<?xml version="1.0" encoding="UTF-8"?>
<root>
<information>
	<iceyefiletype>rulesystem</iceyefiletype>
	<version>5.6.0.007</version>
	<date>2008-07-15</date>
	<name>系统规则</name>
	<copyright>(c)1999-2008 NSFocus</copyright>	
</information>
<sysruledesc>
  <rules>
  <rule ruleid="20874" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Proxy-Authorization字段超长缓冲区溢出攻击" name_chs="HTTP协议Proxy-Authorization字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Proxy-Authorization Field Buffer Overflow" visible="true"/><rule ruleid="30448" enabled="true" group="361766970" action=" db  screen " name="Cisco IOS ILMI SNMP共同体串访问" name_chs="Cisco IOS ILMI SNMP共同体串访问" name_eng="Cisco IOS ILMI SNMP Community String" visible="true"/><rule ruleid="30110" enabled="true" group="136315062" action=" db  screen " name="SysAdmin Magazine man.sh脚本漏洞扫描探测" name_chs="SysAdmin Magazine man.sh脚本漏洞扫描探测" name_eng="SysAdmin Magazine man.sh Script Vulnerability Detection" visible="true"/><rule ruleid="40026" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Unexplained木马建立连接" name_chs="Windows系统下Unexplained木马建立连接" name_eng="Trojan Unexplained Trojan Connectionon Windows" visible="true"/><rule ruleid="40024" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Delta Source木马通信" name_chs="Windows系统下Delta Source木马通信" name_eng="Trojan Delta Source Communication on Windows" visible="true"/><rule ruleid="30114" enabled="true" group="136315066" action=" db  screen " name="NCSA phf脚本漏洞扫描探测" name_chs="NCSA phf脚本漏洞扫描探测" name_eng="NCSA phf Script Vulnerability Detection" visible="true"/><rule ruleid="40022" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Fore木马建立连接" name_chs="Windows系统下Fore木马建立连接" name_eng="Trojan Fore Connection on Windows" visible="true"/><rule ruleid="30116" enabled="true" group="136315062" action=" db  screen " name="获取QuikStore quikstore.cfg配置文件" name_chs="获取QuikStore quikstore.cfg配置文件" name_eng="QuikStore quikstore.cfg File Disclosure" visible="true"/><rule ruleid="30441" enabled="true" group="68157743" action=" db  screen  drop " name="Microsoft IIS 5.0 .printer ISAPI扩展映射远程缓冲区溢出攻击" name_chs="Microsoft IIS 5.0 .printer ISAPI扩展映射远程缓冲区溢出攻击" name_eng="Microsoft IIS 5.0 .printer ISAPI Extension Mapping Remote Buffer Overflow" visible="true"/><rule ruleid="40607" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下WinRat木马通信" name_chs="Windows系统下WinRat木马通信" name_eng="Trojan WinRat Communication on Windows" visible="true"/><rule ruleid="40354" enabled="true" group="68157646" action=" db  screen " name="Frontpage fpsrvadm.exe文件扫描探测" name_chs="Frontpage fpsrvadm.exe文件扫描探测" name_eng="Frontpage fpsrvadm.exe File Detection" visible="true"/><rule ruleid="40604" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下War Trojan木马通信" name_chs="Windows系统下War Trojan木马通信" name_eng="Trojan War Trojan Communication on Windows" visible="true"/><rule ruleid="40351" enabled="true" group="136323126" action=" db  screen " name="PHP/FI mlog.phtml脚本漏洞扫描探测" name_chs="PHP/FI mlog.phtml脚本漏洞扫描探测" name_eng="PHP/FI mlog.phtml Script Vulnerability Detection" visible="true"/><rule ruleid="40601" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Vampire木马通信" name_chs="Windows系统下Vampire木马通信" name_eng="Trojan Vampire Communication on Windows" visible="true"/><rule ruleid="40600" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Vagrnocker木马通信" name_chs="Windows系统下Vagrnocker木马通信" name_eng="Trojan Vagrnocker Communication on Windows" visible="true"/><rule ruleid="20744" enabled="true" group="203423915" action=" db  screen " name="HiveMail远程PHP代码注入攻击" name_chs="HiveMail远程PHP代码注入攻击" name_eng="HiveMail Remote PHP Code Injection" visible="true"/><rule ruleid="20745" enabled="true" group="203423915" action=" db  screen " name="Clever Copy ID参数远程SQL注入攻击" name_chs="Clever Copy ID参数远程SQL注入攻击" name_eng="Clever Copy ID Parameter Remote SQL Injection" visible="true"/><rule ruleid="20746" enabled="true" group="203423914" action=" db  screen " name="WebspotBlogging login.php远程SQL注入攻击" name_chs="WebspotBlogging login.php远程SQL注入攻击" name_eng="WebspotBlogging login.php Remote SQL Injection" visible="true"/><rule ruleid="20747" enabled="true" group="203423915" action=" db  screen " name="eFiction远程SQL注入攻击" name_chs="eFiction远程SQL注入攻击" name_eng="eFiction Remote SQL Injection" visible="true"/><rule ruleid="20740" enabled="true" group="203423915" action=" db  screen " name="TotalCalendar多个远程文件包含攻击" name_chs="TotalCalendar多个远程文件包含攻击" name_eng="TotalCalendar multiple Remote File Inclusions" visible="true"/><rule ruleid="20741" enabled="true" group="203423914" action=" db  screen " name="Blursoft Blur6ex多个远程SQL注入攻击" name_chs="Blursoft Blur6ex多个远程SQL注入攻击" name_eng="Blursoft Blur6ex multiple Remote SQL Injections" visible="true"/><rule ruleid="20742" enabled="true" group="203423915" action=" db  screen " name="Owl Intranet Engine远程文件包含攻击" name_chs="Owl Intranet Engine远程文件包含攻击" name_eng="Owl Intranet Engine Remote File Inclusion" visible="true"/><rule ruleid="20743" enabled="true" group="203423915" action=" db  screen " name="PHPKit UNC路径远程文件包含攻击" name_chs="PHPKit UNC路径远程文件包含攻击" name_eng="PHPKit UNC Path Remote File Inclusion" visible="true"/><rule ruleid="20748" enabled="true" group="203423914" action=" db  screen " name="Website Baker远程SQL注入攻击" name_chs="Website Baker远程SQL注入攻击" name_eng="Website Baker Remote SQL Injection" visible="true"/><rule ruleid="20749" enabled="true" group="203423914" action=" db  screen " name="Edgewall Software Trac Search模块远程SQL注入攻击" name_chs="Edgewall Software Trac Search模块远程SQL注入攻击" name_eng="Edgewall Software Trac Search Module Remote SQL Injection" visible="true"/><rule ruleid="40608" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Xanadu 1.0木马通信" name_chs="Windows系统下Xanadu 1.0木马通信" name_eng="Trojan Xanadu 1.0 Communication on Windows" visible="true"/><rule ruleid="70061" enabled="true" group="209715789" action="" name="SMTP服务返回码535" name_chs="SMTP服务返回码535" name_eng="SMTP Service Returning 535" visible="false"/><rule ruleid="20520" enabled="true" group="88082475" action=" db  screen " name="MySQL/Windows CREATE FUNCTION功能引用特殊函数库攻击" name_chs="MySQL/Windows CREATE FUNCTION功能引用特殊函数库攻击" name_eng="MySQL/Windows CREATE FUNCTION Special Library Reference" visible="true"/><rule ruleid="20521" enabled="true" group="88082475" action=" db  screen " name="MySQL/Windows CREATE FUNCTION功能目录遍历加载任意库攻击" name_chs="MySQL/Windows CREATE FUNCTION功能目录遍历加载任意库攻击" name_eng="MySQL/Windows CREATE FUNCTION Directory Traversal Arbitrary Library Loading" visible="true"/><rule ruleid="20522" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows即插即用功能远程缓冲区溢出攻击" name_chs="Microsoft Windows即插即用功能远程缓冲区溢出攻击" name_eng="Microsoft Windows Plug and Play Function Remote Buffer Overflow" visible="true"/><rule ruleid="10142" enabled="true" group="78645274" action=" db  screen " name="3Com 3CDaemon TFTP保留设备名拒绝服务攻击" name_chs="3Com 3CDaemon TFTP保留设备名拒绝服务攻击" name_eng="3Com 3CDaemon TFTP Reserved Device Name Denial of Service" visible="true"/><rule ruleid="20524" enabled="true" group="203423915" action=" db  screen " name="MyBulletinBoard search.php远程SQL注入攻击" name_chs="MyBulletinBoard search.php远程SQL注入攻击" name_eng="MyBulletinBoard search.php Remote SQL Injection" visible="true"/><rule ruleid="20525" enabled="true" group="203423915" action=" db  screen " name="Woltlab Burning Board modcp.php远程SQL注入攻击" name_chs="Woltlab Burning Board modcp.php远程SQL注入攻击" name_eng="Woltlab Burning Board modcp.php Remote Code Injection" visible="true"/><rule ruleid="20526" enabled="true" group="136315051" action=" db  screen " name="Zorum prod.php远程执行命令攻击" name_chs="Zorum prod.php远程执行命令攻击" name_eng="Zorum prod.php Remote Command Execution" visible="true"/><rule ruleid="10146" enabled="true" group="138414106" action=" db  screen " name="Solaris Telnet服务远程Ctrl-D字符拒绝服务攻击" name_chs="Solaris Telnet服务远程Ctrl-D字符拒绝服务攻击" name_eng="Solaris Telnet Service Remote Ctrl-D Character Denial of Service" visible="true"/><rule ruleid="20528" enabled="true" group="203423919" action=" db  screen " name="WebCalendar send_reminders.php远程执行命令攻击" name_chs="WebCalendar send_reminders.php远程执行命令攻击" name_eng="WebCalendar send_reminders.php Remote Command Execution" visible="true"/><rule ruleid="20529" enabled="true" group="143655215" action=" db  screen " name="GNU Mailutils 0.6 imap4d SEARCH命令远程格式串溢出攻击" name_chs="GNU Mailutils 0.6 imap4d SEARCH命令远程格式串溢出攻击" name_eng="GNU Mailutils 0.6 imap4d SEARCH Command Remote Format String Buffer Overflow" visible="true"/><rule ruleid="20090" enabled="true" group="203423911" action=" db  screen " name="利用Zeroboard _head.php脚本漏洞远程执行命令" name_chs="利用Zeroboard _head.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Zeroboard _head.php Script Vulnerability" visible="true"/><rule ruleid="20091" enabled="true" group="144703787" action=" db  screen " name="BIND iquery远程缓冲区溢出攻击" name_chs="BIND iquery远程缓冲区溢出攻击" name_eng="BIND iquery Remote Buffer Overflow" visible="true"/><rule ruleid="20093" enabled="true" group="166723887" action=" db  screen " name="Solaris CDE dtspcd远程缓冲区溢出攻击" name_chs="Solaris CDE dtspcd远程缓冲区溢出攻击" name_eng="Solaris CDE dtspcd Remote Buffer Overflow" visible="true"/><rule ruleid="40184" enabled="true" group="99618887" action=" db  screen " name="Windows系统下CDK木马建立连接" name_chs="Windows系统下CDK木马建立连接" name_eng="Trojan CDK Connection on Windows" visible="true"/><rule ruleid="40189" enabled="true" group="136323126" action=" db  screen " name="PHP/FI mylog.phtml脚本漏洞扫描探测" name_chs="PHP/FI mylog.phtml脚本漏洞扫描探测" name_eng="PHP/FI mylog.phtml Script Vulnerability Detection" visible="true"/><rule ruleid="20095" enabled="true" group="203423915" action=" db  screen  drop " name="利用B2 b2edit.showposts.php脚本漏洞" name_chs="利用B2 b2edit.showposts.php脚本漏洞" name_eng="B2 b2edit.showposts.php Script Vulnerability" visible="true"/><rule ruleid="20418" enabled="true" group="99615023" action=" db  screen  drop " name="Microsoft PCT协议远程缓冲区溢出攻击" name_chs="Microsoft PCT协议远程缓冲区溢出攻击" name_eng="Microsoft PCT Protocol Remote Buffer Overflow" visible="true"/><rule ruleid="20419" enabled="true" group="136315051" action=" db  screen " name="利用psinclude.cgi脚本漏洞远程执行命令" name_chs="利用psinclude.cgi脚本漏洞远程执行命令" name_eng="Remote Command Execution via psinclude.cgi Script Vulnerability" visible="true"/><rule ruleid="20416" enabled="true" group="136315183" action=" db  screen " name="PHP Post文件上传缓冲区溢出攻击" name_chs="PHP Post文件上传缓冲区溢出攻击" name_eng="PHP Post File Upload Buffer Overflow" visible="true"/><rule ruleid="20417" enabled="true" group="70254879" action=" db  screen  drop " name="Serv-U FTP服务器LIST命令超长-l参数远程拒绝服务攻击" name_chs="Serv-U FTP服务器LIST命令超长-l参数远程拒绝服务攻击" name_eng="Serv-U FTP Server LIST Command Over-long Parameter &quot;-1&quot; Remote Denial of Service" visible="true"/><rule ruleid="20410" enabled="true" group="204472619" action=" db  screen " name="FTP服务NLST命令超长参数溢出攻击" name_chs="FTP服务NLST命令超长参数溢出攻击" name_eng="FTP Service NLST Command Over-long Parameter Buffer Overflow" visible="true"/><rule ruleid="20411" enabled="true" group="99615014" action=" db  screen " name="Windows 95/98 UNC远程溢出攻击" name_chs="Windows 95/98 UNC远程溢出攻击" name_eng="Windows 95/98 UNC Remote Buffer Overflow" visible="true"/><rule ruleid="20412" enabled="true" group="135266607" action=" db  screen " name="Apache Web Server分块畸形编码传输" name_chs="Apache Web Server分块畸形编码传输" name_eng="Apache Web Server Malicious Chunked-Encoding Transmission" visible="true"/><rule ruleid="20413" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows LSA服务远程缓冲区溢出攻击" name_chs="Microsoft Windows LSA服务远程缓冲区溢出攻击" name_eng="Microsoft Windows LSA Service Remote Buffer Overflow" visible="true" merge="[t7200,si]"/><rule ruleid="30411" enabled="true" group="136323126" action=" db  screen " name="chetcpasswd.cgi脚本漏洞扫描探测" name_chs="chetcpasswd.cgi脚本漏洞扫描探测" name_eng="chetcpasswd.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30410" enabled="true" group="203431999" action=" db  screen " name="PHP-Nuke modules.php脚本漏洞扫描探测" name_chs="PHP-Nuke modules.php脚本漏洞扫描探测" name_eng="PHP-Nuke modules.php Script Vulnerability Detection" visible="true"/><rule ruleid="30413" enabled="true" group="136323129" action=" db  screen " name="Oracle 9i应用服务程序示例脚本扫描探测" name_chs="Oracle 9i应用服务程序示例脚本扫描探测" name_eng="Oracle 9i Application Server Sample Script Detection" visible="true"/><rule ruleid="10090" enabled="true" group="99614999" action=" db  screen " name="Artisoft XtraMail远程拒绝服务攻击" name_chs="Artisoft XtraMail远程拒绝服务攻击" name_eng="Artisoft XtraMail Remote Denial of Service" visible="true"/><rule ruleid="30415" enabled="true" group="136323125" action=" db  screen " name="Active PHP Bookmarks脚本漏洞扫描探测" name_chs="Active PHP Bookmarks脚本漏洞扫描探测" name_eng="Active PHP Bookmarks Script Vulnerability Detection" visible="true"/><rule ruleid="30414" enabled="true" group="136323126" action=" db  screen " name="H-Sphere WebShell脚本漏洞扫描探测" name_chs="H-Sphere WebShell脚本漏洞扫描探测" name_eng="H-Sphere WebShell Script Vulnerability Detection" visible="true"/><rule ruleid="30417" enabled="true" group="203431998" action=" db  screen " name="PHP-Nuke mailattach.php脚本漏洞扫描探测" name_chs="PHP-Nuke mailattach.php脚本漏洞扫描探测" name_eng="PHP-Nuke mailattach.php Script Vulnerability Detection" visible="true"/><rule ruleid="30416" enabled="true" group="203431989" action=" db  screen " name="myPHPNuke system_footer.php脚本漏洞扫描探测" name_chs="myPHPNuke system_footer.php脚本漏洞扫描探测" name_eng="myPHPNuke system_footer.php Script Vulnerability Detection" visible="true"/><rule ruleid="30419" enabled="true" group="136315066" action=" db  screen " name="利用EditTag edittag.cgi脚本漏洞远程读取任意文件" name_chs="利用EditTag edittag.cgi脚本漏洞远程读取任意文件" name_eng="Remote Arbitrary File Reading via EditTag edittag.cgi Script Vulnerability" visible="true"/><rule ruleid="30418" enabled="true" group="136323126" action=" db  screen " name="psunami.cgi脚本漏洞扫描探测" name_chs="psunami.cgi脚本漏洞扫描探测" name_eng="psunami.