rule>
  1220.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache TRACE overflow attempt" sid="10220">
  1221.             <Token id="content" type="str">TRACE</Token>
  1222.             <Token id="pcre" type="str">=/^TRACE[^s]{432}/sm</Token>
  1223.         </Rule>
  1224.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache DELETE overflow attempt" sid="10224">
  1225.             <Token id="content" type="str">DELETE</Token>
  1226.             <Token id="pcre" type="str">=/^DELETE[^s]{432}/sm</Token>
  1227.         </Rule>
  1228.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache LOCK overflow attempt" sid="10228">
  1229.             <Token id="content" type="str">LOCK</Token>
  1230.             <Token id="pcre" type="str">=/^LOCK[^s]{432}/sm</Token>
  1231.         </Rule>
  1232.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache MKCOL overflow attempt" sid="10232">
  1233.             <Token id="content" type="str">MKCOL</Token>
  1234.             <Token id="pcre" type="str">=/^MKCOL[^s]{432}/sm</Token>
  1235.         </Rule>
  1236.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache COPY overflow attempt" sid="10236">
  1237.             <Token id="content" type="str">COPY</Token>
  1238.             <Token id="pcre" type="str">=/^COPY[^s]{432}/sm</Token>
  1239.         </Rule>
  1240.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7777-7778" remport="*" name="EXPLOIT Oracle Web Cache MOVE overflow attempt" sid="10240">
  1241.             <Token id="content" type="str">MOVE</Token>
  1242.             <Token id="pcre" type="str">=/^MOVE[^s]{432}/sm</Token>
  1243.         </Rule>
  1244.     </RuleList>
  1245.     <RuleList name="pop2.rules">
  1246.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="109" remport="*" name="POP2 x86 Linux overflow" sid="1136">
  1247.             <Token id="content" type="str">\xEB,[\x89\xD9\x80\xC1\x069\xD9|\a\x80\x01</Token>
  1248.         </Rule>
  1249.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="109" remport="*" name="POP2 x86 Linux overflow" sid="1140">
  1250.             <Token id="content" type="str">\xFF\xFF\xFF/BIN/SH\0</Token>
  1251.         </Rule>
  1252.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="109" remport="*" name="POP2 FOLD overflow attempt" sid="7736">
  1253.             <Token id="isdataat" type="int" rel="relative">256</Token>
  1254.             <Token id="content" type="str">FOLD</Token>
  1255.             <Token id="pcre" type="str">=/^FOLD\s[^\n]{256}/smi</Token>
  1256.         </Rule>
  1257.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="109" remport="*" name="POP2 FOLD arbitrary file attempt" sid="7740">
  1258.             <Token id="pcre" type="str">=/^FOLD\s+\//smi</Token>
  1259.             <Token id="content" type="str">FOLD</Token>
  1260.         </Rule>
  1261.     </RuleList>
  1262.     <RuleList name="pop3.rules">
  1263.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 EXPLOIT x86 BSD overflow" sid="1144">
  1264.             <Token id="content" type="str">^\x0E1\xC0\xB0;\x8D~\x0E\x89\xFA\x89\xF9</Token>
  1265.         </Rule>
  1266.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 EXPLOIT x86 BSD overflow" sid="1148">
  1267.             <Token id="content" type="str">h]^\xFF\xD5\xFF\xD4\xFF\xF5\x8B\xF5\x90f1</Token>
  1268.         </Rule>
  1269.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 EXPLOIT x86 Linux overflow" sid="1152">
  1270.             <Token id="content" type="str">\xD8@\xCD\x80\xE8\xD9\xFF\xFF\xFF/bin/sh</Token>
  1271.         </Rule>
  1272.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 EXPLOIT x86 SCO overflow" sid="1156">
  1273.             <Token id="content" type="str">V\x0E1\xC0\xB0;\x8D~\x12\x89\xF9\x89\xF9</Token>
  1274.         </Rule>
  1275.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 EXPLOIT qpopper overflow" sid="1160">
  1276.             <Token id="content" type="str">\xE8\xD9\xFF\xFF\xFF/bin/sh</Token>
  1277.         </Rule>
  1278.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 PASS overflow attempt" sid="6536">
  1279.             <Token id="content" type="str" nocase="1">PASS</Token>
  1280.             <Token id="isdataat" type="int" rel="relative">50</Token>
  1281.             <Token id="pcre" type="str">=/^PASS\s[^\n]{50}/smi</Token>
  1282.         </Rule>
  1283.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 APOP overflow attempt" sid="6540">
  1284.             <Token id="content" type="str" nocase="1">APOP</Token>
  1285.             <Token id="isdataat" type="int" rel="relative">256</Token>
  1286.             <Token id="pcre" type="str">=/^APOP\s[^\n]{256}/smi</Token>
  1287.         </Rule>
  1288.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 USER overflow attempt" sid="7464">
  1289.             <Token id="content" type="str" nocase="1">USER</Token>
  1290.             <Token id="isdataat" type="int" rel="relative">50</Token>
  1291.             <Token id="pcre" type="str">=/^USER\s[^\n]{50,}/smi</Token>
  1292.         </Rule>
  1293.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 AUTH overflow attempt" sid="7744">
  1294.             <Token id="content" type="str" nocase="1">AUTH</Token>
  1295.             <Token id="isdataat" type="int" rel="relative">50</Token>
  1296.             <Token id="pcre" type="str">=/^AUTH\s[^\n]{50}/smi</Token>
  1297.         </Rule>
  1298.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 LIST overflow attempt" sid="7748">
  1299.             <Token id="content" type="str" nocase="1">LIST</Token>
  1300.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1301.             <Token id="pcre" type="str">=/^LIST\s[^\n]{10}/smi</Token>
  1302.         </Rule>
  1303.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 XTND overflow attempt" sid="7752">
  1304.             <Token id="content" type="str" nocase="1">XTND</Token>
  1305.             <Token id="isdataat" type="int" rel="relative">50</Token>
  1306.             <Token id="pcre" type="str">=/^XTND\s[^\n]{50}/smi</Token>
  1307.         </Rule>
  1308.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 CAPA overflow attempt" sid="8432">
  1309.             <Token id="content" type="str" nocase="1">CAPA</Token>
  1310.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1311.             <Token id="pcre" type="str">=/^CAPA\s[^\n]{10}/smi</Token>
  1312.         </Rule>
  1313.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 TOP overflow attempt" sid="8436">
  1314.             <Token id="content" type="str" nocase="1">TOP</Token>
  1315.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1316.             <Token id="pcre" type="str">=/^TOP\s[^\n]{10}/smi</Token>
  1317.         </Rule>
  1318.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 STAT overflow attempt" sid="8440">
  1319.             <Token id="content" type="str" nocase="1">STAT</Token>
  1320.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1321.             <Token id="pcre" type="str">=/^STAT\s[^\n]{10}/smi</Token>
  1322.         </Rule>
  1323.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 DELE overflow attempt" sid="8444">
  1324.             <Token id="content" type="str" nocase="1">DELE</Token>
  1325.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1326.             <Token id="pcre" type="str">=/^DELE\s[^\n]{10}/smi</Token>
  1327.         </Rule>
  1328.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 RSET overflow attempt" sid="8448">
  1329.             <Token id="content" type="str" nocase="1">RSET</Token>
  1330.             <Token id="isdataat" type="int" rel="relative">10</Token>
  1331.             <Token id="pcre" type="str">=/^RSET\s[^\n]{10}/smi</Token>
  1332.         </Rule>
  1333.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 DELE negative arguement attempt" sid="8484">
  1334.             <Token id="content" type="str" nocase="1">DELE</Token>
  1335.             <Token id="pcre" type="str">=/^DELE\s+-\d/smi</Token>
  1336.         </Rule>
  1337.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 UIDL negative arguement attempt" sid="8488">
  1338.             <Token id="content" type="str" nocase="1">UIDL</Token>
  1339.             <Token id="pcre" type="str">=/^UIDL\s+-\d/smi</Token>
  1340.         </Rule>
  1341.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 USER format string attempt" sid="9000">
  1342.             <Token id="content" type="str" nocase="1">USER</Token>
  1343.             <Token id="content" type="str" distance="1">%</Token>
  1344.             <Token id="content" type="str" distance="1">%</Token>
  1345.         </Rule>
  1346.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="110" remport="*" name="POP3 APOP USER overflow attempt" sid="9636">
  1347.             <Token id="content" type="str" nocase="1">APOP</Token>
  1348.             <Token id="isdataat" type="int" rel="relative">256</Token>
  1349.             <Token id="pcre" type="str">=/^APOP\s+USER\s[^\n]{256}/smi</Token>
  1350.         </Rule>
  1351.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="995" remport="*" name="POP3 SSLv3 invalid timestamp attempt" sid="10004">
  1352.             <Token id="content" type="str" depth="2">\x16\x03</Token>
  1353.             <Token id="content" type="str" depth="1" offset="5">\x01</Token>
  1354.             <Token id="byte_test" type="int" format="big" offset="5" oper="greater" relative="1" size="4">2147483647</Token>
  1355.         </Rule>
  1356.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="995" remport="*" name="POP3 SSLv3 invalid data version attempt" sid="10008">
  1357.             <Token id="content" type="str" depth="2">\x16\x03</Token>
  1358.             <Token id="content" type="str" depth="1" offset="5">\x01</Token>
  1359.             <Token id="content" type="str" complement="1" depth="1" offset="9">\x03</Token>
  1360.         </Rule>
  1361.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="995" remport="*" name="PO3 PCT Client_Hello overflow attempt" sid="10072">
  1362.             <Token id="content" type="str" depth="1" offset="2">\x01</Token>
  1363.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" size="2">0</Token>
  1364.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">0</Token>
  1365.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">16</Token>
  1366.             <Token id="byte_test" type="int" format="big" offset="10" oper="greater" size="2">20</Token>
  1367.             <Token id="content" type="str" depth="1" offset="11">\x8F</Token>
  1368.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="2">32768</Token>
  1369.         </Rule>
  1370.     </RuleList>
  1371.     <RuleList name="finger.rules">
  1372.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER cmd_rootsh backdoor attempt" sid="1280">
  1373.             <Token id="content" type="str">cmd_rootsh</Token>
  1374.         </Rule>
  1375.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER account enumeration attempt" sid="1284">
  1376.             <Token id="content" type="str" nocase="1">a b c d e f</Token>
  1377.         </Rule>
  1378.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER search query" sid="1288">
  1379.             <Token id="content" type="str">search</Token>
  1380.         </Rule>
  1381.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER root query" sid="1292">
  1382.             <Token id="content" type="str">root</Token>
  1383.         </Rule>
  1384.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER null request" sid="1296">
  1385.             <Token id="content" type="str">\0</Token>
  1386.         </Rule>
  1387.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER remote command execution attempt" sid="1304">
  1388.             <Token id="content" type="str">;</Token>
  1389.         </Rule>
  1390.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER remote command pipe execution attempt" sid="1308">
  1391.             <Token id="content" type="str">|</Token>
  1392.         </Rule>
  1393.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER bomb attempt" sid="1312">
  1394.             <Token id="content" type="str">@@</Token>
  1395.         </Rule>
  1396.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER redirection attempt" sid="1320">
  1397.             <Token id="content" type="str">@</Token>
  1398.         </Rule>
  1399.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER cybercop query" sid="1324">
  1400.             <Token id="content" type="str" depth="10">\n     </Token>
  1401.         </Rule>
  1402.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER 0 query" sid="1328">
  1403.             <Token id="content" type="str">0</Token>
  1404.         </Rule>
  1405.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER . query" sid="1332">
  1406.             <Token id="content" type="str">.</Token>
  1407.         </Rule>
  1408.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="79" remport="*" name="FINGER version query" sid="6164">
  1409.             <Token id="content" type="str">version</Token>
  1410.         </Rule>
  1411.     </RuleList>
  1412.     <RuleList name="icmp-info.rules">
  1413.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IRDP router advertisement" sid="1452" enabled="0">
  1414.             <Token id="icmp_type" type="int">9</Token>
  1415.         </Rule>
  1416.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IRDP router selection" sid="1456" enabled="0">
  1417.             <Token id="icmp_type" type="int">10</Token>
  1418.         </Rule>
  1419.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING undefined code" sid="1460" enabled="0">
  1420.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1421.             <Token id="icmp_type" type="int">8</Token>
  1422.         </Rule>
  1423.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING *NIX" sid="1464" enabled="0">
  1424.             <Token id="icmp_type" type="int">8</Token>
  1425.             <Token id="content" type="str" depth="32">\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F</Token>
  1426.         </Rule>
  1427.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING BSDtype" sid="1472" enabled="0">
  1428.             <Token id="icmp_type" type="int">8</Token>
  1429.             <Token id="content" type="str" depth="32">\b\t\n\v\f\r\x0E\x0F\x10\x11\x12\x13\x14\x15\x16\x17</Token>
  1430.         </Rule>
  1431.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING BayRS Router" sid="1476" enabled="0">
  1432.             <Token id="icmp_type" type="int">8</Token>
  1433.             <Token id="content" type="str" depth="32">\x01\x02\x03\x04\x05\x06\a\b\t\n\v\f\r\x0E\x0F</Token>
  1434.         </Rule>
  1435.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING BeOS4.x" sid="1480" enabled="0">
  1436.             <Token id="icmp_type" type="int">8</Token>
  1437.             <Token id="content" type="str" depth="32">\0\0\0\0\0\0\0\0\0\0\0\0\b\t\n\v</Token>
  1438.         </Rule>
  1439.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Cisco Type.x" sid="1484" enabled="0">
  1440.             <Token id="icmp_type" type="int">8</Token>
  1441.             <Token id="content" type="str" depth="32">\xAB\xCD\xAB\xCD\xAB\xCD\xAB\xCD\xAB\xCD\xAB\xCD\xAB\xCD\xAB\xCD</Token>
  1442.         </Rule>
  1443.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Delphi-Piette Windows" sid="1488" enabled="0">
  1444.             <Token id="icmp_type" type="int">8</Token>
  1445.             <Token id="content" type="str" depth="32">Pinging from Del</Token>
  1446.         </Rule>
  1447.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Flowpoint2200 or Network Management Software" sid="1492" enabled="0">
  1448.             <Token id="icmp_type" type="int">8</Token>
  1449.             <Token id="content" type="str" depth="32">\x01\x02\x03\x04\x05\x06\a\b\t\n\v\f\r\x0E\x0F\x10</Token>
  1450.         </Rule>
  1451.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING IP NetMonitor Macintosh" sid="1496" enabled="0">
  1452.             <Token id="icmp_type" type="int">8</Token>
  1453.             <Token id="content" type="str" depth="32">\xA9 Sustainable So</Token>
  1454.         </Rule>
  1455.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING LINUX/*BSD" sid="1500" enabled="0">
  1456.             <Token id="dsize" type="int">8</Token>
  1457.             <Token id="ip_id" type="int">13170</Token>
  1458.             <Token id="icmp_type" type="int">8</Token>
  1459.         </Rule>
  1460.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Microsoft Windows" sid="1504" enabled="0">
  1461.             <Token id="icmp_type" type="int">8</Token>
  1462.             <Token id="content" type="str" depth="32">0123456789abcdefghijklmnop</Token>
  1463.         </Rule>
  1464.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Network Toolbox 3 Windows" sid="1508" enabled="0">
  1465.             <Token id="icmp_type" type="int">8</Token>
  1466.             <Token id="content" type="str" depth="32">================</Token>
  1467.         </Rule>
  1468.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Ping-O-MeterWindows" sid="1512" enabled="0">
  1469.             <Token id="icmp_type" type="int">8</Token>
  1470.             <Token id="content" type="str" depth="32">OMeterObeseArmad</Token>
  1471.         </Rule>
  1472.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Pinger Windows" sid="1516" enabled="0">
  1473.             <Token id="icmp_type" type="int">8</Token>
  1474.             <Token id="content" type="str" depth="32">Data\0\0\0\0\0\0\0\0\0\0\0\0</Token>
  1475.         </Rule>
  1476.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Seer Windows" sid="1520" enabled="0">
  1477.             <Token id="icmp_type" type="int">8</Token>
  1478.             <Token id="content" type="str" depth="32">\x88\x04              </Token>
  1479.         </Rule>
  1480.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Sun Solaris" sid="1524" enabled="0">
  1481.             <Token id="dsize" type="int">8</Token>
  1482.             <Token id="icmp_type" type="int">8</Token>
  1483.         </Rule>
  1484.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Windows" sid="1528" enabled="0">
  1485.             <Token id="icmp_type" type="int">8</Token>
  1486.             <Token id="content" type="str" depth="16">abcdefghijklmnop</Token>
  1487.         </Rule>
  1488.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING" sid="1536" enabled="0">
  1489.             <Token id="icmp_code" type="int">0</Token>
  1490.             <Token id="icmp_type" type="int">8</Token>
  1491.         </Rule>
  1492.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP traceroute" sid="1540" enabled="0">
  1493.             <Token id="icmp_type" type="int">8</Token>
  1494.             <Token id="ip_ttl" type="int">1</Token>
  1495.         </Rule>
  1496.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Address Mask Reply" sid="1544" enabled="0">
  1497.             <Token id="icmp_code" type="int">0</Token>
  1498.             <Token id="icmp_type" type="int">18</Token>
  1499.         </Rule>
  1500.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Address Mask Reply undefined code" sid="1548" enabled="0">
  1501.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1502.             <Token id="icmp_type" type="int">18</Token>
  1503.         </Rule>
  1504.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Address Mask Request" sid="1552" enabled="0">
  1505.             <Token id="icmp_code" type="int">0</Token>
  1506.             <Token id="icmp_type" type="int">17</Token>
  1507.         </Rule>
  1508.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Address Mask Request undefined code" sid="1556" enabled="0">
  1509.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1510.             <Token id="icmp_type" type="int">17</Token>
  1511.         </Rule>
  1512.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Alternate Host Address" sid="1560" enabled="0">
  1513.             <Token id="icmp_code" type="int">0</Token>
  1514.             <Token id="icmp_type" type="int">6</Token>
  1515.         </Rule>
  1516.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Alternate Host Address undefined code" sid="1564" enabled="0">
  1517.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1518.             <Token id="icmp_type" type="int">6</Token>
  1519.         </Rule>
  1520.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Datagram Conversion Error" sid="1568" enabled="0">
  1521.             <Token id="icmp_code" type="int">0</Token>
  1522.             <Token id="icmp_type" type="int">31</Token>
  1523.         </Rule>
  1524.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Datagram Conversion Error undefined code" sid="1572" enabled="0">
  1525.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1526.             <Token id="icmp_type" type="int">31</Token>
  1527.         </Rule>
  1528.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Destination Host Unknown" sid="1576" enabled="0">
  1529.             <Token id="icmp_code" type="int">7</Token>
  1530.             <Token id="icmp_type" type="int">3</Token>
  1531.         </Rule>
  1532.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Destination Network Unknown" sid="1580" enabled="0">
  1533.             <Token id="icmp_code" type="int">6</Token>
  1534.             <Token id="icmp_type" type="int">3</Token>
  1535.         </Rule>
  1536.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Fragmentation Needed and DF bit was set" sid="1584" enabled="0">
  1537.             <Token id="icmp_code" type="int">4</Token>
  1538.             <Token id="icmp_type" type="int">3</Token>
  1539.         </Rule>
  1540.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Host Precedence Violation" sid="1588" enabled="0">
  1541.             <Token id="icmp_code" type="int">14</Token>
  1542.             <Token id="icmp_type" type="int">3</Token>
  1543.         </Rule>
  1544.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Host Unreachable for Type of Service" sid="1592" enabled="0">
  1545.             <Token id="icmp_code" type="int">12</Token>
  1546.             <Token id="icmp_type" type="int">3</Token>
  1547.         </Rule>
  1548.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Host Unreachable" sid="1596" enabled="0">
  1549.             <Token id="icmp_code" type="int">1</Token>
  1550.             <Token id="icmp_type" type="int">3</Token>
  1551.         </Rule>
  1552.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Network Unreachable for Type of Service" sid="1600" enabled="0">
  1553.             <Token id="icmp_code" type="int">11</Token>
  1554.             <Token id="icmp_type" type="int">3</Token>
  1555.         </Rule>
  1556.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Network Unreachable" sid="1604" enabled="0">
  1557.             <Token id="icmp_code" type="int">0</Token>
  1558.             <Token id="icmp_type" type="int">3</Token>
  1559.         </Rule>
  1560.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Port Unreachable" sid="1608" enabled="0">
  1561.             <Token id="icmp_code" type="int">3</Token>
  1562.             <Token id="icmp_type" type="int">3</Token>
  1563.         </Rule>
  1564.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Precedence Cutoff in effect" sid="1612" enabled="0">
  1565.             <Token id="icmp_code" type="int">15</Token>
  1566.             <Token id="icmp_type" type="int">3</Token>
  1567.         </Rule>
  1568.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Protocol Unreachable" sid="1616" enabled="0">
  1569.             <Token id="icmp_code" type="int">2</Token>
  1570.             <Token id="icmp_type" type="int">3</Token>
  1571.         </Rule>
  1572.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Source Host Isolated" sid="1620" enabled="0">
  1573.             <Token id="icmp_code" type="int">8</Token>
  1574.             <Token id="icmp_type" type="int">3</Token>
  1575.         </Rule>
  1576.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable Source Route Failed" sid="1624" enabled="0">
  1577.             <Token id="icmp_code" type="int">5</Token>
  1578.             <Token id="icmp_type" type="int">3</Token>
  1579.         </Rule>
  1580.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Destination Unreachable cndefined code" sid="1628" enabled="0">
  1581.             <Token id="icmp_code" type="int" rel="greater">15</Token>
  1582.             <Token id="icmp_type" type="int">3</Token>
  1583.         </Rule>
  1584.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Echo Reply" sid="1632" enabled="0">
  1585.             <Token id="icmp_code" type="int">0</Token>
  1586.             <Token id="icmp_type" type="int">0</Token>
  1587.         </Rule>
  1588.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Echo Reply undefined code" sid="1636" enabled="0">
  1589.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1590.             <Token id="icmp_type" type="int">0</Token>
  1591.         </Rule>
  1592.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Fragment Reassembly Time Exceeded" sid="1640" enabled="0">
  1593.             <Token id="icmp_code" type="int">1</Token>
  1594.             <Token id="icmp_type" type="int">11</Token>
  1595.         </Rule>
  1596.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IPV6 I-Am-Here" sid="1644" enabled="0">
  1597.             <Token id="icmp_code" type="int">0</Token>
  1598.             <Token id="icmp_type" type="int">34</Token>
  1599.         </Rule>
  1600.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IPV6 I-Am-Here undefined code" sid="1648" enabled="0">
  1601.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1602.             <Token id="icmp_type" type="int">34</Token>
  1603.         </Rule>
  1604.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IPV6 Where-Are-You" sid="1652" enabled="0">
  1605.             <Token id="icmp_code" type="int">0</Token>
  1606.             <Token id="icmp_type" type="int">33</Token>
  1607.         </Rule>
  1608.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP IPV6 Where-Are-You undefined code" sid="1656" enabled="0">
  1609.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1610.             <Token id="icmp_type" type="int">33</Token>
  1611.         </Rule>
  1612.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Information Reply" sid="1660" enabled="0">
  1613.             <Token id="icmp_code" type="int">0</Token>
  1614.             <Token id="icmp_type" type="int">16</Token>
  1615.         </Rule>
  1616.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Information Reply undefined code" sid="1664" enabled="0">
  1617.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1618.             <Token id="icmp_type" type="int">16</Token>
  1619.         </Rule>
  1620.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Information Request" sid="1668" enabled="0">
  1621.             <Token id="icmp_code" type="int">0</Token>
  1622.             <Token id="icmp_type" type="int">15</Token>
  1623.         </Rule>
  1624.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Information Request undefined code" sid="1672" enabled="0">
  1625.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1626.             <Token id="icmp_type" type="int">15</Token>
  1627.         </Rule>
  1628.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Host Redirect" sid="1676" enabled="0">
  1629.             <Token id="icmp_code" type="int">0</Token>
  1630.             <Token id="icmp_type" type="int">32</Token>
  1631.         </Rule>
  1632.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Host Redirect undefined code" sid="1680" enabled="0">
  1633.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1634.             <Token id="icmp_type" type="int">32</Token>
  1635.         </Rule>
  1636.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Registration Reply" sid="1684" enabled="0">
  1637.             <Token id="icmp_code" type="int">0</Token>
  1638.             <Token id="icmp_type" type="int">36</Token>
  1639.         </Rule>
  1640.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Registration Reply undefined code" sid="1688" enabled="0">
  1641.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1642.             <Token id="icmp_type" type="int">36</Token>
  1643.         </Rule>
  1644.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Registration Request" sid="1692" enabled="0">
  1645.             <Token id="icmp_code" type="int">0</Token>
  1646.             <Token id="icmp_type" type="int">35</Token>
  1647.         </Rule>
  1648.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Mobile Registration Request undefined code" sid="1696" enabled="0">
  1649.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1650.             <Token id="icmp_type" type="int">35</Token>
  1651.         </Rule>
  1652.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Parameter Problem Bad Length" sid="1700" enabled="0">
  1653.             <Token id="icmp_code" type="int">2</Token>
  1654.             <Token id="icmp_type" type="int">12</Token>
  1655.         </Rule>
  1656.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Parameter Problem Missing a Required Option" sid="1704" enabled="0">
  1657.             <Token id="icmp_code" type="int">1</Token>
  1658.             <Token id="icmp_type" type="int">12</Token>
  1659.         </Rule>
  1660.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Parameter Problem Unspecified Error" sid="1708" enabled="0">
  1661.             <Token id="icmp_code" type="int">0</Token>
  1662.             <Token id="icmp_type" type="int">12</Token>
  1663.         </Rule>
  1664.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Parameter Problem undefined Code" sid="1712" enabled="0">
  1665.             <Token id="icmp_code" type="int" rel="greater">2</Token>
  1666.             <Token id="icmp_type" type="int">12</Token>
  1667.         </Rule>
  1668.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Photuris Reserved" sid="1716" enabled="0">
  1669.             <Token id="icmp_code" type="int">0</Token>
  1670.             <Token id="icmp_type" type="int">40</Token>
  1671.         </Rule>
  1672.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Photuris Unknown Security Parameters Index" sid="1720" enabled="0">
  1673.             <Token id="icmp_code" type="int">1</Token>
  1674.             <Token id="icmp_type" type="int">40</Token>
  1675.         </Rule>
  1676.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Photuris Valid Security Parameters, But Authentication Failed" sid="1724" enabled="0">
  1677.             <Token id="icmp_code" type="int">2</Token>
  1678.             <Token id="icmp_type" type="int">40</Token>
  1679.         </Rule>
  1680.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Photuris Valid Security Parameters, But Decryption Failed" sid="1728" enabled="0">
  1681.             <Token id="icmp_code" type="int">3</Token>
  1682.             <Token id="icmp_type" type="int">40</Token>
  1683.         </Rule>
  1684.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Photuris undefined code!" sid="1732" enabled="0">
  1685.             <Token id="icmp_code" type="int" rel="greater">3</Token>
  1686.             <Token id="icmp_type" type="int">40</Token>
  1687.         </Rule>
  1688.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Redirect for TOS and Host" sid="1744" enabled="0">
  1689.             <Token id="icmp_code" type="int">3</Token>
  1690.             <Token id="icmp_type" type="int">5</Token>
  1691.         </Rule>
  1692.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Redirect for TOS and Network" sid="1748" enabled="0">
  1693.             <Token id="icmp_code" type="int">2</Token>
  1694.             <Token id="icmp_type" type="int">5</Token>
  1695.         </Rule>
  1696.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Redirect undefined code" sid="1752" enabled="0">
  1697.             <Token id="icmp_code" type="int" rel="greater">3</Token>
  1698.             <Token id="icmp_type" type="int">5</Token>
  1699.         </Rule>
  1700.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Reserved for Security Type 19" sid="1756" enabled="0">
  1701.             <Token id="icmp_code" type="int">0</Token>
  1702.             <Token id="icmp_type" type="int">19</Token>
  1703.         </Rule>
  1704.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Reserved for Security Type 19 undefined code" sid="1760" enabled="0">
  1705.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1706.             <Token id="icmp_type" type="int">19</Token>
  1707.         </Rule>
  1708.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Router Advertisement" sid="1764" enabled="0">
  1709.             <Token id="icmp_code" type="int">0</Token>
  1710.             <Token id="icmp_type" type="int">9</Token>
  1711.         </Rule>
  1712.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Router Selection" sid="1772" enabled="0">
  1713.             <Token id="icmp_code" type="int">0</Token>
  1714.             <Token id="icmp_type" type="int">10</Token>
  1715.         </Rule>
  1716.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP SKIP" sid="1780" enabled="0">
  1717.             <Token id="icmp_code" type="int">0</Token>
  1718.             <Token id="icmp_type" type="int">39</Token>
  1719.         </Rule>
  1720.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP SKIP undefined code" sid="1784" enabled="0">
  1721.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1722.             <Token id="icmp_type" type="int">39</Token>
  1723.         </Rule>
  1724.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Source Quench undefined code" sid="1792" enabled="0">
  1725.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1726.             <Token id="icmp_type" type="int">4</Token>
  1727.         </Rule>
  1728.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Time-To-Live Exceeded in Transit" sid="1796" enabled="0">
  1729.             <Token id="icmp_code" type="int">0</Token>
  1730.             <Token id="icmp_type" type="int">11</Token>
  1731.         </Rule>
  1732.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Time-To-Live Exceeded in Transit undefined code" sid="1800" enabled="0">
  1733.             <Token id="icmp_code" type="int" rel="greater">1</Token>
  1734.             <Token id="icmp_type" type="int">11</Token>
  1735.         </Rule>
  1736.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Timestamp Reply" sid="1804" enabled="0">
  1737.             <Token id="icmp_code" type="int">0</Token>
  1738.             <Token id="icmp_type" type="int">14</Token>
  1739.         </Rule>
  1740.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Timestamp Reply undefined code" sid="1808" enabled="0">
  1741.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1742.             <Token id="icmp_type" type="int">14</Token>
  1743.         </Rule>
  1744.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Timestamp Request" sid="1812" enabled="0">
  1745.             <Token id="icmp_code" type="int">0</Token>
  1746.             <Token id="icmp_type" type="int">13</Token>
  1747.         </Rule>
  1748.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Timestamp Request undefined code" sid="1816" enabled="0">
  1749.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1750.             <Token id="icmp_type" type="int">13</Token>
  1751.         </Rule>
  1752.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Traceroute" sid="1824" enabled="0">
  1753.             <Token id="icmp_code" type="int">0</Token>
  1754.             <Token id="icmp_type" type="int">30</Token>
  1755.         </Rule>
  1756.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Traceroute undefined code" sid="1828" enabled="0">
  1757.             <Token id="icmp_code" type="int" rel="greater">0</Token>
  1758.             <Token id="icmp_type" type="int">30</Token>
  1759.         </Rule>
  1760.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 1" sid="1832" enabled="0">
  1761.             <Token id="icmp_code" type="int">0</Token>
  1762.             <Token id="icmp_type" type="int">1</Token>
  1763.         </Rule>
  1764.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 1 undefined code" sid="1836" enabled="0">
  1765.             <Token id="icmp_type" type="int">1</Token>
  1766.         </Rule>
  1767.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 2" sid="1840" enabled="0">
  1768.             <Token id="icmp_code" type="int">0</Token>
  1769.             <Token id="icmp_type" type="int">2</Token>
  1770.         </Rule>
  1771.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 2 undefined code" sid="1844" enabled="0">
  1772.             <Token id="icmp_type" type="int">2</Token>
  1773.         </Rule>
  1774.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 7" sid="1848" enabled="0">
  1775.             <Token id="icmp_code" type="int">0</Token>
  1776.             <Token id="icmp_type" type="int">7</Token>
  1777.         </Rule>
  1778.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP unassigned type 7 undefined code" sid="1852" enabled="0">
  1779.             <Token id="icmp_type" type="int">7</Token>
  1780.         </Rule>
  1781.     </RuleList>
  1782.     <RuleList name="icmp.rules">
  1783.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP ISS Pinger" sid="1860">
  1784.             <Token id="icmp_type" type="int">8</Token>
  1785.             <Token id="content" type="str" depth="32">ISSPNGRQ</Token>
  1786.         </Rule>
  1787.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP L3retriever Ping" sid="1864">
  1788.             <Token id="icmp_code" type="int">0</Token>
  1789.             <Token id="icmp_type" type="int">8</Token>
  1790.             <Token id="content" type="str" depth="32">ABCDEFGHIJKLMNOPQRSTUVWABCDEFGHI</Token>
  1791.         </Rule>
  1792.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Nemesis v1.1 Echo" sid="1868">
  1793.             <Token id="dsize" type="int">20</Token>
  1794.             <Token id="echo_id" type="int">0</Token>
  1795.             <Token id="echo_seq" type="int">0</Token>
  1796.             <Token id="icmp_type" type="int">8</Token>
  1797.             <Token id="content" type="str">\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0</Token>
  1798.         </Rule>
  1799.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING NMAP" sid="1876">
  1800.             <Token id="dsize" type="int">0</Token>
  1801.             <Token id="icmp_type" type="int">8</Token>
  1802.         </Rule>
  1803.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP icmpenum v1.1.1" sid="1884">
  1804.             <Token id="dsize" type="int">0</Token>
  1805.             <Token id="echo_id" type="int">666</Token>
  1806.             <Token id="echo_seq" type="int">0</Token>
  1807.             <Token id="ip_id" type="int">666</Token>
  1808.             <Token id="icmp_type" type="int">8</Token>
  1809.         </Rule>
  1810.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP redirect host" sid="1888">
  1811.             <Token id="icmp_code" type="int">1</Token>
  1812.             <Token id="icmp_type" type="int">5</Token>
  1813.         </Rule>
  1814.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP redirect net" sid="1892">
  1815.             <Token id="icmp_code" type="int">0</Token>
  1816.             <Token id="icmp_type" type="int">5</Token>
  1817.         </Rule>
  1818.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP superscan echo" sid="1896">
  1819.             <Token id="dsize" type="int">8</Token>
  1820.             <Token id="icmp_type" type="int">8</Token>
  1821.             <Token id="content" type="str">\0\0\0\0\0\0\0\0</Token>
  1822.         </Rule>
  1823.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP traceroute ipopts" sid="1900">
  1824.             <Token id="ip_opt" type="int">0</Token>
  1825.             <Token id="icmp_type" type="int">0</Token>
  1826.         </Rule>
  1827.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP webtrends scanner" sid="1904">
  1828.             <Token id="icmp_code" type="int">0</Token>
  1829.             <Token id="icmp_type" type="int">8</Token>
  1830.             <Token id="content" type="str">\0\0\0\0EEEEEEEEEEEE</Token>
  1831.         </Rule>
  1832.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Source Quench" sid="1908">
  1833.             <Token id="icmp_code" type="int">0</Token>
  1834.             <Token id="icmp_type" type="int">4</Token>
  1835.         </Rule>
  1836.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Broadscan Smurf Scanner" sid="1912">
  1837.             <Token id="dsize" type="int">4</Token>
  1838.             <Token id="echo_id" type="int">0</Token>
  1839.             <Token id="echo_seq" type="int">0</Token>
  1840.             <Token id="icmp_type" type="int">8</Token>
  1841.         </Rule>
  1842.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING speedera" sid="1920">
  1843.             <Token id="icmp_type" type="int">8</Token>
  1844.             <Token id="content" type="str" depth="100">89:;&lt;=&gt;?</Token>
  1845.         </Rule>
  1846.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP TJPingPro1.1Build 2 Windows" sid="1924">
  1847.             <Token id="icmp_type" type="int">8</Token>
  1848.             <Token id="content" type="str" depth="32">TJPingPro by Jim</Token>
  1849.         </Rule>
  1850.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING WhatsupGold Windows" sid="1928">
  1851.             <Token id="icmp_type" type="int">8</Token>
  1852.             <Token id="content" type="str" depth="32">WhatsUp - A Netw</Token>
  1853.         </Rule>
  1854.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING CyberKit 2.2 Windows" sid="1932">
  1855.             <Token id="icmp_type" type="int">8</Token>
  1856.             <Token id="content" type="str" depth="32">\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA\xAA</Token>
  1857.         </Rule>
  1858.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP PING Sniffer Pro/NetXRay network scan" sid="1936">
  1859.             <Token id="icmp_type" type="int">8</Token>
  1860.             <Token id="content" type="str" depth="32">Cinco Network, Inc.</Token>
  1861.         </Rule>
  1862.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication Administratively Prohibited" sid="1940">
  1863.             <Token id="icmp_code" type="int">13</Token>
  1864.             <Token id="icmp_type" type="int">3</Token>
  1865.         </Rule>
  1866.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication Administratively Prohibited" sid="1941">
  1867.             <Token id="icmp_code" type="int">13</Token>
  1868.             <Token id="icmp_type" type="int">3</Token>
  1869.         </Rule>
  1870.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited" sid="1944">
  1871.             <Token id="icmp_code" type="int">10</Token>
  1872.             <Token id="icmp_type" type="int">3</Token>
  1873.         </Rule>
  1874.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited" sid="1945">
  1875.             <Token id="icmp_code" type="int">10</Token>
  1876.             <Token id="icmp_type" type="int">3</Token>
  1877.         </Rule>
  1878.         <Rule al="Monitor" ar="Allow" dir="out" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication with Destination Network is Administratively Prohibited" sid="1948">
  1879.             <Token id="icmp_code" type="int">9</Token>
  1880.             <Token id="icmp_type" type="int">3</Token>
  1881.         </Rule>
  1882.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="all" remaddr_id="all" name="ICMP Destination Unreachable Communication with Destination Network is Administratively Prohibited" sid="1949">
  1883.             <Token id="icmp_code" type="int">9</Token>
  1884.             <Token id="icmp_type" type="int">3</Token>
  1885.         </Rule>
  1886.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP Large ICMP Packet" sid="1996">
  1887.             <Token id="dsize" type="int" rel="greater">800</Token>
  1888.         </Rule>
  1889.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="ICMP digital island bandwidth query" sid="7252">
  1890.             <Token id="content" type="str" depth="22">mailto:ops@digisle.com</Token>
  1891.         </Rule>
  1892.     </RuleList>
  1893.     <RuleList name="info.rules">
  1894.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="80" name="INFO Connection Closed MSG from Port 80" sid="1952" enabled="0">
  1895.             <Token id="content" type="str" nocase="1">Connection closed by foreign host</Token>
  1896.         </Rule>
  1897.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="INFO FTP no password" sid="1956" enabled="0">