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="10098" enabled="true" group="70256667" action=" db  screen  drop " name="Windows NT IIS/4.0 FTP NLST命令远程拒绝服务攻击" name_chs="Windows NT IIS/4.0 FTP NLST命令远程拒绝服务攻击" name_eng="Windows NT IIS/4.0 FTP NLST Command Remote Denial of Service" visible="true"/><rule ruleid="30329" enabled="true" group="136315066" action=" db  screen " name="YaBB YaBB.pl脚本漏洞攻击" name_chs="YaBB YaBB.pl脚本漏洞攻击" name_eng="YaBB YaBB.pl Script Vulnerability" visible="true"/><rule ruleid="30328" enabled="true" group="136315066" action=" db  screen " name="利用SIX-webboard generate.cgi脚本漏洞远程遍历目录" name_chs="利用SIX-webboard generate.cgi脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via SIX-webboard generate.cgi Script Vulnerability" visible="true"/><rule ruleid="40369" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht客户端连接检查" name_chs="DDOS工具Stacheldraht客户端连接检查" name_eng="DDOS Stacheldraht Client Connection Deteciton" visible="true"/><rule ruleid="30323" enabled="true" group="136323126" action=" db  screen " name="ans.pl脚本漏洞扫描探测" name_chs="ans.pl脚本漏洞扫描探测" name_eng="ans.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30322" enabled="true" group="136315062" action=" db  screen " name="store.cgi脚本漏洞扫描利用" name_chs="store.cgi脚本漏洞扫描利用" name_eng="store.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30321" enabled="true" group="203423930" action=" db  screen " name="Lotus Domino Server远程目录遍历攻击" name_chs="Lotus Domino Server远程目录遍历攻击" name_eng="Lotus Domino Server Remote Directory Traversal" visible="true"/><rule ruleid="30320" enabled="true" group="136315062" action=" db  screen " name="Tatantella TTAWebTop.CGI脚本漏洞扫描利用" name_chs="Tatantella TTAWebTop.CGI脚本漏洞扫描利用" name_eng="Tatantella TTAWebTop.CGI Script Vulnerability Detection" visible="true"/><rule ruleid="30327" enabled="true" group="136323130" action=" db  screen " name="SIX-webboard generate.cgi脚本漏洞扫描探测" name_chs="SIX-webboard generate.cgi脚本漏洞扫描探测" name_eng="SIX-webboard generate.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30326" enabled="true" group="136315062" action=" db  screen " name="agora.cgi脚本漏洞扫描利用" name_chs="agora.cgi脚本漏洞扫描利用" name_eng="agora.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30325" enabled="true" group="136323130" action=" db  screen " name="AHG search.cgi脚本漏洞扫描探测" name_chs="AHG search.cgi脚本漏洞扫描探测" name_eng="AHG search.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30324" enabled="true" group="136315062" action=" db  screen " name="利用ans.pl脚本远程漏洞遍历目录" name_chs="利用ans.pl脚本远程漏洞遍历目录" name_eng="Remote Directory Traversal via ans.pl Script" visible="true"/><rule ruleid="40614" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.P@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.P@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.P@mm" visible="true"/><rule ruleid="20250" enabled="true" group="203431993" action=" db  screen " name="Allaire ColdFusion未公开CFML标记漏洞扫描探测" name_chs="Allaire ColdFusion未公开CFML标记漏洞扫描探测" name_eng="Allaire ColdFusion Undocumented CFML Tags Vulnerability Detection" visible="true"/><rule ruleid="30206" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.ypserv服务存在性TCP扫描探测" name_chs="Solaris rpc.ypserv服务存在性TCP扫描探测" name_eng="Solaris rpc.ypserv Service TCP Detection" visible="true"/><rule ruleid="40742" enabled="true" group="99618891" action=" db  screen " name="Windows系统下近墨者木马通信" name_chs="Windows系统下近墨者木马通信" name_eng="Trojan Jinmozhe Communication on Windows" visible="true"/><rule ruleid="40743" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware Gator下载安装程序" name_chs="Windows系统下Adware Gator下载安装程序" name_eng="Adware Gator Downloading Installer on Windows" visible="true"/><rule ruleid="40740" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware AproposMedia下载安装程序" name_chs="Windows系统下Adware AproposMedia下载安装程序" name_eng="Adware AproposMedia Downloading Installer on Windows" visible="true"/><rule ruleid="40741" enabled="true" group="69210191" action=" db  screen " name="Windows系统下黑客帝国ASP后门访问" name_chs="Windows系统下黑客帝国ASP后门访问" name_eng="Hacker's Empire ASP Backdoor on Windows" visible="true"/><rule ruleid="30529" enabled="true" group="203423929" action=" db  screen " name="Caucho Resin viewfile获取脚本源码攻击" name_chs="Caucho Resin viewfile获取脚本源码攻击" name_eng="Caucho Resin viewfile Script Source Code Disclosure" visible="true"/><rule ruleid="40747" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware GameSpy Arcade下载安装程序" name_chs="Windows系统下Adware GameSpy Arcade下载安装程序" name_eng="Adware GameSpy Arcade Downloading Installer on Windows" visible="true"/><rule ruleid="40744" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware TopMoxie下载安装程序" name_chs="Windows系统下Adware TopMoxie下载安装程序" name_eng="Adware TopMoxie Downloading Installer on Windows" visible="true"/><rule ruleid="40745" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware InstantAccess下载安装程序" name_chs="Windows系统下Adware InstantAccess下载安装程序" name_eng="Adware InstantAccess Downloading Installer on Windows" visible="true"/><rule ruleid="30525" enabled="true" group="69206198" action=" db  screen " name="Alibaba alibaba.pl脚本漏洞扫描利用" name_chs="Alibaba alibaba.pl脚本漏洞扫描利用" name_eng="Alibaba alibaba.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30524" enabled="true" group="88088638" action=" db  screen " name="Microsoft SQL Server预验证过程远程缓冲区漏洞探测" name_chs="Microsoft SQL Server预验证过程远程缓冲区漏洞探测" name_eng="Microsoft SQL Server Pre-authentication Process Buffer Vulnerability Detection" visible="true"/><rule ruleid="30255" enabled="true" group="203431994" action=" db  screen " name="vBulletin Calendar.php脚本漏洞扫描探测" name_chs="vBulletin Calendar.php脚本漏洞扫描探测" name_eng="vBulletin Calendar.php Script Vulnerability Detection" visible="true"/><rule ruleid="40749" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Lyyshell木马通信" name_chs="Windows系统下Lyyshell木马通信" name_eng="Trojan Lyyshell Communication on Windows" visible="true"/><rule ruleid="30253" enabled="true" group="203423930" action=" db  screen " name="Tomcat 4.x远程获取JSP源代码攻击" name_chs="Tomcat 4.x远程获取JSP源代码攻击" name_eng="Tomcat 4.x Remote JSP Source Code Disclosure" visible="true"/><rule ruleid="30520" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－ACK扫描" name_chs="服务器端口扫描－ACK扫描" name_eng="Server Port Scan - ACK Scan" visible="true"/><rule ruleid="30523" enabled="true" group="203423934" action=" db  screen " name="Allaire JRun Servlet畸形请求远程获取源码攻击" name_chs="Allaire JRun Servlet畸形请求远程获取源码攻击" name_eng="Allaire JRun Servlet Malformed Request Source Code Disclosure" visible="true"/><rule ruleid="30250" enabled="true" group="136315066" action=" db  screen " name="访问&quot;/_pages&quot;获取Oracle 9iAS JSP源码攻击" name_chs="访问&quot;/_pages&quot;获取Oracle 9iAS JSP源码攻击" name_eng="Oracle 9iAS JSP Source Code Disclosure via &quot;/_pages&quot;" visible="true"/><rule ruleid="40327" enabled="true" group="99618895" action=" db  screen " name="Windows系统下Bluefire木马连接建立" name_chs="Windows系统下Bluefire木马连接建立" name_eng="Trojan Bluefire Connection on Windows" visible="true"/><rule ruleid="40328" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下冰河木马通信" name_chs="Windows系统下冰河木马通信" name_eng="Trojan Glacier Trojan Communication on Windows" visible="true"/><rule ruleid="40568" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下The Prayer木马通信" name_chs="Windows系统下The Prayer木马通信" name_eng="Trojan The Prayer Communication on Windows" visible="true"/><rule ruleid="40569" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PrivatePort木马通信" name_chs="Windows系统下PrivatePort木马通信" name_eng="Trojan PrivatePort Communication on Windows" visible="true"/><rule ruleid="50099" enabled="true" group="99745885" action=" db  screen " name="网络游戏平台中国游戏中心登录" name_chs="网络游戏平台中国游戏中心登录" name_eng="Online Game Platform &quot;chinagames.net&quot; Login" visible="true"/><rule ruleid="50098" enabled="true" group="99680349" action=" db  screen " name="Windows系统远程管理工具Remote Administrator用户认证" name_chs="Windows系统远程管理工具Remote Administrator用户认证" name_eng="Windows Remote Management Tool Remote Administrator Authentication" visible="true"/><rule ruleid="40562" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下OOTLT木马通信" name_chs="Windows系统下OOTLT木马通信" name_eng="Trojan OOTLT Communication on Windows" visible="true"/><rule ruleid="40563" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Optix木马通信" name_chs="Windows系统下Optix木马通信" name_eng="Trojan Optix Communication on Windows" visible="true"/><rule ruleid="40560" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Olive木马通信" name_chs="Windows系统下Olive木马通信" name_eng="Trojan Olive Communication on Windows" visible="true"/><rule ruleid="40561" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下One木马通信" name_chs="Windows系统下One木马通信" name_eng="Trojan One Communication on Windows" visible="true"/><rule ruleid="40566" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Phoenix木马通信" name_chs="Windows系统下Phoenix木马通信" name_eng="Trojan Phoenix Communication on Windows" visible="true"/><rule ruleid="40567" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PitFall木马通信" name_chs="Windows系统下PitFall木马通信" name_eng="Trojan PitFall Communication on Windows" visible="true"/><rule ruleid="40564" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Oxon木马通信" name_chs="Windows系统下Oxon木马通信" name_eng="Trojan Oxon Communication on Windows" visible="true"/><rule ruleid="40565" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PC Invader木马通信" name_chs="Windows系统下PC Invader木马通信" name_eng="Trojan PC Invader Communication on Windows" visible="true"/><rule ruleid="30360" enabled="true" group="69206198" action=" db  screen " name="ION ion-p.exe脚本漏洞扫描利用" name_chs="ION ion-p.exe脚本漏洞扫描利用" name_eng="ION ion-p.exe Script Vulnerability Detection" visible="true"/><rule ruleid="20865" enabled="true" group="68157738" action=" db  screen " name="mIRC IRC URL缓冲区溢出攻击" name_chs="mIRC IRC URL缓冲区溢出攻击" name_eng="mIRC IRC URL Buffer Overflow" visible="true"/><rule ruleid="40299" enabled="true" group="88146015" action=" db  screen " name="Microsoft SQL 客户端SA用户默认空口令连接" name_chs="Microsoft SQL 客户端SA用户默认空口令连接" name_eng="Microsoft SQL Client SA User Default Null Password Connection" visible="true"/><rule ruleid="40458" enabled="true" group="99876911" action=" db  screen " name="Windows系统下利用Novarg/Mydoom后门上传执行程序" name_chs="Windows系统下利用Novarg/Mydoom后门上传执行程序" name_eng="Executable Upload via Novarg/Mydoom Backdoor on Windows" visible="true" merge="[t300,si]"/><rule ruleid="20867" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Accept-Language字段超长缓冲区溢出攻击" name_chs="HTTP协议Accept-Language字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Accept-Language Field Buffer Overflow" visible="true"/><rule ruleid="50075" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN Messenger用户登录" name_chs="即时通信软件MSN Messenger用户登录" name_eng="Instant Messaging Software MSN Messenger User Login" visible="true"/><rule ruleid="50074" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户登录" name_chs="即时通信软件ICQ用户登录" name_eng="Instant Messaging Software ICQ User Login" visible="true"/><rule ruleid="50077" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具BitTorrent获取文件信息" name_chs="P2P文件共享工具BitTorrent获取文件信息" name_eng="P2P File Sharing Tool BitTorrent Obtainning File Information" visible="true" merge="[t3600,si]"/><rule ruleid="40459" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.D@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.D@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.D@mm" visible="true" merge="[t7200,si]"/><rule ruleid="50071" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k连接服务器" name_chs="P2P文件共享工具eDonkey/ed2k连接服务器" name_eng="P2P File Sharing Tool eDonkey/ed2k Server Connection" visible="true"/><rule ruleid="50070" enabled="true" group="68190293" action=" db  screen " name="Web服务TRACK方法请求" name_chs="Web服务TRACK方法请求" name_eng="Web Service TRACK Method Request" visible="true"/><rule ruleid="50073" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k请求文件片断(TCP)" name_chs="P2P文件共享工具eDonkey/ed2k请求文件片断(TCP)" name_eng="P2P File Sharing Tool eDonkey/ed2k File Request Fragment (TCP)" visible="true"/><rule ruleid="50072" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k搜索文件" name_chs="P2P文件共享工具eDonkey/ed2k搜索文件" name_eng="P2P File Sharing Tool eDonkey/ed2k Searching Files" visible="true"/><rule ruleid="50079" enabled="true" group="99745885" action=" db  screen " name="网络游戏星际争霸（Starcraft）客户端连接服务器" name_chs="网络游戏星际争霸（Starcraft）客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Starcraft&quot;" visible="true"/><rule ruleid="50078" enabled="true" group="99745885" action=" db  screen " name="网络游戏反恐精英（CS）客户端连接服务器" name_chs="网络游戏反恐精英（CS）客户端连接服务器" name_eng="Connection from Client to Server of Online Game CS" visible="true"/><rule ruleid="40457" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Novarg/Mydoom蠕虫及其变种Mydoom.U病毒邮件" name_chs="SMTP服务发送Novarg/Mydoom蠕虫及其变种Mydoom.U病毒邮件" name_eng="SMTP Service Sending Mails with Novarg/Mydoom and Variant Mydoom.U" visible="true" merge="[t7200,si]"/><rule ruleid="40633" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AP@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AP@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AP@mm" visible="true"/><rule ruleid="20860" enabled="true" group="70254890" action=" db  