  1898.             <Token id="content" type="str" nocase="1">PASS</Token>
  1899.             <Token id="pcre" type="str">=/^PASS\s*\n/smi</Token>
  1900.         </Rule>
  1901.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="INFO battle-mail traffic" sid="1960" enabled="0">
  1902.             <Token id="content" type="str">BattleMail</Token>
  1903.         </Rule>
  1904.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="INFO FTP Bad login" sid="1964" enabled="0">
  1905.             <Token id="content" type="str">530 </Token>
  1906.             <Token id="pcre" type="str">=/^530\s+(Login|User)/smi</Token>
  1907.         </Rule>
  1908.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="23" remport="*" name="INFO TELNET Bad Login" sid="1968" enabled="0">
  1909.             <Token id="content" type="str" nocase="1">Login failed</Token>
  1910.         </Rule>
  1911.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="INFO psyBNC access" sid="1972" enabled="0">
  1912.             <Token id="content" type="str">Welcome!psyBNC@lam3rz.de</Token>
  1913.         </Rule>
  1914.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="23" remport="*" name="INFO TELNET Bad Login" sid="5004" enabled="0">
  1915.             <Token id="content" type="str" nocase="1">Login incorrect</Token>
  1916.         </Rule>
  1917.     </RuleList>
  1918.     <RuleList name="attack-responses.rules">
  1919.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES command completed" sid="1976">
  1920.             <Token id="content" type="str" nocase="1">Command completed</Token>
  1921.         </Rule>
  1922.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES command error" sid="1980">
  1923.             <Token id="content" type="str" nocase="1">Bad command or filename</Token>
  1924.         </Rule>
  1925.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES file copied ok" sid="1988">
  1926.             <Token id="content" type="str" nocase="1">1 file(s) copied</Token>
  1927.         </Rule>
  1928.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="ATTACK-RESPONSES id check returned root" sid="1992">
  1929.             <Token id="content" type="str">uid=0(root)</Token>
  1930.         </Rule>
  1931.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="ATTACK-RESPONSES id check returned root" sid="1993">
  1932.             <Token id="content" type="str">uid=0(root)</Token>
  1933.         </Rule>
  1934.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES Invalid URL" sid="4800">
  1935.             <Token id="content" type="str" nocase="1">Invalid URL</Token>
  1936.         </Rule>
  1937.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES 403 Forbidden" sid="4804">
  1938.             <Token id="content" type="str" depth="12">HTTP/1.1 403</Token>
  1939.         </Rule>
  1940.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="ATTACK-RESPONSES directory listing" sid="5168">
  1941.             <Token id="content" type="str">Volume Serial Number</Token>
  1942.         </Rule>
  1943.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8002" remport="*" name="ATTACK-RESPONSES oracle one hour install" sid="5856">
  1944.             <Token id="content" type="str">Oracle Applications One-Hour Install</Token>
  1945.         </Rule>
  1946.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="ATTACK-RESPONSES index of /cgi-bin/ response" sid="6664">
  1947.             <Token id="content" type="str" nocase="1">Index of /cgi-bin/</Token>
  1948.         </Rule>
  1949.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="ATTACK-RESPONSES successful gobbles ssh exploit GOBBLE" sid="7240">
  1950.             <Token id="content" type="str">*GOBBLE*</Token>
  1951.         </Rule>
  1952.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="ATTACK-RESPONSES successful gobbles ssh exploit uname" sid="7244">
  1953.             <Token id="content" type="str">uname</Token>
  1954.         </Rule>
  1955.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="ATTACK-RESPONSES id check returned userid" sid="7528">
  1956.             <Token id="content" type="str">uid=</Token>
  1957.             <Token id="byte_test" type="int" format="like-c" oper="less" relative="1" size="5">65537</Token>
  1958.             <Token id="content" type="str" within="15"> gid=</Token>
  1959.             <Token id="byte_test" type="int" format="like-c" oper="less" relative="1" size="5">65537</Token>
  1960.         </Rule>
  1961.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="749" remport="*" name="ATTACK-RESPONSES successful kadmind buffer overflow attempt" sid="7600">
  1962.             <Token id="content" type="str" depth="8">*GOBBLE*</Token>
  1963.         </Rule>
  1964.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="751" remport="*" name="ATTACK-RESPONSES successful kadmind buffer overflow attempt" sid="7604">
  1965.             <Token id="content" type="str" depth="8">*GOBBLE*</Token>
  1966.         </Rule>
  1967.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="512" remport="*" name="ATTACK-RESPONSES rexec username too long response" sid="8416">
  1968.             <Token id="content" type="str" depth="17">username too long</Token>
  1969.         </Rule>
  1970.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="!21-23" remport="*" name="ATTACK-RESPONSES Microsoft cmd.exe banner" sid="8492">
  1971.             <Token id="content" type="str">Microsoft Windows</Token>
  1972.             <Token id="content" type="str" distance="0">(C) Copyright 1985-</Token>
  1973.             <Token id="content" type="str" distance="0">Microsoft Corp.</Token>
  1974.         </Rule>
  1975.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="ATTACK-RESPONSES successful cross site scripting forced download attempt" sid="9648">
  1976.             <Token id="content" type="str">\nReferer: res:/C:</Token>
  1977.         </Rule>
  1978.     </RuleList>
  1979.     <RuleList name="misc.rules">
  1980.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="MISC source route lssr" sid="2000">
  1981.             <Token id="ip_opt" type="int">5</Token>
  1982.         </Rule>
  1983.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="MISC source route lssre" sid="2004">
  1984.             <Token id="ip_opt" type="int">5</Token>
  1985.         </Rule>
  1986.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="MISC source route ssrr" sid="2008">
  1987.             <Token id="ip_opt" type="int">6</Token>
  1988.         </Rule>
  1989.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="0-1023" remport="20" name="MISC Source Port 20 to &lt;1024" sid="2012">
  1990.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  1991.         </Rule>
  1992.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="0-1023" remport="53" name="MISC source port 53 to &lt;1024" sid="2016">
  1993.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  1994.         </Rule>
  1995.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1417" remport="*" name="MISC Insecure TIMBUKTU Password" sid="2020">
  1996.             <Token id="content" type="str" depth="16">\x05\0&gt;</Token>
  1997.         </Rule>
  1998.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5631" remport="*" name="MISC PCAnywhere Attempted Administrator Login" sid="2028">
  1999.             <Token id="content" type="str">ADMINISTRATOR</Token>
  2000.         </Rule>
  2001.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="70" remport="*" name="MISC gopher proxy" sid="2032">
  2002.             <Token id="content" type="str" nocase="1">ftp:</Token>
  2003.             <Token id="content" type="str">@/</Token>
  2004.         </Rule>
  2005.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5631-5632" remport="*" name="MISC PCAnywhere Failed Login" sid="2048">
  2006.             <Token id="content" type="str" depth="16">Invalid login</Token>
  2007.         </Rule>
  2008.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7161" remport="*" name="MISC Cisco Catalyst Remote Access" sid="2052">
  2009.             <Token id="tcp_flg" type="str" mask="12">SA</Token>
  2010.         </Rule>
  2011.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="27374" name="MISC ramen worm" sid="2056">
  2012.             <Token id="content" type="str" depth="8" nocase="1">GET </Token>
  2013.         </Rule>
  2014.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="161" remport="*" name="MISC SNMP NT UserList" sid="2064">
  2015.             <Token id="content" type="str">+\x06\x10@\x14\xD1\x02\x19</Token>
  2016.         </Rule>
  2017.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="177" remport="*" name="MISC xdmcp query" sid="2068">
  2018.             <Token id="content" type="str">\0\x01\0\x03\0\x01\0</Token>
  2019.         </Rule>
  2020.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="MISC Tiny Fragments" sid="2088">
  2021.             <Token id="dsize" type="int" rel="less">25</Token>
  2022.             <Token id="ip_frg" type="str">M</Token>
  2023.         </Rule>
  2024.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1900" remport="*" name="MISC UPnP malformed advertisement" sid="5536">
  2025.             <Token id="content" type="str" nocase="1">NOTIFY * </Token>
  2026.         </Rule>
  2027.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1900" remport="*" name="MISC UPnP Location overflow" sid="5552">
  2028.             <Token id="content" type="str" nocase="1">Location:</Token>
  2029.             <Token id="pcre" type="str">=/^Location\:[^\n]{128}/smi</Token>
  2030.         </Rule>
  2031.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="aim_servers" locport="*" remport="*" name="MISC AIM AddGame attempt" sid="5572">
  2032.             <Token id="content" type="str" nocase="1">aim:AddGame?</Token>
  2033.         </Rule>
  2034.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3389" remport="*" name="MISC MS Terminal server request RDP" sid="5788">
  2035.             <Token id="content" type="str" depth="11">\x03\0\0\v\x06\xE0\0\0\0\0\0</Token>
  2036.         </Rule>
  2037.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3389" remport="*" name="MISC MS Terminal server request" sid="5792">
  2038.             <Token id="content" type="str" depth="3">\x03\0\0</Token>
  2039.             <Token id="content" type="str" depth="6" offset="5">\xE0\0\0\0\0\0</Token>
  2040.         </Rule>
  2041.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="7001" remport="*" name="MISC AFS access" sid="6016">
  2042.             <Token id="content" type="str">\0\0\x03\xE7\0\0\0\0\0\0\0e\0\0\0\0\0\0\0\0\r\x05\0\0\0\0\0\0\0</Token>
  2043.         </Rule>
  2044.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="32000" remport="*" name="MISC Xtramail Username overflow attempt" sid="6544">
  2045.             <Token id="dsize" type="int" rel="greater">500</Token>
  2046.             <Token id="content" type="str" nocase="1">Username:</Token>
  2047.             <Token id="isdataat" type="int" rel="relative">100</Token>
  2048.             <Token id="pcre" type="str">=/^Username\:[^\n]{100}/smi</Token>
  2049.         </Rule>
  2050.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="aim_servers" locport="*" remport="*" name="MISC AIM AddExternalApp attempt" sid="7008">
  2051.             <Token id="content" type="str" nocase="1">aim:AddExternalApp?</Token>
  2052.         </Rule>
  2053.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2533" remport="*" name="MISC Alcatel PABX 4400 connection attempt" sid="7276">
  2054.             <Token id="content" type="str" depth="3">\0\x01C</Token>
  2055.         </Rule>
  2056.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="177" remport="*" name="MISC xdmcp info query" sid="7468">
  2057.             <Token id="content" type="str">\0\x01\0\x02\0\x01\0</Token>
  2058.         </Rule>
  2059.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="443" remport="*" name="MISC OpenSSL Worm traffic" sid="7548">
  2060.             <Token id="content" type="str" nocase="1">TERM=xterm</Token>
  2061.         </Rule>
  2062.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="http_servers" remaddr_id="external_net" locport="2002" remport="2002" name="MISC slapper worm admin traffic" sid="7556">
  2063.             <Token id="content" type="str" depth="10">\0\0E\0\0E\0\0@\0</Token>
  2064.         </Rule>
  2065.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="67" remport="*" name="MISC bootp hardware address length overflow" sid="7756">
  2066.             <Token id="content" type="str" depth="1">\x01</Token>
  2067.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="1">6</Token>
  2068.         </Rule>
  2069.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="67" remport="*" name="MISC bootp invalid hardware type" sid="7760">
  2070.             <Token id="content" type="str" depth="1">\x01</Token>
  2071.             <Token id="byte_test" type="int" format="big" offset="1" oper="greater" size="1">7</Token>
  2072.         </Rule>
  2073.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="27155" remport="*" name="MISC GlobalSunTech Access Point Information Disclosure attempt" sid="7864">
  2074.             <Token id="content" type="str">gstsearch</Token>
  2075.         </Rule>
  2076.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="7100" remport="*" name="MISC xfs overflow attempt" sid="7948">
  2077.             <Token id="dsize" type="int" rel="greater">512</Token>
  2078.             <Token id="content" type="str" depth="3">B\0\x02</Token>
  2079.         </Rule>
  2080.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS invalid user authentication response" sid="8032">
  2081.             <Token id="content" type="str">E Fatal error, aborting.</Token>
  2082.             <Token id="content" type="str">: no such user</Token>
  2083.         </Rule>
  2084.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS invalid repository response" sid="8036">
  2085.             <Token id="content" type="str">error </Token>
  2086.             <Token id="content" type="str">: no such repository</Token>
  2087.             <Token id="content" type="str">I HATE YOU</Token>
  2088.         </Rule>
  2089.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS double free exploit attempt response" sid="8040">
  2090.             <Token id="content" type="str">free(): warning: chunk is already free</Token>
  2091.         </Rule>
  2092.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS invalid directory response" sid="8044">
  2093.             <Token id="content" type="str">E protocol error: invalid directory syntax in</Token>
  2094.         </Rule>
  2095.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS missing cvsroot response" sid="8048">
  2096.             <Token id="content" type="str">E protocol error: Root request missing</Token>
  2097.         </Rule>
  2098.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS invalid module response" sid="8052">
  2099.             <Token id="content" type="str">cvs server: cannot find module</Token>
  2100.             <Token id="content" type="str" distance="1">error</Token>
  2101.         </Rule>
  2102.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="67" remport="*" name="MISC bootp hostname format string attempt" sid="8156">
  2103.             <Token id="content" type="str" depth="1">\x01</Token>
  2104.             <Token id="content" type="str" distance="240">\f</Token>
  2105.             <Token id="content" type="str" distance="0">%</Token>
  2106.             <Token id="content" type="str" distance="1" within="8">%</Token>
  2107.             <Token id="content" type="str" distance="1" within="8">%</Token>
  2108.         </Rule>
  2109.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="49" remport="*" name="MISC xtacacs failed login response" sid="8164">
  2110.             <Token id="content" type="str" depth="2">\x80\x02</Token>
  2111.             <Token id="content" type="str" distance="4">\x02</Token>
  2112.         </Rule>
  2113.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="500" name="MISC isakmp login failed" sid="8172">
  2114.             <Token id="content" type="str" depth="2" offset="17">\x10\x05</Token>
  2115.             <Token id="content" type="str" distance="13" within="8">\0\0\0\x01\x01\0\0\x18</Token>
  2116.         </Rule>
  2117.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="873" remport="*" name="MISC rsyncd module list access" sid="8188">
  2118.             <Token id="content" type="str" depth="5">#list</Token>
  2119.         </Rule>
  2120.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="873" remport="*" name="MISC rsyncd overflow attempt" sid="8192">
  2121.             <Token id="byte_test" type="int" format="big" oper="greater" size="2">4000</Token>
  2122.             <Token id="content" type="str" depth="2" offset="2">\0\0</Token>
  2123.         </Rule>
  2124.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1723" remport="*" name="MISC Microsoft PPTP Start Control Request buffer overflow attempt" sid="8504">
  2125.             <Token id="dsize" type="int" rel="greater">156</Token>
  2126.             <Token id="content" type="str" depth="2" offset="2">\0\x01</Token>
  2127.             <Token id="content" type="str" depth="2" offset="8">\0\x01</Token>
  2128.         </Rule>
  2129.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="179" name="MISC BGP invalid length" sid="8632">
  2130.             <Token id="content" type="str">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2131.             <Token id="byte_test" type="int" format="big" oper="less" relative="1" size="2">19</Token>
  2132.         </Rule>
  2133.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="179" remport="*" name="MISC BGP invalid length" sid="8633">
  2134.             <Token id="content" type="str">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2135.             <Token id="byte_test" type="int" format="big" oper="less" relative="1" size="2">19</Token>
  2136.         </Rule>
  2137.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="179" name="MISC BGP invalid length" sid="8634">
  2138.             <Token id="content" type="str">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2139.             <Token id="byte_test" type="int" format="big" oper="less" relative="1" size="2">19</Token>
  2140.         </Rule>
  2141.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="179" remport="*" name="MISC BGP invalid length" sid="8635">
  2142.             <Token id="content" type="str">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2143.             <Token id="byte_test" type="int" format="big" oper="less" relative="1" size="2">19</Token>
  2144.         </Rule>
  2145.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="179" remport="*" name="MISC BGP invalid type 0" sid="8636">
  2146.             <Token id="content" type="str" depth="16">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2147.             <Token id="content" type="str" distance="2" within="1">\0</Token>
  2148.         </Rule>
  2149.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="179" remport="*" name="MISC BGP invalid type 0" sid="8637">
  2150.             <Token id="content" type="str" depth="16">\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF</Token>
  2151.             <Token id="content" type="str" distance="2" within="1">\0</Token>
  2152.         </Rule>
  2153.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS non-relative path error response" sid="9268">
  2154.             <Token id="content" type="str">E cvs server: warning: cannot make directory CVS in /</Token>
  2155.         </Rule>
  2156.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2401" remport="*" name="MISC CVS non-relative path access attempt" sid="9272">
  2157.             <Token id="content" type="str">Argument</Token>
  2158.             <Token id="pcre" type="str">=m?^Argument\s+/?smi</Token>
  2159.             <Token id="pcre" type="str">=/^Directory/smiR</Token>
  2160.         </Rule>
  2161.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3389" remport="*" name="MISC MS Terminal Server no encryption session initiation attmept" sid="9672">
  2162.             <Token id="content" type="str" depth="3">\x03\0\x01</Token>
  2163.             <Token id="content" type="str" depth="1" offset="288">\0</Token>
  2164.         </Rule>
  2165.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="636" remport="*" name="MISC LDAP SSLv3 invalid data version attempt" sid="10000">
  2166.             <Token id="content" type="str" depth="2">\x16\x03</Token>
  2167.             <Token id="content" type="str" depth="1" offset="5">\x01</Token>
  2168.             <Token id="content" type="str" complement="1" depth="1" offset="9">\x03</Token>
  2169.         </Rule>
  2170.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="639" remport="*" name="MISC LDAP PCT Client_Hello overflow attempt" sid="10064">
  2171.             <Token id="content" type="str" depth="1" offset="2">\x01</Token>
  2172.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" size="2">0</Token>
  2173.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">0</Token>
  2174.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">16</Token>
  2175.             <Token id="byte_test" type="int" format="big" offset="10" oper="greater" size="2">20</Token>
  2176.             <Token id="content" type="str" depth="1" offset="11">\x8F</Token>
  2177.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="2">32768</Token>
  2178.         </Rule>
  2179.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8000" remport="*" name="MISC HP Web JetAdmin remote file upload attempt" sid="10188">
  2180.             <Token id="content" type="str" nocase="1">/plugins/hpjwja/script/devices_update_printer_fw_upload.hts</Token>
  2181.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  2182.             <Token id="content" type="str" distance="0" nocase="1">Multipart</Token>
  2183.         </Rule>
  2184.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8000" remport="*" name="MISC HP Web JetAdmin setinfo access" sid="10192">
  2185.             <Token id="content" type="str" nocase="1">/plugins/hpjdwm/script/test/setinfo.hts</Token>
  2186.         </Rule>
  2187.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8000" remport="*" name="MISC HP Web JetAdmin file write attempt" sid="10196">
  2188.             <Token id="content" type="str" nocase="1">/plugins/framework/script/tree.xms</Token>
  2189.             <Token id="content" type="str" nocase="1">WriteToFile</Token>
  2190.         </Rule>
  2191.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="873" remport="*" name="MISC rsync backup-dir directory traversal attempt" sid="10244">
  2192.             <Token id="content" type="str">--backup-dir</Token>
  2193.             <Token id="pcre" type="str">=/--backup-dir\s+\x2e\x2e\x2f/</Token>
  2194.         </Rule>
  2195.     </RuleList>
  2196.     <RuleList name="web-misc.rules">
  2197.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC PCCS mysql database admin tool access" sid="2036">
  2198.             <Token id="content" type="str" depth="36" nocase="1">pccsmysqladm/incs/dbconnect.inc</Token>
  2199.         </Rule>
  2200.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC carbo.dll access" sid="4004">
  2201.             <Token id="content" type="str" uricont="1">/carbo.dll</Token>
  2202.             <Token id="content" type="str" nocase="1">icatcommand=</Token>
  2203.         </Rule>
  2204.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise DOS" sid="4188">
  2205.             <Token id="content" type="str" depth="9">REVLOG / </Token>
  2206.         </Rule>
  2207.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise directory listing attempt" sid="4192">
  2208.             <Token id="content" type="str" depth="6">INDEX </Token>
  2209.         </Rule>
  2210.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC iPlanet GETPROPERTIES attempt" sid="4200">
  2211.             <Token id="content" type="str" depth="13">GETPROPERTIES</Token>
  2212.         </Rule>
  2213.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC weblogic/tomcat .jsp view source attempt" sid="4216">
  2214.             <Token id="content" type="str" nocase="1" uricont="1">.jsp</Token>
  2215.             <Token id="pcre" type="str">!/^\w+\s+[^\n\s\?]*\.jsp/smi</Token>
  2216.         </Rule>
  2217.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat view source attempt" sid="4224">
  2218.             <Token id="content" type="str" uricont="1">%252ejsp</Token>
  2219.         </Rule>
  2220.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ftp attempt" sid="4228">
  2221.             <Token id="content" type="str" nocase="1">ftp.exe</Token>
  2222.         </Rule>
  2223.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_enumdsn attempt" sid="4232">
  2224.             <Token id="content" type="str" nocase="1">xp_enumdsn</Token>
  2225.         </Rule>
  2226.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_filelist attempt" sid="4236">
  2227.             <Token id="content" type="str" nocase="1">xp_filelist</Token>
  2228.         </Rule>
  2229.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_availablemedia attempt" sid="4240">
  2230.             <Token id="content" type="str" nocase="1">xp_availablemedia</Token>
  2231.         </Rule>
  2232.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_cmdshell attempt" sid="4244">
  2233.             <Token id="content" type="str" nocase="1">xp_cmdshell</Token>
  2234.         </Rule>
  2235.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC nc.exe attempt" sid="4248">
  2236.             <Token id="content" type="str" nocase="1">nc.exe</Token>
  2237.         </Rule>
  2238.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC wsh attempt" sid="4256">
  2239.             <Token id="content" type="str" nocase="1">wsh.exe</Token>
  2240.         </Rule>
  2241.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC rcmd attempt" sid="4260">
  2242.             <Token id="content" type="str" nocase="1">rcmd.exe</Token>
  2243.         </Rule>
  2244.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC telnet attempt" sid="4264">
  2245.             <Token id="content" type="str" nocase="1">telnet.exe</Token>
  2246.         </Rule>
  2247.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC net attempt" sid="4268">
  2248.             <Token id="content" type="str" nocase="1">net.exe</Token>
  2249.         </Rule>
  2250.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC tftp attempt" sid="4272">
  2251.             <Token id="content" type="str" nocase="1">tftp.exe</Token>
  2252.         </Rule>
  2253.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_regread attempt" sid="4276">
  2254.             <Token id="content" type="str" nocase="1">xp_regread</Token>
  2255.         </Rule>
  2256.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC WebDAV search access" sid="4280">
  2257.             <Token id="content" type="str" depth="8" nocase="1">SEARCH </Token>
  2258.         </Rule>
  2259.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .htpasswd access" sid="4284">
  2260.             <Token id="content" type="str" nocase="1">.htpasswd</Token>
  2261.         </Rule>
  2262.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus Domino directory traversal" sid="4288">
  2263.             <Token id="content" type="str" uricont="1">.nsf/</Token>
  2264.             <Token id="content" type="str" nocase="1" uricont="1">../</Token>
  2265.         </Rule>
  2266.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC queryhit.htm access" sid="4308">
  2267.             <Token id="content" type="str" nocase="1" uricont="1">/samples/search/queryhit.htm</Token>
  2268.         </Rule>
  2269.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC counter.exe access" sid="4312">
  2270.             <Token id="content" type="str" nocase="1" uricont="1">/counter.exe</Token>
  2271.         </Rule>
  2272.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC WebDAV propfind access" sid="4316">
  2273.             <Token id="content" type="str" nocase="1">&lt;a:propfind</Token>
  2274.             <Token id="content" type="str" nocase="1">xmlns:a=\"DAV\"&gt;</Token>
  2275.         </Rule>
  2276.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC unify eWave ServletExec upload" sid="4320">
  2277.             <Token id="content" type="str" nocase="1" uricont="1">/servlet/com.unify.servletexec.UploadServlet</Token>
  2278.         </Rule>
  2279.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Servers suite DOS" sid="4324">
  2280.             <Token id="content" type="str" nocase="1" uricont="1">/dsgw/bin/search?context=</Token>
  2281.         </Rule>
  2282.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC amazon 1-click cookie theft" sid="4328">
  2283.             <Token id="content" type="str" nocase="1">ref%3Cscript%20language%3D%22Javascript</Token>
  2284.         </Rule>
  2285.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC unify eWave ServletExec DOS" sid="4332">
  2286.             <Token id="content" type="str" uricont="1">/servlet/ServletExec</Token>
  2287.         </Rule>
  2288.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Allaire JRUN DOS attempt" sid="4336">
  2289.             <Token id="content" type="str" nocase="1" uricont="1">servlet/.......</Token>
  2290.         </Rule>
  2291.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC whisker tab splice attack" sid="4348">
  2292.             <Token id="dsize" type="int" rel="less">5</Token>
  2293.             <Token id="content" type="str">\t</Token>
  2294.         </Rule>
  2295.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ICQ Webfront HTTP DOS" sid="4364">
  2296.             <Token id="content" type="str" uricont="1">??????????</Token>
  2297.         </Rule>
  2298.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Talentsoft Web+ Source Code view access" sid="4380">
  2299.             <Token id="content" type="str" uricont="1">/webplus.exe?script=test.wml</Token>
  2300.         </Rule>
  2301.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Talentsoft Web+ internal IP Address access" sid="4384">
  2302.             <Token id="content" type="str" uricont="1">/webplus.exe?about</Token>
  2303.         </Rule>
  2304.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SmartWin CyberOffice Shopping Cart access" sid="4392">
  2305.             <Token id="content" type="str" uricont="1">_private/shopping_cart.mdb</Token>
  2306.         </Rule>
  2307.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cybercop scan" sid="4396">
  2308.             <Token id="content" type="str" nocase="1" uricont="1">/cybercop</Token>
  2309.         </Rule>
  2310.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC L3retriever HTTP Probe" sid="4400">
  2311.             <Token id="content" type="str">User-Agent: Java1.2.1\r\n</Token>
  2312.         </Rule>
  2313.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Webtrends HTTP probe" sid="4404">
  2314.             <Token id="content" type="str">User-Agent: Webtrends Security Analyzer\r\n</Token>
  2315.         </Rule>
  2316.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Nessus 404 probe" sid="4408">
  2317.             <Token id="content" type="str" depth="32" uricont="1">/nessus_is_probing_you_</Token>
  2318.         </Rule>
  2319.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape admin passwd" sid="4412">
  2320.             <Token id="content" type="str" nocase="1" uricont="1">/admin-serv/config/admpw</Token>
  2321.         </Rule>
  2322.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC whisker space splice attack" sid="4416">
  2323.             <Token id="dsize" type="int">1</Token>
  2324.             <Token id="content" type="str"> </Token>
  2325.         </Rule>
  2326.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC BigBrother access" sid="4420">
  2327.             <Token id="content" type="str" nocase="1" uricont="1">/bb-hostsvc.sh?HOSTSVC</Token>
  2328.         </Rule>
  2329.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ftp.pl access" sid="4428">
  2330.             <Token id="content" type="str" nocase="1" uricont="1">/ftp.pl</Token>
  2331.         </Rule>
  2332.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat server snoop access" sid="4432">
  2333.             <Token id="content" type="str" uricont="1">/jsp/snp/</Token>
  2334.             <Token id="content" type="str" uricont="1">.snp</Token>
  2335.         </Rule>
  2336.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ROXEN directory list attempt" sid="4436">
  2337.             <Token id="content" type="str" uricont="1">/%00</Token>
  2338.         </Rule>
  2339.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC apache source.asp file access" sid="4440">
  2340.             <Token id="content" type="str" nocase="1" uricont="1">/site/eg/source.asp</Token>
  2341.         </Rule>
  2342.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat server exploit access" sid="4444">
  2343.             <Token id="content" type="str" nocase="1" uricont="1">/contextAdmin/contextAdmin.html</Token>
  2344.         </Rule>
  2345.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC http directory traversal" sid="4448">
  2346.             <Token id="content" type="str">..\\</Token>
  2347.         </Rule>
  2348.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC http directory traversal" sid="4452">
  2349.             <Token id="content" type="str">../</Token>
  2350.         </Rule>
  2351.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ICQ webserver DOS" sid="4460">
  2352.             <Token id="content" type="str" nocase="1" uricont="1">.html/......</Token>
  2353.         </Rule>
  2354.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus DelDoc attempt" sid="4464">
  2355.             <Token id="content" type="str" nocase="1" uricont="1">?DeleteDocument</Token>
  2356.         </Rule>
  2357.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus EditDoc attempt" sid="4468">
  2358.             <Token id="content" type="str" nocase="1" uricont="1">?EditDocument</Token>
  2359.         </Rule>
  2360.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ls%20-l" sid="4472">
  2361.             <Token id="content" type="str" nocase="1">ls%20-l</Token>
  2362.         </Rule>
  2363.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mlog.phtml access" sid="4476">
  2364.             <Token id="content" type="str" nocase="1" uricont="1">/mlog.phtml</Token>
  2365.         </Rule>
  2366.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mylog.phtml access" sid="4480">
  2367.             <Token id="content" type="str" nocase="1" uricont="1">/mylog.phtml</Token>
  2368.         </Rule>
  2369.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /etc/passwd" sid="4488">
  2370.             <Token id="content" type="str" nocase="1">/etc/passwd</Token>
  2371.         </Rule>
  2372.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ?PageServices access" sid="4492">
  2373.             <Token id="content" type="str" nocase="1" uricont="1">?PageServices</Token>
  2374.         </Rule>
  2375.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Ecommerce check.txt access" sid="4496">
  2376.             <Token id="content" type="str" nocase="1" uricont="1">/config/check.txt</Token>
  2377.         </Rule>
  2378.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webcart access" sid="4500">
  2379.             <Token id="content" type="str" nocase="1" uricont="1">/webcart/</Token>
  2380.         </Rule>
  2381.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC AuthChangeUrl access" sid="4504">
  2382.             <Token id="content" type="str" nocase="1" uricont="1">_AuthChangeUrl?</Token>
  2383.         </Rule>
  2384.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC convert.bas access" sid="4508">
  2385.             <Token id="content" type="str" nocase="1" uricont="1">/scripts/convert.bas</Token>
  2386.         </Rule>
  2387.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cpshost.dll access" sid="4512">
  2388.             <Token id="content" type="str" nocase="1" uricont="1">/scripts/cpshost.dll</Token>
  2389.         </Rule>
  2390.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .htaccess access" sid="4516">
  2391.             <Token id="content" type="str" nocase="1">.htaccess</Token>
  2392.         </Rule>
  2393.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .wwwacl access" sid="4520">
  2394.             <Token id="content" type="str" nocase="1" uricont="1">.wwwacl</Token>
  2395.         </Rule>
  2396.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .wwwacl access" sid="4524">
  2397.             <Token id="content" type="str" nocase="1" uricont="1">.www_acl</Token>
  2398.         </Rule>
  2399.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="457" remport="*" name="WEB-MISC Netscape Unixware overflow" sid="4528">
  2400.             <Token id="content" type="str">\xEB_\x9A\xFF\xFF\xFF\xFF\a\xFF\xC3^1\xC0\x89F\x9D</Token>
  2401.         </Rule>
  2402.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cd.." sid="4544">
  2403.             <Token id="content" type="str" nocase="1">cd..</Token>
  2404.         </Rule>
  2405.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC whisker HEAD/./" sid="4556">
  2406.             <Token id="content" type="str">HEAD/./</Token>
  2407.         </Rule>
  2408.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC guestbook.pl access" sid="4560">
  2409.             <Token id="content" type="str" nocase="1" uricont="1">/guestbook.pl</Token>
  2410.         </Rule>
  2411.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC handler access" sid="4564">
  2412.             <Token id="content" type="str" nocase="1" uricont="1">/handler</Token>
  2413.         </Rule>
  2414.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /.... access" sid="4568">
  2415.             <Token id="content" type="str">/....</Token>
  2416.         </Rule>
  2417.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ///cgi-bin access" sid="4572">
  2418.             <Token id="content" type="str" nocase="1" uricont="1">///cgi-bin</Token>
  2419.         </Rule>
  2420.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /cgi-bin/// access" sid="4576">
  2421.             <Token id="content" type="str" nocase="1" uricont="1">/cgi-bin///</Token>
  2422.         </Rule>
  2423.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /~root access" sid="4580">
  2424.             <Token id="content" type="str" nocase="1" uricont="1">/~root</Token>
  2425.         </Rule>
  2426.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Ecommerce import.txt access" sid="4584">
  2427.             <Token id="content" type="str" nocase="1" uricont="1">/config/import.txt</Token>
  2428.         </Rule>
  2429.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cat%20 access" sid="4588">
  2430.             <Token id="content" type="str" nocase="1">cat%20</Token>
  2431.         </Rule>
  2432.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Ecommerce import.txt access" sid="4592">
  2433.             <Token id="content" type="str" nocase="1" uricont="1">/orders/import.txt</Token>
  2434.         </Rule>
  2435.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino catalog.nsf access" sid="4600">
  2436.             <Token id="content" type="str" nocase="1" uricont="1">/catalog.nsf</Token>
  2437.         </Rule>
  2438.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino domcfg.nsf access" sid="4604">
  2439.             <Token id="content" type="str" nocase="1" uricont="1">/domcfg.nsf</Token>
  2440.         </Rule>
  2441.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino domlog.nsf access" sid="4608">
  2442.             <Token id="content" type="str" nocase="1" uricont="1">/domlog.nsf</Token>
  2443.         </Rule>
  2444.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino log.nsf access" sid="4612">
  2445.             <Token id="content" type="str" nocase="1" uricont="1">/log.nsf</Token>
  2446.         </Rule>
  2447.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino names.nsf access" sid="4616">
  2448.             <Token id="content" type="str" nocase="1" uricont="1">/names.nsf</Token>
  2449.         </Rule>
  2450.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Ecommerce checks.txt access" sid="4620">
  2451.             <Token id="content" type="str" nocase="1" uricont="1">/orders/checks.txt</Token>
  2452.         </Rule>
  2453.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC apache DOS attempt" sid="4624">
  2454.             <Token id="content" type="str">////////</Token>
  2455.         </Rule>
  2456.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape PublishingXpert access" sid="4628">
  2457.             <Token id="content" type="str" nocase="1" uricont="1">/PSUser/PSCOErrPage.htm</Token>
  2458.         </Rule>
  2459.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC windmail.exe access" sid="4632">
  2460.             <Token id="content" type="str" nocase="1" uricont="1">/windmail.exe</Token>
  2461.         </Rule>
  2462.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webplus access" sid="4636">
  2463.             <Token id="content" type="str" nocase="1" uricont="1">/webplus?script</Token>
  2464.         </Rule>
  2465.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape dir index wp" sid="4640">
  2466.             <Token id="content" type="str" nocase="1" uricont="1">?wp-</Token>
  2467.         </Rule>
  2468.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cart 32 AdminPwd access" sid="4648">
  2469.             <Token id="content" type="str" nocase="1" uricont="1">/c32web.exe/ChangeAdminPassword</Token>
  2470.         </Rule>
  2471.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC shopping cart access" sid="4656">
  2472.             <Token id="content" type="str" nocase="1" uricont="1">/quikstore.cfg</Token>
  2473.         </Rule>
  2474.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Novell Groupwise gwweb.exe access" sid="4660">
  2475.             <Token id="content" type="str" nocase="1">/GWWEB.EXE</Token>
  2476.         </Rule>
  2477.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ws_ftp.ini access" sid="4664">
  2478.             <Token id="content" type="str" nocase="1" uricont="1">/ws_ftp.ini</Token>
  2479.         </Rule>
  2480.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC rpm_query access" sid="4668">
  2481.             <Token id="content" type="str" nocase="1" uricont="1">/rpm_query</Token>
  2482.         </Rule>
  2483.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mall log order access" sid="4672">
  2484.             <Token id="content" type="str" nocase="1" uricont="1">/mall_log_files/order.log</Token>
  2485.         </Rule>
  2486.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC architext_query.pl access" sid="4692">
  2487.             <Token id="content" type="str" nocase="1" uricont="1">/ews/architext_query.pl</Token>
  2488.         </Rule>
  2489.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC wwwboard.pl access" sid="4700">
  2490.             <Token id="content" type="str" nocase="1" uricont="1">/wwwboard.pl</Token>
  2491.         </Rule>
  2492.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC order.log access" sid="4704">
  2493.             <Token id="content" type="str" nocase="1" uricont="1">/admin_files/order.log</Token>
  2494.         </Rule>
  2495.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4708">
  2496.             <Token id="content" type="str" nocase="1" uricont="1">?wp-verify-link</Token>
  2497.         </Rule>
  2498.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC get32.exe access" sid="4720">
  2499.             <Token id="content" type="str" nocase="1" uricont="1">/get32.exe</Token>
  2500.         </Rule>
  2501.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Annex Terminal DOS attempt" sid="4724">
  2502.             <Token id="content" type="str" uricont="1">/ping?query=</Token>
  2503.         </Rule>
  2504.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cgitest.exe attempt" sid="4728">
  2505.             <Token id="content" type="str" nocase="1" uricont="1">/cgitest.exe\r\nuser</Token>
  2506.         </Rule>
  2507.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4732">
  2508.             <Token id="content" type="str" nocase="1" uricont="1">?wp-cs-dump</Token>
  2509.         </Rule>
  2510.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4736">
  2511.             <Token id="content" type="str" nocase="1" uricont="1">?wp-ver-info</Token>
  2512.         </Rule>
  2513.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4744">