screen " name="FTP服务器SIZE命令超长参数远程缓冲区溢出攻击" name_chs="FTP服务器SIZE命令超长参数远程缓冲区溢出攻击" name_eng="FTP Server SIZE Command Over-Long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20863" enabled="true" group="68157738" action=" db  screen " name="XMPlay播放列表文件远程栈溢出攻击" name_chs="XMPlay播放列表文件远程栈溢出攻击" name_eng="XMPlay Playlist File Remote Stack Overflow" visible="true"/><rule ruleid="20572" enabled="true" group="203423915" action=" db  screen " name="MyBB showteam.php远程SQL注入攻击" name_chs="MyBB showteam.php远程SQL注入攻击" name_eng="MyBB showteam.php Remote SQL Injection" visible="true"/><rule ruleid="30227" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.ttdbserverd服务存在性UDP扫描探测" name_chs="Solaris rpc.ttdbserverd服务存在性UDP扫描探测" name_eng="Solaris rpc.ttdbserverd Service UDP Detection" visible="true"/><rule ruleid="20731" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP 超长To字段缓冲区溢出攻击" name_chs="Cisco CallManager SIP 超长To字段缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long To Field Buffer Overflow" visible="true"/><rule ruleid="20730" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP超长主机名UDP远程缓冲区溢出攻击" name_chs="Cisco CallManager SIP超长主机名UDP远程缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long Host Name UDP Remote Buffer Overflow" visible="true"/><rule ruleid="20733" enabled="true" group="99615019" action=" db  screen " name="Symantec Antivirus Rtvscan.exe远程栈溢出攻击" name_chs="Symantec Antivirus Rtvscan.exe远程栈溢出攻击" name_eng="Symantec Antivirus Rtvscan.exe Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20732" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP超长主机名TCP远程缓冲区溢出攻击" name_chs="Cisco CallManager SIP超长主机名TCP远程缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long Host Name TCP Remote Buffer Overflow" visible="true"/><rule ruleid="20735" enabled="true" group="99616811" action=" db  screen " name="Microsoft IE DHTML引擎竞争条件攻击" name_chs="Microsoft IE DHTML引擎竞争条件攻击" name_eng="Microsoft IE DHTML Engine Race Condition" visible="true"/><rule ruleid="20734" enabled="true" group="75497771" action=" db  screen " name="Foxmail Serve MAIL FROM远程缓冲区溢出攻击" name_chs="Foxmail Serve MAIL FROM远程缓冲区溢出攻击" name_eng="Foxmail Serve MAIL FROM Remote Buffer Overflow" visible="true"/><rule ruleid="20737" enabled="true" group="99615019" action=" db  screen " name="Netscape NSS库SSLV2畸形Hello消息远程缓冲区溢出攻击" name_chs="Netscape NSS库SSLV2畸形Hello消息远程缓冲区溢出攻击" name_eng="Netscape NSS Lib SSLV2 Malformed Hello Message Remote Buffer Overflow" visible="true"/><rule ruleid="20736" enabled="true" group="233832747" action=" db  screen " name="SIP畸形URI远程缓冲区溢出攻击" name_chs="SIP畸形URI远程缓冲区溢出攻击" name_eng="SIP Malformed URI Remote Buffer Overflow" visible="true"/><rule ruleid="20739" enabled="true" group="203423915" action=" db  screen " name="EQdkp dbal.php远程文件包含攻击" name_chs="EQdkp dbal.php远程文件包含攻击" name_eng="EQdkp dbal.php Remote File Inclusion" visible="true"/><rule ruleid="20738" enabled="true" group="99615019" action=" db  screen " name="Apache Mod_SSL/Apache-SSL远程缓冲区溢出攻击" name_chs="Apache Mod_SSL/Apache-SSL远程缓冲区溢出攻击" name_eng="Apache Mod_SSL/Apache-SSL Remote Buffer Overflow" visible="true"/><rule ruleid="10152" enabled="true" group="300943386" action=" db  screen " name="H.225协议destinationAddress email-ID数据畸形" name_chs="H.225协议destinationAddress email-ID数据畸形" name_eng="H.225 Protocol destinationAddress email-ID Malformed Data" visible="true"/><rule ruleid="10153" enabled="true" group="300943386" action=" db  screen " name="H.225协议sourceAddress序列数据畸形" name_chs="H.225协议sourceAddress序列数据畸形" name_eng="H.225 Protocol sourceAddress Sequence Malformed Data" visible="true"/><rule ruleid="10150" enabled="true" group="300943386" action=" db  screen " name="Q.931协议Calling Party Number Length数据畸形" name_chs="Q.931协议Calling Party Number Length数据畸形" name_eng="Q.931 Protocol Calling Party Number Length Malformed Data" visible="true"/><rule ruleid="10151" enabled="true" group="300943386" action=" db  screen " name="H.225协议DestinationAddress序列数据畸形" name_chs="H.225协议DestinationAddress序列数据畸形" name_eng="H.225 Protocol DestinationAddress Sequence Malformed Data" visible="true"/><rule ruleid="10156" enabled="true" group="300943386" action=" db  screen " name="H.225协议Destination AliasAddress e164Number数据畸形" name_chs="H.225协议Destination AliasAddress e164Number数据畸形" name_eng="H.225 Protocol Destination AliasAddress e164Number Malformed Data" visible="true"/><rule ruleid="10157" enabled="true" group="300943386" action=" db  screen " name="H.225协议DestinationAddress H323-ID数据畸形" name_chs="H.225协议DestinationAddress H323-ID数据畸形" name_eng="H.225 Protocol DestinationAddress H323-ID Malformed Data" visible="true"/><rule ruleid="20089" enabled="true" group="136315051" action=" db  screen " name="利用WEBgais websendmail脚本漏洞远程执行命令" name_chs="利用WEBgais websendmail脚本漏洞远程执行命令" name_eng="Remote Code Execution via WEBgais websendmail Script Vulnerability" visible="true"/><rule ruleid="10155" enabled="true" group="300943386" action=" db  screen " name="H.225协议Destination AliasAddress Choice扩展选项数据畸形" name_chs="H.225协议Destination AliasAddress Choice扩展选项数据畸形" name_eng="H.225 Protocol Destination AliasAddress Choice Extended Option Malformed Data" visible="true"/><rule ruleid="20087" enabled="true" group="136315051" action=" db  screen  drop " name="利用Matt Wright textcounter.pl脚本漏洞远程执行命令" name_chs="利用Matt Wright textcounter.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via Matt Wright textcounter.pl Script Vulnerability" visible="true"/><rule ruleid="20086" enabled="true" group="136315051" action=" db  screen " name="利用NCSA phf脚本漏洞远程执行命令" name_chs="利用NCSA phf脚本漏洞远程执行命令" name_eng="Remote Code Execution via  NCSA phf Script Vulnerability" visible="true"/><rule ruleid="10158" enabled="true" group="78645274" action=" db  screen " name="TFTPD32远程格式串文件名拒绝服务攻击" name_chs="TFTPD32远程格式串文件名拒绝服务攻击" name_eng="TFTPD32 Username Remote Format String Denial of Service" visible="true"/><rule ruleid="20084" enabled="true" group="136315051" action=" db  screen " name="利用IRIX handler脚本漏洞远程执行命令" name_chs="利用IRIX handler脚本漏洞远程执行命令" name_eng="Remote Code Execution via IRIX handler Script Vulnerability" visible="true"/><rule ruleid="20083" enabled="true" group="136315051" action=" db  screen  drop " name="利用FormMail formmail.pl脚本漏洞远程执行命令" name_chs="利用FormMail formmail.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via FormMail formmail.pl Script Vulnerability" visible="true"/><rule ruleid="20082" enabled="true" group="136315051" action=" db  screen  drop " name="利用Hylafax faxsurvey脚本漏洞远程执行命令" name_chs="利用Hylafax faxsurvey脚本漏洞远程执行命令" name_eng="Remote Code Execution via Hylafax faxsurvey Script Vulnerability" visible="true"/><rule ruleid="20081" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csNews.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csNews.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csNews.cgi Script Vulnerability" visible="true"/><rule ruleid="20080" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csLiveSupport.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csLiveSupport.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csLiveSupport.cgi Script Vulnerability" visible="true"/><rule ruleid="20649" enabled="true" group="203423915" action=" db  screen " name="WowBB view_user.php远程SQL注入攻击" name_chs="WowBB view_user.php远程SQL注入攻击" name_eng="WowBB view_user.php Remote SQL Injection" visible="true"/><rule ruleid="20648" enabled="true" group="99615019" action=" db  screen " name="eStara Softphone SIP SDP请求远程缓冲区溢出攻击" name_chs="eStara Softphone SIP SDP请求远程缓冲区溢出攻击" name_eng="eStara Softphone SIP SDP Request Remote Buffer Overflow" visible="true"/><rule ruleid="20645" enabled="true" group="203423915" action=" db  screen " name="RaXnet Cacti远程文件包含执行命令攻击" name_chs="RaXnet Cacti远程文件包含执行命令攻击" name_eng="RaXnet Cacti Remote File Inclusion Code Execution" visible="true"/><rule ruleid="20644" enabled="true" group="203423919" action=" db  screen " name="miniBB news.php远程文件包含攻击" name_chs="miniBB news.php远程文件包含攻击" name_eng="miniBB news.php Remote File Inclusion" visible="true"/><rule ruleid="20647" enabled="true" group="203423915" action=" db  screen " name="osTicket include_dir变量远程文件包含攻击" name_chs="osTicket include_dir变量远程文件包含攻击" name_eng="osTicket include_dir Variable Remote File Inclusion" visible="true"/><rule ruleid="20646" enabled="true" group="203423915" action=" db  screen " name="PmWiki pmwiki.php远程文件包含攻击" name_chs="PmWiki pmwiki.php远程文件包含攻击" name_eng="PmWiki pmwiki.php Remote File Inclusion" visible="true"/><rule ruleid="20641" enabled="true" group="99615019" action=" db  screen " name="Microsoft Windows Server驱动Mailslot远程堆溢出攻击" name_chs="Microsoft Windows Server驱动Mailslot远程堆溢出攻击" name_eng="Microsoft Windows Server Driver Mailslot Remote Heap Overflow" visible="true"/><rule ruleid="20640" enabled="true" group="203423915" action=" db  screen " name="Mambo/Joomla mosConfig_absolute_path远程文件包含攻击" name_chs="Mambo/Joomla mosConfig_absolute_path远程文件包含攻击" name_eng="Mambo/Joomla mosConfig_absolute_path Remote File Inclusion" visible="true"/><rule ruleid="20643" enabled="true" group="300941611" action=" db  screen " name="D-Link路由器UPNP远程缓冲区溢出攻击" name_chs="D-Link路由器UPNP远程缓冲区溢出攻击" name_eng="D-Link Rounter UPNP Remote Buffer Overflow" visible="true"/><rule ruleid="20642" enabled="true" group="97517871" action=" db  screen " name="Microsoft Windows DHCP Client服务ACK应答处理缓冲区溢出攻击" name_chs="Microsoft Windows DHCP Client服务ACK应答处理缓冲区溢出攻击" name_eng="Microsoft Windows DHCP Client Service ACK Response Handling Buffer Overflow" visible="true"/><rule ruleid="40178" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NetSphere木马建立连接" name_chs="Windows系统下NetSphere木马建立连接" name_eng="Trojan NetSphere Connection on Windows" visible="true"/><rule ruleid="40174" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Hack a tack木马建立连接" name_chs="Windows系统下Hack a tack木马建立连接" name_eng="Trojan Hack a tack Connection on Windows" visible="true"/><rule ruleid="40176" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下WinCrash 1.0木马建立连接" name_chs="Windows系统下WinCrash 1.0木马建立连接" name_eng="Trojan WinCrash 1.0 Connection on Windows" visible="true"/><rule ruleid="40171" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht服务器回应堵塞" name_chs="DDOS工具Stacheldraht服务器回应堵塞" name_eng="DDOS Tool Stacheldraht Server Response Block" visible="true"/><rule ruleid="40173" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下DonaldDick木马建立连接" name_chs="Windows系统下DonaldDick木马建立连接" name_eng="Trojan DonaldDick Connection on Windows" visible="true"/><rule ruleid="40172" enabled="true" group="99618895" action=" db  screen " name="Windows系统下的PhaseZero木马连接建立" name_chs="Windows系统下的PhaseZero木马连接建立" name_eng="Trojan PhaseZero Connection on Windows" visible="true"/><rule ruleid="20469" enabled="true" group="203423919" action=" db  screen " name="PHPNews sendtofriend.php远程SQL注入攻击" name_chs="PHPNews sendtofriend.php远程SQL注入攻击" name_eng="PHPNews sendtofriend.php Remote SQL Injection" visible="true"/><rule ruleid="20468" enabled="true" group="203423915" action=" db  screen " name="PowerPortal index.php远程SQL注入攻击" name_chs="PowerPortal index.php远程SQL注入攻击" name_eng="PowerPortal index.php Remote SQL Injection" visible="true"/><rule ruleid="20399" enabled="true" group="99615791" action=" db  screen  drop " name="Windows系统下Witty蠕虫传播" name_chs="Windows系统下Witty蠕虫传播" name_eng="Windows Witty Worm Propagation" visible="true"/><rule ruleid="20398" enabled="true" group="69206315" action=" db  screen " name="利用MDaemon form2raw.cgi CGI脚本漏洞溢出攻击" name_chs="利用MDaemon form2raw.cgi CGI脚本漏洞溢出攻击" name_eng="Buffer Overflow via MDaemon form2raw.cgi CGI Script Vulnerability" visible="true"/><rule ruleid="20461" enabled="true" group="203423915" action=" db  screen " name="Phorum follow.php远程SQL注入攻击" name_chs="Phorum follow.php远程SQL注入攻击" name_eng="Phorum follow.php Remote SQL Injection" visible="true"/><rule ruleid="20460" enabled="true" group="99615019" action=" db  screen " name="Oracle 8i TNS Listener缓冲区溢出攻击" name_chs="Oracle 8i TNS Listener缓冲区溢出攻击" name_eng="Oracle 8i TNS Listener Buffer Overflow" visible="true"/><rule ruleid="20463" enabled="true" group="203423919" action=" db  screen " name="miniBB bb_func_usernfo.php远程SQL注入攻击" name_chs="miniBB bb_func_usernfo.php远程SQL注入攻击" name_eng="miniBB bb_func_usernfo.php Remote SQL Injection" visible="true"/><rule ruleid="20462" enabled="true" group="203423919" action=" db  screen " name="vBulletin Forum last.php远程SQL注入攻击" name_chs="vBulletin Forum last.php远程SQL注入攻击" name_eng="vBulletin Forum last.php Remote SQL Injection" visible="true"/><rule ruleid="20465" enabled="true" group="203423919" action=" db  screen " name="利用phpBB admin_cash.php CGI脚本漏洞远程执行命令" name_chs="利用phpBB admin_cash.php CGI脚本漏洞远程执行命令" name_eng="Remote Command Execution via phpBB admin_cash.php CGI Script Vulnerability" visible="true"/><rule ruleid="20396" enabled="true" group="70254895" action=" db  screen  drop " name="Serv-U FTP服务器MDTM命令远程缓冲区溢出攻击" name_chs="Serv-U FTP服务器MDTM命令远程缓冲区溢出攻击" name_eng="Serv-U FTP Server MDTM Command Remote Buffer Overflow" visible="true"/><rule ruleid="20467" enabled="true" group="203423919" action=" db  screen " name="Invision Power Board index.php远程SQL注入攻击" name_chs="Invision Power Board index.php远程SQL注入攻击" name_eng="Invision Power Board index.php Remote SQL Injection" visible="true"/><rule ruleid="20466" enabled="true" group="203423919" action=" db  screen  drop " name="phpBB URL编码远程任意命令执行攻击" name_chs="phpBB URL编码远程任意命令执行攻击" name_eng="phpBB URL Encoding Remote Arbitrary Command Execution" visible="true"/><rule ruleid="30402" enabled="true" group="136315062" action=" db  screen " name="利用Home Free search.cgi脚本漏洞目录遍历攻击" name_chs="利用Home Free search.cgi脚本漏洞目录遍历攻击" name_eng="Directory Traversal via Home Free search.cgi Script Vulnerability" visible="true"/><rule ruleid="30403" enabled="true" group="136315066" action=" db  screen " name="利用Moreover.com cached_feed.cgi脚本远程遍历目录" name_chs="利用Moreover.com cached_feed.cgi脚本远程遍历目录" name_eng="Remote Directory Traversal via Moreover.com cached_feed.cgi Script" visible="true"/><rule ruleid="30400" enabled="true" group="136315066" action=" db  screen " name="利用PHP-Nuke CGI脚本漏洞获取目录信息" name_chs="利用PHP-Nuke CGI脚本漏洞获取目录信息" name_eng="Directory Information Disclosure via PHP-Nuke CGI Script Vulnerability" visible="true"/><rule ruleid="30401" enabled="true" group="69214266" action=" db  screen " name="利用Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞" name_chs="利用Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞" name_eng="Trend Micro OfficeScan jdkRqNotify.exe Script Vulnerability" visible="true"/><rule ruleid="10088" enabled="true" group="69206171" action=" db  screen " name="利用Microsoft Outlook Web Access漏洞进行拒绝服务攻击" name_chs="利用Microsoft Outlook Web Access漏洞进行拒绝服务攻击" name_eng="Denial of Service via Microsoft Outlook Web Access Vulnerability" visible="true"/><rule ruleid="10089" enabled="true" group="137365535" action=" db  screen " name="ProFTPD STAT命令远程拒绝服务攻击" name_chs="ProFTPD STAT命令远程拒绝服务攻击" name_eng="ProFTPD STAT Command Remote Denial of Service" visible="true"/><rule ruleid="30404" enabled="true" group="136315066" action=" db  screen " name="Moreover.com cached_feed.cgi脚本漏洞扫描探测" name_chs="Moreover.com cached_feed.cgi脚本漏洞扫描探测" name_eng="Moreover.com cached_feed.