  2514.             <Token id="content" type="str" nocase="1" uricont="1">?wp-ver-diff</Token>
  2515.         </Rule>
  2516.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SalesLogix Eviewer web command attempt" sid="4748">
  2517.             <Token id="content" type="str" nocase="1" uricont="1">/slxweb.dll/admin?command=</Token>
  2518.         </Rule>
  2519.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4752">
  2520.             <Token id="content" type="str" nocase="1" uricont="1">?wp-start-ver</Token>
  2521.         </Rule>
  2522.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4756">
  2523.             <Token id="content" type="str" nocase="1" uricont="1">?wp-stop-ver</Token>
  2524.         </Rule>
  2525.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4760">
  2526.             <Token id="content" type="str" nocase="1" uricont="1">?wp-uncheckout</Token>
  2527.         </Rule>
  2528.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4764">
  2529.             <Token id="content" type="str" nocase="1" uricont="1">?wp-html-rend</Token>
  2530.         </Rule>
  2531.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Trend Micro OfficeScan access" sid="4768">
  2532.             <Token id="content" type="str" nocase="1" uricont="1">/officescan/cgi/jdkRqNotify.exe</Token>
  2533.         </Rule>
  2534.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC oracle web arbitrary command execution attempt" sid="4772">
  2535.             <Token id="content" type="str" nocase="1" uricont="1">/ows-bin/</Token>
  2536.             <Token id="content" type="str" uricont="1">?&amp;</Token>
  2537.         </Rule>
  2538.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Netscape Enterprise Server directory view" sid="4792">
  2539.             <Token id="content" type="str" nocase="1" uricont="1">?wp-usr-prop</Token>
  2540.         </Rule>
  2541.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2301" remport="*" name="WEB-MISC Compaq Insight directory traversal" sid="4796">
  2542.             <Token id="content" type="str">../</Token>
  2543.         </Rule>
  2544.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC search.vts access" sid="4808">
  2545.             <Token id="content" type="str" uricont="1">/search.vts</Token>
  2546.         </Rule>
  2547.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC htgrep access" sid="4828">
  2548.             <Token id="content" type="str" uricont="1">/htgrep</Token>
  2549.         </Rule>
  2550.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .nsconfig access" sid="4836">
  2551.             <Token id="content" type="str" uricont="1">/.nsconfig</Token>
  2552.         </Rule>
  2553.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Admin_files access" sid="4848">
  2554.             <Token id="content" type="str" nocase="1" uricont="1">/admin_files</Token>
  2555.         </Rule>
  2556.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC backup access" sid="4852">
  2557.             <Token id="content" type="str" nocase="1" uricont="1">/backup</Token>
  2558.         </Rule>
  2559.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC intranet access" sid="4856">
  2560.             <Token id="content" type="str" nocase="1" uricont="1">/intranet/</Token>
  2561.         </Rule>
  2562.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC filemail access" sid="4864">
  2563.             <Token id="content" type="str" nocase="1" uricont="1">/filemail</Token>
  2564.         </Rule>
  2565.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC plusmail access" sid="4868">
  2566.             <Token id="content" type="str" nocase="1" uricont="1">/plusmail</Token>
  2567.         </Rule>
  2568.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC adminlogin access" sid="4872">
  2569.             <Token id="content" type="str" nocase="1" uricont="1">/adminlogin</Token>
  2570.         </Rule>
  2571.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ultraboard access" sid="4880">
  2572.             <Token id="content" type="str" nocase="1" uricont="1">/ultraboard</Token>
  2573.         </Rule>
  2574.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC musicat empower access" sid="4884">
  2575.             <Token id="content" type="str" nocase="1" uricont="1">/empower</Token>
  2576.         </Rule>
  2577.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ROADS search.pl attempt" sid="4896">
  2578.             <Token id="content" type="str" uricont="1">/ROADS/cgi-bin/search.pl</Token>
  2579.             <Token id="content" type="str" nocase="1">form=</Token>
  2580.         </Rule>
  2581.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC VirusWall FtpSave access" sid="4920">
  2582.             <Token id="content" type="str" nocase="1" uricont="1">/FtpSave.dll</Token>
  2583.         </Rule>
  2584.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC VirusWall catinfo access" sid="4924">
  2585.             <Token id="content" type="str" nocase="1" uricont="1">/catinfo</Token>
  2586.         </Rule>
  2587.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1812" remport="*" name="WEB-MISC VirusWall catinfo access" sid="4928">
  2588.             <Token id="content" type="str" nocase="1">/catinfo</Token>
  2589.         </Rule>
  2590.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC VirusWall FtpSaveCSP access" sid="4936">
  2591.             <Token id="content" type="str" nocase="1" uricont="1">/FtpSaveCSP.dll</Token>
  2592.         </Rule>
  2593.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC VirusWall FtpSaveCVP access" sid="4940">
  2594.             <Token id="content" type="str" nocase="1" uricont="1">/FtpSaveCVP.dll</Token>
  2595.         </Rule>
  2596.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SWEditServlet directory traversal attempt" sid="4964">
  2597.             <Token id="content" type="str" uricont="1">/SWEditServlet</Token>
  2598.             <Token id="content" type="str">template=../../../</Token>
  2599.         </Rule>
  2600.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Cisco IOS HTTP configuration attempt" sid="5000">
  2601.             <Token id="content" type="str" uricont="1">/level/</Token>
  2602.             <Token id="content" type="str" uricont="1">/exec/</Token>
  2603.         </Rule>
  2604.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC HP OpenView Manager DOS" sid="5032">
  2605.             <Token id="content" type="str" nocase="1" uricont="1">/OvCgi/OpenView5.exe?Context=Snmp&amp;Action=Snmp&amp;Host=&amp;Oid=</Token>
  2606.         </Rule>
  2607.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SWEditServlet access" sid="5036">
  2608.             <Token id="content" type="str" uricont="1">/SWEditServlet</Token>
  2609.         </Rule>
  2610.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC long basic authorization string" sid="5040">
  2611.             <Token id="content" type="str" nocase="1">Authorization: Basic </Token>
  2612.             <Token id="content" type="str" complement="1" within="512">\n</Token>
  2613.         </Rule>
  2614.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC sml3com access" sid="5164">
  2615.             <Token id="content" type="str" uricont="1">/graphics/sml3com</Token>
  2616.         </Rule>
  2617.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC console.exe access" sid="5208">
  2618.             <Token id="content" type="str" nocase="1" uricont="1">/cgi-bin/console.exe</Token>
  2619.         </Rule>
  2620.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cs.exe access" sid="5212">
  2621.             <Token id="content" type="str" nocase="1" uricont="1">/cgi-bin/cs.exe</Token>
  2622.         </Rule>
  2623.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC sadmind worm access" sid="5500">
  2624.             <Token id="content" type="str" depth="15">GET x HTTP/1.0</Token>
  2625.         </Rule>
  2626.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC jrun directory browse attempt" sid="5504">
  2627.             <Token id="content" type="str" uricont="1">/?.jsp</Token>
  2628.         </Rule>
  2629.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Trend Micro OfficeScan attempt" sid="5524">
  2630.             <Token id="content" type="str" nocase="1" uricont="1">/officescan/cgi/jdkRqNotify.exe?</Token>
  2631.             <Token id="content" type="str" nocase="1" uricont="1">domain=</Token>
  2632.             <Token id="content" type="str" nocase="1" uricont="1">event=</Token>
  2633.         </Rule>
  2634.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mod-plsql administration access" sid="5540">
  2635.             <Token id="content" type="str" uricont="1">/admin_/</Token>
  2636.         </Rule>
  2637.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Phorecast remote code execution attempt" sid="5564">
  2638.             <Token id="content" type="str">includedir=</Token>
  2639.         </Rule>
  2640.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC viewcode access" sid="5612">
  2641.             <Token id="content" type="str" uricont="1">/viewcode</Token>
  2642.         </Rule>
  2643.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC showcode access" sid="5616">
  2644.             <Token id="content" type="str" uricont="1">/showcode</Token>
  2645.         </Rule>
  2646.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .history access" sid="5732">
  2647.             <Token id="content" type="str" uricont="1">/.history</Token>
  2648.         </Rule>
  2649.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .bash_history access" sid="5736">
  2650.             <Token id="content" type="str" uricont="1">/.bash_history</Token>
  2651.         </Rule>
  2652.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /~nobody access" sid="5956">
  2653.             <Token id="content" type="str" uricont="1">/~nobody</Token>
  2654.         </Rule>
  2655.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC RBS ISP /newuser  directory traversal attempt" sid="5968">
  2656.             <Token id="content" type="str" uricont="1">/newuser?Image=../..</Token>
  2657.         </Rule>
  2658.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC RBS ISP /newuser access" sid="5972">
  2659.             <Token id="content" type="str" uricont="1">/newuser</Token>
  2660.         </Rule>
  2661.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cross site scripting attempt" sid="5988">
  2662.             <Token id="content" type="str" nocase="1">&lt;SCRIPT&gt;</Token>
  2663.         </Rule>
  2664.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8181" remport="*" name="WEB-MISC PIX firewall manager directory traversal attempt" sid="5992">
  2665.             <Token id="content" type="str">/../../</Token>
  2666.         </Rule>
  2667.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8888" remport="*" name="WEB-MISC SiteScope Service access" sid="5996">
  2668.             <Token id="content" type="str">/SiteScope/cgi/go.exe/SiteScope</Token>
  2669.         </Rule>
  2670.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ExAir access" sid="6000">
  2671.             <Token id="content" type="str" uricont="1">/exair/search/</Token>
  2672.         </Rule>
  2673.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8000" remport="*" name="WEB-MISC nstelemetry.adp access" sid="6072">
  2674.             <Token id="content" type="str">/nstelemetry.adp</Token>
  2675.         </Rule>
  2676.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC apache ?M=D directory list attempt" sid="6076">
  2677.             <Token id="content" type="str" uricont="1">/?M=D</Token>
  2678.         </Rule>
  2679.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC server-info access" sid="6080">
  2680.             <Token id="content" type="str" uricont="1">/server-info</Token>
  2681.         </Rule>
  2682.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC server-status access" sid="6084">
  2683.             <Token id="content" type="str" uricont="1">/server-status</Token>
  2684.         </Rule>
  2685.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ans.pl attempt" sid="6088">
  2686.             <Token id="content" type="str" uricont="1">/ans.pl?p=../../</Token>
  2687.         </Rule>
  2688.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ans.pl access" sid="6092">
  2689.             <Token id="content" type="str" uricont="1">/ans.pl</Token>
  2690.         </Rule>
  2691.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC AxisStorpoint CD attempt" sid="6096">
  2692.             <Token id="content" type="str" uricont="1">/cd/../config/html/cnf_gi.htm</Token>
  2693.         </Rule>
  2694.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Axis Storpoint CD access" sid="6100">
  2695.             <Token id="content" type="str" uricont="1">/config/html/cnf_gi.htm</Token>
  2696.         </Rule>
  2697.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC basilix sendmail.inc access" sid="6104">
  2698.             <Token id="content" type="str" uricont="1">/inc/sendmail.inc</Token>
  2699.         </Rule>
  2700.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC basilix mysql.class access" sid="6108">
  2701.             <Token id="content" type="str" uricont="1">/class/mysql.class</Token>
  2702.         </Rule>
  2703.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC BBoard access" sid="6112">
  2704.             <Token id="content" type="str" uricont="1">/servlet/sunexamples.BBoardServlet</Token>
  2705.         </Rule>
  2706.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Cisco Catalyst command execution attempt" sid="6176">
  2707.             <Token id="content" type="str" nocase="1" uricont="1">/exec/show/config/cr</Token>
  2708.         </Rule>
  2709.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /CVS/Entries access" sid="6204">
  2710.             <Token id="content" type="str" uricont="1">/CVS/Entries</Token>
  2711.         </Rule>
  2712.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cvsweb version access" sid="6208">
  2713.             <Token id="content" type="str" uricont="1">/cvsweb/version</Token>
  2714.         </Rule>
  2715.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="WEB-MISC Delegate whois overflow attempt" sid="6232">
  2716.             <Token id="content" type="str" nocase="1">whois://</Token>
  2717.         </Rule>
  2718.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /doc/packages access" sid="6236">
  2719.             <Token id="content" type="str" nocase="1" uricont="1">/doc/packages</Token>
  2720.         </Rule>
  2721.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /doc/ access" sid="6240">
  2722.             <Token id="content" type="str" nocase="1" uricont="1">/doc/</Token>
  2723.         </Rule>
  2724.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC login.htm attempt" sid="6252">
  2725.             <Token id="content" type="str" nocase="1" uricont="1">/login.htm?password=</Token>
  2726.         </Rule>
  2727.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC login.htm access" sid="6256">
  2728.             <Token id="content" type="str" nocase="1" uricont="1">/login.htm</Token>
  2729.         </Rule>
  2730.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino mab.nsf access" sid="6300">
  2731.             <Token id="content" type="str" nocase="1" uricont="1">/mab.nsf</Token>
  2732.         </Rule>
  2733.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino cersvr.nsf access" sid="6304">
  2734.             <Token id="content" type="str" nocase="1" uricont="1">/cersvr.nsf</Token>
  2735.         </Rule>
  2736.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino setup.nsf access" sid="6308">
  2737.             <Token id="content" type="str" nocase="1" uricont="1">/setup.nsf</Token>
  2738.         </Rule>
  2739.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino statrep.nsf access" sid="6312">
  2740.             <Token id="content" type="str" nocase="1" uricont="1">/statrep.nsf</Token>
  2741.         </Rule>
  2742.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino webadmin.nsf access" sid="6316">
  2743.             <Token id="content" type="str" nocase="1" uricont="1">/webadmin.nsf</Token>
  2744.         </Rule>
  2745.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino events4.nsf access" sid="6320">
  2746.             <Token id="content" type="str" nocase="1" uricont="1">/events4.nsf</Token>
  2747.         </Rule>
  2748.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino ntsync4.nsf access" sid="6324">
  2749.             <Token id="content" type="str" nocase="1" uricont="1">/ntsync4.nsf</Token>
  2750.         </Rule>
  2751.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino collect4.nsf access" sid="6328">
  2752.             <Token id="content" type="str" nocase="1" uricont="1">/collect4.nsf</Token>
  2753.         </Rule>
  2754.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino mailw46.nsf access" sid="6332">
  2755.             <Token id="content" type="str" nocase="1" uricont="1">/mailw46.nsf</Token>
  2756.         </Rule>
  2757.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino bookmark.nsf access" sid="6336">
  2758.             <Token id="content" type="str" nocase="1" uricont="1">/bookmark.nsf</Token>
  2759.         </Rule>
  2760.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino agentrunner.nsf access" sid="6340">
  2761.             <Token id="content" type="str" nocase="1" uricont="1">/agentrunner.nsf</Token>
  2762.         </Rule>
  2763.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Domino mail.box access" sid="6344">
  2764.             <Token id="content" type="str" nocase="1" uricont="1">/mail.box</Token>
  2765.         </Rule>
  2766.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cgitest.exe access" sid="6348">
  2767.             <Token id="content" type="str" nocase="1" uricont="1">/cgitest.exe</Token>
  2768.         </Rule>
  2769.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SalesLogix Eviewer access" sid="6352">
  2770.             <Token id="content" type="str" nocase="1" uricont="1">/slxweb.dll</Token>
  2771.         </Rule>
  2772.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC musicat empower attempt" sid="6356">
  2773.             <Token id="content" type="str" nocase="1" uricont="1">/empower?DB=</Token>
  2774.         </Rule>
  2775.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC DELETE attempt" sid="6412">
  2776.             <Token id="content" type="str" depth="7" nocase="1">DELETE </Token>
  2777.         </Rule>
  2778.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="4080" remport="*" name="WEB-MISC iChat directory traversal attempt" sid="6416">
  2779.             <Token id="content" type="str">/../../</Token>
  2780.         </Rule>
  2781.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ftp.pl attempt" sid="6448">
  2782.             <Token id="content" type="str" nocase="1" uricont="1">/ftp.pl?dir=../..</Token>
  2783.         </Rule>
  2784.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC handler attempt" sid="6452">
  2785.             <Token id="content" type="str" uricont="1">/handler</Token>
  2786.             <Token id="content" type="str" nocase="1" uricont="1">|</Token>
  2787.         </Rule>
  2788.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Novell Groupwise gwweb.exe attempt" sid="6456">
  2789.             <Token id="content" type="str" nocase="1" uricont="1">/GWWEB.EXE?HELP=</Token>
  2790.         </Rule>
  2791.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC htgrep attempt" sid="6460">
  2792.             <Token id="content" type="str" uricont="1">/htgrep</Token>
  2793.             <Token id="content" type="str">hdr=/</Token>
  2794.         </Rule>
  2795.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /~ftp access" sid="6648">
  2796.             <Token id="content" type="str" nocase="1" uricont="1">/~ftp</Token>
  2797.         </Rule>
  2798.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC *%0a.pl access" sid="6652">
  2799.             <Token id="content" type="str" nocase="1" uricont="1">/*\n.pl</Token>
  2800.         </Rule>
  2801.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mkplog.exe access" sid="6656">
  2802.             <Token id="content" type="str" nocase="1" uricont="1">/mkplog.exe</Token>
  2803.         </Rule>
  2804.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cross site scripting HTML Image tag set to javascript attempt" sid="6668">
  2805.             <Token id="content" type="str" nocase="1">img src=javascript</Token>
  2806.         </Rule>
  2807.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /home/ftp access" sid="6680">
  2808.             <Token id="content" type="str" nocase="1" uricont="1">/home/ftp</Token>
  2809.         </Rule>
  2810.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /home/www access" sid="6684">
  2811.             <Token id="content" type="str" nocase="1" uricont="1">/home/www</Token>
  2812.         </Rule>
  2813.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC global.inc access" sid="6952">
  2814.             <Token id="content" type="str" nocase="1" uricont="1">/global.inc</Token>
  2815.         </Rule>
  2816.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SecureSite authentication bypass attempt" sid="6976">
  2817.             <Token id="content" type="str" nocase="1">secure_site, ok</Token>
  2818.         </Rule>
  2819.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC b2 arbitrary command execution attempt" sid="7028">
  2820.             <Token id="content" type="str" uricont="1">/b2/b2-include/</Token>
  2821.             <Token id="content" type="str">b2inc</Token>
  2822.             <Token id="content" type="str">http://</Token>
  2823.         </Rule>
  2824.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC b2 access" sid="7032">
  2825.             <Token id="content" type="str" uricont="1">/b2/b2-include/</Token>
  2826.             <Token id="content" type="str">b2inc</Token>
  2827.             <Token id="content" type="str">http://</Token>
  2828.         </Rule>
  2829.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC search.dll directory listing attempt" sid="7064">
  2830.             <Token id="content" type="str" uricont="1">/search.dll</Token>
  2831.             <Token id="content" type="str">query=%00</Token>
  2832.         </Rule>
  2833.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC search.dll access" sid="7068">
  2834.             <Token id="content" type="str" uricont="1">/search.dll</Token>
  2835.         </Rule>
  2836.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .DS_Store access" sid="7076">
  2837.             <Token id="content" type="str" uricont="1">/.DS_Store</Token>
  2838.         </Rule>
  2839.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC .FBCIndex access" sid="7080">
  2840.             <Token id="content" type="str" uricont="1">/.FBCIndex</Token>
  2841.         </Rule>
  2842.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Chunked-Encoding transfer attempt" sid="7228">
  2843.             <Token id="content" type="str" nocase="1">Transfer-Encoding:</Token>
  2844.             <Token id="content" type="str" nocase="1">chunked</Token>
  2845.         </Rule>
  2846.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC apache chunked encoding memory corruption exploit attempt" sid="7232">
  2847.             <Token id="content" type="str">\xC0PR\x89\xE1PQRP\xB8;\0\0\0\xCD\x80</Token>
  2848.         </Rule>
  2849.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Apache Chunked-Encoding worm attempt" sid="7236">
  2850.             <Token id="content" type="str" nocase="1">CCCCCCC: AAAAAAAAAAAAAAAAAAA</Token>
  2851.         </Rule>
  2852.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC CISCO VoIP DOS ATTEMPT" sid="7256">
  2853.             <Token id="content" type="str" uricont="1">/StreamingStatistics</Token>
  2854.         </Rule>
  2855.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC IBM Net.Commerce orderdspc.d2w access" sid="7280">
  2856.             <Token id="content" type="str" uricont="1">/ncommerce3/ExecMacro/orderdspc.d2w</Token>
  2857.         </Rule>
  2858.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC WEB-INF access" sid="7304">
  2859.             <Token id="content" type="str" nocase="1" uricont="1">/WEB-INF</Token>
  2860.         </Rule>
  2861.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat servlet mapping cross site scripting attempt" sid="7308">
  2862.             <Token id="content" type="str" uricont="1">/servlet/</Token>
  2863.             <Token id="content" type="str" uricont="1">/org.apache.</Token>
  2864.         </Rule>
  2865.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC iPlanet Search directory traversal attempt" sid="7312">
  2866.             <Token id="content" type="str" uricont="1">/search</Token>
  2867.             <Token id="content" type="str">NS-query-pat=</Token>
  2868.             <Token id="content" type="str">../../</Token>
  2869.         </Rule>
  2870.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat TroubleShooter servlet access" sid="7316">
  2871.             <Token id="content" type="str" uricont="1">/examples/servlet/TroubleShooter</Token>
  2872.         </Rule>
  2873.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat SnoopServlet servlet access" sid="7320">
  2874.             <Token id="content" type="str" uricont="1">/examples/servlet/SnoopServlet</Token>
  2875.         </Rule>
  2876.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC jigsaw dos attempt" sid="7324">
  2877.             <Token id="content" type="str" uricont="1">/servlet/con</Token>
  2878.         </Rule>
  2879.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Macromedia SiteSpring cross site scripting attempt" sid="7340">
  2880.             <Token id="content" type="str" nocase="1" uricont="1">/error/500error.jsp</Token>
  2881.             <Token id="content" type="str" uricont="1">et=</Token>
  2882.             <Token id="content" type="str" nocase="1" uricont="1">&lt;script</Token>
  2883.         </Rule>
  2884.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mailman cross site scripting attempt" sid="7356">
  2885.             <Token id="content" type="str" nocase="1" uricont="1">/mailman/</Token>
  2886.             <Token id="content" type="str" uricont="1">?</Token>
  2887.             <Token id="content" type="str" uricont="1">info=</Token>
  2888.             <Token id="content" type="str" nocase="1" uricont="1">&lt;script</Token>
  2889.         </Rule>
  2890.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webalizer access" sid="7388">
  2891.             <Token id="content" type="str" nocase="1" uricont="1">/webalizer/</Token>
  2892.         </Rule>
  2893.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webcart-lite access" sid="7392">
  2894.             <Token id="content" type="str" nocase="1" uricont="1">/webcart-lite/</Token>
  2895.         </Rule>
  2896.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webfind.exe access" sid="7396">
  2897.             <Token id="content" type="str" nocase="1" uricont="1">/webfind.exe</Token>
  2898.         </Rule>
  2899.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC active.log access" sid="7404">
  2900.             <Token id="content" type="str" nocase="1" uricont="1">/active.log</Token>
  2901.         </Rule>
  2902.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC robots.txt access" sid="7408">
  2903.             <Token id="content" type="str" nocase="1" uricont="1">/robots.txt</Token>
  2904.         </Rule>
  2905.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC robot.txt access" sid="7428">
  2906.             <Token id="content" type="str" nocase="1" uricont="1">/robot.txt</Token>
  2907.         </Rule>
  2908.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8181" remport="*" name="WEB-MISC CISCO PIX Firewall Manager directory traversal attempt" sid="7432">
  2909.             <Token id="content" type="str">/pixfir~1/how_to_login.html</Token>
  2910.         </Rule>
  2911.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="9090" remport="*" name="WEB-MISC Sun JavaServer default password login attempt" sid="7436">
  2912.             <Token id="content" type="str">/servlet/admin</Token>
  2913.             <Token id="content" type="str">ae9f86d6beaa3f9ecb9a5b7e072a4138</Token>
  2914.         </Rule>
  2915.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="WEB-MISC Linksys router default password login attempt" sid="7440">
  2916.             <Token id="content" type="str">Authorization: Basic OmFkbWlu</Token>
  2917.         </Rule>
  2918.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="WEB-MISC Linksys router default username and password login attempt" sid="7444">
  2919.             <Token id="content" type="str" nocase="1">Authorization: </Token>
  2920.             <Token id="content" type="str" nocase="1"> Basic </Token>
  2921.             <Token id="content" type="str">YWRtaW46YWRtaW4</Token>
  2922.         </Rule>
  2923.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Oracle XSQLConfig.xml access" sid="7484">
  2924.             <Token id="content" type="str" uricont="1">/XSQLConfig.xml</Token>
  2925.         </Rule>
  2926.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Oracle Dynamic Monitoring Services dms access" sid="7488">
  2927.             <Token id="content" type="str" uricont="1">/dms0</Token>
  2928.         </Rule>
  2929.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC globals.jsa access" sid="7492">
  2930.             <Token id="content" type="str" uricont="1">/globals.jsa</Token>
  2931.         </Rule>
  2932.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Oracle Java Process Manager access" sid="7496">
  2933.             <Token id="content" type="str" uricont="1">/oprocmgr-status</Token>
  2934.         </Rule>
  2935.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC oracle web application server access" sid="7520">
  2936.             <Token id="content" type="str" nocase="1" uricont="1">/ows-bin/</Token>
  2937.         </Rule>
  2938.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC bad HTTP/1.1 request, Potentially worm attack" sid="7524">
  2939.             <Token id="content" type="str" depth="18">GET / HTTP/1.1\r\n\r\n</Token>
  2940.         </Rule>
  2941.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /Carello/add.exe access" sid="7772">
  2942.             <Token id="content" type="str" nocase="1" uricont="1">/Carello/add.exe</Token>
  2943.         </Rule>
  2944.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /ecscripts/ecware.exe access" sid="7776">
  2945.             <Token id="content" type="str" nocase="1" uricont="1">/ecscripts/ecware.exe</Token>
  2946.         </Rule>
  2947.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8888" remport="*" name="WEB-MISC answerbook2 admin attempt" sid="7784">
  2948.             <Token id="content" type="str">/cgi-bin/admin/admin</Token>
  2949.         </Rule>
  2950.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8888" remport="*" name="WEB-MISC answerbook2 arbitrary command execution attempt" sid="7788">
  2951.             <Token id="content" type="str">/ab2/</Token>
  2952.             <Token id="content" type="str" distance="1">;</Token>
  2953.         </Rule>
  2954.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ion-p access" sid="7876">
  2955.             <Token id="content" type="str" nocase="1" uricont="1">/ion-p</Token>
  2956.         </Rule>
  2957.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_regwrite attempt" sid="7908">
  2958.             <Token id="content" type="str" nocase="1">xp_regwrite</Token>
  2959.         </Rule>
  2960.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC xp_regdeletekey attempt" sid="7912">
  2961.             <Token id="content" type="str" nocase="1">xp_regdeletekey</Token>
  2962.         </Rule>
  2963.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC perl post attempt" sid="7916">
  2964.             <Token id="content" type="str" depth="4">POST</Token>
  2965.             <Token id="content" type="str" uricont="1">/perl/</Token>
  2966.         </Rule>
  2967.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC TRACE attempt" sid="8224">
  2968.             <Token id="content" type="str" depth="5">TRACE</Token>
  2969.         </Rule>
  2970.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC helpout.exe access" sid="8228">
  2971.             <Token id="content" type="str" uricont="1">/helpout.exe</Token>
  2972.         </Rule>
  2973.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC MsmMask.exe attempt" sid="8232">
  2974.             <Token id="content" type="str" uricont="1">/MsmMask.exe</Token>
  2975.             <Token id="content" type="str">mask=</Token>
  2976.         </Rule>
  2977.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC MsmMask.exe access" sid="8236">
  2978.             <Token id="content" type="str" uricont="1">/MsmMask.exe</Token>
  2979.         </Rule>
  2980.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC DB4Web access" sid="8240">
  2981.             <Token id="content" type="str" uricont="1">/DB4Web/</Token>
  2982.         </Rule>
  2983.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Tomcat null byte directory listing attempt" sid="8244">
  2984.             <Token id="content" type="str" uricont="1">\0.jsp</Token>
  2985.         </Rule>
  2986.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC iPlanet .perf access" sid="8248">
  2987.             <Token id="content" type="str" uricont="1">/.perf</Token>
  2988.         </Rule>
  2989.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Demarc SQL injection attempt" sid="8252">
  2990.             <Token id="content" type="str" uricont="1">/dm/demarc</Token>
  2991.             <Token id="content" type="str">s_key=</Token>
  2992.             <Token id="content" type="str" distance="0">'</Token>
  2993.             <Token id="content" type="str" distance="1">'</Token>
  2994.             <Token id="content" type="str" distance="0">'</Token>
  2995.         </Rule>
  2996.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus Notes .csp script source download attempt" sid="8256">
  2997.             <Token id="content" type="str" uricont="1">.csp</Token>
  2998.             <Token id="content" type="str">.csp</Token>
  2999.             <Token id="content" type="str" within="1">.</Token>
  3000.         </Rule>
  3001.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus Notes .pl script source download attempt" sid="8264">
  3002.             <Token id="content" type="str" uricont="1">.pl</Token>
  3003.             <Token id="content" type="str">.pl</Token>
  3004.             <Token id="content" type="str" within="1">.</Token>
  3005.         </Rule>
  3006.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Lotus Notes .exe script source download attempt" sid="8268">
  3007.             <Token id="content" type="str" uricont="1">.exe</Token>
  3008.             <Token id="content" type="str">.exe</Token>
  3009.             <Token id="content" type="str" within="1">.</Token>
  3010.         </Rule>
  3011.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC BitKeeper arbitrary command attempt" sid="8272">
  3012.             <Token id="content" type="str" uricont="1">/diffs/</Token>
  3013.             <Token id="content" type="str">'</Token>
  3014.             <Token id="content" type="str" distance="0">;</Token>
  3015.             <Token id="content" type="str" distance="1">'</Token>
  3016.         </Rule>
  3017.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC chip.ini access" sid="8276">
  3018.             <Token id="content" type="str" uricont="1">/chip.ini</Token>
  3019.         </Rule>
  3020.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC post32.exe arbitrary command attempt" sid="8280">
  3021.             <Token id="content" type="str" uricont="1">/post32.exe|</Token>
  3022.         </Rule>
  3023.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC post32.exe access" sid="8284">
  3024.             <Token id="content" type="str" uricont="1">/post32.exe</Token>
  3025.         </Rule>
  3026.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC lyris.pl access" sid="8288">
  3027.             <Token id="content" type="str" uricont="1">/lyris.pl</Token>
  3028.         </Rule>
  3029.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC globals.pl access" sid="8292">
  3030.             <Token id="content" type="str" uricont="1">/globals.pl</Token>
  3031.         </Rule>
  3032.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC philboard.mdb access" sid="8540">
  3033.             <Token id="content" type="str" uricont="1">/philboard.mdb</Token>
  3034.         </Rule>
  3035.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC philboard_admin.asp authentication bypass attempt" sid="8544">
  3036.             <Token id="content" type="str" uricont="1">/philboard_admin.asp</Token>
  3037.             <Token id="content" type="str" nocase="1">Cookie</Token>
  3038.             <Token id="content" type="str" distance="0">philboard_admin=True</Token>
  3039.         </Rule>
  3040.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC philboard_admin.asp access" sid="8548">
  3041.             <Token id="content" type="str" uricont="1">/philboard_admin.asp</Token>
  3042.         </Rule>
  3043.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC logicworks.ini access" sid="8552">
  3044.             <Token id="content" type="str" uricont="1">/logicworks.ini</Token>
  3045.         </Rule>
  3046.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC /*.shtml access" sid="8556">
  3047.             <Token id="content" type="str" uricont="1">/*.shtml</Token>
  3048.         </Rule>
  3049.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC mod_gzip_status access" sid="8624">
  3050.             <Token id="content" type="str" uricont="1">/mod_gzip_status</Token>
  3051.         </Rule>
  3052.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC NetGear router default password login attempt admin/password" sid="8920">
  3053.             <Token id="content" type="str" nocase="1">Authorization: </Token>
  3054.             <Token id="content" type="str" nocase="1"> Basic </Token>
  3055.             <Token id="content" type="str">YWRtaW46cGFzc3dvcmQ</Token>
  3056.         </Rule>
  3057.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC register.dll access" sid="8924">
  3058.             <Token id="content" type="str" nocase="1" uricont="1">/register.dll</Token>
  3059.         </Rule>
  3060.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ContentFilter.dll access" sid="8928">
  3061.             <Token id="content" type="str" nocase="1" uricont="1">/ContentFilter.dll</Token>
  3062.         </Rule>
  3063.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SFNofitication.dll access" sid="8932">
  3064.             <Token id="content" type="str" nocase="1" uricont="1">/SFNofitication.dll</Token>
  3065.         </Rule>
  3066.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC TOP10.dll access" sid="8936">
  3067.             <Token id="content" type="str" nocase="1" uricont="1">/TOP10.dll</Token>
  3068.         </Rule>
  3069.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC SpamExcp.dll access" sid="8940">
  3070.             <Token id="content" type="str" nocase="1" uricont="1">/SpamExcp.dll</Token>
  3071.         </Rule>
  3072.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC spamrule.dll access" sid="8944">
  3073.             <Token id="content" type="str" nocase="1" uricont="1">/spamrule.dll</Token>
  3074.         </Rule>
  3075.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cgiWebupdate.exe access" sid="8948">
  3076.             <Token id="content" type="str" nocase="1" uricont="1">/cgiWebupdate.exe</Token>
  3077.         </Rule>
  3078.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC WebLogic ConsoleHelp view source attempt" sid="8952">
  3079.             <Token id="content" type="str" nocase="1" uricont="1">/ConsoleHelp/</Token>
  3080.             <Token id="content" type="str" nocase="1" uricont="1">.jsp</Token>
  3081.         </Rule>
  3082.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC redirect.exe access" sid="8956">
  3083.             <Token id="content" type="str" nocase="1" uricont="1">/redirect.exe</Token>
  3084.         </Rule>
  3085.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC changepw.exe access" sid="8960">
  3086.             <Token id="content" type="str" nocase="1" uricont="1">/changepw.exe</Token>
  3087.         </Rule>
  3088.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC cwmail.exe access" sid="8964">
  3089.             <Token id="content" type="str" nocase="1" uricont="1">/cwmail.exe</Token>
  3090.         </Rule>
  3091.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ddicgi.exe access" sid="8968">
  3092.             <Token id="content" type="str" nocase="1" uricont="1">/ddicgi.exe</Token>
  3093.         </Rule>
  3094.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ndcgi.exe access" sid="8972">
  3095.             <Token id="content" type="str" nocase="1" uricont="1">/ndcgi.exe</Token>
  3096.         </Rule>
  3097.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC VsSetCookie.exe access" sid="8976">
  3098.             <Token id="content" type="str" nocase="1" uricont="1">/VsSetCookie.exe</Token>
  3099.         </Rule>
  3100.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Webnews.exe access" sid="8980">
  3101.             <Token id="content" type="str" nocase="1" uricont="1">/Webnews.exe</Token>
  3102.         </Rule>
  3103.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC webadmin.dll access" sid="8984">
  3104.             <Token id="content" type="str" nocase="1" uricont="1">/webadmin.dll</Token>
  3105.         </Rule>
  3106.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC oracle portal demo access" sid="9104">
  3107.             <Token id="content" type="str" nocase="1" uricont="1">/pls/portal/PORTAL_DEMO</Token>
  3108.         </Rule>
  3109.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC PeopleSoft PeopleBooks psdoccgi access" sid="9108">
  3110.             <Token id="content" type="str" nocase="1" uricont="1">/psdoccgi</Token>
  3111.         </Rule>
  3112.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC negative Content-Length attempt" sid="9112">
  3113.             <Token id="content" type="str" nocase="1">Content-Length:</Token>
  3114.             <Token id="pcre" type="str">=/^Content-Length\x3a\s+-\d+/smi</Token>
  3115.         </Rule>
  3116.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC bsml.pl access" sid="9308">
  3117.             <Token id="content" type="str" nocase="1" uricont="1">/bsml.pl</Token>
  3118.         </Rule>
  3119.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ISAPISkeleton.dll access" sid="9476">
  3120.             <Token id="content" type="str" nocase="1" uricont="1">/ISAPISkeleton.dll</Token>
  3121.         </Rule>
  3122.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC BugPort config.conf file access" sid="9480">
  3123.             <Token id="content" type="str" nocase="1" uricont="1">/config.conf</Token>
  3124.         </Rule>
  3125.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Sample_showcode.html access" sid="9484">
  3126.             <Token id="content" type="str" nocase="1" uricont="1">/Sample_showcode.html</Token>
  3127.             <Token id="content" type="str">fname</Token>
  3128.         </Rule>
  3129.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC schema overflow attempt" sid="9524">
  3130.             <Token id="content" type="str" uricont="1">://</Token>
  3131.             <Token id="pcre" type="str">=/^[^\/]{14,}?\x3a\/\//U</Token>
  3132.         </Rule>
  3133.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="2301" remport="*" name="WEB-MISC Compaq web-based management agent denial of service attempt" sid="9576">
  3134.             <Token id="content" type="str" depth="75">&lt;!</Token>
  3135.             <Token id="content" type="str" within="50">&gt;</Token>
  3136.         </Rule>
  3137.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC InteractiveQuery.jsp access" sid="9580">
  3138.             <Token id="content" type="str" nocase="1" uricont="1">/InteractiveQuery.jsp</Token>
  3139.         </Rule>
  3140.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC edittag.pl access" sid="9600">
  3141.             <Token id="content" type="str" nocase="1" uricont="1">/edittag.pl</Token>
  3142.         </Rule>
  3143.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC util.pl access" sid="9628">
  3144.             <Token id="content" type="str" nocase="1" uricont="1">/util.pl</Token>
  3145.         </Rule>
  3146.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC Invision Power Board search.pl access" sid="9632">
  3147.             <Token id="content" type="str" uricont="1">/search.pl</Token>
  3148.             <Token id="content" type="str" nocase="1">st=</Token>
  3149.         </Rule>
  3150.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="554" remport="*" name="WEB-MISC Real Server DESCRIBE buffer overflow attempt" sid="9644">
  3151.             <Token id="content" type="str" nocase="1">DESCRIBE</Token>
  3152.             <Token id="content" type="str" distance="1">../</Token>
  3153.             <Token id="pcre" type="str">=/^DESCRIBE\s[^\n]{300}/smi</Token>
  3154.         </Rule>
  3155.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC NetObserve authentication bypass attempt" sid="9764">
  3156.             <Token id="content" type="str" nocase="1">login=0</Token>
  3157.             <Token id="content" type="str" nocase="1">Cookie:</Token>
  3158.             <Token id="pcre" type="str">=/^Cookie\x3a[^\n]*?login=0/smi</Token>
  3159.         </Rule>
  3160.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="8000-8001" remport="*" name="WEB-MISC Quicktime User-Agent buffer overflow attempt" sid="9768">
  3161.             <Token id="content" type="str" nocase="1">User-Agent:</Token>
  3162.             <Token id="pcre" type="str">=/^User-Agent\x3a[^\n]{244,255}/smi</Token>
  3163.         </Rule>
  3164.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC ServletManager access" sid="9788">
  3165.             <Token id="content" type="str" nocase="1" uricont="1">/servlet/ServletManager</Token>
  3166.         </Rule>
  3167.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC setinfo.hts access" sid="9792">
  3168.             <Token id="content" type="str" nocase="1" uricont="1">/setinfo.hts</Token>
  3169.         </Rule>
  3170.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-MISC source.jsp access" sid="9936">
  3171.             <Token id="content" type="str" nocase="1" uricont="1">/source.jsp</Token>
  3172.         </Rule>
  3173.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="443" remport="*" name="WEB-MISC SSLv3 invalid data version attempt" sid="10020">
  3174.             <Token id="content" type="str" depth="2">\x16\x03</Token>
  3175.             <Token id="content" type="str" depth="1" offset="5">\x01</Token>
  3176.             <Token id="content" type="str" complement="1" depth="1" offset="9">\x03</Token>
  3177.         </Rule>
  3178.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="443" remport="*" name="WEB-MISC PCT Client_Hello overflow attempt" sid="10060">
  3179.             <Token id="content" type="str" depth="1" offset="2">\x01</Token>
  3180.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" size="2">0</Token>
  3181.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">0</Token>
  3182.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">16</Token>
  3183.             <Token id="byte_test" type="int" format="big" offset="10" oper="greater" size="2">20</Token>
  3184.             <Token id="content" type="str" depth="1" offset="11">\x8F</Token>
  3185.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="2">32768</Token>
  3186.         </Rule>
  3187.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="81" remport="*" name="WEB-MISC McAfee ePO file upload attempt" sid="10248">
  3188.             <Token id="content" type="str" nocase="1">/spipe/repl_file</Token>
  3189.             <Token id="content" type="str" nocase="1">Command=BEGIN</Token>
  3190.         </Rule>
  3191.     </RuleList>
  3192.     <RuleList name="policy.rules">
  3193.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="9000-9002" remport="*" name="POLICY HP JetDirect LCD modification attempt" sid="2040" enabled="0">
  3194.             <Token id="content" type="str">@PJL RDYMSG DISPLAY =</Token>
  3195.         </Rule>
  3196.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'STOR 1MB' possible warez site" sid="2172" enabled="0">
  3197.             <Token id="content" type="str" nocase="1">STOR</Token>
  3198.             <Token id="content" type="str" distance="1" nocase="1">1MB</Token>
  3199.         </Rule>
  3200.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'RETR 1MB' possible warez site" sid="2176" enabled="0">
  3201.             <Token id="content" type="str" nocase="1">RETR</Token>
  3202.             <Token id="content" type="str" distance="1" nocase="1">1MB</Token>
  3203.         </Rule>
  3204.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'CWD / ' possible warez site" sid="2180" enabled="0">
  3205.             <Token id="content" type="str" nocase="1">CWD</Token>
  3206.             <Token id="content" type="str" distance="1">/ </Token>
  3207.         </Rule>
  3208.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'CWD  ' possible warez site" sid="2184" enabled="0">
  3209.             <Token id="content" type="str" depth="5" nocase="1">CWD  </Token>
  3210.         </Rule>
  3211.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'MKD  ' possible warez site" sid="2188" enabled="0">
  3212.             <Token id="content" type="str" depth="5" nocase="1">MKD  </Token>
  3213.         </Rule>
  3214.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'MKD .' possible warez site" sid="2192" enabled="0">
  3215.             <Token id="content" type="str" depth="5" nocase="1">MKD .</Token>
  3216.         </Rule>
  3217.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP anonymous login attempt" sid="2212" enabled="0">
  3218.             <Token id="content" type="str" nocase="1">USER</Token>
  3219.             <Token id="pcre" type="str">=/^USER\s+(anonymous|ftp)/smi</Token>
  3220.         </Rule>
  3221.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP 'MKD / ' possible warez site" sid="2216" enabled="0">
  3222.             <Token id="content" type="str" nocase="1">MKD</Token>
  3223.             <Token id="content" type="str" distance="1">/ </Token>
  3224.         </Rule>
  3225.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="23" remport="*" name="POLICY WinGate telnet server response" sid="2220" enabled="0">
  3226.             <Token id="content" type="str">WinGate&gt;</Token>
  3227.         </Rule>
  3228.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="POLICY VNC server response" sid="2240" enabled="0">
  3229.             <Token id="content" type="str" depth="5">RFB 0</Token>
  3230.             <Token id="content" type="str" depth="2" offset="7">.0</Token>
  3231.         </Rule>
  3232.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="5632" remport="*" name="POLICY PCAnywhere server response" sid="2264" enabled="0">
  3233.             <Token id="content" type="str" depth="2">ST</Token>
  3234.         </Rule>
  3235.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="POLICY SMTP relaying denied" sid="2268" enabled="0">
  3236.             <Token id="content" type="str" depth="70">550 5.7.1</Token>
  3237.         </Rule>
  3238.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="9100" remport="*" name="POLICY HP JetDirect LCD modification attempt" sid="2272" enabled="0">
  3239.             <Token id="content" type="str">@PJL RDYMSG DISPLAY =</Token>
  3240.         </Rule>
  3241.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="address of POLICY poll.gotomypc.com access" name="POLICY poll.gotomypc.com access" sid="5716" enabled="0"/>
  3242.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="21" remport="*" name="POLICY FTP file_id.diz access possible warez site" sid="5780" enabled="0">
  3243.             <Token id="content" type="str" nocase="1">RETR</Token>
  3244.             <Token id="content" type="str" distance="1" nocase="1">file_id.diz</Token>
  3245.         </Rule>
  3246.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500" remport="*" name="POLICY IPSec PGPNet connection attempt" sid="7084" enabled="0">
  3247.             <Token id="content" type="str">\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x01\x10\x02\0\0\0\0\0\0\0\0\x88\r\0\0\\\0\0\0\x01\0\0\0\x01\0\0\0P\x01\x01\0\x02\x03\0\0$\x01\x01\0\0\x80\x01\0\x06\x80\x02\0\x02\x80\x03\0\x03\x80\x04\0\x05\x80\v\0\x01\0\f\0\x04\0\x01Q\x80\0\0\0$\x02\x01\0\0\x80\x01\0\x05\x80\x02\0\x01\x80\x03\0\x03\x80\x04\0\x02\x80\v\0\x01\0\f\0\x04\0\x01Q\x80\0\0\0\x10</Token>
  3248.         </Rule>
  3249.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="5800-5802" remport="*" name="POLICY vncviewer Java applet download attempt" sid="7384" enabled="0">
  3250.             <Token id="content" type="str">/vncviewer.jar</Token>
  3251.         </Rule>
  3252.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="49" remport="*" name="POLICY xtacacs login attempt" sid="8160" enabled="0">
  3253.             <Token id="content" type="str" depth="2">\x80\x01</Token>
  3254.             <Token id="content" type="str" distance="4">\0</Token>
  3255.         </Rule>
  3256.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="49" remport="*" name="POLICY xtacacs accepted login response" sid="8168" enabled="0">
  3257.             <Token id="content" type="str" depth="2">\x80\x02</Token>
  3258.             <Token id="content" type="str" distance="4">\x01</Token>
  3259.         </Rule>
  3260.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1723" remport="*" name="POLICY PPTP Start Control Request attempt" sid="8176" enabled="0">
  3261.             <Token id="content" type="str" depth="2" offset="2">\0\x01</Token>
  3262.             <Token id="content" type="str" depth="2" offset="8">\0\x01</Token>
  3263.         </Rule>
  3264.     </RuleList>
  3265.     <RuleList name="tftp.rules">
  3266.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="69" remport="*" name="TFTP Put" sid="2072">
  3267.             <Token id="content" type="str" depth="2">\0\x02</Token>
  3268.         </Rule>
  3269.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="69" remport="*" name="TFTP parent directory" sid="2076">
  3270.             <Token id="content" type="str" offset="2">..</Token>
  3271.         </Rule>
  3272.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="69" remport="*" name="TFTP root directory" sid="2080">
  3273.             <Token id="content" type="str" depth="3">\0\x01/</Token>
  3274.         </Rule>
  3275.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP GET Admin.dll" sid="5156">
  3276.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3277.             <Token id="content" type="str" nocase="1" offset="2">admin.dll</Token>
  3278.         </Rule>
  3279.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP GET Admin.dll" sid="5157">
  3280.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3281.             <Token id="content" type="str" nocase="1" offset="2">admin.dll</Token>
  3282.         </Rule>
  3283.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP GET nc.exe" sid="5764">
  3284.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3285.             <Token id="content" type="str" nocase="1" offset="2">nc.exe</Token>
  3286.         </Rule>
  3287.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP GET nc.exe" sid="5765">
  3288.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3289.             <Token id="content" type="str" nocase="1" offset="2">nc.exe</Token>
  3290.         </Rule>
  3291.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP GET shadow" sid="5768">
  3292.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3293.             <Token id="content" type="str" nocase="1" offset="2">shadow</Token>
  3294.         </Rule>
  3295.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP GET shadow" sid="5769">
  3296.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3297.             <Token id="content" type="str" nocase="1" offset="2">shadow</Token>
  3298.         </Rule>
  3299.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP GET passwd" sid="5772">
  3300.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3301.             <Token id="content" type="str" nocase="1" offset="2">passwd</Token>
  3302.         </Rule>
  3303.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP GET passwd" sid="5773">
  3304.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3305.             <Token id="content" type="str" nocase="1" offset="2">passwd</Token>
  3306.         </Rule>
  3307.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="69" remport="*" name="TFTP Get" sid="5776">
  3308.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3309.         </Rule>
  3310.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP GET filename overflow attempt" sid="7764">
  3311.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3312.             <Token id="content" type="str" complement="1" within="100">\0</Token>
  3313.         </Rule>
  3314.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP GET filename overflow attempt" sid="7765">
  3315.             <Token id="content" type="str" depth="2">\0\x01</Token>
  3316.             <Token id="content" type="str" complement="1" within="100">\0</Token>
  3317.         </Rule>
  3318.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="all" remaddr_id="all" locport="*" remport="69" name="TFTP PUT filename overflow attempt" sid="9348">
  3319.             <Token id="content" type="str" depth="2">\0\x02</Token>
  3320.             <Token id="content" type="str" complement="1" within="100">\0</Token>
  3321.         </Rule>
  3322.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="all" remaddr_id="all" locport="69" remport="*" name="TFTP PUT filename overflow attempt" sid="9349">
  3323.             <Token id="content" type="str" depth="2">\0\x02</Token>
  3324.             <Token id="content" type="str" complement="1" within="100">\0</Token>
  3325.         </Rule>
  3326.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="69" remport="*" name="TFTP NULL command attempt" sid="9356">
  3327.             <Token id="content" type="str" depth="2">\0\0</Token>
  3328.         </Rule>
  3329.     </RuleList>
  3330.     <RuleList name="bad-traffic.rules">
  3331.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="BAD-TRAFFIC ip reserved bit set" sid="2092">
  3332.             <Token id="ip_frg" type="str">R</Token>
  3333.         </Rule>
  3334.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="0" remport="*" name="BAD-TRAFFIC tcp port 0 traffic" sid="2096"/>
  3335.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="0" remport="*" name="BAD-TRAFFIC tcp port 0 traffic" sid="2097"/>
  3336.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="0" remport="*" name="BAD-TRAFFIC udp port 0 traffic" sid="2100"/>
  3337.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="0" remport="*" name="BAD-TRAFFIC udp port 0 traffic" sid="2101"/>
  3338.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="BAD-TRAFFIC data in TCP SYN packet" sid="2104">
  3339.             <Token id="dsize" type="int" rel="greater">6</Token>
  3340.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  3341.         </Rule>
  3342.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC same SRC/DST" sid="2108">
  3343.             <Token id="sameadr" type="bool">1</Token>
  3344.         </Rule>
  3345.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC same SRC/DST" sid="2109">
  3346.             <Token id="sameadr" type="bool">1</Token>
  3347.         </Rule>
  3348.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="loopback" name="BAD-TRAFFIC loopback traffic" sid="2112"/>
  3349.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="loopback" remaddr_id="all" name="BAD-TRAFFIC loopback traffic" sid="2113"/>
  3350.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="loopback" name="BAD-TRAFFIC loopback traffic" sid="2114"/>
  3351.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="loopback" remaddr_id="all" name="BAD-TRAFFIC loopback traffic" sid="2115"/>
  3352.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="BAD-TRAFFIC 0 ttl" sid="5284">
  3353.             <Token id="ip_ttl" type="int">0</Token>
  3354.         </Rule>
  3355.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="multicast" locport="*" remport="*" name="BAD-TRAFFIC syn to multicast address" sid="5724">
  3356.             <Token id="tcp_flg" type="str">S+</Token>
  3357.         </Rule>
  3358.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="multicast" remaddr_id="all" locport="*" remport="*" name="BAD-TRAFFIC syn to multicast address" sid="5725">
  3359.             <Token id="tcp_flg" type="str">S+</Token>
  3360.         </Rule>
  3361.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="BAD-TRAFFIC Unassigned/Reserved IP protocol" sid="6508">
  3362.             <Token id="ip_ptc" type="int" rel="greater">134</Token>
  3363.         </Rule>
  3364.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 53 SWIPE" sid="8744">
  3365.             <Token id="ip_ptc" type="int">53</Token>
  3366.         </Rule>
  3367.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 53 SWIPE" sid="8745">
  3368.             <Token id="ip_ptc" type="int">53</Token>
  3369.         </Rule>
  3370.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 55 IP Mobility" sid="8748">
  3371.             <Token id="ip_ptc" type="int">55</Token>
  3372.         </Rule>
  3373.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 55 IP Mobility" sid="8749">
  3374.             <Token id="ip_ptc" type="int">55</Token>
  3375.         </Rule>
  3376.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 77 Sun ND" sid="8752">
  3377.             <Token id="ip_ptc" type="int">77</Token>
  3378.         </Rule>
  3379.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 77 Sun ND" sid="8753">
  3380.             <Token id="ip_ptc" type="int">77</Token>
  3381.         </Rule>
  3382.         <Rule al="Monitor" ar="Allow" dir="out" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 103 PIM" sid="8756">
  3383.             <Token id="ip_ptc" type="int">103</Token>
  3384.         </Rule>
  3385.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="all" remaddr_id="all" name="BAD-TRAFFIC IP Proto 103 PIM" sid="8757">
  3386.             <Token id="ip_ptc" type="int">103</Token>
  3387.         </Rule>
  3388.     </RuleList>
  3389.     <RuleList name="netbios.rules">
  3390.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS DOS RFPoison" sid="2116">
  3391.             <Token id="content" type="str">\\\0\\\0*\0S\0M\0B\0S\0E\0R\0V\0E\0R\0\0\0\0\0\x01\0\0\0\x01\0\0\0\0\0\0\0\xFF\xFF\xFF\xFF\0\0\0\0</Token>
  3392.         </Rule>
  3393.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS NT NULL session" sid="2120">
  3394.             <Token id="content" type="str">\0\0\0\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \01\03\08\01</Token>
  3395.         </Rule>
  3396.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB ADMIN$ share access" sid="2128">
  3397.             <Token id="content" type="str" depth="1">\0</Token>
  3398.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3399.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3400.             <Token id="content" type="str" distance="32" nocase="1">ADMIN$\0</Token>
  3401.         </Rule>
  3402.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB C$ share access" sid="2132">
  3403.             <Token id="content" type="str" depth="1">\0</Token>
  3404.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3405.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3406.             <Token id="content" type="str" distance="32" nocase="1">C$\0</Token>
  3407.         </Rule>
  3408.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB CD.." sid="2136">
  3409.             <Token id="content" type="str">\\../\0\0\0</Token>
  3410.         </Rule>
  3411.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB CD..." sid="2140">
  3412.             <Token id="content" type="str">\\...\0\0\0</Token>
  3413.         </Rule>
  3414.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB D$ share access" sid="2144">
  3415.             <Token id="content" type="str" depth="1">\0</Token>
  3416.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3417.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3418.             <Token id="content" type="str" distance="32" nocase="1">D$\0</Token>
  3419.         </Rule>
  3420.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB IPC$ share access" sid="2148">
  3421.             <Token id="content" type="str" depth="1">\0</Token>
  3422.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3423.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3424.             <Token id="content" type="str" distance="32" nocase="1">IPC$\0</Token>
  3425.         </Rule>
  3426.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB IPC$ share unicode access" sid="2152">
  3427.             <Token id="content" type="str" depth="1">\0</Token>
  3428.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3429.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3430.             <Token id="content" type="str" distance="32" nocase="1">I\0P\0C\0$\0\0</Token>
  3431.         </Rule>
  3432.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS RFParalyze Attempt" sid="4956">
  3433.             <Token id="content" type="str">BEAVIS</Token>
  3434.             <Token id="content" type="str">yep yep</Token>
  3435.         </Rule>
  3436.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS nimda .eml" sid="5172">
  3437.             <Token id="content" type="str">\0.\0E\0M\0L</Token>
  3438.         </Rule>
  3439.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS nimda .nws" sid="5176">
  3440.             <Token id="content" type="str">\0.\0N\0W\0S</Token>
  3441.         </Rule>
  3442.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS nimda RICHED20.DLL" sid="5180">
  3443.             <Token id="content" type="str">R\0I\0C\0H\0E\0D\02\00</Token>
  3444.         </Rule>
  3445.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB SMB_COM_TRANSACTION Max Parameter and Max Count of 0 DOS Attempt" sid="8404">
  3446.             <Token id="content" type="str" depth="1">\0</Token>
  3447.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB%</Token>
  3448.             <Token id="content" type="str" depth="4" offset="43">\0\0\0\0</Token>
  3449.         </Rule>
  3450.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB trans2open buffer overflow attempt" sid="8412">
  3451.             <Token id="content" type="str" depth="1">\0</Token>
  3452.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB2</Token>
  3453.             <Token id="content" type="str" depth="2" offset="60">\0\x14</Token>
  3454.             <Token id="byte_test" type="int" oper="greater" relative="1" size="2">256</Token>
  3455.         </Rule>
  3456.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB winreg access" sid="8696">
  3457.             <Token id="content" type="str" depth="1">\0</Token>
  3458.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB\xA2</Token>
  3459.             <Token id="content" type="str" nocase="1" offset="85">\\winreg\0</Token>
  3460.         </Rule>
  3461.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB winreg unicode access" sid="8700">
  3462.             <Token id="content" type="str" depth="1">\0</Token>
  3463.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB\xA2</Token>
  3464.             <Token id="content" type="str" nocase="1" offset="85">\\\0w\0i\0n\0r\0e\0g\0</Token>
  3465.         </Rule>
  3466.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB startup folder access" sid="8704">
  3467.             <Token id="content" type="str" depth="1">\0</Token>
  3468.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB2</Token>
  3469.             <Token id="content" type="str" distance="0" nocase="1">Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\0</Token>
  3470.         </Rule>
  3471.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB startup folder unicode access" sid="8708">
  3472.             <Token id="content" type="str" depth="1">\0</Token>
  3473.             <Token id="content" type="str" depth="5" offset="4">\xFFSMB2</Token>
  3474.             <Token id="content" type="str" distance="0" nocase="1">\\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\\\0P\0r\0o\0g\0r\0a\0m\0s\0\\\0S\0t\0a\0r\0t\0u\0p</Token>
  3475.         </Rule>
  3476.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="135" remport="*" name="NETBIOS DCERPC invalid bind attempt" sid="8760">
  3477.             <Token id="content" type="str" within="1">\x05</Token>
  3478.             <Token id="content" type="str" distance="1" within="1">\v</Token>
  3479.             <Token id="byte_test" type="int" format="big" oper="and" relative="1" size="1">1</Token>
  3480.             <Token id="content" type="str" distance="21" within="1">\0</Token>
  3481.         </Rule>
  3482.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB DCERPC invalid bind attempt" sid="8764">
  3483.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3484.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3485.             <Token id="content" type="str" distance="5" nocase="1" within="12">\\\0P\0I\0P\0E\0\\\0</Token>
  3486.             <Token id="content" type="str" distance="2" within="1">\x05</Token>
  3487.             <Token id="content" type="str" distance="1" within="1">\v</Token>
  3488.             <Token id="byte_test" type="int" format="big" oper="and" relative="1" size="1">1</Token>
  3489.             <Token id="content" type="str" distance="21" within="1">\0</Token>
  3490.         </Rule>
  3491.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB DCERPC ISystemActivator bind attempt" sid="8772">
  3492.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3493.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3494.             <Token id="content" type="str" distance="5" nocase="1" within="12">\\\0P\0I\0P\0E\0\\\0</Token>
  3495.             <Token id="content" type="str" distance="0" within="1">\x05</Token>
  3496.             <Token id="content" type="str" distance="1" within="1">\v</Token>
  3497.             <Token id="byte_test" type="int" format="big" oper="and" relative="1" size="1">1</Token>
  3498.             <Token id="content" type="str" distance="29" within="16">\xA0\x01\0\0\0\0\0\0\xC0\0\0\0\0\0\0F</Token>
  3499.         </Rule>
  3500.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="135" remport="*" name="NETBIOS DCERPC Remote Activation bind attempt" sid="9004">
  3501.             <Token id="content" type="str" within="1">\x05</Token>
  3502.             <Token id="content" type="str" distance="1" within="1">\v</Token>
  3503.             <Token id="byte_test" type="int" format="big" oper="and" relative="1" size="1">1</Token>
  3504.             <Token id="content" type="str" distance="29" within="16">\xB8J\x9FM\x1C}\xCF\x11\x86\x1E\0 \xAFn|W</Token>
  3505.         </Rule>
  3506.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC Remote Activation bind attempt" sid="9008">
  3507.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3508.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3509.             <Token id="content" type="str" distance="5" nocase="1" within="12">\\\0P\0I\0P\0E\0\\\0</Token>
  3510.             <Token id="content" type="str" within="1">\x05</Token>
  3511.             <Token id="content" type="str" distance="1" within="1">\v</Token>
  3512.             <Token id="byte_test" type="int" format="big" oper="and" relative="1" size="1">1</Token>
  3513.             <Token id="content" type="str" distance="29" within="16">\xB8J\x9FM\x1C}\xCF\x11\x86\x1E\0 \xAFn|W</Token>
  3514.         </Rule>
  3515.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="135" remport="*" name="NETBIOS DCERPC Messenger Service buffer overflow attempt" sid="9028">
  3516.             <Token id="content" type="str" depth="2">\x04\0</Token>
  3517.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" relative="1" size="1">15</Token>
  3518.             <Token id="byte_jump" type="int" align="1" offset="86" relative="1">4</Token>
  3519.             <Token id="byte_jump" type="int" align="1" offset="8" relative="1">4</Token>
  3520.             <Token id="byte_test" type="int" oper="greater" relative="1" size="4">1024</Token>
  3521.         </Rule>
  3522.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC Messenger Service buffer overflow attempt" sid="9032">
  3523.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3524.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3525.             <Token id="content" type="str" distance="5" nocase="1" within="12">\\\0P\0I\0P\0E\0\\\0</Token>
  3526.             <Token id="content" type="str" within="2">\x04\0</Token>
  3527.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" relative="1" size="1">15</Token>
  3528.             <Token id="byte_jump" type="int" align="1" offset="86" relative="1">4</Token>
  3529.             <Token id="byte_jump" type="int" align="1" offset="8" relative="1">4</Token>
  3530.             <Token id="byte_test" type="int" oper="greater" relative="1" size="4">1024</Token>
  3531.         </Rule>
  3532.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB DCERPC Workstation Service unicode bind attempt" sid="9232">
  3533.             <Token id="content" type="str" depth="1">\0</Token>
  3534.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3535.             <Token id="byte_test" type="int" format="big" offset="5" oper="and" relative="1" size="2">1</Token>
  3536.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3537.             <Token id="content" type="str" distance="4" within="15">\\\0P\0I\0P\0E\0\\\0\x05\0\v</Token>
  3538.             <Token id="byte_test" type="int" format="big" offset="1" oper="and" relative="1" size="1">16</Token>
  3539.             <Token id="content" type="str" distance="29" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3540.         </Rule>
  3541.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB DCERPC Workstation Service bind attempt" sid="9236">
  3542.             <Token id="content" type="str" depth="1">\0</Token>
  3543.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3544.             <Token id="byte_test" type="int" format="big" offset="5" oper="xor" relative="1" size="2">1</Token>
  3545.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3546.             <Token id="content" type="str" distance="4" within="10">\\PIPE\\\0\x05\0\v</Token>
  3547.             <Token id="byte_test" type="int" format="big" offset="1" oper="and" relative="1" size="1">16</Token>
  3548.             <Token id="content" type="str" distance="29" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3549.         </Rule>
  3550.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC Workstation Service unicode bind attempt" sid="9240">
  3551.             <Token id="content" type="str" depth="1">\0</Token>
  3552.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3553.             <Token id="byte_test" type="int" format="big" offset="5" oper="and" relative="1" size="2">1</Token>
  3554.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3555.             <Token id="content" type="str" distance="4" within="15">\\\0P\0I\0P\0E\0\\\0\x05\0\v</Token>
  3556.             <Token id="byte_test" type="int" format="big" offset="1" oper="and" relative="1" size="1">16</Token>
  3557.             <Token id="content" type="str" distance="29" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3558.         </Rule>
  3559.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC Workstation Service bind attempt" sid="9244">
  3560.             <Token id="content" type="str" depth="1">\0</Token>
  3561.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMB%</Token>
  3562.             <Token id="byte_test" type="int" format="big" offset="5" oper="xor" relative="1" size="2">1</Token>
  3563.             <Token id="content" type="str" distance="56" within="2">&amp;\0</Token>
  3564.             <Token id="content" type="str" distance="4" within="10">\\PIPE\\\0\x05\0\v</Token>
  3565.             <Token id="byte_test" type="int" format="big" offset="1" oper="and" relative="1" size="1">16</Token>
  3566.             <Token id="content" type="str" distance="29" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3567.         </Rule>
  3568.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1024-65535" remport="*" name="NETBIOS DCERPC Workstation Service direct service bind attempt" sid="9260">
  3569.             <Token id="content" type="str" depth="3">\x05\0\v</Token>
  3570.             <Token id="byte_test" type="int" format="big" offset="1" oper="and" relative="1" size="1">16</Token>
  3571.             <Token id="content" type="str" distance="29" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3572.         </Rule>
  3573.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1024-65535" remport="*" name="NETBIOS DCERPC Workstation Service direct service access attempt" sid="9264">
  3574.             <Token id="content" type="str" depth="2">\x04\0</Token>
  3575.             <Token id="byte_test" type="int" format="big" offset="2" oper="and" relative="1" size="1">16</Token>
  3576.             <Token id="content" type="str" distance="22" within="16">\x98\xD0\xFFk\x12\xA1\x106\x983F\xC3\xF8~4Z</Token>
  3577.         </Rule>
  3578.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="135" remport="*" name="NETBIOS DCERPC ISystemActivator path overflow attempt little endian" sid="9404">
  3579.             <Token id="content" type="str" distance="0" within="1">\x05</Token>
  3580.             <Token id="byte_test" type="int" format="big" offset="3" oper="and" relative="1" size="1">16</Token>
  3581.             <Token id="content" type="str">\\\0\\\0</Token>
  3582.             <Token id="byte_test" type="int" offset="-8" oper="greater" relative="1" size="4">256</Token>
  3583.         </Rule>
  3584.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB NTLMSSP invalid mechtype attempt" sid="9528">
  3585.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3586.             <Token id="content" type="str" depth="1" offset="63">`</Token>
  3587.             <Token id="content" type="str" distance="1" within="8">\x06\x06+\x06\x01\x05\x05\x02</Token>
  3588.             <Token id="content" type="str" distance="0">\x06\n+\x06\x01\x04\x01\x827\x02\x02\n</Token>
  3589.             <Token id="content" type="str" distance="0">\xA1\x05#\x03\x03\x01\a</Token>
  3590.         </Rule>
  3591.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC NTLMSSP invalid mechtype attempt" sid="9532">
  3592.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3593.             <Token id="content" type="str" depth="1" offset="63">`</Token>
  3594.             <Token id="content" type="str" distance="1" within="8">\x06\x06+\x06\x01\x05\x05\x02</Token>
  3595.             <Token id="content" type="str" distance="0">\x06\n+\x06\x01\x04\x01\x827\x02\x02\n</Token>
  3596.             <Token id="content" type="str" distance="0">\xA1\x05#\x03\x03\x01\a</Token>
  3597.         </Rule>
  3598.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB NTLMSSP invalid mechlistMIC attempt" sid="9536">
  3599.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3600.             <Token id="content" type="str" depth="1" offset="63">`</Token>
  3601.             <Token id="content" type="str" distance="1" within="15">\0\0\0b\x06\x83\0\0\x06+\x06\x01\x05\x05\x02</Token>
  3602.             <Token id="content" type="str" distance="0">\x06\n+\x06\x01\x04\x01\x827\x02\x02\n</Token>
  3603.             <Token id="content" type="str" distance="0">\xA3&gt;0&lt;\xA00</Token>
  3604.         </Rule>
  3605.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS DCERPC NTLMSSP invalid mechlistMIC attempt" sid="9540">
  3606.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3607.             <Token id="content" type="str" depth="1" offset="63">`</Token>
  3608.             <Token id="content" type="str" distance="1" within="15">\0\0\0b\x06\x83\0\0\x06+\x06\x01\x05\x05\x02</Token>
  3609.             <Token id="content" type="str" distance="0">\x06\n+\x06\x01\x04\x01\x827\x02\x02\n</Token>
  3610.             <Token id="content" type="str" distance="0">\xA3&gt;0&lt;\xA00</Token>
  3611.         </Rule>
  3612.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB Session Setup AndX request username overflow attempt" sid="9604">
  3613.             <Token id="content" type="str" depth="1">\0</Token>
  3614.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="2">322</Token>
  3615.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3616.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3617.             <Token id="content" type="str" distance="42" within="4">\0\0\0\0</Token>
  3618.             <Token id="byte_test" type="int" offset="8" oper="greater" relative="1" size="2">255</Token>
  3619.             <Token id="content" type="str" complement="1" distance="10" within="255">\0</Token>
  3620.         </Rule>
  3621.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS Session Setup AndX request username overflow attempt" sid="9608">
  3622.             <Token id="content" type="str" depth="1">\0</Token>
  3623.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="2">322</Token>
  3624.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3625.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3626.             <Token id="content" type="str" distance="42" within="4">\0\0\0\0</Token>
  3627.             <Token id="byte_test" type="int" offset="8" oper="greater" relative="1" size="2">255</Token>
  3628.             <Token id="content" type="str" complement="1" distance="10" within="255">\0</Token>
  3629.         </Rule>
  3630.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB Session Setup AndX request unicode username overflow attempt" sid="9612">
  3631.             <Token id="content" type="str" distance="0">\0\0</Token>
  3632.             <Token id="content" type="str" distance="0">\0\0</Token>
  3633.             <Token id="content" type="str" depth="1">\0</Token>
  3634.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="2">322</Token>
  3635.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3636.             <Token id="byte_test" type="int" format="big" offset="6" oper="and" relative="1" size="1">128</Token>
  3637.             <Token id="byte_test" type="int" offset="54" oper="greater" relative="1" size="2">255</Token>
  3638.             <Token id="content" type="str" distance="56">\0</Token>
  3639.             <Token id="content" type="str" distance="255">\0\0</Token>
  3640.             <Token id="content" type="str" distance="0">\0\0</Token>
  3641.         </Rule>
  3642.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS Session Setup AndX request unicode username overflow attempt" sid="9616">
  3643.             <Token id="content" type="str" distance="0">\0\0</Token>
  3644.             <Token id="content" type="str" distance="0">\0\0</Token>
  3645.             <Token id="content" type="str" depth="1">\0</Token>
  3646.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="2">322</Token>
  3647.             <Token id="content" type="str" depth="5" nocase="1" offset="4">\xFFSMBs</Token>
  3648.             <Token id="byte_test" type="int" format="big" offset="6" oper="and" relative="1" size="1">128</Token>
  3649.             <Token id="byte_test" type="int" offset="54" oper="greater" relative="1" size="2">255</Token>
  3650.             <Token id="content" type="str" distance="56">\0</Token>
  3651.             <Token id="content" type="str" distance="255">\0\0</Token>
  3652.             <Token id="content" type="str" distance="0">\0\0</Token>
  3653.         </Rule>
  3654.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS IPC$ share access" sid="9860">
  3655.             <Token id="content" type="str" depth="1">\0</Token>
  3656.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3657.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3658.             <Token id="content" type="str" distance="32" nocase="1">IPC$\0</Token>
  3659.         </Rule>
  3660.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS IPC$ share unicode access" sid="9864">
  3661.             <Token id="content" type="str" depth="1">\0</Token>
  3662.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3663.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3664.             <Token id="content" type="str" distance="32" nocase="1">I\0P\0C\0$\0\0</Token>
  3665.         </Rule>
  3666.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB D$ share unicode access" sid="9868">
  3667.             <Token id="content" type="str" depth="1">\0</Token>
  3668.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3669.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3670.             <Token id="content" type="str" distance="32" nocase="1">D\0$\0\0</Token>
  3671.         </Rule>
  3672.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS D$ share access" sid="9872">
  3673.             <Token id="content" type="str" depth="1">\0</Token>
  3674.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3675.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3676.             <Token id="content" type="str" distance="32" nocase="1">D$\0</Token>
  3677.         </Rule>
  3678.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS D$ share unicode access" sid="9876">
  3679.             <Token id="content" type="str" depth="1">\0</Token>
  3680.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3681.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3682.             <Token id="content" type="str" distance="32" nocase="1">D\0$\0\0</Token>
  3683.         </Rule>
  3684.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB C$ share unicode access" sid="9880">
  3685.             <Token id="content" type="str" depth="1">\0</Token>
  3686.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3687.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3688.             <Token id="content" type="str" distance="32" nocase="1">C\0$\0\0</Token>
  3689.         </Rule>
  3690.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS C$ share access" sid="9884">
  3691.             <Token id="content" type="str" depth="1">\0</Token>
  3692.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3693.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3694.             <Token id="content" type="str" distance="32" nocase="1">C$\0</Token>
  3695.         </Rule>
  3696.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS C$ share unicode access" sid="9888">
  3697.             <Token id="content" type="str" depth="1">\0</Token>
  3698.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3699.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3700.             <Token id="content" type="str" distance="32" nocase="1">C\0$\0\0</Token>
  3701.         </Rule>
  3702.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="139" remport="*" name="NETBIOS SMB ADMIN$ share unicode access" sid="9892">
  3703.             <Token id="content" type="str" depth="1">\0</Token>
  3704.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3705.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3706.             <Token id="content" type="str" distance="32" nocase="1">A\0D\0M\0I\0N\0$\0\0</Token>
  3707.         </Rule>
  3708.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS ADMIN$ share access" sid="9896">
  3709.             <Token id="content" type="str" depth="1">\0</Token>
  3710.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3711.             <Token id="byte_test" type="int" format="big" offset="6" oper="less" relative="1" size="1">128</Token>
  3712.             <Token id="content" type="str" distance="32" nocase="1">ADMIN$\0</Token>
  3713.         </Rule>
  3714.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="445" remport="*" name="NETBIOS SMB-DS ADMIN$ share unicode access" sid="9900">
  3715.             <Token id="content" type="str" depth="1">\0</Token>
  3716.             <Token id="content" type="str" depth="5" offset="4">\xFFSMBu</Token>
  3717.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" relative="1" size="1">127</Token>
  3718.             <Token id="content" type="str" distance="32" nocase="1">A\0D\0M\0I\0N\0$\0\0</Token>
  3719.         </Rule>
  3720.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="137" name="NETBIOS NS lookup response name overflow attempt" sid="10252">
  3721.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="1">127</Token>
  3722.             <Token id="content" type="str" depth="2" offset="6">\0\x01</Token>
  3723.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" size="1">32</Token>
  3724.         </Rule>
  3725.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="137" remport="137" name="NETBIOS NS lookup short response attempt" sid="10256">