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30405" enabled="true" group="202407995" action=" db  screen " name="通过Web服务访问Netscape SuiteSpot管理员口令文件" name_chs="通过Web服务访问Netscape SuiteSpot管理员口令文件" name_eng="Access to Netscape SuiteSpot Admin Password File via Web Service" visible="true"/><rule ruleid="10084" enabled="true" group="368052247" action=" db  screen " name="Ascend系列路由器UDP/9端口拒绝服务攻击" name_chs="Ascend系列路由器UDP/9端口拒绝服务攻击" name_eng="Ascend Routers Port UDP/9 Denial of Service" visible="true"/><rule ruleid="10086" enabled="true" group="136315035" action=" db  screen " name="利用HP Openview Manager OpenView5.exe程序漏洞拒绝服务攻击" name_chs="利用HP Openview Manager OpenView5.exe程序漏洞拒绝服务攻击" name_eng="Denial of Service via HP Openview Manager OpenView5.exe Vulnerability" visible="true"/><rule ruleid="30409" enabled="true" group="136323130" action=" db  screen " name="Open WebMail openwebmail-shared.pl脚本漏洞扫描探测" name_chs="Open WebMail openwebmail-shared.pl脚本漏洞扫描探测" name_eng="Open WebMail openwebmail-shared.pl Script Vulnerability Detection" visible="true"/><rule ruleid="10080" enabled="true" group="337641627" action=" db  screen " name="Cisco VoIP Phone流量统计请求拒绝服务攻击" name_chs="Cisco VoIP Phone流量统计请求拒绝服务攻击" name_eng="Cisco VoIP Phone Traffic Statistic Request Denial of Service" visible="true"/><rule ruleid="10081" enabled="true" group="70256667" action=" db  screen " name="TransSoft FTP-Broker远程拒绝服务攻击" name_chs="TransSoft FTP-Broker远程拒绝服务攻击" name_eng="TransSoft FTP-Broker Remote Denial of Service" visible="true"/><rule ruleid="10082" enabled="true" group="203423899" action=" db  screen " name="Real Networks RealServer远程拒绝服务攻击" name_chs="Real Networks RealServer远程拒绝服务攻击" name_eng="Real Networks RealServer Remote Denial of Service" visible="true"/><rule ruleid="40313" enabled="true" group="68157743" action=" db  screen " name="Microsoft IIS 4.0/5.0 .asp ISAPI扩展远程缓冲区溢出攻击" name_chs="Microsoft IIS 4.0/5.0 .asp ISAPI扩展远程缓冲区溢出攻击" name_eng="Microsoft IIS 4.0/5.0 .asp ISAPI Extension Remote Buffer Overflow" visible="true"/><rule ruleid="20266" enabled="true" group="69206187" action=" db  screen " name="Oracle 9i应用服务器无需授权访问管理目录漏洞攻击" name_chs="Oracle 9i应用服务器无需授权访问管理目录漏洞攻击" name_eng="Unauthorized Access to Oracle 9i Application Server Admin Directory" visible="true"/><rule ruleid="20263" enabled="true" group="166723879" action=" db  screen " name="AIX pdnsd远程缓冲区溢出攻击" name_chs="AIX pdnsd远程缓冲区溢出攻击" name_eng="AIX pdnsd Remote Buffer Overflow" visible="true"/><rule ruleid="20262" enabled="true" group="136315055" action=" db  screen " name="利用NETCODE book.cgi脚本漏洞远程执行命令" name_chs="利用NETCODE book.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via NETCODE book.cgi Script Vulnerability" visible="true"/><rule ruleid="20067" enabled="true" group="141558063" action=" db  screen " name="SSH1守护程序crc32补偿攻击检测安全漏洞攻击" name_chs="SSH1守护程序crc32补偿攻击检测安全漏洞攻击" name_eng="SSH1 Daemon crc32 Compensation Attack Detection" visible="true"/><rule ruleid="20060" enabled="true" group="83886383" action=" db  screen " name="Solaris ypbind TCP远程缓冲区溢出攻击" name_chs="Solaris ypbind TCP远程缓冲区溢出攻击" name_eng="Solaris ypbind TCP Remote Buffer Overflow" visible="true"/><rule ruleid="20068" enabled="true" group="137365551" action=" db  screen  drop " name="Wu-ftpd畸形文件名扩展请求远程堆溢出攻击" name_chs="Wu-ftpd畸形文件名扩展请求远程堆溢出攻击" name_eng="Wu-ftpd Malformed Filename Extension Request Remote Heap Overflow" visible="true"/><rule ruleid="30248" enabled="true" group="136347710" action=" db  screen " name="通过Web服务访问Oracle 9i默认配置文件XSQLConfig.xml" name_chs="通过Web服务访问Oracle 9i默认配置文件XSQLConfig.xml" name_eng="Access to Oracle 9i Default Config File XSQLConfig.xml via Web Service" visible="true"/><rule ruleid="30249" enabled="true" group="136347710" action=" db  screen " name="通过Web服务访问Oracle 9i默认配置文件soapConfig.xml" name_chs="通过Web服务访问Oracle 9i默认配置文件soapConfig.xml" name_eng="Access to Oracle 9i Default Config File soapConfig.xml via Web Service" visible="true"/><rule ruleid="40779" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows Media Player畸形PNG块文档邮件附件传播" name_chs="Microsoft Windows Media Player畸形PNG块文档邮件附件传播" name_eng="Microsoft Windows Media Player Malformed PNG Chunk Document Attachment Propagation" visible="true"/><rule ruleid="40778" enabled="true" group="75563082" action=" db  screen " name="Microsoft Excel畸形STYLE格式文档邮件附件传播" name_chs="Microsoft Excel畸形STYLE格式文档邮件附件传播" name_eng="Microsoft Excel Malformed STYLE Format Document Attachemtn Propagation" visible="true"/><rule ruleid="40777" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows恶意.lnk文件邮件附件传播" name_chs="Microsoft Windows恶意.lnk文件邮件附件传播" name_eng="Microsoft Windows Malicious .lnk Document Attachment Propagation" visible="true"/><rule ruleid="40776" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Adware Speedbar网络通信" name_chs="Windows系统下Adware Speedbar网络通信" name_eng="Windows Adware Speedbar Network Communication" visible="true"/><rule ruleid="40775" enabled="true" group="71307337" action=" db  screen " name="Microsoft Windows 2000 telnet执行NTLM认证" name_chs="Microsoft Windows 2000 telnet执行NTLM认证" name_eng="Microsoft Windows 2000 telnet NTLM Authentication" visible="true"/><rule ruleid="30535" enabled="true" group="203423930" action=" db  screen " name="Oracle Reports Server获取任意文件部分内容攻击" name_chs="Oracle Reports Server获取任意文件部分内容攻击" name_eng="Oracle Reports Server Partial File Content Disclosure" visible="true"/><rule ruleid="40773" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Adware Conspy下载更新" name_chs="Windows系统下Adware Conspy下载更新" name_eng="Windows Adware Conspy Download Upgrade" visible="true"/><rule ruleid="30245" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－SYNFIN扫描" name_chs="服务器端口扫描－SYNFIN扫描" name_eng="Server Port Scan - SYNFIN Scan" visible="true"/><rule ruleid="30246" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－NULL扫描" name_chs="服务器端口扫描－NULL扫描" name_eng="Server Port Scan - NULL Scan" visible="true"/><rule ruleid="30531" enabled="true" group="69206202" action=" db  screen " name="Caucho Resin Windows远程目录遍历攻击" name_chs="Caucho Resin Windows远程目录遍历攻击" name_eng="Caucho Resin Windows Remote Directory Traversal" visible="true"/><rule ruleid="40557" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NOSecure木马通信" name_chs="Windows系统下NOSecure木马通信" name_eng="Trojan NOSecure Communication on Windows" visible="true"/><rule ruleid="40556" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Nirvana木马通信" name_chs="Windows系统下Nirvana木马通信" name_eng="Trojan Nirvana Communication on Windows" visible="true"/><rule ruleid="40555" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下New Silencer木马通信" name_chs="Windows系统下New Silencer木马通信" name_eng="Trojan New Silencer Communication on Windows" visible="true"/><rule ruleid="40554" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Network Terrorist木马通信" name_chs="Windows系统下Network Terrorist木马通信" name_eng="Trojan Network Terrorist Communication on Windows" visible="true"/><rule ruleid="40553" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NetTrash木马通信" name_chs="Windows系统下NetTrash木马通信" name_eng="Trojan NetTrash Communication on Windows" visible="true"/><rule ruleid="40552" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Taxi木马通信" name_chs="Windows系统下Net Taxi木马通信" name_eng="Trojan Net Taxi Communication on Windows" visible="true"/><rule ruleid="40551" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Controller木马通信" name_chs="Windows系统下Net Controller木马通信" name_eng="Trojan Net Controller Communication on Windows" visible="true"/><rule ruleid="40550" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Raider木马通信" name_chs="Windows系统下Net Raider木马通信" name_eng="Trojan Net Raider Communication on Windows" visible="true"/><rule ruleid="40308" enabled="true" group="154206298" action=" db  screen " name="RLOGIN服务root用户认证" name_chs="RLOGIN服务root用户认证" name_eng="RLOGIN Service root User Authentication" visible="true"/><rule ruleid="40559" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Osiris木马通信" name_chs="Windows系统下Osiris木马通信" name_eng="Trojan Osiris Communication on Windows" visible="true"/><rule ruleid="40558" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Oblivion木马通信" name_chs="Windows系统下Oblivion木马通信" name_eng="Trojan Oblivion Communication on Windows" visible="true"/><rule ruleid="40795" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒刷计数器操作" name_chs="Windows系统下熊猫烧香蠕虫病毒刷计数器操作" name_eng="Nimaya Refreshing the Counter on Windows" visible="true"/><rule ruleid="40794" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒解析恶意网站域名" name_chs="Windows系统下熊猫烧香蠕虫病毒解析恶意网站域名" name_eng="Nimaya Parsing Malicious Website Domain Name on Windows System" visible="true"/><rule ruleid="40797" enabled="true" group="270534729" action=" db  screen " name="Netgear FVS318绕过URL访问过滤攻击" name_chs="Netgear FVS318绕过URL访问过滤攻击" name_eng="Netgear FVS318 URL Sanitization Bypass" visible="true"/><rule ruleid="40796" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒下载恶意代码" name_chs="Windows系统下熊猫烧香蠕虫病毒下载恶意代码" name_eng="Nimaya Downloading Malicious Code on Windows" visible="true"/><rule ruleid="40791" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows图形渲染引擎恶意WMF格式文档邮件附件传播" name_chs="Microsoft Windows图形渲染引擎恶意WMF格式文档邮件附件传播" name_eng="Microsoft Windows Graphics Rendering Engine WMF Format Attachment Propagation" visible="true"/><rule ruleid="40790" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE FTP URI处理漏洞恶意命令代码邮件引用" name_chs="Microsoft IE FTP URI处理漏洞恶意命令代码邮件引用" name_eng="Microsoft IE FTP URI Processing Vulnerability Mail" visible="true"/><rule ruleid="40793" enabled="true" group="99680330" action=" db  screen " name="Microsoft Windows 2000 RPC服务畸形回应" name_chs="Microsoft Windows 2000 RPC服务畸形回应" name_eng="Microsoft Windows 2000 RPC Service Malformed Response" visible="true"/><rule ruleid="40792" enabled="true" group="99680330" action=" db  screen " name="Microsoft Windows 2000 RPC服务畸形请求" name_chs="Microsoft Windows 2000 RPC服务畸形请求" name_eng="Microsoft Windows 2000 RPC Service Malformed Requests" visible="true"/><rule ruleid="50080" enabled="true" group="99745885" action=" db  screen " name="即时通信软件网易泡泡用户登录" name_chs="即时通信软件网易泡泡用户登录" name_eng="Instant Messaging Software POPO User Login" visible="true"/><rule ruleid="50081" enabled="true" group="99745885" action=" db  screen " name="即时通信软件新浪UC用户登录" name_chs="即时通信软件新浪UC用户登录" name_eng="Instant Messaging Software Sina UC User Login" visible="true"/><rule ruleid="50082" enabled="true" group="209780829" action=" db  screen " name="SMTP服务暴力猜测用户名口令" name_chs="SMTP服务暴力猜测用户名口令" name_eng="SMTP Service User Password Brute Forcce" visible="true"/><rule ruleid="50083" enabled="true" group="99680349" action=" db  screen " name="Windows系统远程管理工具终端服务用户登录" name_chs="Windows系统远程管理工具终端服务用户登录" name_eng="Windows Remote Management Tool Terminal Service User Login" visible="true"/><rule ruleid="40799" enabled="true" group="68223050" action=" db  screen " name="Macromedia Shockwave 10 SWDIR.DLL多个ActiveX控件远程拒绝服务攻击" name_chs="Macromedia Shockwave 10 SWDIR.DLL多个ActiveX控件远程拒绝服务攻击" name_eng="Macromedia Shockwave 10 SWDIR.DLL ActiveX Control Remote Denial of Service" visible="true"/><rule ruleid="40798" enabled="true" group="136380473" action=" db  screen " name="Nokia Electronic Documentation连接重定向功能利用" name_chs="Nokia Electronic Documentation连接重定向功能利用" name_eng="Nokia Electronic Documentation Connection Redirection Exploitation" visible="true"/><rule ruleid="50086" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN发现非法信息" name_chs="即时通信软件MSN发现非法信息" name_eng="Instant Messaging Software MSN Illegal Information" visible="true"/><rule ruleid="50087" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN发现传送可疑文件" name_chs="即时通信软件MSN发现传送可疑文件" name_eng="Instant Messaging Software MSN Sending Suspicious Files" visible="true"/><rule ruleid="20894" enabled="true" group="68157738" action=" db  screen " name="Microsoft SQL Server sqldmo.dll ActiveX控件缓冲区溢出攻击" name_chs="Microsoft SQL Server sqldmo.dll ActiveX控件缓冲区溢出攻击" name_eng="Microsoft SQL Server sqldmo.dll ActiveX Control Buffer Overflow" visible="true"/><rule ruleid="30180" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp3.