  3726.             <Token id="dsize" type="int" rel="less">56</Token>
  3727.             <Token id="byte_test" type="int" format="big" offset="2" oper="greater" size="1">127</Token>
  3728.             <Token id="content" type="str" depth="2" offset="6">\0\x01</Token>
  3729.         </Rule>
  3730.     </RuleList>
  3731.     <RuleList name="chat.rules">
  3732.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN message" sid="2160" enabled="0">
  3733.             <Token id="content" type="str" depth="4">MSG </Token>
  3734.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3735.             <Token id="content" type="str" distance="1">text/plain</Token>
  3736.         </Rule>
  3737.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN message" sid="2161" enabled="0">
  3738.             <Token id="content" type="str" depth="4">MSG </Token>
  3739.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3740.             <Token id="content" type="str" distance="1">text/plain</Token>
  3741.         </Rule>
  3742.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="CHAT ICQ access" sid="2164" enabled="0">
  3743.             <Token id="content" type="str">User-Agent:ICQ</Token>
  3744.         </Rule>
  3745.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC nick change" sid="2168" enabled="0">
  3746.             <Token id="content" type="str">NICK </Token>
  3747.         </Rule>
  3748.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC message" sid="5852" enabled="0">
  3749.             <Token id="content" type="str" nocase="1">PRIVMSG </Token>
  3750.         </Rule>
  3751.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC message" sid="5853" enabled="0">
  3752.             <Token id="content" type="str" nocase="1">PRIVMSG </Token>
  3753.         </Rule>
  3754.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="aim_servers" locport="*" remport="*" name="CHAT AIM login" sid="6524" enabled="0">
  3755.             <Token id="content" type="str" depth="2">*\x01</Token>
  3756.         </Rule>
  3757.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="aim_servers" locport="*" remport="*" name="CHAT AIM send message" sid="6528" enabled="0">
  3758.             <Token id="content" type="str" depth="2">*\x02</Token>
  3759.             <Token id="content" type="str" depth="4" offset="6">\0\x04\0\x06</Token>
  3760.         </Rule>
  3761.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="aim_servers" locport="*" remport="*" name="CHAT AIM receive message" sid="6532" enabled="0">
  3762.             <Token id="content" type="str" depth="2">*\x02</Token>
  3763.             <Token id="content" type="str" depth="4" offset="6">\0\x04\0\a</Token>
  3764.         </Rule>
  3765.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC DCC file transfer request" sid="6556" enabled="0">
  3766.             <Token id="content" type="str" nocase="1">PRIVMSG </Token>
  3767.             <Token id="content" type="str" nocase="1"> :.DCC SEND</Token>
  3768.         </Rule>
  3769.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC DCC chat request" sid="6560" enabled="0">
  3770.             <Token id="content" type="str" nocase="1">PRIVMSG </Token>
  3771.             <Token id="content" type="str" nocase="1"> :.DCC CHAT chat</Token>
  3772.         </Rule>
  3773.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC channel join" sid="6916" enabled="0">
  3774.             <Token id="content" type="str" nocase="1">JOIN : #</Token>
  3775.         </Rule>
  3776.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC dns request" sid="7156" enabled="0">
  3777.             <Token id="content" type="str" nocase="1">USERHOST </Token>
  3778.         </Rule>
  3779.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666-7000" name="CHAT IRC dns response" sid="7160" enabled="0">
  3780.             <Token id="content" type="str">:</Token>
  3781.             <Token id="content" type="str"> 302 </Token>
  3782.             <Token id="content" type="str">=+</Token>
  3783.         </Rule>
  3784.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="80" name="CHAT ICQ forced user addition" sid="7328" enabled="0">
  3785.             <Token id="content" type="str" nocase="1">Content-Type: application/x-icq</Token>
  3786.             <Token id="content" type="str">[ICQ User]</Token>
  3787.         </Rule>
  3788.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer request" sid="7944" enabled="0">
  3789.             <Token id="content" type="str" depth="4">MSG </Token>
  3790.             <Token id="content" type="str" distance="0" nocase="1">Content-Type:</Token>
  3791.             <Token id="content" type="str" distance="0" nocase="1">text/x-msmsgsinvite</Token>
  3792.             <Token id="content" type="str">Application-Name:</Token>
  3793.             <Token id="content" type="str" distance="0" nocase="1">File Transfer</Token>
  3794.         </Rule>
  3795.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer request" sid="7945" enabled="0">
  3796.             <Token id="content" type="str" depth="4">MSG </Token>
  3797.             <Token id="content" type="str" distance="0" nocase="1">Content-Type:</Token>
  3798.             <Token id="content" type="str" distance="0" nocase="1">text/x-msmsgsinvite</Token>
  3799.             <Token id="content" type="str">Application-Name:</Token>
  3800.             <Token id="content" type="str" distance="0" nocase="1">File Transfer</Token>
  3801.         </Rule>
  3802.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer accept" sid="7952" enabled="0">
  3803.             <Token id="content" type="str" depth="4">MSG </Token>
  3804.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3805.             <Token id="content" type="str" distance="0">text/x-msmsgsinvite</Token>
  3806.             <Token id="content" type="str">Invitation-Command:</Token>
  3807.             <Token id="content" type="str" distance="1">ACCEPT</Token>
  3808.         </Rule>
  3809.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer accept" sid="7953" enabled="0">
  3810.             <Token id="content" type="str" depth="4">MSG </Token>
  3811.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3812.             <Token id="content" type="str" distance="0">text/x-msmsgsinvite</Token>
  3813.             <Token id="content" type="str">Invitation-Command:</Token>
  3814.             <Token id="content" type="str" distance="1">ACCEPT</Token>
  3815.         </Rule>
  3816.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer reject" sid="7956" enabled="0">
  3817.             <Token id="content" type="str" depth="4">MSG </Token>
  3818.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3819.             <Token id="content" type="str" distance="0">text/x-msmsgsinvite</Token>
  3820.             <Token id="content" type="str">Invitation-Command:</Token>
  3821.             <Token id="content" type="str" distance="0">CANCEL</Token>
  3822.             <Token id="content" type="str" nocase="1">Cancel-Code:</Token>
  3823.             <Token id="content" type="str" distance="0" nocase="1">REJECT</Token>
  3824.         </Rule>
  3825.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN file transfer reject" sid="7957" enabled="0">
  3826.             <Token id="content" type="str" depth="4">MSG </Token>
  3827.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  3828.             <Token id="content" type="str" distance="0">text/x-msmsgsinvite</Token>
  3829.             <Token id="content" type="str">Invitation-Command:</Token>
  3830.             <Token id="content" type="str" distance="0">CANCEL</Token>
  3831.             <Token id="content" type="str" nocase="1">Cancel-Code:</Token>
  3832.             <Token id="content" type="str" distance="0" nocase="1">REJECT</Token>
  3833.         </Rule>
  3834.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN user search" sid="7960" enabled="0">
  3835.             <Token id="content" type="str" depth="4" nocase="1">CAL </Token>
  3836.         </Rule>
  3837.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1863" name="CHAT MSN login attempt" sid="7964" enabled="0">
  3838.             <Token id="content" type="str" depth="4" nocase="1">USR </Token>
  3839.             <Token id="content" type="str" distance="1" nocase="1"> TWN </Token>
  3840.         </Rule>
  3841.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM successful logon" sid="9800" enabled="0">
  3842.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3843.             <Token id="content" type="str" depth="2" offset="10">\0\x01</Token>
  3844.         </Rule>
  3845.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM voicechat" sid="9804" enabled="0">
  3846.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3847.             <Token id="content" type="str" depth="2" offset="10">\0J</Token>
  3848.         </Rule>
  3849.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM ping" sid="9808" enabled="0">
  3850.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3851.             <Token id="content" type="str" depth="2" offset="10">\0\x12</Token>
  3852.         </Rule>
  3853.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM conference invitation" sid="9812" enabled="0">
  3854.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3855.             <Token id="content" type="str" depth="2" offset="10">\0\x18</Token>
  3856.         </Rule>
  3857.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM conference logon success" sid="9816" enabled="0">
  3858.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3859.             <Token id="content" type="str" depth="2" offset="10">\0\x19</Token>
  3860.         </Rule>
  3861.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM conference message" sid="9820" enabled="0">
  3862.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3863.             <Token id="content" type="str" depth="2" offset="10">\0\x1D</Token>
  3864.         </Rule>
  3865.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="5050" name="CHAT Yahoo IM file transfer request" sid="9824" enabled="0">
  3866.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3867.             <Token id="content" type="str" depth="2" offset="10">\0M</Token>
  3868.         </Rule>
  3869.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="5050" remport="*" name="CHAT Yahoo IM file transfer request" sid="9825" enabled="0">
  3870.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3871.             <Token id="content" type="str" depth="2" offset="10">\0M</Token>
  3872.         </Rule>
  3873.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="5101" name="CHAT Yahoo IM message" sid="9828" enabled="0">
  3874.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3875.         </Rule>
  3876.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="5101" remport="*" name="CHAT Yahoo IM message" sid="9829" enabled="0">
  3877.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3878.         </Rule>
  3879.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="all" remaddr_id="all" locport="*" remport="5101" name="CHAT Yahoo IM message" sid="9830" enabled="0">
  3880.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3881.         </Rule>
  3882.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="all" remaddr_id="all" locport="5101" remport="*" name="CHAT Yahoo IM message" sid="9831" enabled="0">
  3883.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3884.         </Rule>
  3885.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM successful chat join" sid="9832" enabled="0">
  3886.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3887.             <Token id="content" type="str" depth="2" offset="10">\0\x98</Token>
  3888.         </Rule>
  3889.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5050" name="CHAT Yahoo IM webcam offer invitation" sid="9836" enabled="0">
  3890.             <Token id="content" type="str" depth="4" nocase="1">YMSG</Token>
  3891.             <Token id="content" type="str" depth="2" offset="10">\0P</Token>
  3892.         </Rule>
  3893.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5100" name="CHAT Yahoo IM webcam request" sid="9840" enabled="0">
  3894.             <Token id="content" type="str" depth="2">&lt;R</Token>
  3895.             <Token id="pcre" type="str">=/^\x3c(REQIMG|RVWCFG)\x3e/ism</Token>
  3896.         </Rule>
  3897.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5100" name="CHAT Yahoo IM webcam watch" sid="9844" enabled="0">
  3898.             <Token id="content" type="str" depth="4">\r\0\x05\0</Token>
  3899.         </Rule>
  3900.     </RuleList>
  3901.     <RuleList name="p2p.rules">
  3902.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="8888" name="P2P napster login" sid="2196" enabled="0">
  3903.             <Token id="content" type="str" depth="3" offset="1">\0\x02\0</Token>
  3904.         </Rule>
  3905.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="8888" name="P2P napster new user login" sid="2200" enabled="0">
  3906.             <Token id="content" type="str" depth="3" offset="1">\0\x06\0</Token>
  3907.         </Rule>
  3908.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8888" remport="*" name="P2P napster download attempt" sid="2204" enabled="0">
  3909.             <Token id="content" type="str" depth="3" offset="1">\0\xCB\0</Token>
  3910.         </Rule>
  3911.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="8888" name="P2P napster upload request" sid="2208" enabled="0">
  3912.             <Token id="content" type="str" depth="3" offset="1">\0_\x02</Token>
  3913.         </Rule>
  3914.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="P2P Outbound GNUTella client request" sid="2224" enabled="0">
  3915.             <Token id="content" type="str" depth="40">GNUTELLA CONNECT</Token>
  3916.         </Rule>
  3917.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="P2P GNUTella client request" sid="2228" enabled="0">
  3918.             <Token id="content" type="str" depth="40">GNUTELLA OK</Token>
  3919.         </Rule>
  3920.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6699" name="P2P Napster Client Data" sid="2244" enabled="0">
  3921.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3922.         </Rule>
  3923.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6699" name="P2P Napster Client Data" sid="2245" enabled="0">
  3924.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3925.         </Rule>
  3926.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="7777" name="P2P Napster Client Data" sid="2248" enabled="0">
  3927.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3928.         </Rule>
  3929.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="7777" name="P2P Napster Client Data" sid="2249" enabled="0">
  3930.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3931.         </Rule>
  3932.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666" name="P2P Napster Client Data" sid="2252" enabled="0">
  3933.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3934.         </Rule>
  3935.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6666" name="P2P Napster Client Data" sid="2253" enabled="0">
  3936.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3937.         </Rule>
  3938.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5555" name="P2P Napster Client Data" sid="2256" enabled="0">
  3939.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3940.         </Rule>
  3941.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="5555" name="P2P Napster Client Data" sid="2257" enabled="0">
  3942.             <Token id="content" type="str" nocase="1">.mp3</Token>
  3943.         </Rule>
  3944.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="8875" name="P2P Napster Server Login" sid="2260" enabled="0">
  3945.             <Token id="content" type="str">anon@napster.com</Token>
  3946.         </Rule>
  3947.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="8875" name="P2P Napster Server Login" sid="2261" enabled="0">
  3948.             <Token id="content" type="str">anon@napster.com</Token>
  3949.         </Rule>
  3950.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1214" remport="*" name="P2P Fastrack kazaa/morpheus GET request" sid="5532" enabled="0">
  3951.             <Token id="content" type="str" depth="4">GET </Token>
  3952.         </Rule>
  3953.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="!80" name="P2P GNUTella GET" sid="5728" enabled="0">
  3954.             <Token id="content" type="str" depth="4">GET </Token>
  3955.         </Rule>
  3956.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="P2P Fastrack kazaa/morpheus traffic" sid="6796" enabled="0">
  3957.             <Token id="content" type="str" depth="3">GET</Token>
  3958.             <Token id="content" type="str">UserAgent: KazaaClient</Token>
  3959.         </Rule>
  3960.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="P2P BitTorrent announce request" sid="8720" enabled="0">
  3961.             <Token id="content" type="str" depth="4">GET</Token>
  3962.             <Token id="content" type="str" distance="1">/announce</Token>
  3963.             <Token id="content" type="str" offset="4">info_hash=</Token>
  3964.             <Token id="content" type="str" offset="4">event=started</Token>
  3965.         </Rule>
  3966.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="6881-6889" name="P2P BitTorrent transfer" sid="8724" enabled="0">
  3967.             <Token id="content" type="str" depth="20">\x13BitTorrent protocol</Token>
  3968.         </Rule>
  3969.     </RuleList>
  3970.     <RuleList name="rpc.rules">
  3971.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC snmpXdmi overflow attempt TCP" sid="2276">
  3972.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x87\x99</Token>
  3973.             <Token id="content" type="str" distance="4" within="4">\0\0\x01\x01</Token>
  3974.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3975.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3976.             <Token id="byte_test" type="int" format="big" offset="20" oper="greater" relative="1" size="4">1024</Token>
  3977.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  3978.         </Rule>
  3979.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP export request" sid="2296">
  3980.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  3981.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x05</Token>
  3982.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  3983.         </Rule>
  3984.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap admind request UDP" sid="2300">
  3985.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  3986.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  3987.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3988.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3989.             <Token id="content" type="str" within="4">\0\x01\x86\xF7</Token>
  3990.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  3991.         </Rule>
  3992.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap amountd request UDP" sid="2304">
  3993.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  3994.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  3995.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3996.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  3997.             <Token id="content" type="str" within="4">\0\x01\x87\x03</Token>
  3998.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  3999.         </Rule>
  4000.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap bootparam request UDP" sid="2308">
  4001.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4002.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4003.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4004.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4005.             <Token id="content" type="str" within="4">\0\x01\x86\xBA</Token>
  4006.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4007.         </Rule>
  4008.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap cmsd request UDP" sid="2312">
  4009.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4010.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4011.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4012.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4013.             <Token id="content" type="str" within="4">\0\x01\x86\xE4</Token>
  4014.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4015.         </Rule>
  4016.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap mountd request UDP" sid="2316">
  4017.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4018.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4019.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4020.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4021.             <Token id="content" type="str" within="4">\0\x01\x86\xA5</Token>
  4022.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4023.         </Rule>
  4024.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap nisd request UDP" sid="2320">
  4025.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4026.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4027.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4028.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4029.             <Token id="content" type="str" within="4">\0\x01\x87\xCC</Token>
  4030.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4031.         </Rule>
  4032.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap pcnfsd request UDP" sid="2324">
  4033.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4034.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4035.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4036.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4037.             <Token id="content" type="str" within="4">\0\x02I\xF1</Token>
  4038.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4039.         </Rule>
  4040.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rexd request UDP" sid="2328">
  4041.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4042.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4043.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4044.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4045.             <Token id="content" type="str" within="4">\0\x01\x86\xB1</Token>
  4046.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4047.         </Rule>
  4048.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rstatd request UDP" sid="2332">
  4049.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4050.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4051.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4052.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4053.             <Token id="content" type="str" within="4">\0\x01\x86\xA1</Token>
  4054.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4055.         </Rule>
  4056.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rusers request UDP" sid="2336">
  4057.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4058.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4059.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4060.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4061.             <Token id="content" type="str" within="4">\0\x01\x86\xA2</Token>
  4062.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4063.         </Rule>
  4064.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap sadmind request UDP" sid="2340">
  4065.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4066.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4067.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4068.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4069.             <Token id="content" type="str" within="4">\0\x01\x87\x88</Token>
  4070.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4071.         </Rule>
  4072.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap selection_svc request UDP" sid="2344">
  4073.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4074.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4075.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4076.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4077.             <Token id="content" type="str" within="4">\0\x01\x86\xAF</Token>
  4078.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4079.         </Rule>
  4080.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap status request UDP" sid="2348">
  4081.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4082.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4083.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4084.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4085.             <Token id="content" type="str" within="4">\0\x01\x86\xB8</Token>
  4086.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4087.         </Rule>
  4088.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ttdbserv request UDP" sid="2352">
  4089.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4090.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4091.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4092.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4093.             <Token id="content" type="str" within="4">\0\x01\x86\xF3</Token>
  4094.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4095.         </Rule>
  4096.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap yppasswd request UDP" sid="2356">
  4097.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4098.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4099.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4100.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4101.             <Token id="content" type="str" within="4">\0\x01\x86\xA9</Token>
  4102.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4103.         </Rule>
  4104.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ypserv request UDP" sid="2360">
  4105.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4106.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4107.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4108.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4109.             <Token id="content" type="str" within="4">\0\x01\x86\xA4</Token>
  4110.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4111.         </Rule>
  4112.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ypupdated request TCP" sid="2364">
  4113.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4114.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4115.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4116.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4117.             <Token id="content" type="str" within="4">\0\x01\x86\xBC</Token>
  4118.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4119.         </Rule>
  4120.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap snmpXdmi request TCP" sid="2372">
  4121.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4122.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4123.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4124.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4125.             <Token id="content" type="str" within="4">\0\x01\x87\x99</Token>
  4126.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4127.         </Rule>
  4128.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap espd request TCP" sid="2380">
  4129.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4130.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4131.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4132.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4133.             <Token id="content" type="str" within="4">\0\x05\xF7u</Token>
  4134.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4135.         </Rule>
  4136.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap listing TCP 111" sid="2392">
  4137.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4138.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4139.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4140.         </Rule>
  4141.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="32771" remport="*" name="RPC portmap listing TCP 32771" sid="2396">
  4142.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4143.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4144.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4145.         </Rule>
  4146.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC rusers query UDP" sid="2448">
  4147.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA2</Token>
  4148.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4149.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4150.         </Rule>
  4151.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap admind request TCP" sid="5048">
  4152.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4153.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4154.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4155.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4156.             <Token id="content" type="str" within="4">\0\x01\x86\xF7</Token>
  4157.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4158.         </Rule>
  4159.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap amountd request TCP" sid="5052">
  4160.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4161.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4162.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4163.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4164.             <Token id="content" type="str" within="4">\0\x01\x87\x03</Token>
  4165.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4166.         </Rule>
  4167.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap bootparam request TCP" sid="5056">
  4168.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4169.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4170.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4171.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4172.             <Token id="content" type="str" within="4">\0\x01\x86\xBA</Token>
  4173.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4174.         </Rule>
  4175.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap cmsd request TCP" sid="5060">
  4176.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4177.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4178.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4179.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4180.             <Token id="content" type="str" within="4">\0\x01\x86\xE4</Token>
  4181.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4182.         </Rule>
  4183.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap mountd request TCP" sid="5064">
  4184.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4185.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4186.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4187.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4188.             <Token id="content" type="str" within="4">\0\x01\x86\xA5</Token>
  4189.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4190.         </Rule>
  4191.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap nisd request TCP" sid="5068">
  4192.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4193.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4194.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4195.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4196.             <Token id="content" type="str" within="4">\0\x01\x87\xCC</Token>
  4197.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4198.         </Rule>
  4199.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap pcnfsd request TCP" sid="5072">
  4200.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4201.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4202.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4203.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4204.             <Token id="content" type="str" within="4">\0\x02I\xF1</Token>
  4205.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4206.         </Rule>
  4207.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rexd request TCP" sid="5076">
  4208.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4209.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4210.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4211.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4212.             <Token id="content" type="str" within="4">\0\x01\x86\xB1</Token>
  4213.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4214.         </Rule>
  4215.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rstatd request TCP" sid="5080">
  4216.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4217.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4218.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4219.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4220.             <Token id="content" type="str" within="4">\0\x01\x86\xA1</Token>
  4221.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4222.         </Rule>
  4223.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rusers request TCP" sid="5084">
  4224.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4225.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4226.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4227.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4228.             <Token id="content" type="str" within="4">\0\x01\x86\xA2</Token>
  4229.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4230.         </Rule>
  4231.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap sadmind request TCP" sid="5088">
  4232.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4233.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4234.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4235.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4236.             <Token id="content" type="str" within="4">\0\x01\x87\x88</Token>
  4237.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4238.         </Rule>
  4239.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap selection_svc request TCP" sid="5092">
  4240.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4241.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4242.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4243.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4244.             <Token id="content" type="str" within="4">\0\x01\x86\xAF</Token>
  4245.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4246.         </Rule>
  4247.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ttdbserv request TCP" sid="5096">
  4248.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4249.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4250.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4251.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4252.             <Token id="content" type="str" within="4">\0\x01\x86\xF3</Token>
  4253.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4254.         </Rule>
  4255.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap yppasswd request TCP" sid="5100">
  4256.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4257.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4258.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4259.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4260.             <Token id="content" type="str" within="4">\0\x01\x86\xA9</Token>
  4261.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4262.         </Rule>
  4263.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ypserv request TCP" sid="5104">
  4264.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4265.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4266.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4267.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4268.             <Token id="content" type="str" within="4">\0\x01\x86\xA4</Token>
  4269.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4270.         </Rule>
  4271.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap ypupdated request UDP" sid="5108">
  4272.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4273.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4274.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4275.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4276.             <Token id="content" type="str" within="4">\0\x01\x86\xBC</Token>
  4277.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4278.         </Rule>
  4279.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap snmpXdmi request UDP" sid="5116">
  4280.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4281.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4282.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4283.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4284.             <Token id="content" type="str" within="4">\0\x01\x87\x99</Token>
  4285.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4286.         </Rule>
  4287.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap listing UDP 111" sid="5120">
  4288.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4289.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4290.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4291.         </Rule>
  4292.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="32771" remport="*" name="RPC portmap listing UDP 32771" sid="5124">
  4293.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4294.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4295.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4296.         </Rule>
  4297.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rwalld request UDP" sid="6928">
  4298.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4299.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4300.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4301.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4302.             <Token id="content" type="str" within="4">\0\x01\x86\xA8</Token>
  4303.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4304.         </Rule>
  4305.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rwalld request TCP" sid="6932">
  4306.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4307.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4308.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4309.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4310.             <Token id="content" type="str" within="4">\0\x01\x86\xA8</Token>
  4311.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4312.         </Rule>
  4313.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap cachefsd request UDP" sid="6984">
  4314.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4315.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4316.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4317.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4318.             <Token id="content" type="str" within="4">\0\x01\x87\x8B</Token>
  4319.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4320.         </Rule>
  4321.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap cachefsd request TCP" sid="6988">
  4322.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4323.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4324.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4325.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4326.             <Token id="content" type="str" within="4">\0\x01\x87\x8B</Token>
  4327.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4328.         </Rule>
  4329.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1024-65535" remport="*" name="RPC status GHBN format string attack" sid="7560">
  4330.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xB8</Token>
  4331.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4332.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4333.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4334.             <Token id="content" type="str" within="256">%x %x</Token>
  4335.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4336.         </Rule>
  4337.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1024-65535" remport="*" name="RPC status GHBN format string attack" sid="7564">
  4338.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xB8</Token>
  4339.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4340.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4341.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4342.             <Token id="content" type="str" within="256">%x %x</Token>
  4343.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4344.         </Rule>
  4345.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD UDP amqproc_mount plog overflow attempt" sid="7620">
  4346.             <Token id="content" type="str" depth="4" offset="12">\0\x04\x93\xF3</Token>
  4347.             <Token id="content" type="str" distance="4" within="4">\0\0\0\a</Token>
  4348.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4349.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4350.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">512</Token>
  4351.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4352.         </Rule>
  4353.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD TCP amqproc_mount plog overflow attempt" sid="7624">
  4354.             <Token id="content" type="str" depth="4" offset="16">\0\x04\x93\xF3</Token>
  4355.             <Token id="content" type="str" distance="4" within="4">\0\0\0\a</Token>
  4356.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4357.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4358.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">512</Token>
  4359.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4360.         </Rule>
  4361.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD UDP CMSD_CREATE buffer overflow attempt" sid="7628">
  4362.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xE4</Token>
  4363.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x15</Token>
  4364.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4365.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4366.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">1024</Token>
  4367.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4368.         </Rule>
  4369.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD TCP CMSD_CREATE buffer overflow attempt" sid="7632">
  4370.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xE4</Token>
  4371.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x15</Token>
  4372.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4373.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4374.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">1024</Token>
  4375.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4376.         </Rule>
  4377.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD TCP CMSD_INSERT buffer overflow attempt" sid="7636">
  4378.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xE4</Token>
  4379.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x06</Token>
  4380.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4381.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4382.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4383.             <Token id="byte_test" type="int" format="big" offset="28" oper="greater" relative="1" size="4">1000</Token>
  4384.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4385.         </Rule>
  4386.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD udp CMSD_INSERT buffer overflow attempt" sid="7640">
  4387.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xE4</Token>
  4388.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x06</Token>
  4389.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4390.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4391.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4392.             <Token id="byte_test" type="int" format="big" offset="28" oper="greater" relative="1" size="4">1000</Token>
  4393.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4394.         </Rule>
  4395.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind UDP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt" sid="7644">
  4396.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x87\x88</Token>
  4397.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4398.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4399.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4400.             <Token id="byte_jump" type="int" align="1" format="big" offset="124" relative="1">4</Token>
  4401.             <Token id="byte_jump" type="int" align="1" format="big" offset="20" relative="1">4</Token>
  4402.             <Token id="byte_test" type="int" format="big" offset="4" oper="greater" relative="1" size="4">512</Token>
  4403.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4404.         </Rule>
  4405.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind TCP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt" sid="7648">
  4406.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x87\x88</Token>
  4407.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4408.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4409.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4410.             <Token id="byte_jump" type="int" align="1" format="big" offset="124" relative="1">4</Token>
  4411.             <Token id="byte_jump" type="int" align="1" format="big" offset="20" relative="1">4</Token>
  4412.             <Token id="byte_test" type="int" format="big" offset="4" oper="greater" relative="1" size="4">512</Token>
  4413.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4414.         </Rule>
  4415.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC STATD UDP stat mon_name format string exploit attempt" sid="7652">
  4416.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xB8</Token>
  4417.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4418.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4419.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4420.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">100</Token>
  4421.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4422.         </Rule>
  4423.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC STATD TCP stat mon_name format string exploit attempt" sid="7656">
  4424.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xB8</Token>
  4425.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4426.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4427.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4428.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">100</Token>
  4429.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4430.         </Rule>
  4431.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC STATD UDP monitor mon_name format string exploit attempt" sid="7660">
  4432.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xB8</Token>
  4433.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4434.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4435.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4436.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">100</Token>
  4437.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4438.         </Rule>
  4439.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC STATD TCP monitor mon_name format string exploit attempt" sid="7664">
  4440.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xB8</Token>
  4441.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4442.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4443.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4444.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">100</Token>
  4445.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4446.         </Rule>
  4447.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap proxy attempt TCP" sid="7688">
  4448.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4449.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x05</Token>
  4450.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4451.         </Rule>
  4452.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap proxy attempt UDP" sid="7692">
  4453.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4454.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x05</Token>
  4455.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4456.         </Rule>
  4457.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP export request" sid="7696">
  4458.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4459.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x05</Token>
  4460.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4461.         </Rule>
  4462.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP exportall request" sid="7700">
  4463.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  4464.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x06</Token>
  4465.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4466.         </Rule>
  4467.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP exportall request" sid="7704">
  4468.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4469.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x06</Token>
  4470.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4471.         </Rule>
  4472.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap SET attempt TCP 111" sid="7796">
  4473.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4474.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4475.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4476.         </Rule>
  4477.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap SET attempt UDP 111" sid="7800">
  4478.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4479.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4480.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4481.         </Rule>
  4482.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP mount request" sid="7804">
  4483.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  4484.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4485.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4486.         </Rule>
  4487.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP mount request" sid="7808">
  4488.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4489.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4490.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4491.         </Rule>
  4492.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD TCP pid request" sid="7812">
  4493.             <Token id="content" type="str" depth="4" offset="16">\0\x04\x93\xF3</Token>
  4494.             <Token id="content" type="str" distance="4" within="4">\0\0\0\t</Token>
  4495.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4496.         </Rule>
  4497.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD UDP pid request" sid="7816">
  4498.             <Token id="content" type="str" depth="4" offset="12">\0\x04\x93\xF3</Token>
  4499.             <Token id="content" type="str" distance="4" within="4">\0\0\0\t</Token>
  4500.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4501.         </Rule>
  4502.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD TCP version request" sid="7820">
  4503.             <Token id="content" type="str" depth="4" offset="16">\0\x04\x93\xF3</Token>
  4504.             <Token id="content" type="str" distance="4" within="4">\0\0\0\b</Token>
  4505.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4506.         </Rule>
  4507.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="500-65535" remport="*" name="RPC AMD UDP version request" sid="7824">
  4508.             <Token id="content" type="str" depth="4" offset="12">\0\x04\x93\xF3</Token>
  4509.             <Token id="content" type="str" distance="4" within="4">\0\0\0\b</Token>
  4510.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4511.         </Rule>
  4512.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind UDP PING" sid="7828">
  4513.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x87\x88</Token>
  4514.             <Token id="content" type="str" distance="4" within="4">\0\0\0\0</Token>
  4515.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4516.         </Rule>
  4517.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind TCP PING" sid="7832">
  4518.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x87\x88</Token>
  4519.             <Token id="content" type="str" distance="4" within="4">\0\0\0\0</Token>
  4520.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4521.         </Rule>
  4522.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap NFS request UDP" sid="7836">
  4523.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4524.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4525.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4526.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4527.             <Token id="content" type="str" within="4">\0\x01\x86\xA3</Token>
  4528.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4529.         </Rule>
  4530.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap NFS request TCP" sid="7840">
  4531.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4532.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4533.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4534.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4535.             <Token id="content" type="str" within="4">\0\x01\x86\xA3</Token>
  4536.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4537.         </Rule>
  4538.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap RQUOTA request UDP" sid="7844">
  4539.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4540.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4541.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4542.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4543.             <Token id="content" type="str" within="4">\0\x01\x86\xAB</Token>
  4544.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4545.         </Rule>
  4546.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap RQUOTA request TCP" sid="7848">
  4547.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4548.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4549.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4550.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4551.             <Token id="content" type="str" within="4">\0\x01\x86\xAB</Token>
  4552.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4553.         </Rule>
  4554.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC RQUOTA getquota overflow attempt UDP" sid="7852">
  4555.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xAB</Token>
  4556.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4557.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4558.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4559.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">128</Token>
  4560.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4561.         </Rule>
  4562.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC tooltalk UDP overflow attempt" sid="7856">
  4563.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xF3</Token>
  4564.             <Token id="content" type="str" distance="4" within="4">\0\0\0\a</Token>
  4565.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4566.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4567.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">128</Token>
  4568.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4569.         </Rule>
  4570.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC tooltalk TCP overflow attempt" sid="7860">
  4571.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xF3</Token>
  4572.             <Token id="content" type="str" distance="4" within="4">\0\0\0\a</Token>
  4573.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4574.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4575.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">128</Token>
  4576.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4577.         </Rule>
  4578.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap kcms_server request UDP" sid="8020">
  4579.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4580.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4581.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4582.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4583.             <Token id="content" type="str" within="4">\0\x01\x87}</Token>
  4584.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4585.         </Rule>
  4586.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap kcms_server request TCP" sid="8024">
  4587.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4588.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4589.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4590.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4591.             <Token id="content" type="str" within="4">\0\x01\x87}</Token>
  4592.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4593.         </Rule>
  4594.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="32771-34000" remport="*" name="RPC kcms_server directory traversal attempt" sid="8028">
  4595.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x87}</Token>
  4596.             <Token id="byte_jump" type="int" align="1" format="big" offset="20" relative="1">4</Token>
  4597.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4598.             <Token id="content" type="str" distance="0">/../</Token>
  4599.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4600.         </Rule>
  4601.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap UNSET attempt TCP 111" sid="8056">
  4602.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4603.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4604.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4605.         </Rule>
  4606.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap UNSET attempt UDP 111" sid="8060">
  4607.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4608.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4609.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4610.         </Rule>
  4611.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap status request TCP" sid="8064">
  4612.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4613.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4614.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4615.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4616.             <Token id="content" type="str" within="4">\0\x01\x86\xB8</Token>
  4617.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4618.         </Rule>
  4619.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap espd request UDP" sid="8068">
  4620.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4621.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4622.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4623.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4624.             <Token id="content" type="str" within="4">\0\x05\xF7u</Token>
  4625.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4626.         </Rule>
  4627.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP dump request" sid="8072">
  4628.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  4629.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4630.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4631.         </Rule>
  4632.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP dump request" sid="8076">
  4633.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4634.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x02</Token>
  4635.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4636.         </Rule>
  4637.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP unmount request" sid="8080">
  4638.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  4639.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4640.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4641.         </Rule>
  4642.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP unmount request" sid="8084">
  4643.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4644.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4645.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4646.         </Rule>
  4647.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP unmountall request" sid="8088">
  4648.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA5</Token>
  4649.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4650.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4651.         </Rule>
  4652.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP unmountall request" sid="8092">
  4653.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA5</Token>
  4654.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x04</Token>
  4655.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4656.         </Rule>
  4657.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC RQUOTA getquota overflow attempt TCP" sid="8096">
  4658.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xAB</Token>
  4659.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4660.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4661.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4662.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">128</Token>
  4663.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4664.         </Rule>
  4665.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd username overflow attempt UDP" sid="8100">
  4666.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA9</Token>
  4667.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4668.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4669.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4670.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4671.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4672.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4673.         </Rule>
  4674.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd username overflow attempt TCP" sid="8104">
  4675.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA9</Token>
  4676.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4677.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4678.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4679.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4680.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4681.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4682.         </Rule>
  4683.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd old password overflow attempt UDP" sid="8108">
  4684.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA9</Token>
  4685.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4686.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4687.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4688.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4689.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4690.         </Rule>
  4691.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd old password overflow attempt TCP" sid="8112">
  4692.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA9</Token>
  4693.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4694.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4695.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4696.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4697.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4698.         </Rule>
  4699.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd new password overflow attempt UDP" sid="8116">
  4700.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA9</Token>
  4701.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4702.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4703.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4704.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4705.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4706.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4707.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4708.         </Rule>
  4709.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd new password overflow attempt TCP" sid="8120">
  4710.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA9</Token>
  4711.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4712.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4713.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4714.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4715.             <Token id="byte_jump" type="int" align="1" format="big" relative="1">4</Token>
  4716.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">64</Token>
  4717.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4718.         </Rule>
  4719.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd user update UDP" sid="8124">
  4720.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA9</Token>
  4721.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4722.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4723.         </Rule>
  4724.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC yppasswd user update TCP" sid="8128">
  4725.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA9</Token>
  4726.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4727.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4728.         </Rule>
  4729.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC ypserv maplist request UDP" sid="8132">
  4730.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA4</Token>
  4731.             <Token id="content" type="str" distance="4" within="4">\0\0\0\v</Token>
  4732.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4733.         </Rule>
  4734.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC ypserv maplist request TCP" sid="8136">
  4735.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA4</Token>
  4736.             <Token id="content" type="str" distance="4" within="4">\0\0\0\v</Token>
  4737.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4738.         </Rule>
  4739.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap network-status-monitor request UDP" sid="8140">
  4740.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4741.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4742.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4743.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4744.             <Token id="content" type="str" within="4">\0\x03\rp</Token>
  4745.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4746.         </Rule>
  4747.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap network-status-monitor request TCP" sid="8144">
  4748.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4749.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4750.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4751.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4752.             <Token id="content" type="str" within="4">\0\x03\rp</Token>
  4753.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4754.         </Rule>
  4755.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC network-status-monitor mon-callback request UDP" sid="8148">
  4756.             <Token id="content" type="str" depth="4" offset="12">\0\x03\rp</Token>
  4757.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4758.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4759.         </Rule>
  4760.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC network-status-monitor mon-callback request TCP" sid="8152">
  4761.             <Token id="content" type="str" depth="4" offset="16">\0\x03\rp</Token>
  4762.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4763.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4764.         </Rule>
  4765.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC snmpXdmi overflow attempt UDP" sid="8180">
  4766.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x87\x99</Token>
  4767.             <Token id="content" type="str" distance="4" within="4">\0\0\x01\x01</Token>
  4768.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4769.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4770.             <Token id="byte_test" type="int" format="big" offset="20" oper="greater" relative="1" size="4">1024</Token>
  4771.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4772.         </Rule>
  4773.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap nlockmgr request UDP" sid="8316">
  4774.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4775.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4776.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4777.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4778.             <Token id="content" type="str" within="4">\0\x01\x86\xB5</Token>
  4779.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4780.         </Rule>
  4781.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap nlockmgr request TCP" sid="8320">
  4782.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4783.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4784.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4785.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4786.             <Token id="content" type="str" within="4">\0\x01\x86\xB5</Token>
  4787.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4788.         </Rule>
  4789.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rpc.xfsmd request UDP" sid="8324">
  4790.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xA0</Token>
  4791.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4792.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4793.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4794.             <Token id="content" type="str" within="4">\0\x05\xF7h</Token>
  4795.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4796.         </Rule>
  4797.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap rpc.xfsmd request TCP" sid="8328">
  4798.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xA0</Token>
  4799.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x03</Token>
  4800.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4801.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4802.             <Token id="content" type="str" within="4">\0\x05\xF7h</Token>
  4803.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4804.         </Rule>
  4805.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC rpc.xfsmd xfs_export attempt UDP" sid="8332">
  4806.             <Token id="content" type="str" depth="4" offset="12">\0\x05\xF7h</Token>
  4807.             <Token id="content" type="str" distance="4" within="4">\0\0\0\r</Token>
  4808.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4809.         </Rule>
  4810.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC rpc.xfsmd xfs_export attempt TCP" sid="8336">
  4811.             <Token id="content" type="str" depth="4" offset="16">\0\x05\xF7h</Token>
  4812.             <Token id="content" type="str" distance="4" within="4">\0\0\0\r</Token>
  4813.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4814.         </Rule>
  4815.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC ypupdated arbitrary command attempt UDP" sid="8352">
  4816.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xBC</Token>
  4817.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4818.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4819.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4820.             <Token id="content" type="str" distance="4">|</Token>
  4821.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4822.         </Rule>
  4823.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC ypupdated arbitrary command attempt TCP" sid="8356">
  4824.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xBC</Token>
  4825.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x01</Token>
  4826.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4827.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4828.             <Token id="content" type="str" distance="4">|</Token>
  4829.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4830.         </Rule>
  4831.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap proxy integer overflow attempt UDP" sid="8368">
  4832.             <Token id="content" type="str" depth="5" offset="12">\0\x01\x86\xA0\0</Token>
  4833.             <Token id="content" type="str" distance="3" within="4">\0\0\0\x05</Token>
  4834.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4835.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4836.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="4">2048</Token>
  4837.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4838.         </Rule>
  4839.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="111" remport="*" name="RPC portmap proxy integer overflow attempt TCP" sid="8372">
  4840.             <Token id="content" type="str" depth="5" offset="16">\0\x01\x86\xA0\0</Token>
  4841.             <Token id="content" type="str" distance="3" within="4">\0\0\0\x05</Token>
  4842.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4843.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4844.             <Token id="byte_test" type="int" format="big" offset="12" oper="greater" relative="1" size="4">2048</Token>
  4845.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4846.         </Rule>
  4847.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD UDP CMSD_CREATE array buffer overflow attempt" sid="8376">
  4848.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x86\xE4</Token>
  4849.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x15</Token>
  4850.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4851.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4852.             <Token id="byte_test" type="int" format="big" offset="20" oper="greater" relative="1" size="4">1024</Token>
  4853.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4854.         </Rule>
  4855.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC CMSD TCP CMSD_CREATE array buffer overflow attempt" sid="8380">
  4856.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x86\xE4</Token>
  4857.             <Token id="content" type="str" distance="4" within="4">\0\0\0\x15</Token>
  4858.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4859.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4860.             <Token id="byte_test" type="int" format="big" offset="20" oper="greater" relative="1" size="4">1024</Token>
  4861.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4862.         </Rule>
  4863.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd TCP mount path overflow attempt" sid="8736">
  4864.             <Token id="content" type="str" depth="5" offset="16">\0\x01\x86\xA5\0</Token>
  4865.             <Token id="content" type="str" distance="3" within="4">\0\0\0\x01</Token>
  4866.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4867.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4868.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">1023</Token>
  4869.             <Token id="content" type="str" depth="4" offset="8">\0\0\0\0</Token>
  4870.         </Rule>
  4871.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC mountd UDP mount path overflow attempt" sid="8740">
  4872.             <Token id="content" type="str" depth="5" offset="12">\0\x01\x86\xA5\0</Token>
  4873.             <Token id="content" type="str" distance="3" within="4">\0\0\0\x01</Token>
  4874.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4875.             <Token id="byte_jump" type="int" align="1" format="big" offset="4" relative="1">4</Token>
  4876.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="4">1023</Token>
  4877.             <Token id="content" type="str" depth="4" offset="4">\0\0\0\0</Token>
  4878.         </Rule>
  4879.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind query with root credentials attempt TCP" sid="9020">
  4880.             <Token id="content" type="str" depth="4" offset="16">\0\x01\x87\x88</Token>
  4881.             <Token id="content" type="str" distance="4" within="8">\0\0\0\x01\0\0\0\x01</Token>
  4882.             <Token id="byte_jump" type="int" align="1" format="big" offset="8" relative="1">4</Token>
  4883.             <Token id="content" type="str" within="4">\0\0\0\0</Token>
  4884.         </Rule>
  4885.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="RPC sadmind query with root credentials attempt UDP" sid="9024">
  4886.             <Token id="content" type="str" depth="4" offset="12">\0\x01\x87\x88</Token>
  4887.             <Token id="content" type="str" distance="4" within="8">\0\0\0\x01\0\0\0\x01</Token>
  4888.             <Token id="byte_jump" type="int" align="1" format="big" offset="8" relative="1">4</Token>
  4889.             <Token id="content" type="str" within="4">\0\0\0\0</Token>
  4890.         </Rule>
  4891.     </RuleList>
  4892.     <RuleList name="rservices.rules">
  4893.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin LinuxNIS" sid="2404">
  4894.             <Token id="content" type="str">::::::::\0::::::::</Token>
  4895.         </Rule>
  4896.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin bin" sid="2408">
  4897.             <Token id="content" type="str">bin\0bin\0</Token>
  4898.         </Rule>
  4899.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin echo++" sid="2412">
  4900.             <Token id="content" type="str">echo \" + + \"</Token>
  4901.         </Rule>
  4902.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rsh froot" sid="2416">
  4903.             <Token id="content" type="str">-froot\0</Token>
  4904.         </Rule>
  4905.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin login failure" sid="2420">
  4906.             <Token id="content" type="str">login incorrect</Token>
  4907.         </Rule>
  4908.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin root" sid="2424">
  4909.             <Token id="content" type="str">root\0root\0</Token>
  4910.         </Rule>
  4911.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="514" remport="*" name="RSERVICES rsh bin" sid="2428">
  4912.             <Token id="content" type="str">bin\0bin\0</Token>
  4913.         </Rule>
  4914.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="514" remport="*" name="RSERVICES rsh echo + +" sid="2432">
  4915.             <Token id="content" type="str">echo \"+ +\"</Token>
  4916.         </Rule>
  4917.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="514" remport="*" name="RSERVICES rsh froot" sid="2436">
  4918.             <Token id="content" type="str">-froot\0</Token>
  4919.         </Rule>
  4920.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="514" remport="*" name="RSERVICES rsh root" sid="2440">
  4921.             <Token id="content" type="str">root\0root\0</Token>
  4922.         </Rule>
  4923.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="513" remport="*" name="RSERVICES rlogin login failure" sid="2444">
  4924.             <Token id="content" type="str">\x01rlogind: Permission denied.</Token>
  4925.         </Rule>
  4926.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="512" remport="*" name="RSERVICES rexec username overflow attempt" sid="8452">
  4927.             <Token id="content" type="str" offset="9">\0</Token>
  4928.             <Token id="content" type="str" distance="0">\0</Token>
  4929.             <Token id="content" type="str" distance="0">\0</Token>
  4930.         </Rule>
  4931.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="512" remport="*" name="RSERVICES rexec password overflow attempt" sid="8456">
  4932.             <Token id="content" type="str">\0</Token>
  4933.             <Token id="content" type="str" distance="33">\0</Token>
  4934.             <Token id="content" type="str" distance="0">\0</Token>
  4935.         </Rule>
  4936.     </RuleList>
  4937.     <RuleList name="scan.rules">
  4938.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="10101" name="SCAN myscan" sid="2452">
  4939.             <Token id="tcp_ack" type="int">0</Token>
  4940.             <Token id="tcp_flg" type="str">S</Token>
  4941.             <Token id="ip_ttl" type="int" rel="greater">220</Token>
  4942.         </Rule>
  4943.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="1080" remport="*" name="SCAN SOCKS Proxy attempt" sid="2460">
  4944.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  4945.         </Rule>
  4946.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="113" remport="*" name="SCAN ident version request" sid="2464">
  4947.             <Token id="content" type="str" depth="16">VERSION\n</Token>
  4948.         </Rule>
  4949.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="3128" remport="*" name="SCAN Squid Proxy attempt" sid="2472">
  4950.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  4951.         </Rule>
  4952.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="80" remport="*" name="SCAN cybercop os probe" sid="2476">
  4953.             <Token id="dsize" type="int">0</Token>
  4954.             <Token id="tcp_flg" type="str">FS12</Token>
  4955.         </Rule>
  4956.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="8080" remport="*" name="SCAN Proxy Port 8080 attempt" sid="2480">
  4957.             <Token id="tcp_flg" type="str" mask="12">S</Token>
  4958.         </Rule>
  4959.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN FIN" sid="2484">
  4960.             <Token id="tcp_flg" type="str" mask="12">F</Token>
  4961.         </Rule>
  4962.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN ipEye SYN scan" sid="2488">
  4963.             <Token id="tcp_flg" type="str">S</Token>
  4964.             <Token id="tcp_seq" type="int">1958810375</Token>
  4965.         </Rule>
  4966.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN NULL" sid="2492">
  4967.             <Token id="tcp_ack" type="int">0</Token>
  4968.             <Token id="tcp_flg" type="str">F</Token>
  4969.             <Token id="tcp_seq" type="int">0</Token>
  4970.         </Rule>
  4971.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN SYN FIN" sid="2496">
  4972.             <Token id="tcp_flg" type="str" mask="12">FS</Token>
  4973.         </Rule>
  4974.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN XMAS" sid="2500">
  4975.             <Token id="tcp_flg" type="str" mask="12">FSRPAU</Token>
  4976.         </Rule>
  4977.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN cybercop os PA12 attempt" sid="2504">
  4978.             <Token id="tcp_flg" type="str">PA12</Token>
  4979.             <Token id="content" type="str" depth="16">AAAAAAAAAAAAAAAA</Token>
  4980.         </Rule>
  4981.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN cybercop os SFU12 probe" sid="2508">
  4982.             <Token id="tcp_ack" type="int">0</Token>
  4983.             <Token id="tcp_flg" type="str">FSU12</Token>
  4984.             <Token id="content" type="str" depth="16">AAAAAAAAAAAAAAAA</Token>
  4985.         </Rule>
  4986.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN synscan portscan" sid="2520">
  4987.             <Token id="tcp_flg" type="str">FS</Token>
  4988.             <Token id="ip_id" type="int">39426</Token>
  4989.         </Rule>
  4990.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="10080-10081" remport="*" name="SCAN Amanda client version request" sid="2536">
  4991.             <Token id="content" type="str" nocase="1">Amanda</Token>
  4992.         </Rule>
  4993.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="49" remport="*" name="SCAN XTACACS logout" sid="2540">
  4994.             <Token id="content" type="str">\x80\a\0\0\a\0\0\x04\0\0\0\0\0</Token>
  4995.         </Rule>
  4996.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="7" remport="*" name="SCAN cybercop udp bomb" sid="2544">
  4997.             <Token id="content" type="str">cybercop</Token>
  4998.         </Rule>
  4999.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN Webtrends Scanner UDP Probe" sid="2548">
  5000.             <Token id="content" type="str">\nhelp\nquite\n</Token>
  5001.         </Rule>
  5002.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="SCAN cybercop os probe" sid="4532">
  5003.             <Token id="tcp_ack" type="int">0</Token>
  5004.             <Token id="tcp_flg" type="str">FSP</Token>
  5005.             <Token id="content" type="str" depth="16">AAAAAAAAAAAAAAAA</Token>
  5006.         </Rule>
  5007.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="*" name="SCAN nmap XMAS" sid="4912">
  5008.             <Token id="tcp_flg" type="str" mask="12">FPU</Token>
  5009.         </Rule>
  5010.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="22" remport="*" name="SCAN SSH Version map attempt" sid="6552">
  5011.             <Token id="content" type="str" nocase="1">Version_Mapper</Token>
  5012.         </Rule>
  5013.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1900" remport="*" name="SCAN UPnP service discover attempt" sid="7668">
  5014.             <Token id="content" type="str" depth="9">M-SEARCH </Token>
  5015.             <Token id="content" type="str">ssdp:discover</Token>
  5016.         </Rule>
  5017.         <Rule al="Monitor" ar="Allow" dir="in" prot="icmp" locaddr_id="home_net" remaddr_id="external_net" name="SCAN SolarWinds IP scan attempt" sid="7672">
  5018.             <Token id="icmp_code" type="int">0</Token>
  5019.             <Token id="icmp_type" type="int">8</Token>
  5020.             <Token id="content" type="str">SolarWinds.Net</Token>
  5021.         </Rule>
  5022.     </RuleList>
  5023.     <RuleList name="smtp.rules">
  5024.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP ehlo cybercop attempt" sid="2524">
  5025.             <Token id="content" type="str">ehlo cybercop\nquit\n</Token>
  5026.         </Rule>
  5027.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP expn cybercop attempt" sid="2528">
  5028.             <Token id="content" type="str">expn cybercop</Token>
  5029.         </Rule>
  5030.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP RCPT TO overflow" sid="2616">
  5031.             <Token id="content" type="str" nocase="1">rcpt to:</Token>
  5032.             <Token id="isdataat" type="int" rel="relative">300</Token>
  5033.             <Token id="pcre" type="str">=/^RCPT TO\s[^\n]{300}/ism</Token>
  5034.         </Rule>
  5035.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="113" name="SMTP sendmail 8.6.9 exploit" sid="2620">
  5036.             <Token id="content" type="str">\nD/</Token>
  5037.         </Rule>
  5038.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP chameleon overflow" sid="2628">
  5039.             <Token id="content" type="str" nocase="1">HELP</Token>
  5040.             <Token id="isdataat" type="int" rel="relative">500</Token>
  5041.             <Token id="pcre" type="str">=/^HELP\s[^\n]{500}/ism</Token>
  5042.         </Rule>
  5043.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP exchange mime DOS" sid="2632">
  5044.             <Token id="content" type="str">charset = \"\"</Token>
  5045.         </Rule>
  5046.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP expn decode" sid="2636">
  5047.             <Token id="content" type="str" nocase="1">expn</Token>
  5048.             <Token id="content" type="str" nocase="1">decode</Token>
  5049.             <Token id="pcre" type="str">=/^expn\s+decode/smi</Token>
  5050.         </Rule>
  5051.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP expn root" sid="2640">
  5052.             <Token id="content" type="str" nocase="1">expn</Token>
  5053.             <Token id="content" type="str" nocase="1">root</Token>
  5054.             <Token id="pcre" type="str">=/^expn\s+root/smi</Token>
  5055.         </Rule>
  5056.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP majordomo ifs" sid="2644">
  5057.             <Token id="content" type="str">eply-to: a~.`/bin/</Token>
  5058.         </Rule>
  5059.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 5.5.5 exploit" sid="2648">
  5060.             <Token id="content" type="str" nocase="1">mail from: \"|</Token>
  5061.         </Rule>
  5062.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP rcpt to command attempt" sid="2652">
  5063.             <Token id="content" type="str" nocase="1">rcpt to:</Token>
  5064.             <Token id="pcre" type="str">=/^rcpt\s+to\:\s+[|\x3b]/smi</Token>
  5065.         </Rule>
  5066.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP RCPT TO decode attempt" sid="2656">
  5067.             <Token id="content" type="str">rcpt to:</Token>
  5068.             <Token id="content" type="str" distance="0" nocase="1">decode</Token>
  5069.             <Token id="pcre" type="str">=/^rcpt to\:\s+decode/smi</Token>
  5070.         </Rule>
  5071.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 5.6.5 exploit" sid="2660">
  5072.             <Token id="content" type="str" nocase="1">MAIL FROM: |/usr/ucb/tail</Token>
  5073.         </Rule>
  5074.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 8.6.10 exploit" sid="2668">
  5075.             <Token id="content" type="str">Croot\r\nMprog, P=/bin/</Token>
  5076.         </Rule>
  5077.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 8.6.10 exploit" sid="2672">
  5078.             <Token id="content" type="str">Croot\t\t\t\t\t\t\tMprog,P=/bin</Token>
  5079.         </Rule>
  5080.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 8.6.9 exploit" sid="2676">
  5081.             <Token id="content" type="str">\nCroot\nMprog</Token>
  5082.         </Rule>
  5083.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 8.6.9 exploit" sid="2680">
  5084.             <Token id="content" type="str">\nC:daemon\nR</Token>