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp3.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp3.htr File" visible="true"/><rule ruleid="30335" enabled="true" group="136315066" action=" db  screen " name="HyperSeek hsx.cgi脚本漏洞扫描利用" name_chs="HyperSeek hsx.cgi脚本漏洞扫描利用" name_eng="HyperSeek hsx.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30336" enabled="true" group="136323130" action=" db  screen " name="CGIScript.net cspassword.cgi脚本漏洞扫描探测" name_chs="CGIScript.net cspassword.cgi脚本漏洞扫描探测" name_eng="CGIScript.net cspassword.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30337" enabled="true" group="136323130" action=" db  screen " name="password.cgi.tmp文件扫描探测" name_chs="password.cgi.tmp文件扫描探测" name_eng="password.cgi.tmp File Detection" visible="true"/><rule ruleid="30330" enabled="true" group="203423925" action=" db  screen " name="IBM Net.Data document.d2w脚本漏洞扫描利用" name_chs="IBM Net.Data document.d2w脚本漏洞扫描利用" name_eng="IBM Net.Data document.d2w Script Vulnerability Detection" visible="true"/><rule ruleid="30331" enabled="true" group="69206198" action=" db  screen " name="Alibaba tst.bat脚本漏洞扫描利用" name_chs="Alibaba tst.bat脚本漏洞扫描利用" name_eng="Alibaba tst.bat Script Vulnerability Detection" visible="true"/><rule ruleid="30332" enabled="true" group="136315062" action=" db  screen " name="cal_make.pl脚本漏洞扫描利用" name_chs="cal_make.pl脚本漏洞扫描利用" name_eng="cal_make.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30333" enabled="true" group="136315062" action=" db  screen " name="利用pagelog.cgi脚本遍历目录" name_chs="利用pagelog.cgi脚本遍历目录" name_eng="Directory Traversal via pagelog.cgi Script" visible="true"/><rule ruleid="30338" enabled="true" group="136323126" action=" db  screen " name="pagelog.cgi脚本漏洞扫描探测" name_chs="pagelog.cgi脚本漏洞扫描探测" name_eng="pagelog.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30339" enabled="true" group="136315062" action=" db  screen " name="classifieds.cgi脚本漏洞扫描利用" name_chs="classifieds.cgi脚本漏洞扫描利用" name_eng="classifieds.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40301" enabled="true" group="361824349" action=" db  screen " name="SNMP服务试图使用默认public口令访问" name_chs="SNMP服务试图使用默认public口令访问" name_eng="SNMP Service Access Attempt with Default public Password" visible="true" merge="[t86400,si]"/><rule ruleid="30222" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 5.0 +.htr文件泄漏漏洞获取源代码攻击" name_chs="Microsoft IIS 5.0 +.htr文件泄漏漏洞获取源代码攻击" name_eng="Source Code Disclosure from Microsoft IIS 5.0 +.htr File" visible="true"/><rule ruleid="30223" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage orders.htm文件获取服务器信息" name_chs="访问Frontpage orders.htm文件获取服务器信息" name_eng="Server Information Disclosure from Frontpage orders.htm File" visible="true"/><rule ruleid="40420" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问匿名管道" name_chs="Windows SMB访问匿名管道" name_eng="Windows SMB Accessing Anonymous Pipe" visible="true" merge="[t7200,si,di]"/><rule ruleid="40427" enabled="true" group="99618890" action=" db  screen  drop " name="Windows系统下Dagger 1.4.0木马服务端返回系统信息" name_chs="Windows系统下Dagger 1.4.0木马服务端返回系统信息" name_eng="Trojan Dagger 1.4.0 Server Returning System Information on Windows" visible="true"/><rule ruleid="40426" enabled="true" group="99618890" action=" db  screen " name="Windows系统下Dagger 1.4.0木马客户端发送控制信号" name_chs="Windows系统下Dagger 1.4.0木马客户端发送控制信号" name_eng="Trojan Dagger 1.4.0 Client Sending Control Signals on Windows" visible="true"/><rule ruleid="40425" enabled="true" group="154141259" action=" db  screen " name="RLOGIN服务用户认证 失败" name_chs="RLOGIN服务用户认证 失败" name_eng="RLOGIN Service User Authentication Failed" visible="true"/><rule ruleid="40429" enabled="true" group="136315078" action=" db  screen " name="利用MyPHPLinks index.php脚本漏洞绕过验证访问" name_chs="利用MyPHPLinks index.php脚本漏洞绕过验证访问" name_eng="Authentication Bypass via MyPHPLinks index.php Script Vulnerability" visible="true"/><rule ruleid="40428" enabled="true" group="73401423" action=" db  screen " name="Windows系统下iraq_oil蠕虫活动" name_chs="Windows系统下iraq_oil蠕虫活动" name_eng="Worm iraq_oil on Windows" visible="true"/><rule ruleid="20278" enabled="true" group="139460907" action=" db  screen " name="Qualcomm qpopper AUTH命令远程缓冲区溢出攻击" name_chs="Qualcomm qpopper AUTH命令远程缓冲区溢出攻击" name_eng="Qualcomm qpopper AUTH Command Remote Buffer Overflow" visible="true"/><rule ruleid="50066" enabled="true" group="154206298" action=" db  screen " name="RLOGIN服务信任用户认证" name_chs="RLOGIN服务信任用户认证" name_eng="RLOGIN Service Trusting User Authentication" visible="true"/><rule ruleid="50067" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享C$" name_chs="Windows SMB访问默认共享C$" name_eng="Windows SMB Accessing the Default Share C$" visible="true" merge="[t7200,si,di]"/><rule ruleid="50064" enabled="true" group="233898074" action=" db  screen " name="Oracle数据库远程执行命令操作" name_chs="Oracle数据库远程执行命令操作" name_eng="Oracle Database Remote Command Execution" visible="true"/><rule ruleid="50065" enabled="false" group="95486045" action=" db  screen " name="Windows NBTSTAT信息探测" name_chs="Windows NBTSTAT信息探测" name_eng="Windows NBTSTAT Information Detection" visible="true" merge="[t86400,si]"/><rule ruleid="50062" enabled="true" group="95682639" action=" db  screen " name="Windows系统Worm.SoBig蠕虫病毒利用共享传播" name_chs="Windows系统Worm.SoBig蠕虫病毒利用共享传播" name_eng="Windows Worm.SoBig Propagation Through Sharing" visible="true"/><rule ruleid="50063" enabled="true" group="95486030" action=" db  screen " name="Windows系统下可疑蠕虫病毒通过共享传播" name_chs="Windows系统下可疑蠕虫病毒通过共享传播" name_eng="Windows Suspicious Worms Propagation Through Sharing" visible="true" merge="[t7200,si]"/><rule ruleid="50060" enabled="true" group="72613967" action=" db  screen " name="POP3服务接收Worm.MiMail蠕虫病毒邮件" name_chs="POP3服务接收Worm.MiMail蠕虫病毒邮件" name_eng="POP3 Service Sending Mails with Worm.MiMail" visible="true"/><rule ruleid="50061" enabled="true" group="72613967" action=" db  screen " name="POP3服务接收Worm.SoBig蠕虫病毒邮件" name_chs="POP3服务接收Worm.SoBig蠕虫病毒邮件" name_eng="POP3 Service Receiving Mails with Worm.SoBig" visible="true"/><rule ruleid="40095" enabled="true" group="138444893" action=" db  screen " name="TELNET服务客户端解析服务器配置" name_chs="TELNET服务客户端解析服务器配置" name_eng="TELNET Service Client Parsing Server Configuration" visible="true"/><rule ruleid="50068" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享D$" name_chs="Windows SMB访问默认共享D$" name_eng="Windows SMB Accessing the Default Share D$" visible="true" merge="[t7200,si,di]"/><rule ruleid="50069" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享ADMIN$" name_chs="Windows SMB访问默认共享ADMIN$" name_eng="Windows SMB Accessing the Default Share ADMIN$" visible="true" merge="[t7200,si,di]"/><rule ruleid="20379" enabled="true" group="69206319" action=" db  screen " name="Windows Media服务nsiislog.dll远程缓冲区溢出攻击" name_chs="Windows Media服务nsiislog.dll远程缓冲区溢出攻击" name_eng="Windows Media Service nsiislog.dll Remote Buffer Overflow" visible="true"/><rule ruleid="40769" enabled="true" group="368054347" action=" db  screen " name="SyGate未公开远程管理端口通信" name_chs="SyGate未公开远程管理端口通信" name_eng="SyGate Inpublic Remote Management Port Communication" visible="true"/><rule ruleid="20722" enabled="true" group="203423915" action=" db  screen " name="phpMyDirectory ROOT_PATH参数远程文件包含攻击" name_chs="phpMyDirectory ROOT_PATH参数远程文件包含攻击" name_eng="phpMyDirectory ROOT_PATH Parameter Remote File Inclusion" visible="true"/><rule ruleid="20723" enabled="true" group="203423915" action=" db  screen " name="ScozNet ScozNews CONFIG[main_path]参数远程文件包含攻击" name_chs="ScozNet ScozNews CONFIG[main_path]参数远程文件包含攻击" name_eng="ScozNet ScozNews CONFIG[main_path] Parameter Remote File Inclusion" visible="true"/><rule ruleid="20720" enabled="true" group="203423915" action=" db  screen " name="TR Newsportal poll.php远程文件包含攻击" name_chs="TR Newsportal poll.php远程文件包含攻击" name_eng="TR Newsportal poll.php Remote File Inclusion" visible="true"/><rule ruleid="20721" enabled="true" group="203423915" action=" db  screen " name="phpBazar classified_right.php远程文件包含攻击" name_chs="phpBazar classified_right.php远程文件包含攻击" name_eng="phpBazar classified_right.php Remote File Inclusion" visible="true"/><rule ruleid="20726" enabled="true" group="203423915" action=" db  screen " name="paFileDB pafiledb_constants.php远程文件包含攻击" name_chs="paFileDB pafiledb_constants.php远程文件包含攻击" name_eng="paFileDB pafiledb_constants.php Remote File Inclusion" visible="true"/><rule ruleid="20895" enabled="true" group="68157738" action=" db  screen " name="Ask Toolbar ToolbarSettings ActiveX控件远程栈溢出攻击" name_chs="Ask Toolbar ToolbarSettings ActiveX控件远程栈溢出攻击" name_eng="Ask Toolbar ToolbarSettings ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="20896" enabled="true" group="68157738" action=" db  screen " name="迅雷ActiveX控件DownURL2方式远程缓冲区溢出攻击" name_chs="迅雷ActiveX控件DownURL2方式远程缓冲区溢出攻击" name_eng="Xunlei ActiveX Control DownURL2 Method Remote Buffer Overflow" visible="true"/><rule ruleid="20725" enabled="true" group="203423915" action=" db  screen " name="Squirrelcart cart_content.php远程文件包含攻击" name_chs="Squirrelcart cart_content.php远程文件包含攻击" name_eng="Squirrelcart cart_content.php Remote File Inclusion" visible="true"/><rule ruleid="20898" enabled="true" group="68157738" action=" db  screen " name="雅虎通YVerInfo.dll ActiveX控件远程栈缓冲区溢出攻击" name_chs="雅虎通YVerInfo.dll ActiveX控件远程栈缓冲区溢出攻击" name_eng="Yahoo! Messenger YVerInfo.dll ActiveX Control Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20899" enabled="true" group="68159530" action=" db  screen " name="Macrovision InstallShield Update Service ActiveX非授权下载执行任意程序攻击" name_chs="Macrovision InstallShield Update Service ActiveX非授权下载执行任意程序攻击" name_eng="Macrovision InstallShield Update Service ActiveX Unauthorized Arbitrary Program Execution" visible="true"/><rule ruleid="20728" enabled="true" group="83886383" action=" db  screen " name="Windows RPC DCOM接口UDP长路径名远程堆缓冲区溢出攻击" name_chs="Windows RPC DCOM接口UDP长路径名远程堆缓冲区溢出攻击" name_eng="Windows RPC DCOM Interface UDP Long Path Name Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20729" enabled="true" group="71303467" action=" db  screen " name="InterAccess TelnetD Server远程缓冲区溢出攻击" name_chs="InterAccess TelnetD Server远程缓冲区溢出攻击" name_eng="InterAccess TelnetD Server Remote Buffer Overflow" visible="true"/><rule ruleid="30502" enabled="true" group="203423929" action=" db  screen " name="利用HP Web Jetadmin CGI脚本漏洞及配置文件获取信息" name_chs="利用HP Web Jetadmin CGI脚本漏洞及配置文件获取信息" name_eng="Information Disclosure via HP Web Jetadmin CGI Script Vulnerability and Configuration Files" visible="true"/><rule ruleid="30501" enabled="true" group="136323130" action=" db  screen " name="psinclude.cgi脚本漏洞扫描探测" name_chs="psinclude.cgi脚本漏洞扫描探测" name_eng="psinclude.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="70002" enabled="true" group="233832751" action=" db  screen " name="协议数据溢出SHELLCODE攻击" name_chs="协议数据溢出SHELLCODE攻击" name_eng="Protocol Data Buffer Overflow SHELLCODE Attacks" visible="true"/><rule ruleid="70003" enabled="true" group="233898073" action=" db  screen " name="非默认端口上发现已知协议" name_chs="非默认端口上发现已知协议" name_eng="Known Protocol on Non-default Port" visible="true" merge="[t86400,di]"/><rule ruleid="70001" enabled="true" group="233832783" action=" db  screen " name="协议命令参数超长" name_chs="协议命令参数超长" name_eng="Over-long Protocol Command Argument" visible="true" merge="[t3600]"/><rule ruleid="70004" enabled="false" group="233898073" action=" db  screen " name="发现异常的HTTP协议" name_chs="发现异常的HTTP协议" name_eng="Abnormal HTTP Protocol" visible="false"/><rule ruleid="30507" enabled="true" group="203431998" action=" db  screen " name="漏洞扫描器Nessus扫描探测CGI漏洞" name_chs="漏洞扫描器Nessus扫描探测CGI漏洞" name_eng="Nessus Scanner CGI Vulnerability Detection" visible="true"/><rule ruleid="30506" enabled="true" group="162531390" action=" db  screen  drop " name="Samba远程畸形路径名导致目录遍历攻击" name_chs="Samba远程畸形路径名导致目录遍历攻击" name_eng="Samba Remote Malformed Path Name Directory Traversal" visible="true"/><rule ruleid="40766" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht客户端确认通信" name_chs="DDOS工具Stacheldraht客户端确认通信" name_eng="DDOS Stacheldraht Client Communication Confirmation" visible="true"/><rule ruleid="40767" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht主控端向分布端发送指令" name_chs="DDOS工具Stacheldraht主控端向分布端发送指令" name_eng="DDOS Tool Stacheldraht Console Sending Command to Distributed End" visible="true"/><rule ruleid="10169" enabled="true" group="294651930" action=" db  screen " name="SNMPv3畸形报文处理拒绝服务攻击" name_chs="SNMPv3畸形报文处理拒绝服务攻击" name_eng="SNMPv3 Malformed Message Handling Denial of Service" visible="true"/><rule ruleid="10168" enabled="true" group="300943386" action=" db  screen " name="Cisco IP Phone畸形SIP协议请求拒绝服务攻击" name_chs="Cisco IP Phone畸形SIP协议请求拒绝服务攻击" name_eng="Cisco IP Phone Malformed SIP Protocol Request Denial of Service" visible="true"/><rule ruleid="10167" enabled="true" group="160434202" action=" db  screen " name="GNU Radius SNMP字符串长度整数溢出拒绝服务攻击" name_chs="GNU Radius SNMP字符串长度整数溢出拒绝服务攻击" name_eng="GNU Radius SNMP String Length Integer Overflow Denial of Service" visible="true"/><rule ruleid="10166" enabled="true" group="69208090" action=" db  screen " name="Apache Tomcat MS-DOS设备名远程拒绝服务攻击" name_chs="Apache Tomcat MS-DOS设备名远程拒绝服务攻击" name_eng="Apache Tomcat MS-DOS Device Name Remote Denial of