  5085.         </Rule>
  5086.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP sendmail 8.6.9c exploit" sid="2684">
  5087.             <Token id="content" type="str">\nCroot\r\nMprog</Token>
  5088.         </Rule>
  5089.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP vrfy decode" sid="2688">
  5090.             <Token id="content" type="str" nocase="1">vrfy</Token>
  5091.             <Token id="content" type="str" distance="1" nocase="1">decode</Token>
  5092.             <Token id="pcre" type="str">=/^vrfy\s+decode/smi</Token>
  5093.         </Rule>
  5094.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP vrfy root" sid="5784">
  5095.             <Token id="content" type="str" nocase="1">vrfy</Token>
  5096.             <Token id="content" type="str" distance="1" nocase="1">root</Token>
  5097.             <Token id="pcre" type="str">=/^vrfy\s+root/smi</Token>
  5098.         </Rule>
  5099.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP expn *@" sid="5800">
  5100.             <Token id="content" type="str" nocase="1">expn</Token>
  5101.             <Token id="content" type="str">*@</Token>
  5102.             <Token id="pcre" type="str">=/^expn\s+\*@/smi</Token>
  5103.         </Rule>
  5104.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP HELO overflow attempt" sid="6196">
  5105.             <Token id="content" type="str">HELO</Token>
  5106.             <Token id="isdataat" type="int" rel="relative">500</Token>
  5107.             <Token id="pcre" type="str">=/^HELO\s[^\n]{500}/smi</Token>
  5108.         </Rule>
  5109.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP ETRN overflow attempt" sid="6200">
  5110.             <Token id="content" type="str">ETRN</Token>
  5111.             <Token id="isdataat" type="int" rel="relative">500</Token>
  5112.             <Token id="pcre" type="str">=/^ETRN\s[^\n]{500}/smi</Token>
  5113.         </Rule>
  5114.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP From comment overflow attempt" sid="8348">
  5115.             <Token id="content" type="str">From:</Token>
  5116.             <Token id="content" type="str" distance="0">&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;</Token>
  5117.             <Token id="content" type="str" distance="1">(</Token>
  5118.             <Token id="content" type="str" distance="1">)</Token>
  5119.         </Rule>
  5120.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP Content-Transfer-Encoding overflow attempt" sid="8732">
  5121.             <Token id="content" type="str">Content-Transfer-Encoding:</Token>
  5122.             <Token id="isdataat" type="int" rel="relative">100</Token>
  5123.             <Token id="content" type="str" complement="1" within="100">\n</Token>
  5124.         </Rule>
  5125.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP XEXCH50 overflow attempt" sid="9012">
  5126.             <Token id="content" type="str" nocase="1">XEXCH50</Token>
  5127.             <Token id="pcre" type="str">=/^XEXCH50\s+-\d/smi</Token>
  5128.         </Rule>
  5129.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP EXPN overflow attempt" sid="9036">
  5130.             <Token id="content" type="str" nocase="1">EXPN</Token>
  5131.             <Token id="pcre" type="str">=/^EXPN[^\n]{255,}/smi</Token>
  5132.         </Rule>
  5133.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP VRFY overflow attempt" sid="9040">
  5134.             <Token id="content" type="str" nocase="1">VRFY</Token>
  5135.             <Token id="pcre" type="str">=/^VRFY[^\n]{255,}/smi</Token>
  5136.         </Rule>
  5137.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SEND FROM sendmail prescan too many addresses overflow" sid="9044">
  5138.             <Token id="content" type="str" nocase="1">SEND FROM:</Token>
  5139.             <Token id="pcre" type="str">=/^SEND FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi</Token>
  5140.         </Rule>
  5141.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SEND FROM sendmail prescan too long addresses overflow" sid="9048">
  5142.             <Token id="content" type="str" nocase="1">SEND FROM:</Token>
  5143.             <Token id="pcre" type="str">=/^SEND FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}/smi</Token>
  5144.         </Rule>
  5145.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SAML FROM sendmail prescan too many addresses overflow" sid="9052">
  5146.             <Token id="content" type="str" nocase="1">SAML FROM:</Token>
  5147.             <Token id="pcre" type="str">=/^SAML FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi</Token>
  5148.         </Rule>
  5149.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SAML FROM sendmail prescan too long addresses overflow" sid="9056">
  5150.             <Token id="content" type="str" nocase="1">SAML FROM:</Token>
  5151.             <Token id="pcre" type="str">=/^SAML FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}/smi</Token>
  5152.         </Rule>
  5153.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SOML FROM sendmail prescan too many addresses overflow" sid="9060">
  5154.             <Token id="content" type="str" nocase="1">SOML FROM:</Token>
  5155.             <Token id="pcre" type="str">=/^SOML FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi</Token>
  5156.         </Rule>
  5157.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP SOML FROM sendmail prescan too long addresses overflow" sid="9064">
  5158.             <Token id="content" type="str" nocase="1">SOML FROM:</Token>
  5159.             <Token id="pcre" type="str">=/^SOML FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}/smi</Token>
  5160.         </Rule>
  5161.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP MAIL FROM sendmail prescan too many addresses overflow" sid="9068">
  5162.             <Token id="content" type="str" nocase="1">MAIL FROM:</Token>
  5163.             <Token id="pcre" type="str">=/^MAIL FROM\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi</Token>
  5164.         </Rule>
  5165.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP MAIL FROM sendmail prescan too long addresses overflow" sid="9072">
  5166.             <Token id="content" type="str" nocase="1">MAIL FROM:</Token>
  5167.             <Token id="pcre" type="str">=/^MAIL FROM\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}/smi</Token>
  5168.         </Rule>
  5169.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP RCPT TO sendmail prescan too many addresses overflow" sid="9076">
  5170.             <Token id="content" type="str" nocase="1">RCPT TO:</Token>
  5171.             <Token id="pcre" type="str">=/^RCPT TO\x3a\s*[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;[^\n]*?&lt;/smi</Token>
  5172.         </Rule>
  5173.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP RCPT TO sendmail prescan too long addresses overflow" sid="9080">
  5174.             <Token id="content" type="str" nocase="1">RCPT TO:</Token>
  5175.             <Token id="pcre" type="str">=/^RCPT TO\x3a\s+[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}\x3b[\w\s@\.]{200,}/smi</Token>
  5176.         </Rule>
  5177.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP AUTH LOGON brute force attempt" sid="9100">
  5178.             <Token id="content" type="str" nocase="1" offset="54">Authentication unsuccessful</Token>
  5179.         </Rule>
  5180.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP WinZip MIME content-type buffer overflow" sid="9948">
  5181.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  5182.             <Token id="pcre" type="str">=/name=[^\r\n]*?\.(mim|uue|uu|b64|bhx|hqx|xxe)/smi</Token>
  5183.             <Token id="pcre" type="str">=/(name|id|number|total|boundary)=\s*[^\r\n\x3b\s\x2c]{300}/smi</Token>
  5184.         </Rule>
  5185.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="25" remport="*" name="SMTP WinZip MIME content-disposition buffer overflow" sid="9952">
  5186.             <Token id="content" type="str" nocase="1">Content-Type:</Token>
  5187.             <Token id="pcre" type="str">=/name=[^\r\n]*?\.(mim|uue|uu|b64|bhx|hqx|xxe)/smi</Token>
  5188.             <Token id="content" type="str" nocase="1">Content-Disposition:</Token>
  5189.             <Token id="pcre" type="str">=/name=\s*[^\r\n\x3b\s\x2c]{300}/smi</Token>
  5190.         </Rule>
  5191.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="465" remport="*" name="SMTP SSLv3 invalid data version attempt" sid="10016">
  5192.             <Token id="content" type="str" depth="2">\x16\x03</Token>
  5193.             <Token id="content" type="str" depth="1" offset="5">\x01</Token>
  5194.             <Token id="content" type="str" complement="1" depth="1" offset="9">\x03</Token>
  5195.         </Rule>
  5196.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="smtp_servers" remaddr_id="external_net" locport="465" remport="*" name="SMTP Client_Hello overflow attempt" sid="10076">
  5197.             <Token id="content" type="str" depth="1" offset="2">\x01</Token>
  5198.             <Token id="byte_test" type="int" format="big" offset="6" oper="greater" size="2">0</Token>
  5199.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">0</Token>
  5200.             <Token id="byte_test" type="int" complement="1" format="big" offset="8" size="2">16</Token>
  5201.             <Token id="byte_test" type="int" format="big" offset="10" oper="greater" size="2">20</Token>
  5202.             <Token id="content" type="str" depth="1" offset="11">\x8F</Token>
  5203.             <Token id="byte_test" type="int" format="big" oper="greater" relative="1" size="2">32768</Token>
  5204.         </Rule>
  5205.     </RuleList>
  5206.     <RuleList name="shellcode.rules">
  5207.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE SGI NOOP" sid="2552" enabled="0">
  5208.             <Token id="content" type="str">\x03\xE0\xF8%\x03\xE0\xF8%\x03\xE0\xF8%\x03\xE0\xF8%</Token>
  5209.         </Rule>
  5210.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE SGI NOOP" sid="2556" enabled="0">
  5211.             <Token id="content" type="str">$\x0F\x124$\x0F\x124$\x0F\x124$\x0F\x124</Token>
  5212.         </Rule>
  5213.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE AIX NOOP" sid="2560" enabled="0">
  5214.             <Token id="content" type="str">O\xFF\xFB\x82O\xFF\xFB\x82O\xFF\xFB\x82O\xFF\xFB\x82</Token>
  5215.         </Rule>
  5216.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE Digital UNIX NOOP" sid="2564" enabled="0">
  5217.             <Token id="content" type="str">G\xFF\x04\x1FG\xFF\x04\x1FG\xFF\x04\x1FG\xFF\x04\x1F</Token>
  5218.         </Rule>
  5219.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE HP-UX NOOP" sid="2568" enabled="0">
  5220.             <Token id="content" type="str">\b!\x02\x80\b!\x02\x80\b!\x02\x80\b!\x02\x80</Token>
  5221.         </Rule>
  5222.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE HP-UX NOOP" sid="2572" enabled="0">
  5223.             <Token id="content" type="str">\v9\x02\x80\v9\x02\x80\v9\x02\x80\v9\x02\x80</Token>
  5224.         </Rule>
  5225.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE sparc NOOP" sid="2576" enabled="0">
  5226.             <Token id="content" type="str">\x13\xC0\x1C\xA6\x13\xC0\x1C\xA6\x13\xC0\x1C\xA6\x13\xC0\x1C\xA6</Token>
  5227.         </Rule>
  5228.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE sparc NOOP" sid="2580" enabled="0">
  5229.             <Token id="content" type="str">\x80\x1C@\x11\x80\x1C@\x11\x80\x1C@\x11\x80\x1C@\x11</Token>
  5230.         </Rule>
  5231.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE sparc NOOP" sid="2584" enabled="0">
  5232.             <Token id="content" type="str">\xA6\x1C\xC0\x13\xA6\x1C\xC0\x13\xA6\x1C\xC0\x13\xA6\x1C\xC0\x13</Token>
  5233.         </Rule>
  5234.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE sparc setuid 0" sid="2588" enabled="0">
  5235.             <Token id="content" type="str">\x82\x10 \x17\x91\xD0 \b</Token>
  5236.         </Rule>
  5237.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 NOOP" sid="2592" enabled="0">
  5238.             <Token id="content" type="str" depth="128">\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90</Token>
  5239.         </Rule>
  5240.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 setgid 0" sid="2596" enabled="0">
  5241.             <Token id="content" type="str">\xB0\xB5\xCD\x80</Token>
  5242.         </Rule>
  5243.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 setuid 0" sid="2600" enabled="0">
  5244.             <Token id="content" type="str">\xB0\x17\xCD\x80</Token>
  5245.         </Rule>
  5246.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 stealth NOOP" sid="2604" enabled="0">
  5247.             <Token id="content" type="str">\xEB\x02\xEB\x02\xEB\x02</Token>
  5248.         </Rule>
  5249.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE Linux shellcode" sid="2608" enabled="0">
  5250.             <Token id="content" type="str">\x90\x90\x90\xE8\xC0\xFF\xFF\xFF/bin/sh</Token>
  5251.         </Rule>
  5252.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 unicode NOOP" sid="2612" enabled="0">
  5253.             <Token id="content" type="str">\x90\0\x90\0\x90\0\x90\0\x90\0</Token>
  5254.         </Rule>
  5255.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 inc ebx NOOP" sid="5560" enabled="0">
  5256.             <Token id="content" type="str">CCCCCCCCCCCCCCCCCCCCCCCC</Token>
  5257.         </Rule>
  5258.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 NOOP" sid="5576" enabled="0">
  5259.             <Token id="content" type="str">aaaaaaaaaaaaaaaaaaaaa</Token>
  5260.         </Rule>
  5261.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 0xEB0C NOOP" sid="5696" enabled="0">
  5262.             <Token id="content" type="str">\xEB\f\xEB\f\xEB\f\xEB\f\xEB\f\xEB\f\xEB\f\xEB\f</Token>
  5263.         </Rule>
  5264.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 0x71FB7BAB NOOP" sid="9248" enabled="0">
  5265.             <Token id="content" type="str">q\xFB{\xABq\xFB{\xABq\xFB{\xABq\xFB{\xAB</Token>
  5266.         </Rule>
  5267.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 0x71FB7BAB NOOP unicode" sid="9252" enabled="0">
  5268.             <Token id="content" type="str">q\0\xFB\0{\0\xAB\0q\0\xFB\0{\0\xAB\0q\0\xFB\0{\0\xAB\0q\0\xFB\0{\0\xAB\0</Token>
  5269.         </Rule>
  5270.         <Rule al="Monitor" ar="Allow" dir="in" prot="ip" locaddr_id="home_net" remaddr_id="external_net" name="SHELLCODE x86 0x90 NOOP unicode" sid="9256" enabled="0">
  5271.             <Token id="content" type="str">\x90\0\x90\0\x90\0\x90\0\x90\0\x90\0\x90\0\x90\0</Token>
  5272.         </Rule>
  5273.     </RuleList>
  5274.     <RuleList name="sql.rules">
  5275.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL sp_start_job - program execution" sid="2692">
  5276.             <Token id="content" type="str" nocase="1">s\0p\0_\0s\0t\0a\0r\0t\0_\0j\0o\0b\0</Token>
  5277.         </Rule>
  5278.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_displayparamstmt possible buffer overflow" sid="2696">
  5279.             <Token id="content" type="str" nocase="1">x\0p\0_\0d\0i\0s\0p\0l\0a\0y\0p\0a\0r\0a\0m\0s\0t\0m\0t</Token>
  5280.         </Rule>
  5281.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_setsqlsecurity possible buffer overflow" sid="2700">
  5282.             <Token id="content" type="str" nocase="1">x\0p\0_\0s\0e\0t\0s\0q\0l\0s\0e\0c\0u\0r\0i\0t\0y\0</Token>
  5283.         </Rule>
  5284.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB sp_start_job - program execution" sid="2704">
  5285.             <Token id="content" type="str" depth="32" nocase="1" offset="32">s\0p\0_\0s\0t\0a\0r\0t\0_\0j\0o\0b\0</Token>
  5286.         </Rule>
  5287.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB sp_password password change" sid="2708">
  5288.             <Token id="content" type="str" nocase="1">s\0p\0_\0p\0a\0s\0s\0w\0o\0r\0d\0</Token>
  5289.         </Rule>
  5290.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB sp_delete_alert log file deletion" sid="2712">
  5291.             <Token id="content" type="str" nocase="1">s\0p\0_\0d\0e\0l\0e\0t\0e\0_\0a\0l\0e\0</Token>
  5292.         </Rule>
  5293.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB sp_adduser database user creation" sid="2716">
  5294.             <Token id="content" type="str" depth="32" nocase="1" offset="32">s\0p\0_\0a\0d\0d\0u\0s\0e\0r\0</Token>
  5295.         </Rule>
  5296.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB sa login failed" sid="2720">
  5297.             <Token id="content" type="str" offset="83">Login failed for user 'sa'</Token>
  5298.         </Rule>
  5299.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_cmdshell program execution" sid="2724">
  5300.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0c\0m\0d\0s\0h\0e\0l\0l\0</Token>
  5301.         </Rule>
  5302.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_enumresultset possible buffer overflow" sid="2728">
  5303.             <Token id="content" type="str" nocase="1">x\0p\0_\0e\0n\0u\0m\0r\0e\0s\0u\0l\0t\0s\0e\0t\0</Token>
  5304.         </Rule>
  5305.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL sp_password - password change" sid="2732">
  5306.             <Token id="content" type="str" nocase="1">s\0p\0_\0p\0a\0s\0s\0w\0o\0r\0d\0</Token>
  5307.         </Rule>
  5308.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL sp_delete_alert log file deletion" sid="2736">
  5309.             <Token id="content" type="str" nocase="1">s\0p\0_\0d\0e\0l\0e\0t\0e\0_\0a\0l\0e\0r\0t\0</Token>
  5310.         </Rule>
  5311.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL sp_adduser - database user creation" sid="2740">
  5312.             <Token id="content" type="str" nocase="1">s\0p\0_\0a\0d\0d\0u\0s\0e\0r\0</Token>
  5313.         </Rule>
  5314.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_reg* - registry access" sid="2744">
  5315.             <Token id="content" type="str" nocase="1">x\0p\0_\0r\0e\0g\0</Token>
  5316.         </Rule>
  5317.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_cmdshell - program execution" sid="2748">
  5318.             <Token id="content" type="str" nocase="1">x\0p\0_\0c\0m\0d\0s\0h\0e\0l\0l\0</Token>
  5319.         </Rule>
  5320.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL sa login failed" sid="2752">
  5321.             <Token id="content" type="str">Login failed for user 'sa'</Token>
  5322.         </Rule>
  5323.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_reg* registry access" sid="2756">
  5324.             <Token id="content" type="str" depth="32" nocase="1" offset="32">x\0p\0_\0r\0e\0g\0</Token>
  5325.         </Rule>
  5326.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_printstatements possible buffer overflow" sid="2760">
  5327.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0p\0r\0i\0n\0t\0s\0t\0a\0t\0e\0m\0e\0n\0t\0s\0</Token>
  5328.         </Rule>
  5329.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL shellcode attempt" sid="2764">
  5330.             <Token id="content" type="str">9 \xD0\0\x92\x01\xC2\0R\0U\09 \xEC\0</Token>
  5331.         </Rule>
  5332.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB shellcode attempt" sid="2768">
  5333.             <Token id="content" type="str">9 \xD0\0\x92\x01\xC2\0R\0U\09 \xEC\0</Token>
  5334.         </Rule>
  5335.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL shellcode attempt" sid="2772">
  5336.             <Token id="content" type="str">H\0%\0x\0w\0\x90\0\x90\0\x90\0\x90\0\x90\03\0\xC0\0P\0h\0.\0</Token>
  5337.         </Rule>
  5338.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB shellcode attempt" sid="2776">
  5339.             <Token id="content" type="str">H\0%\0x\0w\0\x90\0\x90\0\x90\0\x90\0\x90\03\0\xC0\0P\0h\0.\0</Token>
  5340.         </Rule>
  5341.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_sprintf possible buffer overflow" sid="2780">
  5342.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0s\0p\0r\0i\0n\0t\0f\0</Token>
  5343.         </Rule>
  5344.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_showcolv possible buffer overflow" sid="2784">
  5345.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0s\0h\0o\0w\0c\0o\0l\0v\0</Token>
  5346.         </Rule>
  5347.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_peekqueue possible buffer overflow" sid="2788">
  5348.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0p\0e\0e\0k\0q\0u\0e\0u\0e\0</Token>
  5349.         </Rule>
  5350.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_proxiedmetadata possible buffer overflow" sid="2792">
  5351.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0p\0r\0o\0x\0i\0e\0d\0m\0e\0t\0a\0d\0a\0t\0a\0</Token>
  5352.         </Rule>
  5353.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_printstatements possible buffer overflow" sid="2796">
  5354.             <Token id="content" type="str" nocase="1">x\0p\0_\0p\0r\0i\0n\0t\0s\0t\0a\0t\0e\0m\0e\0n\0t\0s\0</Token>
  5355.         </Rule>
  5356.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_updatecolvbm possible buffer overflow" sid="2800">
  5357.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0u\0p\0d\0a\0t\0e\0c\0o\0l\0v\0b\0m\0</Token>
  5358.         </Rule>
  5359.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_updatecolvbm possible buffer overflow" sid="2804">
  5360.             <Token id="content" type="str" nocase="1">x\0p\0_\0u\0p\0d\0a\0t\0e\0c\0o\0l\0v\0b\0m\0</Token>
  5361.         </Rule>
  5362.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_displayparamstmt possible buffer overflow" sid="2808">
  5363.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0d\0i\0s\0p\0l\0a\0y\0p\0a\0r\0a\0m\0s\0t\0m\0t\0</Token>
  5364.         </Rule>
  5365.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_setsqlsecurity possible buffer overflow" sid="2812">
  5366.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0s\0e\0t\0s\0q\0l\0s\0e\0c\0u\0r\0i\0t\0y\0</Token>
  5367.         </Rule>
  5368.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_sprintf possible buffer overflow" sid="2816">
  5369.             <Token id="content" type="str" nocase="1">x\0p\0_\0s\0p\0r\0i\0n\0t\0f\0</Token>
  5370.         </Rule>
  5371.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_showcolv possible buffer overflow" sid="2820">
  5372.             <Token id="content" type="str" nocase="1">x\0p\0_\0s\0h\0o\0w\0c\0o\0l\0v\0</Token>
  5373.         </Rule>
  5374.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_peekqueue possible buffer overflow" sid="2824">
  5375.             <Token id="content" type="str" nocase="1">x\0p\0_\0p\0e\0e\0k\0q\0u\0e\0u\0e\0</Token>
  5376.         </Rule>
  5377.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL xp_proxiedmetadata possible buffer overflow" sid="2828">
  5378.             <Token id="content" type="str" nocase="1">x\0p\0_\0p\0r\0o\0x\0i\0e\0d\0m\0e\0t\0a\0d\0a\0t\0a\0</Token>
  5379.         </Rule>
  5380.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB xp_enumresultset possible buffer overflow" sid="2832">
  5381.             <Token id="content" type="str" nocase="1" offset="32">x\0p\0_\0e\0n\0u\0m\0r\0e\0s\0u\0l\0t\0s\0e\0t\0</Token>
  5382.         </Rule>
  5383.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="139" remport="*" name="MS-SQL/SMB raiserror possible buffer overflow" sid="5544">
  5384.             <Token id="content" type="str" nocase="1" offset="32">r\0a\0i\0s\0e\0r\0r\0o\0r\0</Token>
  5385.         </Rule>
  5386.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="1433" remport="*" name="MS-SQL raiserror possible buffer overflow" sid="5548">
  5387.             <Token id="content" type="str" nocase="1">r\0a\0i\0s\0e\0r\0r\0o\0r\0</Token>
  5388.         </Rule>
  5389.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="sql_servers" remaddr_id="external_net" locport="445" remport="*" name="MS-SQL xp_cmdshell program execution 445" sid="7036">
  5390.             <Token id="content" type="str" nocase="1">x\0p\0_\0c\0m\0d\0s\0h\0e\0l\0l\0</Token>
  5391.         </Rule>
  5392.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1434" remport="*" name="MS-SQL Worm propagation attempt" sid="8012">
  5393.             <Token id="content" type="str" depth="1">\x04</Token>
  5394.             <Token id="content" type="str">\x81\xF1\x03\x01\x04\x9B\x81\xF1\x01</Token>
  5395.             <Token id="content" type="str">sock</Token>
  5396.             <Token id="content" type="str">send</Token>
  5397.         </Rule>
  5398.         <Rule al="Monitor" ar="Allow" dir="out" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="1434" name="MS-SQL Worm propagation attempt OUTBOUND" sid="8016">
  5399.             <Token id="content" type="str" depth="1">\x04</Token>
  5400.             <Token id="content" type="str">\x81\xF1\x03\x01\x04\x9B\x81\xF1</Token>
  5401.             <Token id="content" type="str">sock</Token>
  5402.             <Token id="content" type="str">send</Token>
  5403.         </Rule>
  5404.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1434" remport="*" name="MS-SQL ping attempt" sid="8196">
  5405.             <Token id="content" type="str" depth="1">\x02</Token>
  5406.         </Rule>
  5407.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="home_net" remaddr_id="external_net" locport="1434" remport="*" name="MS-SQL version overflow attempt" sid="8200">
  5408.             <Token id="dsize" type="int" rel="greater">100</Token>
  5409.             <Token id="content" type="str" depth="1">\x04</Token>
  5410.         </Rule>
  5411.         <Rule al="Monitor" ar="Allow" dir="in" prot="udp" locaddr_id="sql_servers" remaddr_id="external_net" locport="*" remport="*" name="MS-SQL probe response overflow attempt" sid="9316">
  5412.             <Token id="content" type="str" depth="1">\x05</Token>
  5413.             <Token id="byte_test" type="int" format="big" offset="1" oper="greater" size="2">512</Token>
  5414.             <Token id="content" type="str" distance="0">;</Token>
  5415.             <Token id="isdataat" type="int" rel="relative">512</Token>
  5416.             <Token id="content" type="str" complement="1" within="512">;</Token>
  5417.         </Rule>
  5418.     </RuleList>
  5419.     <RuleList name="telnet.rules">
  5420.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET 4Dgifts SGI account attempt" sid="2836">
  5421.             <Token id="content" type="str">4Dgifts</Token>
  5422.         </Rule>
  5423.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET EZsetup account attempt" sid="2840">
  5424.             <Token id="content" type="str">OutOfBox</Token>
  5425.         </Rule>
  5426.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET SGI telnetd format bug" sid="2844">
  5427.             <Token id="content" type="str">_RLD</Token>
  5428.             <Token id="content" type="str">bin/sh</Token>
  5429.         </Rule>
  5430.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET ld_library_path" sid="2848">
  5431.             <Token id="content" type="str">ld_library_path</Token>
  5432.         </Rule>
  5433.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET livingston DOS" sid="2852">
  5434.             <Token id="content" type="str">\xFF\xF3\xFF\xF3\xFF\xF3\xFF\xF3\xFF\xF3</Token>
  5435.         </Rule>
  5436.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET resolv_host_conf" sid="2856">
  5437.             <Token id="content" type="str">resolv_host_conf</Token>
  5438.         </Rule>
  5439.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET Attempted SU from wrong group" sid="2860">
  5440.             <Token id="content" type="str" nocase="1">to su root</Token>
  5441.         </Rule>
  5442.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET access" sid="2864">
  5443.             <Token id="content" type="str">\xFF\xFD</Token>
  5444.             <Token id="content" type="str" distance="0">\xFF\xFD</Token>
  5445.             <Token id="content" type="str" distance="0">\xFF\xFD</Token>
  5446.         </Rule>
  5447.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET not on console" sid="2868">
  5448.             <Token id="content" type="str" nocase="1">not on system console</Token>
  5449.         </Rule>
  5450.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET login incorrect" sid="2872">
  5451.             <Token id="content" type="str">Login incorrect</Token>
  5452.         </Rule>
  5453.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET root login" sid="2876">
  5454.             <Token id="content" type="str">login: root</Token>
  5455.         </Rule>
  5456.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET bsd telnet exploit response" sid="5008">
  5457.             <Token id="content" type="str">\r\n[Yes]\r\n\xFF\xFE\b\xFF\xFD&amp;</Token>
  5458.         </Rule>
  5459.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET bsd exploit client finishing" sid="5012">
  5460.             <Token id="dsize" type="int" rel="greater">200</Token>
  5461.             <Token id="content" type="str" depth="50" offset="200">\xFF\xF6\xFF\xF6\xFF\xFB\b\xFF\xF6</Token>
  5462.         </Rule>
  5463.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET Solaris memory mismanagement exploit attempt" sid="5720">
  5464.             <Token id="content" type="str">\xA0#\xA0\x10\xAE#\x80\x10\xEE#\xBF\xEC\x82\x05\xE0\xD6\x90%\xE0</Token>
  5465.         </Rule>
  5466.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="telnet_servers" remaddr_id="external_net" locport="23" remport="*" name="TELNET APC SmartSlot default admin account attempt" sid="9624">
  5467.             <Token id="content" type="str">TENmanUFactOryPOWER</Token>
  5468.         </Rule>
  5469.     </RuleList>
  5470.     <RuleList name="virus.rules">
  5471.         <Rule al="Monitor" ar="Allow" dir="out" prot="tcp" locaddr_id="home_net" remaddr_id="external_net" locport="*" remport="25" name="VIRUS OUTBOUND bad file attachment" sid="2884" enabled="0">
  5472.             <Token id="content" type="str" nocase="1">Content-Disposition:</Token>
  5473.             <Token id="pcre" type="str">=/filename\s*=\s*.*?\.(?=[abcdehijlmnoprsvwx])(a(d[ep]|s[dfx])|c([ho]m|li|md|pp)|d(iz|ll|ot)|e(m[fl]|xe)|h(lp|sq|ta)|jse?|m(d[abew]|s[ip])|p(p[st]|if|[lm]|ot)|r(eg|tf)|s(cr|[hy]s|wf)|v(b[es]?|cf|xd)|w(m[dfsz]|p[dmsz]|s[cfh])|xl[stw]|bat|ini|lnk|nws|ocx)[\x27\x22\n\r\s]/iR</Token>
  5474.         </Rule>
  5475.     </RuleList>
  5476.     <RuleList name="web-cgi.rules">
  5477.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI HyperSeek hsx.cgi directory traversal attempt" sid="3212">
  5478.             <Token id="content" type="str" uricont="1">/hsx.cgi</Token>
  5479.             <Token id="content" type="str">../../</Token>
  5480.             <Token id="content" type="str" distance="1">%00</Token>
  5481.         </Rule>
  5482.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI SWSoft ASPSeek Overflow attempt" sid="3216">
  5483.             <Token id="content" type="str" nocase="1" uricont="1">/s.cgi</Token>
  5484.             <Token id="content" type="str">tmpl=</Token>
  5485.         </Rule>
  5486.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webspeed access" sid="3220">
  5487.             <Token id="content" type="str" nocase="1" uricont="1">/wsisa.dll/WService=</Token>
  5488.             <Token id="content" type="str" nocase="1">WSMadmin</Token>
  5489.         </Rule>
  5490.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI yabb directory traversal attempt" sid="3224">
  5491.             <Token id="content" type="str" nocase="1" uricont="1">/YaBB</Token>
  5492.             <Token id="content" type="str">../</Token>
  5493.         </Rule>
  5494.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /wwwboard/passwd.txt access" sid="3228">
  5495.             <Token id="content" type="str" nocase="1" uricont="1">/wwwboard/passwd.txt</Token>
  5496.         </Rule>
  5497.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webdriver access" sid="3232">
  5498.             <Token id="content" type="str" nocase="1" uricont="1">/webdriver</Token>
  5499.         </Rule>
  5500.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI whois_raw.cgi arbitrary command execution attempt" sid="3236">
  5501.             <Token id="content" type="str" uricont="1">/whois_raw.cgi?</Token>
  5502.             <Token id="content" type="str">\n</Token>
  5503.         </Rule>
  5504.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI whois_raw.cgi access" sid="3240">
  5505.             <Token id="content" type="str" uricont="1">/whois_raw.cgi</Token>
  5506.         </Rule>
  5507.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI websitepro path access" sid="3244">
  5508.             <Token id="content" type="str" nocase="1"> /HTTP/1.</Token>
  5509.         </Rule>
  5510.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webplus version access" sid="3248">
  5511.             <Token id="content" type="str" nocase="1" uricont="1">/webplus?about</Token>
  5512.         </Rule>
  5513.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webplus directory traversal" sid="3252">
  5514.             <Token id="content" type="str" nocase="1" uricont="1">/webplus?script</Token>
  5515.             <Token id="content" type="str">../</Token>
  5516.         </Rule>
  5517.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI websendmail access" sid="3260">
  5518.             <Token id="content" type="str" nocase="1" uricont="1">/websendmail</Token>
  5519.         </Rule>
  5520.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dcboard.cgi invalid user addition attempt" sid="3268">
  5521.             <Token id="content" type="str" uricont="1">/dcboard.cgi</Token>
  5522.             <Token id="content" type="str">command=register</Token>
  5523.             <Token id="content" type="str">%7cadmin</Token>
  5524.         </Rule>
  5525.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dcforum.cgi access" sid="3272">
  5526.             <Token id="content" type="str" uricont="1">/dcforum.cgi</Token>
  5527.         </Rule>
  5528.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI mmstdod.cgi access" sid="3276">
  5529.             <Token id="content" type="str" nocase="1" uricont="1">/mmstdod.cgi</Token>
  5530.         </Rule>
  5531.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI anaconda directory transversal attempt" sid="3280">
  5532.             <Token id="content" type="str" uricont="1">/apexec.pl</Token>
  5533.             <Token id="content" type="str" nocase="1">template=../</Token>
  5534.         </Rule>
  5535.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI imagemap.exe overflow attempt" sid="3284">
  5536.             <Token id="content" type="str" nocase="1" uricont="1">/imagemap.exe?</Token>
  5537.         </Rule>
  5538.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cvsweb.cgi access" sid="3292">
  5539.             <Token id="content" type="str" nocase="1" uricont="1">/cvsweb.cgi</Token>
  5540.         </Rule>
  5541.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI php.cgi access" sid="3296">
  5542.             <Token id="content" type="str" nocase="1" uricont="1">/php.cgi</Token>
  5543.         </Rule>
  5544.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI glimpse access" sid="3300">
  5545.             <Token id="content" type="str" nocase="1" uricont="1">/glimpse</Token>
  5546.         </Rule>
  5547.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI htmlscript access" sid="3304">
  5548.             <Token id="content" type="str" nocase="1" uricont="1">/htmlscript</Token>
  5549.         </Rule>
  5550.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI info2www access" sid="3308">
  5551.             <Token id="content" type="str" nocase="1" uricont="1">/info2www</Token>
  5552.         </Rule>
  5553.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI maillist.pl access" sid="3312">
  5554.             <Token id="content" type="str" nocase="1" uricont="1">/maillist.pl</Token>
  5555.         </Rule>
  5556.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI nph-test-cgi access" sid="3316">
  5557.             <Token id="content" type="str" nocase="1" uricont="1">/nph-test-cgi</Token>
  5558.         </Rule>
  5559.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI NPH-publish access" sid="3320">
  5560.             <Token id="content" type="str" nocase="1" uricont="1">/nph-publish</Token>
  5561.         </Rule>
  5562.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI perl.exe access" sid="3328">
  5563.             <Token id="content" type="str" nocase="1" uricont="1">/perl.exe</Token>
  5564.         </Rule>
  5565.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI rguest.exe access" sid="3332">
  5566.             <Token id="content" type="str" nocase="1" uricont="1">/rguest.exe</Token>
  5567.         </Rule>
  5568.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI rwwwshell.pl access" sid="3336">
  5569.             <Token id="content" type="str" nocase="1" uricont="1">/rwwwshell.pl</Token>
  5570.         </Rule>
  5571.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI test-cgi access" sid="3340">
  5572.             <Token id="content" type="str" nocase="1" uricont="1">/test-cgi</Token>
  5573.         </Rule>
  5574.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI textcounter.pl access" sid="3344">
  5575.             <Token id="content" type="str" nocase="1" uricont="1">/textcounter.pl</Token>
  5576.         </Rule>
  5577.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI uploader.exe access" sid="3348">
  5578.             <Token id="content" type="str" nocase="1" uricont="1">/uploader.exe</Token>
  5579.         </Rule>
  5580.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webgais access" sid="3352">
  5581.             <Token id="content" type="str" nocase="1" uricont="1">/webgais</Token>
  5582.         </Rule>
  5583.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI finger access" sid="3356">
  5584.             <Token id="content" type="str" nocase="1" uricont="1">/finger</Token>
  5585.         </Rule>
  5586.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI perlshop.cgi access" sid="3360">
  5587.             <Token id="content" type="str" nocase="1" uricont="1">/perlshop.cgi</Token>
  5588.         </Rule>
  5589.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pfdisplay.cgi access" sid="3364">
  5590.             <Token id="content" type="str" nocase="1" uricont="1">/pfdisplay.cgi</Token>
  5591.         </Rule>
  5592.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI aglimpse access" sid="3368">
  5593.             <Token id="content" type="str" nocase="1" uricont="1">/aglimpse</Token>
  5594.         </Rule>
  5595.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI anform2 access" sid="3372">
  5596.             <Token id="content" type="str" nocase="1" uricont="1">/AnForm2</Token>
  5597.         </Rule>
  5598.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI args.bat access" sid="3376">
  5599.             <Token id="content" type="str" nocase="1" uricont="1">/args.bat</Token>
  5600.         </Rule>
  5601.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI AT-admin.cgi access" sid="3380">
  5602.             <Token id="content" type="str" nocase="1" uricont="1">/AT-admin.cgi</Token>
  5603.         </Rule>
  5604.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bnbform.cgi access" sid="3384">
  5605.             <Token id="content" type="str" nocase="1" uricont="1">/bnbform.cgi</Token>
  5606.         </Rule>
  5607.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI campas access" sid="3388">
  5608.             <Token id="content" type="str" nocase="1" uricont="1">/campas</Token>
  5609.         </Rule>
  5610.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI view-source directory traversal" sid="3392">
  5611.             <Token id="content" type="str" nocase="1" uricont="1">/view-source</Token>
  5612.             <Token id="content" type="str" nocase="1">../</Token>
  5613.         </Rule>
  5614.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI view-source access" sid="3396">
  5615.             <Token id="content" type="str" nocase="1" uricont="1">/view-source</Token>
  5616.         </Rule>
  5617.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wais.pl access" sid="3400">
  5618.             <Token id="content" type="str" nocase="1" uricont="1">/wais.pl</Token>
  5619.         </Rule>
  5620.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI files.pl access" sid="3404">
  5621.             <Token id="content" type="str" nocase="1" uricont="1">/files.pl</Token>
  5622.         </Rule>
  5623.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wguest.exe access" sid="3408">
  5624.             <Token id="content" type="str" nocase="1" uricont="1">/wguest.exe</Token>
  5625.         </Rule>
  5626.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wrap access" sid="3412">
  5627.             <Token id="content" type="str" uricont="1">/wrap</Token>
  5628.         </Rule>
  5629.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI classifieds.cgi access" sid="3416">
  5630.             <Token id="content" type="str" nocase="1" uricont="1">/classifieds.cgi</Token>
  5631.         </Rule>
  5632.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI environ.cgi access" sid="3424">
  5633.             <Token id="content" type="str" nocase="1" uricont="1">/environ.cgi</Token>
  5634.         </Rule>
  5635.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI faxsurvey access" sid="3428">
  5636.             <Token id="content" type="str" nocase="1" uricont="1">/faxsurvey</Token>
  5637.         </Rule>
  5638.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI filemail access" sid="3432">
  5639.             <Token id="content" type="str" nocase="1" uricont="1">/filemail.pl</Token>
  5640.         </Rule>
  5641.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI man.sh access" sid="3436">
  5642.             <Token id="content" type="str" nocase="1" uricont="1">/man.sh</Token>
  5643.         </Rule>
  5644.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI snork.bat access" sid="3440">
  5645.             <Token id="content" type="str" nocase="1" uricont="1">/snork.bat</Token>
  5646.         </Rule>
  5647.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI w3-msql access" sid="3444">
  5648.             <Token id="content" type="str" nocase="1" uricont="1">/w3-msql/</Token>
  5649.         </Rule>
  5650.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI csh access" sid="3448">
  5651.             <Token id="content" type="str" nocase="1" uricont="1">/csh</Token>
  5652.         </Rule>
  5653.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI day5datacopier.cgi access" sid="3452">
  5654.             <Token id="content" type="str" nocase="1" uricont="1">/day5datacopier.cgi</Token>
  5655.         </Rule>
  5656.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI day5datanotifier.cgi access" sid="3456">
  5657.             <Token id="content" type="str" nocase="1" uricont="1">/day5datanotifier.cgi</Token>
  5658.         </Rule>
  5659.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ksh access" sid="3460">
  5660.             <Token id="content" type="str" nocase="1" uricont="1">/ksh</Token>
  5661.         </Rule>
  5662.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI post-query access" sid="3464">
  5663.             <Token id="content" type="str" nocase="1" uricont="1">/post-query</Token>
  5664.         </Rule>
  5665.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI visadmin.exe access" sid="3468">
  5666.             <Token id="content" type="str" nocase="1" uricont="1">/visadmin.exe</Token>
  5667.         </Rule>
  5668.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI rsh access" sid="3472">
  5669.             <Token id="content" type="str" nocase="1" uricont="1">/rsh</Token>
  5670.         </Rule>
  5671.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dumpenv.pl access" sid="3476">
  5672.             <Token id="content" type="str" nocase="1" uricont="1">/dumpenv.pl</Token>
  5673.         </Rule>
  5674.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI snorkerz.cmd access" sid="3480">
  5675.             <Token id="content" type="str" nocase="1" uricont="1">/snorkerz.cmd</Token>
  5676.         </Rule>
  5677.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI survey.cgi access" sid="3484">
  5678.             <Token id="content" type="str" nocase="1" uricont="1">/survey.cgi</Token>
  5679.         </Rule>
  5680.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI tcsh access" sid="3488">
  5681.             <Token id="content" type="str" nocase="1" uricont="1">/tcsh</Token>
  5682.         </Rule>
  5683.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI scriptalias access" sid="3492">
  5684.             <Token id="content" type="str" uricont="1">///</Token>
  5685.         </Rule>
  5686.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI win-c-sample.exe access" sid="3500">
  5687.             <Token id="content" type="str" nocase="1" uricont="1">/win-c-sample.exe</Token>
  5688.         </Rule>
  5689.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI rksh access" sid="3508">
  5690.             <Token id="content" type="str" nocase="1" uricont="1">/rksh</Token>
  5691.         </Rule>
  5692.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI w3tvars.pm access" sid="3512">
  5693.             <Token id="content" type="str" nocase="1" uricont="1">/w3tvars.pm</Token>
  5694.         </Rule>
  5695.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI admin.pl access" sid="3516">
  5696.             <Token id="content" type="str" nocase="1" uricont="1">/admin.pl</Token>
  5697.         </Rule>
  5698.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI LWGate access" sid="3520">
  5699.             <Token id="content" type="str" nocase="1" uricont="1">/LWGate</Token>
  5700.         </Rule>
  5701.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI archie access" sid="3524">
  5702.             <Token id="content" type="str" nocase="1" uricont="1">/archie</Token>
  5703.         </Rule>
  5704.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI calendar access" sid="3528">
  5705.             <Token id="content" type="str" nocase="1" uricont="1">/calendar</Token>
  5706.         </Rule>
  5707.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI flexform access" sid="3532">
  5708.             <Token id="content" type="str" nocase="1" uricont="1">/flexform</Token>
  5709.         </Rule>
  5710.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI formmail access" sid="3536">
  5711.             <Token id="content" type="str" nocase="1" uricont="1">/formmail</Token>
  5712.         </Rule>
  5713.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bash access" sid="3540">
  5714.             <Token id="content" type="str" nocase="1" uricont="1">/bash</Token>
  5715.         </Rule>
  5716.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI phf access" sid="3544">
  5717.             <Token id="content" type="str" nocase="1" uricont="1">/phf</Token>
  5718.         </Rule>
  5719.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI www-sql access" sid="3548">
  5720.             <Token id="content" type="str" nocase="1" uricont="1">/www-sql</Token>
  5721.         </Rule>
  5722.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wwwadmin.pl access" sid="3552">
  5723.             <Token id="content" type="str" nocase="1" uricont="1">/wwwadmin.pl</Token>
  5724.         </Rule>
  5725.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ppdscgi.exe access" sid="3556">
  5726.             <Token id="content" type="str" nocase="1" uricont="1">/ppdscgi.exe</Token>
  5727.         </Rule>
  5728.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI sendform.cgi access" sid="3560">
  5729.             <Token id="content" type="str" nocase="1" uricont="1">/sendform.cgi</Token>
  5730.         </Rule>
  5731.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI upload.pl access" sid="3564">
  5732.             <Token id="content" type="str" nocase="1" uricont="1">/upload.pl</Token>
  5733.         </Rule>
  5734.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI AnyForm2 access" sid="3568">
  5735.             <Token id="content" type="str" nocase="1" uricont="1">/AnyForm2</Token>
  5736.         </Rule>
  5737.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI MachineInfo access" sid="3572">
  5738.             <Token id="content" type="str" nocase="1" uricont="1">/MachineInfo</Token>
  5739.         </Rule>
  5740.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-hist.sh access" sid="3576">
  5741.             <Token id="content" type="str" nocase="1" uricont="1">/bb-hist.sh</Token>
  5742.         </Rule>
  5743.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI redirect access" sid="3580">
  5744.             <Token id="content" type="str" nocase="1" uricont="1">/redirect</Token>
  5745.         </Rule>
  5746.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI way-board access" sid="3584">
  5747.             <Token id="content" type="str" nocase="1" uricont="1">/way-board</Token>
  5748.         </Rule>
  5749.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pals-cgi access" sid="3588">
  5750.             <Token id="content" type="str" nocase="1" uricont="1">/pals-cgi</Token>
  5751.         </Rule>
  5752.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI commerce.cgi access" sid="3592">
  5753.             <Token id="content" type="str" nocase="1" uricont="1">/commerce.cgi</Token>
  5754.         </Rule>
  5755.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Amaya templates sendtemp.pl directory traversal attempt" sid="3596">
  5756.             <Token id="content" type="str" nocase="1" uricont="1">/sendtemp.pl</Token>
  5757.             <Token id="content" type="str" nocase="1">templ=</Token>
  5758.         </Rule>
  5759.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webspirs.cgi directory traversal attempt" sid="3600">
  5760.             <Token id="content" type="str" nocase="1" uricont="1">/webspirs.cgi</Token>
  5761.             <Token id="content" type="str" nocase="1">../../</Token>
  5762.         </Rule>
  5763.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webspirs.cgi access" sid="3604">
  5764.             <Token id="content" type="str" nocase="1" uricont="1">/webspirs.cgi</Token>
  5765.         </Rule>
  5766.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI tstisapi.dll access" sid="3608">
  5767.             <Token id="content" type="str" nocase="1" uricont="1">tstisapi.dll</Token>
  5768.         </Rule>
  5769.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI technote main.cgi file directory traversal attempt" sid="4204">
  5770.             <Token id="content" type="str" nocase="1" uricont="1">/technote/main.cgi</Token>
  5771.             <Token id="content" type="str" nocase="1">filename=</Token>
  5772.             <Token id="content" type="str">../../</Token>
  5773.         </Rule>
  5774.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI technote print.cgi directory traversal attempt" sid="4208">
  5775.             <Token id="content" type="str" nocase="1" uricont="1">/technote/print.cgi</Token>
  5776.             <Token id="content" type="str" nocase="1">board=</Token>
  5777.             <Token id="content" type="str">../../</Token>
  5778.             <Token id="content" type="str">%00</Token>
  5779.         </Rule>
  5780.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ads.cgi command execution attempt" sid="4212">
  5781.             <Token id="content" type="str" nocase="1" uricont="1">/ads.cgi</Token>
  5782.             <Token id="content" type="str" nocase="1">file=</Token>
  5783.             <Token id="content" type="str">../../</Token>
  5784.             <Token id="content" type="str">|</Token>
  5785.         </Rule>
  5786.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI eXtropia webstore directory traversal" sid="4352">
  5787.             <Token id="content" type="str" uricont="1">/web_store.cgi</Token>
  5788.             <Token id="content" type="str">page=../</Token>
  5789.         </Rule>
  5790.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI shopping cart directory traversal" sid="4356">
  5791.             <Token id="content" type="str" uricont="1">/shop.cgi</Token>
  5792.             <Token id="content" type="str">page=../</Token>
  5793.         </Rule>
  5794.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Allaire Pro Web Shell attempt" sid="4360">
  5795.             <Token id="content" type="str" uricont="1">/authenticate.cgi?PASSWORD</Token>
  5796.             <Token id="content" type="str">config.ini</Token>
  5797.         </Rule>
  5798.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Armada Style Master Index directory traversal" sid="4368">
  5799.             <Token id="content" type="str" uricont="1">/search.cgi?keys</Token>
  5800.             <Token id="content" type="str">catigory=../</Token>
  5801.         </Rule>
  5802.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cached_feed.cgi moreover shopping cart directory traversal" sid="4372">
  5803.             <Token id="content" type="str" uricont="1">/cached_feed.cgi</Token>
  5804.             <Token id="content" type="str">../</Token>
  5805.         </Rule>
  5806.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Talentsoft Web+ exploit attempt" sid="4388">
  5807.             <Token id="content" type="str" uricont="1">/webplus.cgi?Script=/webplus/webping/webping.wml</Token>
  5808.         </Rule>
  5809.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Poll-it access" sid="4424">
  5810.             <Token id="content" type="str" nocase="1" uricont="1">/pollit/Poll_It_SSI_v2.0.cgi</Token>
  5811.         </Rule>
  5812.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI count.cgi access" sid="4596">
  5813.             <Token id="content" type="str" nocase="1" uricont="1">/count.cgi</Token>
  5814.         </Rule>
  5815.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI webdist.cgi access" sid="4652">
  5816.             <Token id="content" type="str" nocase="1" uricont="1">/webdist.cgi</Token>
  5817.         </Rule>
  5818.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bigconf.cgi access" sid="4688">
  5819.             <Token id="content" type="str" nocase="1" uricont="1">/bigconf.cgi</Token>
  5820.         </Rule>
  5821.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /cgi-bin/jj access" sid="4696">
  5822.             <Token id="content" type="str" nocase="1" uricont="1">/cgi-bin/jj</Token>
  5823.         </Rule>
  5824.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bizdbsearch attempt" sid="4740">
  5825.             <Token id="content" type="str" nocase="1" uricont="1">/bizdb1-search.cgi</Token>
  5826.             <Token id="content" type="str" nocase="1">mail</Token>
  5827.         </Rule>
  5828.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI sojourn.cgi File attempt" sid="4776">
  5829.             <Token id="content" type="str" uricont="1">/sojourn.cgi?cat=</Token>
  5830.             <Token id="content" type="str" nocase="1">%00</Token>
  5831.         </Rule>
  5832.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI sojourn.cgi access" sid="4780">
  5833.             <Token id="content" type="str" nocase="1" uricont="1">/sojourn.cgi</Token>
  5834.         </Rule>
  5835.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI SGI InfoSearch fname attempt" sid="4784">
  5836.             <Token id="content" type="str" uricont="1">/infosrch.cgi?</Token>
  5837.             <Token id="content" type="str" nocase="1">fname=</Token>
  5838.         </Rule>
  5839.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ax-admin.cgi access" sid="4816">
  5840.             <Token id="content" type="str" uricont="1">/ax-admin.cgi</Token>
  5841.         </Rule>
  5842.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI axs.cgi access" sid="4820">
  5843.             <Token id="content" type="str" uricont="1">/axs.cgi</Token>
  5844.         </Rule>
  5845.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cachemgr.cgi access" sid="4824">
  5846.             <Token id="content" type="str" uricont="1">/cachemgr.cgi</Token>
  5847.         </Rule>
  5848.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI responder.cgi access" sid="4832">
  5849.             <Token id="content" type="str" uricont="1">/responder.cgi</Token>
  5850.         </Rule>
  5851.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI web-map.cgi access" sid="4844">
  5852.             <Token id="content" type="str" uricont="1">/web-map.cgi</Token>
  5853.         </Rule>
  5854.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ministats admin access" sid="4860">
  5855.             <Token id="content" type="str" nocase="1" uricont="1">/ministats/admin.cgi</Token>
  5856.         </Rule>
  5857.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dfire.cgi access" sid="4876">
  5858.             <Token id="content" type="str" nocase="1" uricont="1">/dfire.cgi</Token>
  5859.         </Rule>
  5860.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pals-cgi arbitrary file access attempt" sid="4888">
  5861.             <Token id="content" type="str" nocase="1" uricont="1">/pals-cgi</Token>
  5862.             <Token id="content" type="str">documentName=</Token>
  5863.         </Rule>
  5864.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI txt2html.cgi access" sid="5216">
  5865.             <Token id="content" type="str" nocase="1" uricont="1">/txt2html.cgi</Token>
  5866.         </Rule>
  5867.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI txt2html.cgi directory traversal attempt" sid="5220">
  5868.             <Token id="content" type="str" nocase="1" uricont="1">/txt2html.cgi</Token>
  5869.             <Token id="content" type="str">/../../../../</Token>
  5870.         </Rule>
  5871.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI store.cgi access" sid="5228">
  5872.             <Token id="content" type="str" nocase="1" uricont="1">/store.cgi</Token>
  5873.         </Rule>
  5874.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI sendmessage.cgi access" sid="5232">
  5875.             <Token id="content" type="str" nocase="1" uricont="1">/sendmessage.cgi</Token>
  5876.         </Rule>
  5877.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI zsh access" sid="5236">
  5878.             <Token id="content" type="str" nocase="1" uricont="1">/zsh</Token>
  5879.         </Rule>
  5880.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI lastlines.cgi access" sid="5568">
  5881.             <Token id="content" type="str" nocase="1" uricont="1">/lastlines.cgi</Token>
  5882.         </Rule>
  5883.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI zml.cgi attempt" sid="5580">
  5884.             <Token id="content" type="str" uricont="1">/zml.cgi</Token>
  5885.             <Token id="content" type="str">file=../</Token>
  5886.         </Rule>
  5887.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI zml.cgi access" sid="5584">
  5888.             <Token id="content" type="str" uricont="1">/zml.cgi</Token>
  5889.         </Rule>
  5890.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wayboard attempt" sid="5588">
  5891.             <Token id="content" type="str" uricont="1">/way-board/way-board.cgi</Token>
  5892.             <Token id="content" type="str">db=</Token>
  5893.             <Token id="content" type="str" nocase="1">../..</Token>
  5894.         </Rule>
  5895.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI AHG search.cgi access" sid="5620">
  5896.             <Token id="content" type="str" nocase="1" uricont="1">/publisher/search.cgi</Token>
  5897.             <Token id="content" type="str" nocase="1">template=</Token>
  5898.         </Rule>
  5899.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI agora.cgi access" sid="5624">
  5900.             <Token id="content" type="str" nocase="1" uricont="1">/store/agora.cgi</Token>
  5901.         </Rule>
  5902.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dcboard.cgi access" sid="5640">
  5903.             <Token id="content" type="str" uricont="1">/dcboard.cgi</Token>
  5904.         </Rule>
  5905.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI NPH-publish access" sid="5804">
  5906.             <Token id="content" type="str" nocase="1" uricont="1">/nph-maillist.pl</Token>
  5907.         </Rule>
  5908.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI args.cmd access" sid="5808">
  5909.             <Token id="content" type="str" nocase="1" uricont="1">/args.cmd</Token>
  5910.         </Rule>
  5911.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI AT-generated.cgi access" sid="5812">
  5912.             <Token id="content" type="str" nocase="1" uricont="1">/AT-generated.cgi</Token>
  5913.         </Rule>
  5914.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI wwwwais access" sid="5816">
  5915.             <Token id="content" type="str" nocase="1" uricont="1">/wwwwais</Token>
  5916.         </Rule>
  5917.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI calender.pl access" sid="5820">
  5918.             <Token id="content" type="str" nocase="1" uricont="1">/calender.pl</Token>
  5919.         </Rule>
  5920.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI user_update_admin.pl access" sid="5828">
  5921.             <Token id="content" type="str" nocase="1" uricont="1">/user_update_admin.pl</Token>
  5922.         </Rule>
  5923.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI user_update_passwd.pl access" sid="5832">
  5924.             <Token id="content" type="str" nocase="1" uricont="1">/user_update_passwd.pl</Token>
  5925.         </Rule>
  5926.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-histlog.sh access" sid="5836">
  5927.             <Token id="content" type="str" nocase="1" uricont="1">/bb-histlog.sh</Token>
  5928.         </Rule>
  5929.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-histsvc.sh access" sid="5840">
  5930.             <Token id="content" type="str" nocase="1" uricont="1">/bb-histsvc.sh</Token>
  5931.         </Rule>
  5932.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-rep.sh access" sid="5844">
  5933.             <Token id="content" type="str" nocase="1" uricont="1">/bb-rep.sh</Token>
  5934.         </Rule>
  5935.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-replog.sh access" sid="5848">
  5936.             <Token id="content" type="str" nocase="1" uricont="1">/bb-replog.sh</Token>
  5937.         </Rule>
  5938.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI auktion.cgi access" sid="5860">
  5939.             <Token id="content" type="str" nocase="1" uricont="1">/auktion.cgi</Token>
  5940.         </Rule>
  5941.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cgiforum.pl access" sid="5864">
  5942.             <Token id="content" type="str" nocase="1" uricont="1">/cgiforum.pl</Token>
  5943.         </Rule>
  5944.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI directorypro.cgi access" sid="5868">
  5945.             <Token id="content" type="str" nocase="1" uricont="1">/directorypro.cgi</Token>
  5946.         </Rule>
  5947.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Web Shopper shopper.cgi attempt" sid="5872">
  5948.             <Token id="content" type="str" nocase="1" uricont="1">/shopper.cgi</Token>
  5949.             <Token id="content" type="str" nocase="1">newpage=../</Token>
  5950.         </Rule>
  5951.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Web Shopper shopper.cgi access" sid="5876">
  5952.             <Token id="content" type="str" nocase="1" uricont="1">/shopper.cgi</Token>
  5953.         </Rule>
  5954.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI listrec.pl access" sid="5880">
  5955.             <Token id="content" type="str" nocase="1" uricont="1">/listrec.pl</Token>
  5956.         </Rule>
  5957.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI mailnews.cgi access" sid="5884">
  5958.             <Token id="content" type="str" nocase="1" uricont="1">/mailnews.cgi</Token>
  5959.         </Rule>
  5960.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI book.cgi access" sid="5888">
  5961.             <Token id="content" type="str" nocase="1" uricont="1">/book.cgi</Token>
  5962.         </Rule>
  5963.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI newsdesk.cgi access" sid="5892">
  5964.             <Token id="content" type="str" nocase="1" uricont="1">/newsdesk.cgi</Token>
  5965.         </Rule>
  5966.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cal_make.pl access" sid="5896">
  5967.             <Token id="content" type="str" nocase="1" uricont="1">/cal_make.pl</Token>
  5968.         </Rule>
  5969.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI mailit.pl access" sid="5900">
  5970.             <Token id="content" type="str" nocase="1" uricont="1">/mailit.pl</Token>
  5971.         </Rule>
  5972.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI sdbsearch.cgi access" sid="5904">
  5973.             <Token id="content" type="str" nocase="1" uricont="1">/sdbsearch.cgi</Token>
  5974.         </Rule>
  5975.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI swc access" sid="5912">
  5976.             <Token id="content" type="str" nocase="1" uricont="1">/swc</Token>
  5977.         </Rule>
  5978.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ttawebtop.cgi arbitrary file attempt" sid="5916">
  5979.             <Token id="content" type="str" nocase="1" uricont="1">/ttawebtop.cgi</Token>
  5980.             <Token id="content" type="str" nocase="1">pg=../</Token>
  5981.         </Rule>
  5982.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ttawebtop.cgi access" sid="5920">
  5983.             <Token id="content" type="str" nocase="1" uricont="1">/ttawebtop.cgi</Token>
  5984.         </Rule>
  5985.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI upload.cgi access" sid="5924">
  5986.             <Token id="content" type="str" nocase="1" uricont="1">/upload.cgi</Token>
  5987.         </Rule>
  5988.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI view_source access" sid="5928">
  5989.             <Token id="content" type="str" nocase="1" uricont="1">/view_source</Token>
  5990.         </Rule>
  5991.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ustorekeeper.pl access" sid="5932">
  5992.             <Token id="content" type="str" nocase="1" uricont="1">/ustorekeeper.pl</Token>
  5993.         </Rule>
  5994.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI store.cgi directory traversal attempt" sid="5952">
  5995.             <Token id="content" type="str" nocase="1" uricont="1">/store.cgi</Token>
  5996.             <Token id="content" type="str">../</Token>
  5997.         </Rule>
  5998.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI SIX webboard generate.cgi attempt" sid="5976">
  5999.             <Token id="content" type="str" uricont="1">/generate.cgi</Token>
  6000.             <Token id="content" type="str">content=../</Token>
  6001.         </Rule>
  6002.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI SIX webboard generate.cgi access" sid="5980">
  6003.             <Token id="content" type="str" uricont="1">/generate.cgi</Token>
  6004.         </Rule>
  6005.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI spin_client.cgi access" sid="5984">
  6006.             <Token id="content" type="str" uricont="1">/spin_client.cgi</Token>
  6007.         </Rule>
  6008.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI a1stats a1disp3.cgi directory traversal attempt" sid="6004">
  6009.             <Token id="content" type="str" uricont="1">/a1disp3.cgi?/../../</Token>
  6010.         </Rule>
  6011.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI a1stats a1disp3.cgi access" sid="6008">
  6012.             <Token id="content" type="str" uricont="1">/a1disp3.cgi</Token>
  6013.         </Rule>
  6014.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI admentor admin.asp access" sid="6012">
  6015.             <Token id="content" type="str" uricont="1">/admentor/admin/admin.asp</Token>
  6016.         </Rule>
  6017.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI alchemy http server PRN arbitrary command execution attempt" sid="6020">
  6018.             <Token id="content" type="str" uricont="1">/PRN/../../</Token>
  6019.         </Rule>
  6020.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI alchemy http server NUL arbitrary command execution attempt" sid="6024">
  6021.             <Token id="content" type="str" uricont="1">/NUL/../../</Token>
  6022.         </Rule>
  6023.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI alibaba.pl arbitrary command execution attempt" sid="6028">
  6024.             <Token id="content" type="str" uricont="1">/alibaba.pl|</Token>
  6025.         </Rule>
  6026.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI alibaba.pl access" sid="6032">
  6027.             <Token id="content" type="str" uricont="1">/alibaba.pl</Token>
  6028.         </Rule>
  6029.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI AltaVista Intranet Search directory traversal attempt" sid="6036">
  6030.             <Token id="content" type="str" uricont="1">/query?mss=..</Token>
  6031.         </Rule>
  6032.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI test.bat arbitrary command execution attempt" sid="6040">
  6033.             <Token id="content" type="str" uricont="1">/test.bat|</Token>
  6034.         </Rule>
  6035.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI test.bat access" sid="6044">
  6036.             <Token id="content" type="str" uricont="1">/test.bat</Token>
  6037.         </Rule>
  6038.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI input.bat arbitrary command execution attempt" sid="6048">
  6039.             <Token id="content" type="str" uricont="1">/input.bat|</Token>
  6040.         </Rule>
  6041.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI input.bat access" sid="6052">
  6042.             <Token id="content" type="str" uricont="1">/input.bat</Token>
  6043.         </Rule>
  6044.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI input2.bat arbitrary command execution attempt" sid="6056">
  6045.             <Token id="content" type="str" uricont="1">/input2.bat|</Token>
  6046.         </Rule>
  6047.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI input2.bat access" sid="6060">
  6048.             <Token id="content" type="str" uricont="1">/input2.bat</Token>
  6049.         </Rule>
  6050.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI envout.bat arbitrary command execution attempt" sid="6064">
  6051.             <Token id="content" type="str" uricont="1">/envout.bat|</Token>
  6052.         </Rule>
  6053.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI envout.bat access" sid="6068">
  6054.             <Token id="content" type="str" uricont="1">/envout.bat</Token>
  6055.         </Rule>
  6056.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-hist.sh attempt" sid="6124">
  6057.             <Token id="content" type="str" nocase="1" uricont="1">/bb-hist.sh?HISTFILE=../..</Token>
  6058.         </Rule>
  6059.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-hostscv.sh attempt" sid="6128">
  6060.             <Token id="content" type="str" nocase="1" uricont="1">/bb-hostsvc.sh?HOSTSVC?../..</Token>
  6061.         </Rule>
  6062.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bb-hostscv.sh access" sid="6132">
  6063.             <Token id="content" type="str" nocase="1" uricont="1">/bb-hostsvc.sh</Token>
  6064.         </Rule>
  6065.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI agora.cgi attempt" sid="6136">
  6066.             <Token id="content" type="str" nocase="1" uricont="1">/store/agora.cgi?cart_id=&lt;SCRIPT&gt;</Token>
  6067.         </Rule>
  6068.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bizdbsearch access" sid="6140">
  6069.             <Token id="content" type="str" nocase="1" uricont="1">/bizdb1-search.cgi</Token>
  6070.         </Rule>
  6071.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI calendar_admin.pl arbitrary command execution attempt" sid="6144">
  6072.             <Token id="content" type="str" uricont="1">/calendar_admin.pl?config=|</Token>
  6073.         </Rule>
  6074.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI calendar_admin.pl access" sid="6148">
  6075.             <Token id="content" type="str" uricont="1">/calendar_admin.pl</Token>
  6076.         </Rule>
  6077.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /cgi-bin/ls access" sid="6156">
  6078.             <Token id="content" type="str" nocase="1" uricont="1">/cgi-bin/ls</Token>
  6079.         </Rule>
  6080.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cgimail access" sid="6168">
  6081.             <Token id="content" type="str" nocase="1" uricont="1">/cgimail</Token>
  6082.         </Rule>
  6083.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cgiwrap access" sid="6172">
  6084.             <Token id="content" type="str" nocase="1" uricont="1">/cgiwrap</Token>
  6085.         </Rule>
  6086.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI csSearch.cgi arbitrary command execution attempt" sid="6188">
  6087.             <Token id="content" type="str" uricont="1">/csSearch.cgi</Token>
  6088.             <Token id="content" type="str">setup=</Token>
  6089.             <Token id="content" type="str">`</Token>
  6090.             <Token id="content" type="str" distance="1">`</Token>
  6091.         </Rule>
  6092.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI csSearch.cgi access" sid="6192">
  6093.             <Token id="content" type="str" uricont="1">/csSearch.cgi</Token>
  6094.         </Rule>
  6095.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /cart/cart.cgi access" sid="6212">
  6096.             <Token id="content" type="str" uricont="1">/cart/cart.cgi</Token>
  6097.         </Rule>
  6098.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dbman db.cgi access" sid="6216">
  6099.             <Token id="content" type="str" uricont="1">/dbman/db.cgi</Token>
  6100.         </Rule>
  6101.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI DCShop access" sid="6220">
  6102.             <Token id="content" type="str" nocase="1" uricont="1">/dcshop</Token>
  6103.         </Rule>
  6104.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI DCShop orders.txt access" sid="6224">
  6105.             <Token id="content" type="str" nocase="1" uricont="1">/orders/orders.txt</Token>
  6106.         </Rule>
  6107.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI DCShop auth_user_file.txt access" sid="6228">
  6108.             <Token id="content" type="str" nocase="1" uricont="1">/auth_data/auth_user_file.txt</Token>
  6109.         </Rule>
  6110.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI eshop.pl arbitrary commane execution attempt" sid="6260">
  6111.             <Token id="content" type="str" nocase="1" uricont="1">/eshop.pl?seite=;</Token>
  6112.         </Rule>
  6113.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI eshop.pl access" sid="6264">
  6114.             <Token id="content" type="str" nocase="1" uricont="1">/eshop.pl</Token>
  6115.         </Rule>
  6116.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI loadpage.cgi directory traversal attempt" sid="6276">
  6117.             <Token id="content" type="str" uricont="1">/loadpage.cgi</Token>
  6118.             <Token id="content" type="str" nocase="1">file=../</Token>
  6119.         </Rule>
  6120.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI loadpage.cgi access" sid="6280">
  6121.             <Token id="content" type="str" nocase="1" uricont="1">/loadpage.cgi</Token>
  6122.         </Rule>
  6123.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI dcforum.cgi directory traversal attempt" sid="6284">
  6124.             <Token id="content" type="str" uricont="1">/dcforum.cgi</Token>
  6125.             <Token id="content" type="str">forum=../..</Token>
  6126.         </Rule>
  6127.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI commerce.cgi arbitrary file access attempt" sid="6288">
  6128.             <Token id="content" type="str" uricont="1">/commerce.cgi</Token>
  6129.             <Token id="content" type="str">page=</Token>
  6130.             <Token id="content" type="str" nocase="1">/../</Token>
  6131.         </Rule>
  6132.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cgiforum.pl attempt" sid="6292">
  6133.             <Token id="content" type="str" nocase="1" uricont="1">/cgiforum.pl?thesection=../..</Token>
  6134.         </Rule>
  6135.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI directorypro.cgi attempt" sid="6296">
  6136.             <Token id="content" type="str" uricont="1">/directorypro.cgi</Token>
  6137.             <Token id="content" type="str">show=</Token>
  6138.             <Token id="content" type="str" distance="1" nocase="1">../..</Token>
  6139.         </Rule>
  6140.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI faqmanager.cgi arbitrary file access attempt" sid="6360">
  6141.             <Token id="content" type="str" uricont="1">/faqmanager.cgi?toc=</Token>
  6142.             <Token id="content" type="str" nocase="1" uricont="1">\0</Token>
  6143.         </Rule>
  6144.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI faqmanager.cgi access" sid="6364">
  6145.             <Token id="content" type="str" nocase="1" uricont="1">/faqmanager.cgi</Token>
  6146.         </Rule>
  6147.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /fcgi-bin/echo.exe access" sid="6368">
  6148.             <Token id="content" type="str" nocase="1" uricont="1">/fcgi-bin/echo.exe</Token>
  6149.         </Rule>
  6150.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI FormHandler.cgi external site redirection attempt" sid="6372">
  6151.             <Token id="content" type="str" nocase="1" uricont="1">/FormHandler.cgi</Token>
  6152.             <Token id="content" type="str">redirect=http</Token>
  6153.         </Rule>
  6154.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI FormHandler.cgi access" sid="6376">
  6155.             <Token id="content" type="str" nocase="1" uricont="1">/FormHandler.cgi</Token>
  6156.         </Rule>
  6157.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI guestbook.cgi access" sid="6388">
  6158.             <Token id="content" type="str" nocase="1" uricont="1">/guestbook.cgi</Token>
  6159.         </Rule>
  6160.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Home Free search.cgi directory traversal attempt" sid="6392">
  6161.             <Token id="content" type="str" uricont="1">/search.cgi</Token>
  6162.             <Token id="content" type="str" nocase="1">letter=../..</Token>
  6163.         </Rule>
  6164.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI search.cgi access" sid="6396">
  6165.             <Token id="content" type="str" nocase="1" uricont="1">/search.cgi</Token>
  6166.         </Rule>
  6167.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI htsearch arbitrary configuration file attempt" sid="6400">
  6168.             <Token id="content" type="str" nocase="1" uricont="1">/htsearch?-c</Token>
  6169.         </Rule>
  6170.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI htsearch arbitrary file read attempt" sid="6404">
  6171.             <Token id="content" type="str" nocase="1" uricont="1">/htsearch?exclude=`</Token>
  6172.         </Rule>
  6173.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI htsearch access" sid="6408">
  6174.             <Token id="content" type="str" nocase="1" uricont="1">/htsearch</Token>
  6175.         </Rule>
  6176.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI icat access" sid="6424">
  6177.             <Token id="content" type="str" uricont="1">/icat</Token>
  6178.         </Rule>
  6179.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI HyperSeek hsx.cgi access" sid="6428">
  6180.             <Token id="content" type="str" uricont="1">/hsx.cgi</Token>
  6181.         </Rule>
  6182.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI htmlscript attempt" sid="6432">
  6183.             <Token id="content" type="str" nocase="1" uricont="1">/htmlscript?../..</Token>
  6184.         </Rule>
  6185.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI formmail arbitrary command execution attempt" sid="6440">
  6186.             <Token id="content" type="str" nocase="1" uricont="1">/formmail</Token>
  6187.             <Token id="content" type="str" nocase="1">%0a</Token>
  6188.         </Rule>
  6189.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI eXtropia webstore access" sid="6444">
  6190.             <Token id="content" type="str" uricont="1">/web_store.cgi</Token>
  6191.         </Rule>
  6192.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Bugzilla doeditvotes.cgi access" sid="6468">
  6193.             <Token id="content" type="str" uricont="1">/doeditvotes.cgi</Token>
  6194.         </Rule>
  6195.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI FormHandler.cgi directory traversal attempt attempt" sid="6512">
  6196.             <Token id="content" type="str" nocase="1" uricont="1">/FormHandler.cgi</Token>
  6197.             <Token id="content" type="str" nocase="1">reply_message_attach=</Token>
  6198.             <Token id="content" type="str">/../</Token>
  6199.         </Rule>
  6200.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI yabb access" sid="6548">
  6201.             <Token id="content" type="str" nocase="1" uricont="1">/YaBB</Token>
  6202.         </Rule>
  6203.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI document.d2w access" sid="6568">
  6204.             <Token id="content" type="str" uricont="1">/document.d2w</Token>
  6205.         </Rule>
  6206.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI db2www access" sid="6572">
  6207.             <Token id="content" type="str" uricont="1">/db2www</Token>
  6208.         </Rule>
  6209.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI test-cgi attempt" sid="6576">
  6210.             <Token id="content" type="str" nocase="1" uricont="1">/test-cgi/*?*</Token>
  6211.         </Rule>
  6212.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI testcgi access" sid="6580">
  6213.             <Token id="content" type="str" nocase="1" uricont="1">/testcgi</Token>
  6214.         </Rule>
  6215.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI test.cgi access" sid="6584">
  6216.             <Token id="content" type="str" nocase="1" uricont="1">/test.cgi</Token>
  6217.         </Rule>
  6218.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI perl.exe command attempt" sid="6592">
  6219.             <Token id="content" type="str" nocase="1" uricont="1">/perl.exe?</Token>
  6220.         </Rule>
  6221.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI perl command attempt" sid="6596">
  6222.             <Token id="content" type="str" nocase="1" uricont="1">/perl?</Token>
  6223.         </Rule>
  6224.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI tst.bat access" sid="6600">
  6225.             <Token id="content" type="str" uricont="1">/tst.bat</Token>
  6226.         </Rule>
  6227.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI enivorn.pl access" sid="6604">
  6228.             <Token id="content" type="str" nocase="1" uricont="1">/enivron.pl</Token>
  6229.         </Rule>
  6230.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI campus attempt" sid="6608">
  6231.             <Token id="content" type="str" nocase="1" uricont="1">/campus?\n</Token>
  6232.         </Rule>
  6233.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI campus access" sid="6612">
  6234.             <Token id="content" type="str" nocase="1" uricont="1">/campus</Token>
  6235.         </Rule>
  6236.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cart32.exe access" sid="6616">
  6237.             <Token id="content" type="str" nocase="1" uricont="1">/cart32.exe</Token>
  6238.         </Rule>
  6239.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pfdispaly.cgi arbitrary command execution attempt" sid="6620">
  6240.             <Token id="content" type="str" nocase="1" uricont="1">/pfdispaly.cgi?'</Token>
  6241.         </Rule>
  6242.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pfdispaly.cgi access" sid="6624">
  6243.             <Token id="content" type="str" nocase="1" uricont="1">/pfdispaly.cgi</Token>
  6244.         </Rule>
  6245.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pagelog.cgi directory traversal attempt" sid="6628">
  6246.             <Token id="content" type="str" nocase="1" uricont="1">/pagelog.cgi</Token>
  6247.             <Token id="content" type="str" nocase="1">name=../</Token>
  6248.         </Rule>
  6249.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI pagelog.cgi access" sid="6632">
  6250.             <Token id="content" type="str" nocase="1" uricont="1">/pagelog.cgi</Token>
  6251.         </Rule>
  6252.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /cgi-bin/ access" sid="6672">
  6253.             <Token id="content" type="str" uricont="1">/cgi-bin/</Token>
  6254.             <Token id="content" type="str" nocase="1">/cgi-bin/ HTTP</Token>
  6255.         </Rule>
  6256.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI /cgi-dos/ access" sid="6676">
  6257.             <Token id="content" type="str" uricont="1">/cgi-dos/</Token>
  6258.             <Token id="content" type="str" nocase="1">/cgi-dos/ HTTP</Token>
  6259.         </Rule>
  6260.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI imagemap.exe access" sid="6800">
  6261.             <Token id="content" type="str" nocase="1" uricont="1">/imagemap.exe</Token>
  6262.         </Rule>
  6263.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI calendar-admin.pl access" sid="6804">
  6264.             <Token id="content" type="str" nocase="1" uricont="1">/calendar-admin.pl</Token>
  6265.         </Rule>
  6266.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI Amaya templates sendtemp.pl access" sid="6808">
  6267.             <Token id="content" type="str" nocase="1" uricont="1">/sendtemp.pl</Token>
  6268.         </Rule>
  6269.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI auktion.cgi directory traversal attempt" sid="6812">
  6270.             <Token id="content" type="str" nocase="1" uricont="1">/auktion.cgi</Token>
  6271.             <Token id="content" type="str" nocase="1">menue=../../</Token>
  6272.         </Rule>
  6273.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cal_make.pl directory traversal attempt" sid="6816">
  6274.             <Token id="content" type="str" nocase="1" uricont="1">/cal_make.pl</Token>
  6275.             <Token id="content" type="str" nocase="1">p0=../../</Token>
  6276.         </Rule>
  6277.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI echo.bat arbitrary command execution attempt" sid="6820">
  6278.             <Token id="content" type="str" uricont="1">/echo.bat</Token>
  6279.             <Token id="content" type="str">&amp;</Token>
  6280.         </Rule>
  6281.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI echo.bat access" sid="6824">
  6282.             <Token id="content" type="str" uricont="1">/echo.bat</Token>
  6283.         </Rule>
  6284.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI hello.bat arbitrary command execution attempt" sid="6828">
  6285.             <Token id="content" type="str" uricont="1">/hello.bat</Token>
  6286.             <Token id="content" type="str">&amp;</Token>
  6287.         </Rule>
  6288.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI hello.bat access" sid="6832">
  6289.             <Token id="content" type="str" uricont="1">/hello.bat</Token>
  6290.         </Rule>
  6291.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI ad.cgi access" sid="6836">
  6292.             <Token id="content" type="str" nocase="1" uricont="1">/ad.cgi</Token>
  6293.         </Rule>
  6294.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bbs_forum.cgi access" sid="6840">
  6295.             <Token id="content" type="str" nocase="1" uricont="1">/bbs_forum.cgi</Token>
  6296.         </Rule>
  6297.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bsguest.cgi access" sid="6844">
  6298.             <Token id="content" type="str" nocase="1" uricont="1">/bsguest.cgi</Token>
  6299.         </Rule>
  6300.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI bslist.cgi access" sid="6848">
  6301.             <Token id="content" type="str" nocase="1" uricont="1">/bslist.cgi</Token>
  6302.         </Rule>
  6303.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI cgforum.cgi access" sid="6852">
  6304.             <Token id="content" type="str" nocase="1" uricont="1">/cgforum.cgi</Token>
  6305.         </Rule>
  6306.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI newdesk access" sid="6856">
  6307.             <Token id="content" type="str" nocase="1" uricont="1">/newdesk</Token>
  6308.         </Rule>
  6309.         <Rule al="Monitor" ar="Allow" dir="in" prot="tcp" locaddr_id="http_servers" remaddr_id="external_net" locport="80" remport="*" name="WEB-CGI register.cgi access" sid="6860">
  6310.             <Token id="content" type="str" nocase="1" uricont="1">/register.cgi</Token>
  6311.         </Rule>
  6312.         <Rule al="Monitor" ar="Allow" d