Service" visible="true"/><rule ruleid="10165" enabled="true" group="294651930" action=" db  screen " name="Cisco IOS畸形SNMP消息处理远程拒绝服务攻击" name_chs="Cisco IOS畸形SNMP消息处理远程拒绝服务攻击" name_eng="Cisco IOS Malformed SNMP Message Handling Remote Denial of Service" visible="true"/><rule ruleid="10164" enabled="true" group="202377242" action=" db  screen " name="HTTP请求负值Content-Length字段远程拒绝服务攻击" name_chs="HTTP请求负值Content-Length字段远程拒绝服务攻击" name_eng="HTTP Request Negative Content-Length Field Remote Denial of Service" visible="true"/><rule ruleid="20094" enabled="true" group="136315051" action=" db  screen  drop " name="利用WebGlimpse aglimpse脚本漏洞" name_chs="利用WebGlimpse aglimpse脚本漏洞" name_eng="WebGlimpse aglimpse Script Vulnerability" visible="true"/><rule ruleid="10162" enabled="true" group="68159514" action=" db  screen " name="Mbedthis Software AppWeb HTTP Server设备名访问拒绝服务攻击" name_chs="Mbedthis Software AppWeb HTTP Server设备名访问拒绝服务攻击" name_eng="Mbedthis Software AppWeb HTTP Server Device Name Denial of Service" visible="true"/><rule ruleid="10161" enabled="true" group="68159510" action=" db  screen " name="Jeuce Personal Web Server远程拒绝服务攻击" name_chs="Jeuce Personal Web Server远程拒绝服务攻击" name_eng="Jeuce Personal Web Server Remote Denial of Service" visible="true"/><rule ruleid="10160" enabled="true" group="69206170" action=" db  screen " name="Apple QuickTime/Darwin流服务器MS-DOS设备文件名拒绝服务攻击" name_chs="Apple QuickTime/Darwin流服务器MS-DOS设备文件名拒绝服务攻击" name_eng="Apple QuickTime/Darwin Streaming Server MS-DOS Device Filename Denial of Service" visible="true"/><rule ruleid="40309" enabled="true" group="83894326" action=" db  screen " name="Solaris rpc.rwalld服务存在性UDP扫描探测" name_chs="Solaris rpc.rwalld服务存在性UDP扫描探测" name_eng="Solaris rpc.rwalld Service UDP Detection" visible="true"/><rule ruleid="20658" enabled="true" group="136315051" action=" db  screen " name="YACS远程文件包含攻击" name_chs="YACS远程文件包含攻击" name_eng="YACS Remote File Inclusion" visible="true"/><rule ruleid="20659" enabled="true" group="69206186" action=" db  screen " name="Business Objects Crystal Reports Web表单查看器目录遍历攻击" name_chs="Business Objects Crystal Reports Web表单查看器目录遍历攻击" name_eng="Business Objects Crystal Reports Web Form Viewer Directory Traversal" visible="true"/><rule ruleid="20656" enabled="true" group="203423915" action=" db  screen " name="phpECard远程文件包含攻击" name_chs="phpECard远程文件包含攻击" name_eng="phpECard Remote File Inclusion" visible="true"/><rule ruleid="20657" enabled="true" group="136315051" action=" db  screen " name="FlashChat远程文件包含攻击" name_chs="FlashChat远程文件包含攻击" name_eng="FlashChat Remote File Inclusion" visible="true"/><rule ruleid="20654" enabled="true" group="99615019" action=" db  screen " name="eIQnetworks ESA  LICMGR_ADDLICENSE命令远程缓冲区溢出攻击" name_chs="eIQnetworks ESA  LICMGR_ADDLICENSE命令远程缓冲区溢出攻击" name_eng="eIQnetworks ESA  LICMGR_ADDLICENSE Command Remote Buffer Overflow" visible="true"/><rule ruleid="20655" enabled="true" group="89129259" action=" db  screen " name="NIPrint LPD打印服务程序远程缓冲区溢出攻击" name_chs="NIPrint LPD打印服务程序远程缓冲区溢出攻击" name_eng="NIPrint LPD Spooler Remote Buffer Overflow" visible="true"/><rule ruleid="20653" enabled="true" group="203423915" action=" db  screen " name="phpCoin远程文件包含攻击" name_chs="phpCoin远程文件包含攻击" name_eng="phpCoin Remote File Inclusion" visible="true"/><rule ruleid="20650" enabled="true" group="68157739" action=" db  screen " name="Apache mod_rewrite模块单字节缓冲区溢出攻击" name_chs="Apache mod_rewrite模块单字节缓冲区溢出攻击" name_eng="Apache mod_rewrite Module Off-by-one Buffer Overflow" visible="true"/><rule ruleid="20651" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows Server服务远程缓冲区溢出攻击" name_chs="Microsoft Windows Server服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Server Service Remote Buffer Overflow" visible="true"/><rule ruleid="20384" enabled="true" group="95420975" action=" db  screen " name="Windows SMB暴力猜测用户口令" name_chs="Windows SMB暴力猜测用户口令" name_eng="Windows SMB User Password Brute Force" visible="true"/><rule ruleid="20385" enabled="true" group="99876907" action=" db  screen " name="Windows系统下W32.HLLW.Lovgate蠕虫病毒后门访问" name_chs="Windows系统下W32.HLLW.Lovgate蠕虫病毒后门访问" name_eng="Windows W32.HLLW.Lovgate Backdoor" visible="true"/><rule ruleid="20387" enabled="true" group="136315051" action=" db  screen " name="利用VisualShapers EZContents module.php脚本漏洞远程执行命令" name_chs="利用VisualShapers EZContents module.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via VisualShapers EZContents module.php Script Vulnerability" visible="true"/><rule ruleid="20380" enabled="true" group="233832751" action=" db  screen  drop " name="Real Networks Helix Universal Server RTSP URI处理远程缓冲区溢出攻击" name_chs="Real Networks Helix Universal Server RTSP URI处理远程缓冲区溢出攻击" name_eng="Real Networks Helix Universal Server RTSP URI Processing Remote Buffer Overflow" visible="true"/><rule ruleid="20381" enabled="true" group="202375726" action=" db  screen " name="HTTP服务暴力猜测口令攻击" name_chs="HTTP服务暴力猜测口令攻击" name_eng="HTTP Service Brute-force" visible="true" merge="[t7200,di]"/><rule ruleid="20382" enabled="true" group="99615023" action=" db  screen " name="Microsoft Windows工作站服务远程缓冲区溢出攻击" name_chs="Microsoft Windows工作站服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Workstation Service Remote Buffer Overflow" visible="true"/><rule ruleid="20383" enabled="true" group="69206315" action=" db  screen " name="Microsoft FrontPage POST请求远程缓冲区溢出攻击" name_chs="Microsoft FrontPage POST请求远程缓冲区溢出攻击" name_eng="Microsoft FrontPage POST Request Remote Buffer Overflow" visible="true"/><rule ruleid="20388" enabled="true" group="136315055" action=" db  screen " name="利用PHPDig config.php脚本漏洞远程执行命令" name_chs="利用PHPDig config.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via PHPDig config.php Script Vulnerability" visible="true"/><rule ruleid="20389" enabled="true" group="70254895" action=" db  screen  drop " name="Serv-U FTP服务器SITE CHMOD命令超长文件名远程溢出攻击" name_chs="Serv-U FTP服务器SITE CHMOD命令超长文件名远程溢出攻击" name_eng="Serv-U FTP Server SITE CHMOD Command Over-long Filename Remote Buffer Overflow" visible="true"/><rule ruleid="20478" enabled="true" group="203423919" action=" db  screen " name="PHPKIT CGI脚本SQL注入攻击" name_chs="PHPKIT CGI脚本SQL注入攻击" name_eng="PHPKIT CGI Script SQL Injection" visible="true"/><rule ruleid="20479" enabled="true" group="99615019" action=" db  screen  drop " name="CA BrightStor ARCserve/Enterprise发现服务SERVICEPC远程溢出攻击" name_chs="CA BrightStor ARCserve/Enterprise发现服务SERVICEPC远程溢出攻击" name_eng="CA BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow" visible="true"/><rule ruleid="20472" enabled="true" group="99616811" action=" db  screen " name="Microsoft WINS内存覆盖任意指令执行攻击" name_chs="Microsoft WINS内存覆盖任意指令执行攻击" name_eng="Microsoft WINS Memory Overwriting Arbitrary Code Execution" visible="true"/><rule ruleid="20473" enabled="true" group="99615019" action=" db  screen " name="Microsoft WINS服务畸形包远程缓冲区溢出攻击" name_chs="Microsoft WINS服务畸形包远程缓冲区溢出攻击" name_eng="Microsoft WINS Service Malformed Packet Remote Buffer Overflow" visible="true"/><rule ruleid="20470" enabled="true" group="203424047" action=" db  screen " name="Microsoft Windows GDI+ JPG解析组件缓冲区溢出攻击" name_chs="Microsoft Windows GDI+ JPG解析组件缓冲区溢出攻击" name_eng="Microsoft Windows GDI+ JPG Resolution Buffer Overflow" visible="true"/><rule ruleid="20471" enabled="true" group="204472623" action=" db  screen " name="WS_FTP Server命令参数处理缓冲区溢出攻击" name_chs="WS_FTP Server命令参数处理缓冲区溢出攻击" name_eng="WS_FTP Server Command Parameter Handling Buffer Overflow" visible="true"/><rule ruleid="20476" enabled="true" group="69206187" action=" db  screen " name="Windows NT IIS MSDAC RDS远程执行命令攻击" name_chs="Windows NT IIS MSDAC RDS远程执行命令攻击" name_eng="Windows NT IIS MSDAC RDS Remote Code Execution" visible="true"/><rule ruleid="20477" enabled="true" group="203423919" action=" db  screen " name="利用AwStats CGI脚本远程执行命令攻击" name_chs="利用AwStats CGI脚本远程执行命令攻击" name_eng="Remomte Code Execution via AwStats CGI Script" visible="true"/><rule ruleid="20474" enabled="true" group="203423915" action=" db  screen " name="Ikonboard ikonboard.cgi远程SQL注入攻击" name_chs="Ikonboard ikonboard.cgi远程SQL注入攻击" name_eng="Ikonboard ikonboard.cgi Remote SQL Injection" visible="true"/><rule ruleid="20475" enabled="true" group="203423915" action=" db  screen " name="利用Zeroboard多个CGI脚本远程执行命令攻击" name_chs="利用Zeroboard多个CGI脚本远程执行命令攻击" name_eng="Zeroboard multiple CGI Scripts Remomte Code Execution" visible="true"/><rule ruleid="30293" enabled="true" group="136323129" action=" db  screen " name="Phorum系列脚本漏洞扫描探测" name_chs="Phorum系列脚本漏洞扫描探测" name_eng="PhorumSeries Script Vulnerability Detection" visible="true"/><rule ruleid="30439" enabled="true" group="136323130" action=" db  screen " name="upload.cgi脚本漏洞扫描探测" name_chs="upload.cgi脚本漏洞扫描探测" name_eng="upload.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30438" enabled="true" group="203431994" action=" db  screen " name="Webchat defines.php脚本漏洞扫描探测" name_chs="Webchat defines.php脚本漏洞扫描探测" name_eng="Webchat defines.php Script Vulnerability Detection" visible="true"/><rule ruleid="30437" enabled="true" group="136323126" action=" db  screen " name="phping脚本漏洞扫描探测" name_chs="phping脚本漏洞扫描探测" name_eng="phping Script Vulnerability Detection" visible="true"/><rule ruleid="30435" enabled="true" group="203431994" action=" db  screen " name="通过Web服务访问password.txt文件获取数据信息" name_chs="通过Web服务访问password.txt文件获取数据信息" name_eng="Data Disclosure from password.txt via Web Service" visible="true"/><rule ruleid="30433" enabled="true" group="203431998" action=" db  screen " name="Invision Board ipchat.php脚本漏洞扫描探测" name_chs="Invision Board ipchat.php脚本漏洞扫描探测" name_eng="Invision Board ipchat.php Script Vulnerability Detection" visible="true"/><rule ruleid="30432" enabled="true" group="203431994" action=" db  screen " name="IRIX parse_xml.cgi脚本漏洞扫描探测" name_chs="IRIX parse_xml.cgi脚本漏洞扫描探测" name_eng="IRIX parse_xml.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30431" enabled="true" group="203431994" action=" db  screen " name="DotBr system.php3脚本漏洞扫描探测" name_chs="DotBr system.php3脚本漏洞扫描探测" name_eng="DotBr system.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="30430" enabled="true" group="203431994" action=" db  screen " name="DotBr exec.php3脚本漏洞扫描探测" name_chs="DotBr exec.php3脚本漏洞扫描探测" name_eng="DotBr exec.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="40785" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE JavaScript OnLoad处理器畸形代码邮件引用" name_chs="Microsoft IE JavaScript OnLoad处理器畸形代码邮件引用" name_eng="Microsoft IE JavaScript OnLoad Processor Vulnerability Mail" visible="true"/><rule ruleid="30297" enabled="true" group="136323130" action=" db  screen " name="vpopmail-CGIApps vadddomain脚本漏洞扫描探测" name_chs="vpopmail-CGIApps vadddomain脚本漏洞扫描探测" name_eng="vpopmail-CGIApps vadddomain Script Vulnerability Detection" visible="true"/><rule ruleid="30296" enabled="true" group="78645306" action=" db  screen " name="SolarWinds TFTP服务程序目录遍历攻击" name_chs="SolarWinds TFTP服务程序目录遍历攻击" name_eng="SolarWinds TFTP Server Directory Traversal" visible="true"/><rule ruleid="30187" enabled="true" group="136323126" action=" db  screen " name="Amaya sendtemp.pl脚本漏洞扫描探测" name_chs="Amaya sendtemp.pl脚本漏洞扫描探测" name_eng="Amaya sendtemp.pl Script Vulnerability Detection" visible="true"/><rule ruleid="10141" enabled="true" group="233834522" action=" db  screen " name="IBM DB2 Discovery服务UDP远程拒绝服务攻击" name_chs="IBM DB2 Discovery服务UDP远程拒绝服务攻击" name_eng="IBM DB2 Discovery Service UDP Remote Denial of Service" visible="true"/><rule ruleid="30185" enabled="true" group="203431994" action=" db  screen " name="EZShopper loadpage.cgi脚本漏洞扫描探测" name_chs="EZShopper loadpage.cgi脚本漏洞扫描探测" name_eng="EZShopper loadpage.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30184" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/anot3.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/anot3.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/anot3.htr File" visible="true"/><rule ruleid="30183" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/anot.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/anot.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/anot.htr File" visible="true"/><rule ruleid="30182" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr File" visible="true"/><rule ruleid="30181" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp4.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp4.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp4.htr File" visible="true"/><rule ruleid="10140" enabled="true" group="203425818" action=" db  screen " name="Oracle9iAS Web Cache远程拒绝服务攻击" name_chs="Oracle9iAS Web Cache远程拒绝服务攻击" name_eng="Oracle9iAS Web Cache Remote Denial of Service" visible="true"/><rule ruleid="30294" enabled="true" group="203423926" action=" db  screen " name="myPHPNuke phptonuke.php脚本漏洞扫描探测" name_chs="myPHPNuke phptonuke.php脚本漏洞扫描探测" name_eng="myPHPNuke phptonuke.php Script Vulnerability Detection" visible="true"/><rule ruleid="40306" enabled="true" group="337641643" action=" db  screen " name="Cisco IOS Web配置接口绕过安全认证攻击" name_chs="Cisco IOS Web配置接口绕过安全认证攻击" name_eng="Cisco IOS Web Config Interface Authentication Bypass" visible="true"/><rule ruleid="40307" enabled="true" group="153157722" action=" db  screen " name="RSH服务root用户操作" name_chs="RSH服务root用户操作" name_eng="RSH Service root User Operation" visible="true"/><rule ruleid="30189" enabled="true" group="136323130" action=" db  screen " name="CdomainFree whois_raw.cgi脚本漏洞扫描探测" name_chs="CdomainFree whois_raw.cgi脚本漏洞扫描探测" name_eng="CdomainFree whois_raw.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30188" enabled="true" group="136315062" action=" db  screen " name="利用WebSPIRS webspirs.cgi脚本漏洞远程遍历目录" name_chs="利用WebSPIRS webspirs.cgi脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via WebSPIRS webspirs.cgi Script Vulnerability" visible="true"/><rule ruleid="20271" enabled="true" group="70254891" action=" db  screen " name="WS_FTP Server CPWD远程缓冲区溢出攻击" name_chs="WS_FTP Server CPWD远程缓冲区溢出攻击" name_eng="WS_FTP Server CPWD Remote Buffer Overflow" visible="true"/><rule ruleid="20273" enabled="true" group="137365562" action=" db  screen " name="Solaris FTP畸形CWD命令引发CoreDump攻击" name_chs="Solaris FTP畸形CWD命令引发CoreDump攻击" name_eng="Solaris FTP Malformed CWD Command CoreDump Attack" visible="true"/><rule ruleid="20274" enabled="true" group="88080683" action=" db  screen " name="Microsoft SQL Server/MSDE扩展存储过程xp_displayparamstmt远程缓冲区溢出攻击" name_chs="Microsoft SQL Server/MSDE扩展存储过程xp_displayparamstmt远程缓冲区溢出攻击" name_eng="Microsoft SQL Server/MSDE Exteneded Stored Procedure xp_displayparamstmt Remote Buffer Overflow" visible="true"/><rule ruleid="20275" enabled="true" group="88080683" action=" db  screen " name="Microsoft SQL Server/MSDE扩展存储过程xp_setsqlsecurity远程缓冲区溢出攻击" name_chs="Microsoft SQL Server/MSDE扩展存储过程xp_setsqlsecurity远程缓冲区溢出攻击" name_eng="Microsoft SQL Server/MSDE Extended Stored Procedure xp_setsqlsecurity Remote Buffer Overflow" visible="true"/><rule ruleid="20276" enabled="true" group="88080687" action=" db  screen " name="Microsoft SQL Server RAISERROR语句缓冲区溢出攻击" name_chs="Microsoft SQL Server RAISERROR语句缓冲区溢出攻击" name_eng="Microsoft SQL Server RAISERROR Statement Buffer Overflow" visible="true"/><rule ruleid="40092" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Prosiak木马建立连接" name_chs="Windows系统下Prosiak木马建立连接" name_eng="Trojan Prosiak Connection on Windows" visible="true"/><rule ruleid="10145" enabled="true" group="272631834" action=" db  screen " name="Cisco IOS TELNET环境变量处理拒绝服务攻击" name_chs="Cisco IOS TELNET环境变量处理拒绝服务攻击" name_eng="Cisco IOS TELNET Environment Variable Handling Denial of Service" visible="true"/><rule ruleid="10144" enabled="true" group="275777562" action=" db  screen " name="Cisco VPN 3000系列畸形SSH初始化包拒绝服务攻击" name_chs="Cisco VPN 3000系列畸形SSH初始化包拒绝服务攻击" name_eng="Cisco VPN 3000 Series Malformed SSH Initialization Packet Denial of Service" visible="true"/><rule ruleid="20076" enabled="true" group="136315066" action=" db  screen  drop " name="利用NCSA nph-test-cgi脚本漏洞远程浏览目录" name_chs="利用NCSA nph-test-cgi脚本漏洞远程浏览目录" name_eng="Remote Directory Browsing via NCSA nph-test-cgi Script Vulnerability" visible="true"/><rule ruleid="20075" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.cachefsd远程堆溢出攻击" name_chs="Solaris rpc.cachefsd远程堆溢出攻击" name_eng="Solaris rpc.cachefsd Remote Heap Overflow" visible="true"/><rule ruleid="10180" enabled="true" group="83888154" action=" db  screen " name="Microsoft Windows打印后台程序GetPrinterData过程远程拒绝服务攻击" name_chs="Microsoft Windows打印后台程序GetPrinterData过程远程拒绝服务攻击" name_eng="Microsoft Windows Spooler GetPrinterData Procedure Remote Denial of Service" visible="true"/><rule ruleid="20527" enabled="true" group="83887151" action=" db  screen  drop " name="Windows系统下ZoTob蠕虫利用MS05-039漏洞传播" name_chs="Windows系统下ZoTob蠕虫利用MS05-039漏洞传播" name_eng="Windows ZoTob Propagation via MS05-039 Vulnerability" visible="true"/><rule ruleid="10189" enabled="false" group="99616794" action=" db  screen " name="传奇假人拒绝服务攻击" name_chs="传奇假人拒绝服务攻击" name_eng="Legend Dummy Denial of Service" visible="false"/><rule ruleid="20079" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csChatRBox.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csChatRBox.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csChatRBox.cgi Script Vulnerability" visible="true"/><rule ruleid="40768" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Infector 1.7木马通信" name_chs="Windows系统下Infector 1.7木马通信" name_eng="Trojan Infector 1.7 Communication on Windows" visible="true"/><rule ruleid="10149" enabled="true" group="300943386" action=" db  screen " name="H.323协议Calling Party Number数据畸形" name_chs="H.323协议Calling Party Number数据畸形" name_eng="H.323 Protocol Calling Party Number Malformed Data" visible="true"/><rule ruleid="30509" enabled="true" group="233840702" action=" db  screen " name="端口扫描器ICMP PING扫描操作" name_chs="端口扫描器ICMP PING扫描操作" name_eng="Port Scanner ICMP PING Scanning" visible="true"/><rule ruleid="30508" enabled="true" group="204480574" action=" db  screen " name="漏洞扫描器Nessus扫描探测FTP漏洞" name_chs="漏洞扫描器Nessus扫描探测FTP漏洞" name_eng="Nessus Scanner Detecting FTP Vulnerability" visible="true"/><rule ruleid="10148" enabled="true" group="300943386" action=" db  screen " name="H.323协议Called Party Number数据畸形" name_chs="H.323协议Called Party Number数据畸形" name_eng="H.323 Protocol Called Party Number Malformed Data" visible="true"/><rule ruleid="40760" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Furax木马通信" name_chs="Windows系统下Furax木马通信" name_eng="Trojan Furax Communication on Windows" visible="true"/><rule ruleid="40761" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下黑星木马通信" name_chs="Windows系统下黑星木马通信" name_eng="Trojan BlackStar Trojan Communnication" visible="true"/><rule ruleid="40762" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Institution2004木马通信" name_chs="Windows系统下Institution2004木马通信" name_eng="Trojan Institution2004 Communication on Windows" visible="true"/><rule ruleid="40763" enabled="true" group="99876939" action=" db  screen " name="Windows系统下威金蠕虫病毒解析恶意网站域名" name_chs="Windows系统下威金蠕虫病毒解析恶意网站域名" name_eng="Worm.Viking Parsing Malicious Website Domain Name on Windows System" visible="true"/><rule ruleid="40764" enabled="true" group="99618887" action=" db  screen " name="Windows系统下流萤 2.5木马通信" name_chs="Windows系统下流萤 2.5木马通信" name_eng="FireFly 2.5 Communication on Windows" visible="true"/><rule ruleid="40765" enabled="true" group="99618890" action=" db  screen  drop " name="Windows系统下自由远程管理系统木马侧通信" name_chs="Windows系统下自由远程管理系统木马侧通信" name_eng="Free Remote Management System Communication on Windows" visible="true"/><rule ruleid="30505" enabled="true" group="136315070" action=" db  screen " name="利用Turbo Seek tseekdir.cgi脚本漏洞读取文件" name_chs="利用Turbo Seek tseekdir.cgi脚本漏洞读取文件" name_eng="File Reading via Turbo Seek tseekdir.cgi Script Vulnerability" visible="true"/><rule ruleid="30504" enabled="true" group="163610685" action=" db  screen " name="CVS未文档化命令获取信息攻击" name_chs="CVS未文档化命令获取信息攻击" name_eng="CVS Undocument Command Information Disclosure" visible="true"/><rule ruleid="40540" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Meet The Lamer木马通信" name_chs="Windows系统下Meet The Lamer木马通信" name_eng="Trojan Meet The Lamer Communication on Windows" visible="true"/><rule ruleid="40541" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Michal木马通信" name_chs="Windows系统下Michal木马通信" name_eng="Trojan Michal Communication on Windows" visible="true"/><rule ruleid="40542" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Microspy木马通信" name_chs="Windows系统下Microspy木马通信" name_eng="Trojan Microspy Communication on Windows" visible="true"/><rule ruleid="40543" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Millenium木马通信" name_chs="Windows系统下Millenium木马通信" name_eng="Trojan Millenium Communication on Windows" visible="true"/><rule ruleid="40544" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mini Oblivion木马通信" name_chs="Windows系统下Mini Oblivion木马通信" name_eng="Trojan Mini Oblivion Communication on Windows" visible="true"/><rule ruleid="40545" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mneah Trojan木马通信" name_chs="Windows系统下Mneah Trojan木马通信" name_eng="Trojan Mneah Trojan Communication on Windows" visible="true"/><rule ruleid="40546" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下MoonPie木马通信" name_chs="Windows系统下MoonPie木马通信" name_eng="Trojan MoonPie Communication on Windows" visible="true"/><rule ruleid="40547" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mosucker木马通信" name_chs="Windows系统下Mosucker木马通信" name_eng="Trojan Mosucker Communication on Windows" visible="true"/><rule ruleid="40548" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Administrator木马通信" name_chs="Windows系统下Net Administrator木马通信" name_eng="Trojan Net Administrator Communication on Windows" visible="true"/><rule ruleid="40549" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Metropolitan木马通信" name_chs="Windows系统下Net Metropolitan木马通信" name_eng="Trojan Net Metropolitan Communication on Windows" visible="true"/><rule ruleid="40786" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE文件下载对话框控制恶意代码邮件引用" name_chs="Microsoft IE文件下载对话框控制恶意代码邮件引用" name_eng="Microsoft IE File Download Dialog Box Control Mail" visible="true"/><rule ruleid="40787" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE畸形COM对象实例化代码邮件引用" name_chs="Microsoft IE畸形COM对象实例化代码邮件引用" name_eng="Microsoft IE Malformed COM Object Instantiation Vulnerability Mail" visible="true"/><rule ruleid="40784" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE javaprxy.dll COM对象邮件内容引用" name_chs="Microsoft IE javaprxy.dll COM对象邮件内容引用" name_eng="Microsoft IE javaprxy.dll COM Object Vulnerability Mail" visible="true"/><rule ruleid="30290" enabled="true" group="203423926" action=" db  screen " name="mcNews header.php脚本漏洞扫描探测" name_chs="mcNews header.php脚本漏洞扫描探测" name_eng="mcNews header.php Script Vulnerability Detection" visible="true"/><rule ruleid="40782" enabled="true" group="75563082" action=" db  screen " name="Microsoft Word畸形字体文档邮件附件传播" name_chs="Microsoft Word畸形字体文档邮件附件传播" name_eng="Microsoft Word Malformed Font Document Attachment Propagation" visible="true"/><rule ruleid="40783" enabled="true" group="75563082" action=" db  screen " name="Microsoft Outlook Web Access恶意跨站脚本链接邮件传播" name_chs="Microsoft Outlook Web Access恶意跨站脚本链接邮件传播" name_eng="Microsoft Outlook Web Access Malicious Cross Site Scripting Mail Propagation" visible="true"/><rule ruleid="40780" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows资源管理器预览框脚本注入畸形文档邮件附件传播" name_chs="Microsoft Windows资源管理器预览框脚本注入畸形文档邮件附件传播" name_eng="Microsoft Windows Explorer Preview Pane Script Injection Malformed Document Attachment Propagation" visible="true"/><rule ruleid="40781" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows颜色管理模块畸形ICC配置文档邮件附件传播" name_chs="Microsoft Windows颜色管理模块畸形ICC配置文档邮件附件传播" name_eng="Microsoft Windows Color Management Module Malformed ICC Configuration Document Attachment Propagation" visible="true"/><rule ruleid="30299" enabled="true" group="203423930" action=" db  screen " name="利用avatar.php脚本漏洞遍历目录" name_chs="利用avatar.php脚本漏洞遍历目录" name_eng="Directory Traversal via avatar.php Script Vulnerability" visible="true"/><rule ruleid="30298" enabled="true" group="136323125" action=" db  screen " name="Molly系列脚本漏洞扫描探测" name_chs="Molly系列脚本漏洞扫描探测" name_eng="Molly Series Script Vulnerability Detection" visible="true"/><rule ruleid="40788" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows ASN.1库BER解码漏洞SMTP协议攻击" name_chs="Microsoft Windows ASN.1库BER解码漏洞SMTP协议攻击" name_eng="Microsoft Windows ASN.1 Base BER Decoding Vulnerability SMTP Protocol Attack" visible="true"/><rule ruleid="40789" enabled="true" group="75563082" action=" db  screen " name="Microsoft Visual Studio .NET msdds.dll远程代码执行攻击" name_chs="Microsoft Visual Studio .NET msdds.dll远程代码执行攻击" name_eng="Microsoft Visual Studio .NET msdds.dll Remote Code Execution Attack" visible="true"/><rule ruleid="30221" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件registrations.txt获取服务器信息" name_chs="访问Frontpage配置文件registrations.txt获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File registrations.txt" visible="true"/><rule ruleid="30341" enabled="true" group="337641654" action=" db  screen " name="Novell GroupWise GWWEB.EXE程序漏洞扫描利用" name_chs="Novell GroupWise GWWEB.EXE程序漏洞扫描利用" name_eng="Novell GroupWise GWWEB.EXE Detection" visible="true"/><rule ruleid="30340" enabled="true" group="70256687" action=" db  screen  drop " name="Serv-U FTP远程目录遍历攻击" name_chs="Serv-U FTP远程目录遍历攻击" name_eng="Serv-U FTP Remote Directory Traversal" visible="true"/><rule ruleid="30343" enabled="true" group="136315062" action=" db  screen " name="apexec.pl脚本漏洞扫描利用" name_chs="apexec.pl脚本漏洞扫描利用" name_eng="apexec.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30345" enabled="true" group="203431993" action=" db  screen " name="Allaire ColdFusion application.cfm脚本漏洞扫描探测" name_chs="Allaire ColdFusion application.cfm脚本漏洞扫描探测" name_eng="Allaire ColdFusion application.cfm Script Vulnerability Detection" visible="true"/><rule ruleid="30344" enabled="true" group="203423929" action=" db  screen " name="Allaire ColdFusion 4.0x cfcache.map脚本漏洞扫描探测" name_chs="Allaire ColdFusion 4.0x cfcache.map脚本漏洞扫描探测" name_eng="Allaire ColdFusion 4.0x cfcache.map Script Vulnerability Detection" visible="true"/><rule ruleid="30347" enabled="true" group="203423926" action=" db  screen " name="Apache::ASP source.asp脚本漏洞扫描探测" name_chs="Apache::ASP source.asp脚本漏洞扫描探测" name_eng="Apache::ASP source.asp Script Vulnerability Detection" visible="true"/><rule ruleid="30349" enabled="true" group="337641654" action=" db  screen " name="NetWare Web Server 2.x convert.bas脚本漏洞扫描利用" name_chs="NetWare Web Server 2.x convert.bas脚本漏洞扫描利用" name_eng="NetWare Web Server 2.x convert.bas Script Vulnerability Detection" visible="true"/><rule ruleid="30348" enabled="true" group="233840702" action=" db  screen " name="端口扫描器Superscan PING操作" name_chs="端口扫描器Superscan PING操作" name_eng="Port Scanner Superscan PING Operation" visible="true"/><rule ruleid="50181" enabled="true" group="68223061" action=" db  screen " name="HTTP协议CONNECT遂道功能连接访问" name_chs="HTTP协议CONNECT遂道功能连接访问" name_eng="HTTP Protocol CONNECT Tunnel Feature Connection Access" visible="true"/><rule ruleid="50180" enabled="true" group="68223066" action=" db  screen " name="网络代理软件http-tunnel数据通信" name_chs="网络代理软件http-tunnel数据通信" name_eng="Network Agent Software http-tunnel Data Communication" visible="true"/><rule ruleid="40438" enabled="true" group="99615819" action=" db  screen  drop " name="Windows系统Nimda蠕虫利用Unicode漏洞传播" name_chs="Windows系统Nimda蠕虫利用Unicode漏洞传播" name_eng="Worm Nimda Propagation on Windows via Unicode Vulnerability" visible="true"/><rule ruleid="50187" enabled="true" group="99680341" action=" db  screen " name="股票行情分析操作软件天一证券用户登录" name_chs="股票行情分析操作软件天一证券用户登录" name_eng="Stock Market Analtsis Software Tianyi Securities User Login" visible="true"/><rule ruleid="50186" enabled="true" group="68288601" action=" db  screen " name="P2P文件共享工具迅雷通过HTTP协议多线程文件下载" name_chs="P2P文件共享工具迅雷通过HTTP协议多线程文件下载" name_eng="P2P File Sharing Tool Xunlei Multi-thread File Downloading Through HTTP Protocol" visible="true"/><rule ruleid="50189" enabled="true" group="68288601" action=" db  screen " name="P2P文件共享工具迅雷通过HTTP协议单线程文件下载" name_chs="P2P文件共享工具迅雷通过HTTP协议单线程文件下载" name_eng="P2P File Sharing Tool Xunlei Single Thread File Downloading Through HTTP Protocol" visible="true"/><rule ruleid="40435" enabled="false" group="99618895" action=" db  screen " name="Remote Administrator远程控制软件建立连接" name_chs="Remote Administrator远程控制软件建立连接" name_eng="Remote Control Software Remote Administrator Connection" visible="true" merge="[t7200,si,di]"/><rule ruleid="40436" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下BackOrifice 2000木马客户端连接服务端" name_chs="Windows系统下BackOrifice 2000木马客户端连接服务端" name_eng="Trojan BackOrifice 2000 Client Connection to Server on Windows" visible="true"/><rule ruleid="40437" enabled="true" group="72352843" action=" db  screen " name="Windows系统下Happy99邮件蠕虫活动" name_chs="Windows系统下Happy99邮件蠕虫活动" name_eng="Happy99 Mail Virus on Windows" visible="true"/><rule ruleid="40430" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下BackOrifice 1.2木马PING操作" name_chs="Windows系统下BackOrifice 1.2木马PING操作" name_eng="Trojan BackOrifice 1.2 PING Operation on Windows" visible="true"/><rule ruleid="40432" enabled="true" group="202440797" action=" db  screen " name="HTTP服务基本登录认证" name_chs="HTTP服务基本登录认证" name_eng="HTTP Service Basic Login Authentication" visible="true" merge="[t7200,di]"/><rule ruleid="50053" enabled="false" group="138477662" action=" db  screen " name="TELNET服务用户弱口令认证" name_chs="TELNET服务用户弱口令认证" name_eng="User Weak Password Authentication in TELNET Service" visible="true"/><rule ruleid="50052" enabled="true" group="205586526" action=" db  screen " name="TELNET服务root用户认证" name_chs="TELNET服务root用户认证" name_eng="TELNET Service root User Authentication" visible="true"/><rule ruleid="50051" enabled="true" group="205586525" action=" db  screen " name="TELNET服务root用户认证" name_chs="TELNET服务root用户认证" name_eng="TELNET Service root User Authentication" visible="true"/><rule ruleid="50050" enabled="true" group="205586526" action=" db  screen " name="TELNET服务用户认证" name_chs="TELNET服务用户认证" name_eng="TELNET Service User Authentication" visible="true"/><rule ruleid="50057" enabled="true" group="95486045" action=" db  screen " name="Windows XP SMB建立连接" name_chs="Windows XP SMB建立连接" name_eng="Windows XP SMB Connection Establishment" visible="true" merge="[t28800,si,di]"/><rule ruleid="50055" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问系统注册表" name_chs="Windows SMB访问系统注册表" name_eng="Windows SMB Accessing System Registry" visible="true" merge="[t86400,si]"/><rule ruleid="50054" enabled="true" group="138477662" action=" db  screen " name="TELNET服务用户执行su命令" name_chs="TELNET服务用户执行su命令" name_eng="su Command Execution in TELNET Service" visible="true"/><rule ruleid="50059" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Worm.SoBig蠕虫病毒邮件" name_chs="SMTP服务发送Worm.SoBig蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Worm.SoBig" visible="true"/><rule ruleid="50058" enabled="true" group="233898073" action=" db  screen " name="Oracle数据库访问操作" name_chs="Oracle数据库访问操作" name_eng="Oracle Database Access" visible="true"/><rule ruleid="30488" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS bdir.htr脚本漏洞浏览目录" name_chs="利用Microsoft IIS bdir.htr脚本漏洞浏览目录" name_eng="Directory Browsing via Microsoft IIS bdir.htr Script Vulnerability" visible="true"/><rule ruleid="40261" enabled="true" group="69214270" action=" db  screen " name="Microsoft JET adctest.asp脚本漏洞扫描探测" name_chs="Microsoft JET adctest.asp脚本漏洞扫描探测" name_eng="Microsoft JET adctest.asp Script Vulnerability Detection" visible="true"/><rule ruleid="20869" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Cookie字段超长缓冲区溢出攻击" name_chs="HTTP协议Cookie字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Cookie Field Buffer Overflow" visible="true"/><rule ruleid="20868" enabled="true" group="76546346" action=" db  screen " name="Novell Netmail IMAP服务AUTHENTICATE GSSAPI远程缓冲区溢出攻击" name_chs="Novell Netmail IMAP服务AUTHENTICATE GSSAPI远程缓冲区溢出攻击" name_eng="Novell Netmail IMAP Service AUTHENTICATE GSSAPI Remote Buffer Overflow" visible="true"/><rule ruleid="20719" enabled="true" group="203423915" action=" db  screen " name="Docebo全局变量远程文件包含攻击" name_chs="Docebo全局变量远程文件包含攻击" name_eng="Docebo global Variable Remote File Inclusion" visible="true"/><rule ruleid="20718" enabled="true" group="203423914" action=" db  screen " name="phpCommunityCalendar多个脚本远程SQL注入攻击" name_chs="phpCommunityCalendar多个脚本远程SQL注入攻击" name_eng="phpCommunityCalendar multiple Scripts Remote SQL Injection" visible="true"/><rule ruleid="20717" enabled="true" group="203423915" action=" db  screen " name="Ovidentia多个脚本远程文件包含攻击" name_chs="Ovidentia多个脚本远程文件包含攻击" name_eng="Ovidentia multiple Scripts Remote File Inclusion" visible="true"/><rule ruleid="20716" enabled="true" group="136315179" action=" db  screen " name="iShopCart远程缓冲区溢出攻击" name_chs="iShopCart远程缓冲区溢出攻击" name_eng="iShopCart Remote Buffer Overflow" visible="true"/><rule ruleid="20715" enabled="true" group="203423914" action=" db  screen " name="SaPHPLesson add.php远程SQL注入攻击" name_chs="SaPHPLesson add.php远程SQL注入攻击" name_eng="SaPHPLesson add.php Remote SQL Injection" visible="true"/><rule ruleid="20714" enabled="true" group="203423914" action=" db  screen " name="SelectaPix远程SQL注入攻击" name_chs="SelectaPix远程SQL注入攻击" name_eng="SelectaPix Remote SQL Injection" visible="true"/><rule ruleid="20713" enabled="true" group="203423915" action=" db  screen " name="DeluxeBB多个脚本远程文件包含攻击" name_chs="DeluxeBB多个脚本远程文件包含攻击" name_eng="DeluxeBB multiple Scripts Remote File Inclusion" visible="true"/><rule ruleid="20712" enabled="true" group="203423915" action=" db  screen " name="Bee-hive远程文件包含攻击" name_chs="Bee-hive远程文件包含攻击" name_eng="Bee-hive Remote File Inclusion" visible="true"/><rule ruleid="20711" enabled="true" group="203423915" action=" db  screen " name="MF Piadas admin.php远程文件包含攻击" name_chs="MF Piadas admin.php远程文件包含攻击" name_eng="MF Piadas admin.php Remote File Inclusion" visible="true"/><rule ruleid="20710" enabled="true" group="203423915" action=" db  screen " name="Galleria远程文件包含攻击" name_chs="Galleria远程文件包含攻击" name_eng="Galleria Remote File Inclusion" visible="true"/><rule ruleid="10163" enabled="true" group="68159515" action=" db  screen " name="HTTP协议头超长HOST字段缓冲区溢出攻击" name_chs="HTTP协议头超长HOST字段缓冲区溢出攻击" name_eng="HTTP Protocol Header Over-long HOST Field Buffer Overflow" visible="true"/><rule ruleid="30029" enabled="true" group="233898069" action=" db  screen " name="ICMP子网掩码请求消息" name_chs="ICMP子网掩码请求消息" name_eng="ICMP Netmask Request Message" visible="true"/><rule ruleid="40061" enabled="true" group="166756425" action=" db  screen " name="由内网向外网发起X Window应用连接" name_chs="由内网向外网发起X Window应用连接" name_eng="X Windows Application Connection Initiated from Intranet to External Network" visible="true"/><rule ruleid="10178" enabled="true" group="166725658" action=" db  screen " name="Asterisk SIP响应远程拒绝服务攻击" name_chs="Asterisk SIP响应远程拒绝服务攻击" name_eng="Asterisk SIP Response Remote Denial of Service" visible="true"/><rule ruleid="10179" enabled="true" group="166725658" action=" db  screen " name="Linksys SPA941 \377字符拒绝服务攻击" name_chs="Linksys SPA941 \377字符拒绝服务攻击" name_eng="Linksys SPA941 \377 Character Denial of Service" visible="true"/><rule ruleid="10170" enabled="true" group="69208090" action=" db  screen " name="Sambar Web服务器例子程序远程拒绝服务攻击" name_chs="Sambar Web服务器例子程序远程拒绝服务攻击" name_eng="Sambar Web Server Sample Program Remote Denial of Service" visible="true"/><rule ruleid="10171" enabled="true" group="83888154" action=" db  screen " name="CA BrightStor ARCserve Backup catirpc.exe远程拒绝服务攻击" name_chs="CA BrightStor ARCserve Backup catirpc.exe远程拒绝服务攻击" name_eng="CA BrightStor ARCserve Backup catirpc.exe Remote Denial of Service" visible="true"/><rule ruleid="10172" enabled="true" group="99616794" action=" db  screen " name="CA BrightStor ARCServe BackUp LGServer畸形数据长度拒绝服务攻击" name_chs="CA BrightStor ARCServe BackUp LGServer畸形数据长度拒绝服务攻击" name_eng="CA BrightStor ARCServe BackUp LGServer Malformed Data Length Denial of Service" visible="true"/><rule ruleid="10173" enabled="true" group="99616794" action=" db  screen " name="Microsoft Systems Management Server远程拒绝服务攻击" name_chs="Microsoft Systems Management Server远程拒绝服务攻击" name_eng="Microsoft Systems Management Server Remote Denial of Service" visible="true"/><rule ruleid="10174" enabled="true" group="300943386" action=" db  screen " name="Cisco 7940/7960 Phone SIP INVITE消息远程拒绝服务攻击" name_chs="Cisco 7940/7960 Phone SIP INVITE消息远程拒绝服务攻击" name_eng="Cisco 7940/7960 Phone SIP INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="10175" enabled="true" group="166725658" action=" db  screen " name="Asterisk畸形SIP消息远程拒绝服务攻击" name_chs="Asterisk畸形SIP消息远程拒绝服务攻击" name_eng="Asterisk Malformed SIP Message Remote Denial of Service" visible="true"/><rule ruleid="10176" enabled="true" group="166725658" action=" db  screen " name="Asterisk SIP畸形INVITE消息远程拒绝服务攻击" name_chs="Asterisk SIP畸形INVITE消息远程拒绝服务攻击" name_eng="Asterisk SIP Malformed INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="10177" enabled="true" group="300943386" action=" db  screen " name="Grandstream BudgeTone-200畸形INVITE消息远程拒绝服务攻击" name_chs="Grandstream BudgeTone-200畸形INVITE消息远程拒绝服务攻击" name_eng="Grandstream BudgeTone-200 Malformed INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="20669" enabled="true" group="203423915" action=" db  screen " name="phpSecurePages cfgProgDir变量远程文件包含攻击" name_chs="phpSecurePages cfgProgDir变量远程文件包含攻击" name_eng="phpSecurePages cfgProgDir Variable Remote File Inclusion" visible="true"/><rule ruleid="20668" enabled="true" group="203423915" action=" db  screen " name="Site@School远程文件包含攻击" name_chs="Site@School远程文件包含攻击" name_eng="Site@School Remote File Inclusion" visible="true"/><rule ruleid="20663" enabled="true" group="203423915" action=" db  screen " name="phpBB db.php phpbb_root_path远程文件包含攻击" name_chs="phpBB db.php phpbb_root_path远程文件包含攻击" name_eng="phpBB db.php phpbb_root_path Remote File Inclusion" visible="true"/><rule ruleid="20662" enabled="true" group="203423915" action=" db  screen " name="AWStats awstats.pl多个参数远程执行命令攻击" name_chs="AWStats awstats.pl多个参数远程执行命令攻击" name_eng="AWStats awstats.pl multiple Parameters Remote Code Execution" visible="true"/><rule ruleid="20661" enabled="true" group="203423915" action=" db  screen " name="Vivvo Article Manager远程文件包含攻击" name_chs="Vivvo Article Manager远程文件包含攻击" name_eng="Vivvo Article Manager Remote File Inclusion" visible="true"/><rule ruleid="20660" enabled="true" group="203423915" action=" db  screen " name="Open Bulletin Board远程文件包含攻击" name_chs="Open Bulletin Board远程文件包含攻击" name_eng="Open Bulletin Board Remote File Inclusion" visible="true"/><rule ruleid="20667" enabled="true" group="203423915" action=" db  screen " name="AllMyGuests远程文件包含攻击" name_chs="AllMyGuests远程文件包含攻击" name_eng="AllMyGuests Remote File Inclusion" visible="true"/><rule ruleid="20666" enabled="true" group="203423915" action=" db  screen " name="Claroline claro_init_local.inc.php远程文件包含攻击" name_chs="Claroline claro_init_local.inc.php远程文件包含攻击" name_eng="Claroline claro_init_local.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20665" enabled="true" group="203423915" action=" db  screen " name="PhotoPost PP_PATH远程文件包含攻击" name_chs="PhotoPost PP_PATH远程文件包含攻击" name_eng="PhotoPost PP_PATH Remote File Inclusion" visible="true"/><rule ruleid="20664" enabled="true" group="203423915" action=" db  screen " name="Tagger LE PHP代码注入执行攻击" name_chs="Tagger LE PHP代码注入执行攻击" name_eng="Tagger LE PHP Code Injection" visible="true"/><rule ruleid="20556" enabled="true" group="136315047" action=" db  screen  drop " name="HP OpenView网络节点管理器远程命令执行攻击" name_chs="HP OpenView网络节点管理器远程命令执行攻击" name_eng="HP OpenView Network Node Manager Remote Command Execution" visible="true"/><rule ruleid="20551" enabled="true" group="203423915" action=" db  screen " name="Mambo globals.php远程文件包含攻击" name_chs="Mambo globals.php远程文件包含攻击" name_eng="Mambo globals.php Remote File Inclusion" visible="true"/><rule ruleid="70100" enabled="true" group="95420975" action="" name="Windows SMB Openuser操作" name_chs="Windows SMB Openuser操作" name_eng="Windows SMB Openuser Operation " visible="false"/><rule ruleid="20550" enabled="true" group="203423919" action=" db  screen " name="PHP-Nuke query功能SQL注入攻击" name_chs="PHP-Nuke query功能SQL注入攻击" name_eng="PHP-Nuke query function SQL Injection" visible="true"/><rule ruleid="20447" enabled="true" group="203423915" action=" db  screen " na